Privacy policy

How TindaTrack handles data

This policy explains how the TindaTrack mobile point-of-sale application, offered under the ScriptHex brand, handles information across offline use, optional cloud features, subscriptions, advertising, support, and account deletion.

Effective and last updated: August 20, 2026 · Privacy contact: support@scripthex.com

1. Scope and operator contact

This policy applies to TindaTrack for Android and other supported platforms, including Retail, Café, and Restaurant workspaces. It covers offline-first local use and features that connect to cloud, identity, billing, advertising, diagnostics, or support services.

TindaTrack is offered under the ScriptHex brand. Privacy, account-control, and data-rights requests may be sent to support@scripthex.com. This policy does not claim that TindaTrack is compliant with every privacy law in every country; rights and obligations vary by jurisdiction.

2. Data we handle

CategoryExamplesPrimary purpose
Owner account and identityOwner name, email, sign-in provider, verification status, account identifiers, session and recovery stateAuthentication, account recovery, security, workspace ownership, support, and deletion verification
Managed Cashier identity and accessDisplay name, Store Code, username, role, credential state, access status, internal authentication identifier, password-change or reset stateStore-scoped sign-in, authorization, audit attribution, credential lifecycle, access removal, and security
Store and POS recordsStore profile, staff records, products, categories, prices, barcodes, inventory, sales, refunds, voids, shifts, discounts, payment-method labels, receipts, reports, and other merchant-entered business recordsOperate the POS and preserve business records
Café and restaurant recordsMenu items, variants, add-ons, ingredients, packaging, recipes, units, costing, wastage, held orders, open checks, tables where enabled, kitchen tickets, and order notesOrder workflows, inventory and costing, kitchen operations, availability, and reporting
Files and mediaProduct images, store logo, merchant QR images, encrypted backup files, exports, and files deliberately selected for import or sharingCatalog display, receipt branding, merchant payment references, backup/restore, and export
Device, offline authority, sync, and security dataApp version, platform, registered-device identifiers, device ownership/membership state, protected selling-device and Offline Primary authority or lease state, sync queues/status, operation timestamps, security and audit eventsOffline/online coordination, multi-device synchronization, troubleshooting, fraud prevention, and account protection
Subscription, entitlement, advertising, and consent dataPlan, product identifier, purchase or restore status, trial dates, Paid/Complimentary Pro entitlement state, consent status, and advertising SDK dataEnable plan features, enforce Owner/store entitlements, restore purchases, and determine ad eligibility
Support and diagnosticsContact email, support message, user-selected attachments, optional sanitized diagnostics, crash/performance information, and operation errorsRespond to support requests, diagnose failures, improve reliability, and investigate security issues
Tutorial stateLocal tutorial progress or completion state where the guided tutorial is usedResume and complete guided onboarding on the device

TindaTrack does not require you to enter full payment-card numbers or online-banking credentials. Payment-method labels in sales records describe how a transaction was paid; payment processing occurs outside TindaTrack unless a future feature expressly states otherwise.

Google Play Data Safety categories

Depending on the features used, TindaTrack's current Google Play disclosures may include name, email address, user IDs, purchase history, approximate location inferred from an IP address, photos, files and documents, app interactions, other user-generated content, other user actions, crash logs, diagnostics, and device or other identifiers. Some categories are provided directly by the user or merchant; others are processed automatically by authentication, billing, advertising, crash-reporting, security, or cloud-service providers. The provider and purpose details below explain when this occurs.

3. How data is used

  • Provide offline POS, catalog, inventory, recipe, held-order/open-check, optional table, kitchen, receipt, report, backup, and synchronization features.
  • Authenticate Store Owners and Managed Cashiers, apply store-scoped permissions, and preserve security/audit attribution.
  • Calculate merchant-configured prices, discounts, inventory availability, recipe cost, estimated profit, and sales analytics.
  • Administer the TindaTrack account trial and Owner/store subscription or Complimentary Pro entitlement.
  • Determine whether advertising is eligible and request or update privacy/consent information where required.
  • Provide support, crash/error diagnostics, security monitoring, fraud prevention, dispute handling, and account-deletion processing.
  • Meet applicable legal, accounting, security, and retention obligations.

We do not sell or rent TindaTrack account or business data to advertisers. Third-party advertising and analytics SDKs may nevertheless collect or share data with their provider as described below when those SDKs are active.

