How TindaTrack handles data
This policy explains how the TindaTrack mobile point-of-sale application, operated by ScriptHex, accesses, uses, stores, and deletes information.
1. Scope
This policy applies to TindaTrack for Android and other supported platforms, including Retail, Café, and Restaurant workspaces. It covers local offline use and optional cloud-connected features.
2. Data we handle
| Category | Examples | Why it is needed |
|---|---|---|
| Account and identity | Name, email address, account role, verification status, authentication provider, account identifiers | Sign-in, account recovery, workspace access, security, and deletion verification |
| Store and POS data | Store profile, staff records, products, categories, prices, barcodes, sales, discounts, taxes, payment-method labels, receipts | Operate the POS and produce business records and reports |
| Café and restaurant data | Menu items, ingredients, packaging, recipes, units, costing, wastage, variants, add-ons, tables, open checks, kitchen tickets, order notes | Inventory deductions, kitchen workflows, availability, and reporting |
| Files and media | Product images, store logo, encrypted backup files | Catalog display, receipt branding, backup and restore |
| Device and diagnostics | App version, platform, registered-device identifiers, sync status, operation errors, timestamps | Cloud synchronization, troubleshooting, security, and release support |
| Subscription and advertising | Plan, entitlement status, product identifier, purchase status, ad-related SDK data | Enable Pro features, restore purchases, and support ads for eligible Free accounts |
TindaTrack does not require you to enter full card numbers or banking credentials. Payment-method labels in sales records identify how a transaction was paid; payment processing is handled outside TindaTrack unless a future feature clearly states otherwise.
3. How data is used
- Provide offline POS, inventory, recipe, table, kitchen, receipt, backup, sync, and report features.
- Authenticate users and enforce owner, administrator, and cashier permissions.
- Calculate inventory availability, recipe cost, estimated profit, and sales analytics from data entered by the store.
- Process trial and subscription status and show ads where applicable.
- Detect errors, protect accounts, support users, and maintain deletion audit records.
- Comply with applicable legal, security, fraud-prevention, and dispute obligations.
We do not sell TindaTrack account or business data to advertisers.
4. Local and cloud storage
Offline-first local data
Core POS data is stored in a local database on the device so the app can work offline. Local data may remain on a device until the workspace is removed, app data is cleared, or the app is uninstalled.
Optional cloud features
When Cloud Sync, Cloud Backup, account authentication, subscription, or support features are used, relevant data is transmitted to the corresponding service. Cloud backups are encrypted before upload and use an account-specific managed encryption key.
5. Service providers
TindaTrack may use the following processors to provide features:
- Supabase — authentication, synchronized data, encrypted cloud backups, server functions, and operational records.
- Google Play — app distribution, license testing, billing, subscriptions, and purchase management.
- RevenueCat — subscription entitlement and purchase-status management.
- Google Mobile Ads — advertisements for eligible Free accounts.
- Resend or another configured email provider — verification, deletion, recovery, and support notices.
- Expo services — app build and update infrastructure where used.
These providers process data under their own terms and privacy policies. We share only data reasonably needed for the relevant feature.
6. Device permissions
- Camera: barcode scanning and selecting or capturing product/store images when requested.
- Photos/files: importing images, backups, or exports when requested.
- Bluetooth nearby devices: discovering and printing to supported receipt or kitchen printers.
- Network access: authentication, sync, backup, subscription, ads, and support services.
TindaTrack does not request microphone recording for normal app functionality.
7. Security
We use access controls, row-level database policies, authenticated server functions, encrypted transport, encrypted cloud backups, limited administrator access, and operational audit trails. No method of storage or transmission is completely risk-free, so users should secure their devices, accounts, printer connections, and exported files.
8. Retention and account deletion
Active cloud data is generally retained while an account or connected store remains active and as needed to provide the service.
Verified deletion flow
- The owner requests deletion in the app or through the web deletion resource.
- Identity is verified. In-app requests require recent email verification and an exact confirmation phrase.
- The request enters a 30-day recovery period. The account and cloud data remain recoverable during this window.
- If the request is not cancelled or restored, the cloud identity, synchronized store data, membership/device records, active cloud-backup files, and account encryption key are scheduled for permanent deletion.
After purge, TindaTrack redacts the deletion request and retains only limited non-content audit metadata, such as request identifiers, status, timestamps, and security/administrator actions, where reasonably necessary for security, fraud prevention, legal compliance, and proving that a deletion request was processed.
Temporary residual copies may remain in provider disaster-recovery backups until normal backup rotation. They are not used as active account data and are not an in-app recovery method after permanent purge.
9. Your choices
- Use TindaTrack locally without enabling optional cloud inventory/sync features, subject to account requirements of the selected flow.
- Change inventory mode, printer settings, backup behavior, ad/subscription choices, and other supported settings.
- Request access, correction, support, or account deletion by contacting us.
- Use the in-app deletion path or the external web deletion page even after uninstalling the app.
10. Children
TindaTrack is a business point-of-sale application and is not directed to children. Store owners are responsible for assigning staff access appropriately.
11. Changes to this policy
We may update this policy as features, service providers, or legal requirements change. The effective date above will be updated, and material changes may also be communicated in the app or release notes.
12. Contact
Privacy and account-control requests: support@scripthex.com
Service: TindaTrack · Developer/operator: ScriptHex