Popina
Home About Products Catalog Resources Blog Ordering Careers Contact

Policies

  • Terms of Use
  • Accessibility Policy
  • Privacy Policy
  • Do Not Sell My Info

Last updated: September 17, 2026

POPINA Privacy Policy

1. Who we are and what this policy covers

POPINA LLC, operating the Popina Restaurant Supply services ("Popina," "we," "us"), provides wholesale supplies to business customers. This policy covers our website at therealpopina.com, Popina Order Portal, the Popina iOS customer application, and related account, ordering, delivery, document and support activities. It also covers information received through our business telephone, email and website contact or employment inquiries.

The QuickBooks information features described below apply when authorized and enabled. Their description does not mean that a live QuickBooks connection exists or that every customer or account user has access.

2. Information we process

Business accounts and users. We process company names, customer numbers, account identifiers, usernames, authentication information, user roles and permissions, contact names, business email addresses and telephone numbers, delivery locations, and account activation information. If you upload a profile photograph, we process that photograph for your account.

Orders and service activity. We process selected products and options, quantities and ordering units, submitted orders and their references, requested delivery dates, delivery instructions, contact details, notes, status history, and issue, replacement or return requests and related communications. Saved carts, favorites, product preferences, language choices and account-related usage may be stored on your device or in the service, depending on the feature. Account reports use business ordering records.

Delivery evidence. Popina administrators may attach delivery photographs and confirmation information to the relevant order, including the recording administrator and timestamps. A photograph may show packages, labels, a delivery location or incidental personal information visible in the scene. These photographs are private order records, not public catalog images. Our delivery-photo processing creates a resized, re-encoded copy and removes embedded EXIF/GPS/device metadata from the final processed photo. This does not remove personal information visibly captured in the image, and does not change the original on the uploader's device. Temporary upload copies may exist during processing.

Private documents. We process administrator-uploaded historical invoice PDFs and their identifying metadata. When the QuickBooks feature is authorized and enabled, we may also obtain original invoice PDFs from QuickBooks. Documents can contain names, addresses, invoice lines, amounts and other information included by their issuer; viewing a PDF can reveal financial amounts even without permission to view the separate balance screen.

Technical information. Authentication, hosting and application operation involve information such as IP addresses, request and error information, browser or app version, timestamps, identifiers and security events. For enabled iOS push notifications, we process a device notification token, installation identifier, app version and language to deliver account-related notifications. Browser storage, cookies and app storage support login sessions, saved activity and preferences. We do not describe all technical records as anonymous or aggregated.

Please provide only information needed for the business task. Avoid including unrelated personal information, payment-card details or sensitive information in notes, photographs or uploaded documents.

3. QuickBooks information, when authorized and enabled

An authorized Popina administrator may connect Popina's own QuickBooks Online company. Customer users do not connect their own QuickBooks accounts through this feature. Administrators verify which QuickBooks customer records correspond to each Popina business and separately authorize customer access.

The integration reads the connected company's customer registry to support those mappings. Change detection may receive information about changes across the connected QuickBooks company, including customers not yet mapped. Detailed invoice, payment and credit history is retained for customers explicitly mapped by an administrator. Selecting a small number of businesses for detailed synchronization does not mean that only those registry entries are read.

We process source identifiers, invoice references and dates, due dates where available, invoice amounts, remaining amounts, payment and credit evidence, account reports, verification timestamps and order-to-invoice associations. Stored source records may also include contact information, item descriptions or notes contained in the QuickBooks response. We may retain original invoice PDFs and prior versions. These records support document delivery, reconciliation, access controls, error recovery and the history of administrator actions.

QuickBooks remains Popina's accounting source. The integration does not create, modify, delete or send QuickBooks invoices, record payments or collect payments. Its application operations are restricted to reading accounting information, although Intuit's accounting authorization scope is broader than a read-only scope. This customer feature does not use an AI service to match customers or interpret their accounting information.

4. Why we use information

We use information to administer business accounts; receive and review order requests; arrange fulfillment and delivery; provide delivery evidence; investigate product or delivery issues; manage authorized access to private documents; and respond to support and employment inquiries. We also use it to maintain saved preferences, show order reports, deliver operational notifications, prevent unauthorized access and duplicate processing, troubleshoot the service, and maintain relevant operational and administrator audit records.

When enabled and authorized, financial information is used to associate the correct business and orders with invoices, display original documents and verified account information, and identify incomplete or outdated synchronization. We also use relevant records to address disputes and legal or accounting obligations. Displaying invoice or account information is not payment processing.

5. Who can access information

Within Popina. Users with Popina administrator privileges can manage business accounts, orders, documents, financial mappings and access settings as available in their administrative tools. Administrative access is not restricted to one named owner.

Within the customer's business. Customer access is tied to the user's assigned business and applicable permissions. The portal is not a personal vault: business order records can be accessible to other authorized users of that business. New QuickBooks PDF access and financial-screen access are separately controlled by Popina administrators. Being the main contact or having an ordinary account does not automatically grant those permissions. Existing historical-document access remains governed by the applicable archive permissions.

Service providers. The portal uses Netlify for application hosting and functions and Supabase for database, authentication, private file storage and supporting functions. When enabled, the integration communicates with Intuit. Transactional email can use Postmark; optional configured SMS/WhatsApp notifications can use Twilio; enabled iOS notifications use Apple's push service. Providers receive the information needed for the functions they perform. Other business services, such as delivery providers or professional advisers, may receive relevant information for their work. An optional notification channel is not necessarily enabled for every account.