4. Local and cloud processing

Offline-first SQLite storage

Core operational data is stored in an offline SQLite database on the device so TindaTrack can continue to perform supported functions without a continuous internet connection. Local records, images, exports, or cached data may remain until the workspace is removed, app data is cleared, exported files are deleted, or the app is uninstalled.

Cloud-connected features

When cloud features are enabled or required for a selected function, relevant store, profile, catalog, inventory, transaction, device, authority, entitlement, security, and audit records may synchronize through Supabase. User-selected product images, store logos, merchant QR images, and encrypted backups may also be uploaded to configured cloud storage. Support requests may transmit the sender's contact information, message, and optional sanitized diagnostics after the user chooses to send them.

Owner trial and store entitlement

An eligible verified Owner account may receive one 15-day TindaTrack account trial administered through TindaTrack's backend. This trial is separate from Google Play subscription billing, does not charge the Owner, and does not automatically create a paid subscription. Managed Cashiers inherit the Owner/store entitlement and do not receive a separate trial or subscription. While active, Complimentary Pro receives the same functional Pro access without being recorded as a Google Play purchase.

Managed Cashier credentials and Free device access

A normal Managed Cashier signs in with a Store Code, username, and password. The Owner may create or reset a temporary password; the Cashier may be required to change it on first sign-in. A current password change is treated as the Cashier's server-authoritative credential for supported devices. TindaTrack may use an internal system-managed authentication identifier for authentication/session management, authorization, and audit attribution. It is not a personal mailbox and is not presented as the Cashier's contact email.

Older email-based Cashier records may remain only for compatibility with legacy accounts. Normal new Managed Cashier onboarding does not require a separate personal Cashier email address. A Free store permits one Owner and one Managed Cashier identity on the same protected selling device, with one account session active at a time. A second Free Cashier and unauthorized cross-device Free Cashier access are blocked. Trial, Paid Pro, and Complimentary Pro may allow authorized managed or cross-device Cashier access under the current store and device rules.

Offline Access and Owner Approval

Offline Access is device-scoped and may use the account password or an optional six-digit Offline Access PIN or biometric unlock. PIN and biometric material is protected using the device's secure-storage facilities where supported. Online permission verification expires according to the selected policy: Owners default to 30 days and may select up to 90 days; staff default to 7 days and may select up to 30 days.

The separate six-digit Owner Approval PIN is store-scoped. Setting or replacing it requires supported Owner verification. A verifier is stored by the backend and may be securely cached on an authorized device for supported offline approval. A successful approval opens protected Cashier actions for five minutes on that device; it does not replace device authorization or a valid Offline Primary lease.

Offline device copies: deleting a cloud account or authentication identity cannot remotely erase a phone or tablet that is offline or no longer under your control. Local copies must be removed on each device you control.

5. Advertising and privacy consent

Advertisements are eligible only when TindaTrack has verified the store as eligible for the Free plan. Stores with an active TindaTrack account trial, Paid Pro subscription, or Complimentary Pro entitlement are not intended to receive ads. Managed Cashiers inherit the Owner/store advertising status. If entitlement cannot be verified, TindaTrack is designed to fail closed rather than assume that ads are allowed.

Google's consent tools may request or update privacy information where applicable and may expose a Privacy Choices control when required. Consent requirements and ad availability can vary by country or region.

When Google Mobile Ads is active, the SDK may automatically process information such as IP address (which can be used to estimate approximate location), product interactions, diagnostic information, and device/account identifiers for advertising, analytics, and fraud-prevention purposes, subject to configuration and applicable consent requirements.

6. Service providers

TindaTrack may use these service providers when the associated feature applies:

  • Supabase — authentication, synchronized data, server functions, storage, encrypted backups, and operational/security records.
  • Google Identity services — optional Store Owner Google sign-in where offered.
  • Google Play — app distribution, license/testing services, billing, subscriptions, and purchase management.
  • RevenueCat — purchase/entitlement processing and subscription-state management.
  • Google Mobile Ads and User Messaging Platform (UMP) — eligible advertising, consent/privacy messaging, and related device/diagnostic processing.
  • Sentry — production crash, error, and performance diagnostics where enabled.
  • Email delivery providers, such as Resend when configured — Owner verification, deletion/recovery, and service notices.

These providers may process information under their own terms and privacy notices. TindaTrack shares or transmits only information reasonably connected to the feature being used, subject to applicable configuration and law.