We may disclose information where required by law or to address a legal claim or protect rights and security. Relevant information may also be involved in a business transfer, subject to applicable requirements. Our stated practice is not to sell personal information or share it for cross-context behavioral advertising. We do not make private invoice or delivery records public merely because they are stored in the service.

6. Your device, communications and document copies

Cookies and local storage support authentication and functions such as carts, language and appearance preferences. The iOS application also retains local session information and cached content needed for its operation. Clearing a browser or app's local data, signing out, or uninstalling an app is different from deleting server-side business records.

You can control notification permissions in your device settings. Disabling push notifications does not cancel an order, close an account or erase records. Use the relevant system photo or camera controls when selecting images; the feature operates on the images you choose to provide.

Private document delivery requires authorization. Some documents are delivered using short-lived links; a link already issued may remain usable until it expires. Permission changes cannot recall a file someone has already downloaded, printed, photographed or shared. Please protect copies you obtain through the service and the devices on which you view them.

7. Retention, disconnection and deletion

Stored records can include account and order history, delivery evidence, documents, financial source records and snapshots, associations, administrator audit records and technical records. Retention depends on the record category, operational purpose, applicable obligations and any legitimate need to preserve evidence. The service does not implement a single automatic deletion deadline for all these records. This policy does not promise that every category is automatically erased after a fixed number of days. We review whether retained records remain necessary every three months. This is a review interval, not a retention period or an automatic deletion date. A request or obligation requiring earlier action is handled sooner and is not deferred until that review.

Where records need to be retained, we document the relevant reason and scope, such as an applicable accounting or legal recordkeeping obligation, an unresolved order or dispute, or a specific security or evidence-preservation need. These reasons are assessed for the records concerned rather than used as a blanket basis to keep all information indefinitely. The continued need is reconsidered during review and when the relevant circumstances change.

Disconnecting QuickBooks in Popina removes locally stored connection credentials and stops use of that connection for new synchronization. It does not automatically delete previously obtained financial records, PDFs, order associations or audit history, and it does not itself revoke the authorization within Intuit. The QuickBooks account owner can separately manage the app authorization in Intuit.

A confirmed source invoice deletion can leave a retained reference and order association in Popina so that the history is not lost. The deleted invoice is not presented as a current collectible invoice, and a stored old PDF is not automatically offered as its current version. Removing a manual archive document is a separate controlled action; enabling QuickBooks does not itself erase the manual archive.

Account deactivation, access revocation and data deletion are different operations. Removing a user's access does not necessarily remove the business's order or accounting records. Retained backup copies, where present, and documents downloaded by recipients are not necessarily removed by a live-record deletion. We do not promise immediate erasure from every backup or recipient device.

8. Privacy requests

Contact alparslan@therealpopina.com with the subject "Privacy Request" to request access, correction or deletion, or to raise a privacy concern. Identify the account or business involved and the nature of your request, but do not email passwords, access tokens or unnecessary financial documents. Before disclosing or changing a business record, we verify the relevant identity and authority through registered account or business contact channels, with proportionate additional verification where needed. Sending an email alone does not establish authority to receive or delete business information. Requests are reviewed for their actual scope and applicable obligations; you will be informed of the action taken and, where information must remain, the relevant reason and limitations. Receipt of a request does not mean that deletion has been approved or completed.

Depending on applicable law, you may have rights to access, correct, delete, obtain a copy of, or restrict certain uses of personal information, and to act through an authorized agent. We address requests subject to applicable requirements and exceptions. Records needed for accounting, disputes or other lawful obligations may need to be retained; a deletion request is not a promise that all business records will disappear. We do not retaliate for exercising applicable privacy rights. Our existing Do Not Sell or Share My Personal Information page provides an additional contact route.

9. Security and location

The portal uses authenticated access, company-based restrictions, server-side permission checks and private document storage. QuickBooks credentials are kept on the server and encrypted. These measures do not guarantee that all systems, communications or downloaded documents are risk-free, and this policy makes no claim of an independent security certification.

Popina operates in the United States, and the services described here involve processing in the United States. Access from another country may therefore involve transfer to a country with different privacy protections. External services also have their own applicable terms and privacy notices.

10. Children and policy changes

These are business services intended for adults, not services directed to children. If you believe a child has provided personal information, contact us so we can investigate and take appropriate action.

We may revise this policy to reflect changes in the services or practices. The published revision date will identify the applicable version; material changes will be identified on the policy page and any additional notice required by law will be provided. Describing a future, conditional feature does not activate it or grant access.

11. Contact

POPINA LLC — Popina Restaurant Supply
Email: alparslan@therealpopina.com
Company mailing address: 41 State St, Ste 112, Albany, NY 12207-2828, United States
Contact telephone: +1 (267) 394-5353
Existing website general business line: +1 (347) 990-0309

The mailing address is not a stated pickup or returns location. Please obtain delivery or return instructions from Popina before sending goods.

Popina

NYC-based wholesale supply for restaurants, supermarkets, delis, cafes and caterers.

Explore

  • Home
  • About
  • Products
  • Catalog
  • Resources
  • Blog
  • Ordering
  • Careers
  • Contact

Contact

  • +1 (347) 990-0309
  • alparslan@therealpopina.com
  • Brooklyn, NY · 5 boroughs

Hours

  • Mon – Fri8AM – 5PM
  • Saturday8AM – 3PM
  • SundayClosed

Policies

  • Terms of Use
  • Accessibility Policy
  • Privacy Policy
  • Do Not Sell My Info

© 2026 Popina Restaurant Supply. All rights reserved.