7. Device permissions

  • Camera: barcode scanning and, when requested, capturing or selecting supported product/store media.
  • Photos/files: importing or selecting images, backups, exports, or merchant QR media when requested.
  • Bluetooth/nearby devices: discovering and printing to supported receipt or kitchen printers.
  • Network access: authentication, synchronization, backup, subscriptions, entitlement verification, ads/consent, diagnostics, and support.

TindaTrack does not request microphone recording for normal POS functionality.

8. Security

TindaTrack uses measures such as authenticated access, store-scoped authorization, database access policies, authenticated server functions, encrypted transport, encrypted cloud backups, limited administrator access, credential/session controls, and operational audit trails. No storage or transmission method is completely risk-free. Users are responsible for securing devices, accounts, passwords, printer connections, exports, and any third-party services they use with their business.

9. Retention and deletion

Active cloud data is generally retained while an Owner account, connected store, or Managed Cashier access remains active and as needed to provide the service, preserve business records, protect security, or satisfy legal obligations.

Store Owner deletion

  1. The Store Owner requests deletion in the app or through the public account-deletion resource.
  2. Identity is verified using the supported account-control flow.
  3. The request enters a 30-day recovery period, during which the account may remain recoverable.
  4. After the recovery deadline, the request becomes eligible for verified permanent processing. Reaching the deadline alone is not represented as proof that deletion has completed; a request can remain pending, processing, or failed until the server-side process is safely completed or support resolves it.

When permanent deletion is successfully completed and verified, its intended scope includes the Owner authentication identity, covered synchronized database records, active account-backup files, and the account backup key. Separately stored product images, store logos, or merchant QR objects require separate verification/cleanup and are not represented by this policy as automatically verified deleted by the same account-purge transaction. The deletion resource explains how to request follow-up for associated media.

Google Play, RevenueCat, and other external providers may separately retain purchase, billing, fraud-prevention, or transaction records under their own terms and applicable law. Deleting TindaTrack does not itself modify those external records and does not automatically cancel Google Play billing.

Managed Cashier removal and deletion

Removing a Managed Cashier from the store revokes store access immediately. Normal access removal is not represented as a guaranteed automatic seven-day permanent identity-deletion process. Permanent deletion of the Cashier's authentication identity and direct profile identifiers requires a separately verified deletion/cleanup request and may be delayed or restricted where necessary to protect another account or store, preserve pending synchronization, investigate security or fraud, maintain financial/audit records, or satisfy legal obligations.

Completed transactions and operational history may retain a redacted, non-login Cashier reference or historical display label to preserve Store Owner accounting and audit integrity.

Limited retention

TindaTrack may retain limited deletion-request, security, fraud-prevention, financial/audit, dispute, or legally required records for as long as reasonably necessary for those purposes. Temporary residual copies may also remain in provider disaster-recovery backups until normal backup rotation; such copies are not used as an active in-app recovery method after permanent processing.

10. Your privacy choices and rights

Depending on the law that applies to you, you may have rights to request information about processing, access data, correct inaccurate data, object to or restrict certain processing, request deletion or blocking, receive portable data where available, withdraw consent for consent-based processing, and lodge a complaint with an appropriate privacy authority.

  • Use in-app settings for available privacy, account, backup, advertising/privacy-choice, and deletion controls.
  • Use the public deletion resource even if the app is no longer installed.
  • Email support@scripthex.com for access, correction, deletion, support, or other privacy-rights requests.

We may need to verify identity or store relationship before acting on a request. Some rights may be limited by applicable law or by legitimate retention requirements.

11. International processing

TindaTrack is intended for users in multiple countries. Cloud and service providers may process information in countries other than the user's country of operation. Where applicable law requires specific transfer safeguards or notices, those requirements may apply in addition to this policy.

12. Children and intended audience

TindaTrack is intended for adult business operators and is not directed to children. A Store Owner should be at least 18 years old or the age of legal majority applicable to the Owner. Store Owners are responsible for assigning staff access appropriately and for complying with employment, privacy, and age-related laws that apply to their workforce.

13. Changes to this policy

We may update this policy as features, service providers, operational practices, or legal requirements change. The effective date above will be updated, and material changes may also be communicated in the app, store listing, or release notes where appropriate.

14. Contact

Privacy, support, and account-control requests: support@scripthex.com

Service: TindaTrack · Brand/operator contact: ScriptHex