1. Who we are
TindaTrack is an offline-first point-of-sale application operated by ScriptHex. This policy explains how TindaTrack handles information when you use the mobile app, cloud sync, cloud backup, and support.
2. Information we handle
- Account information: name, email address, username, authentication provider, store name, and business type.
- Business records: products, categories, prices, inventory, recipes, menu options, sales, payment labels, customers, store settings, and receipt preferences that you enter.
- Images: product images, store branding, logos, and merchant payment QR images you choose to add.
- Device and sync information: device identifier, device name, platform, app version, sync timestamps, and store membership needed for multi-device use.
- Support information: messages and diagnostics you voluntarily send to us.
3. Offline and cloud storage
Core POS records are stored locally on your device so TindaTrack can continue working without an internet connection. If you enable cloud features, selected store data is transmitted to our cloud service for synchronization and recovery. Cloud backup files are encrypted before upload. Information remaining only on your device is controlled by you and can be removed by deleting the relevant store workspace, clearing app data, or uninstalling the app.
4. Why we use information
We use information to:
- create and secure your account;
- operate the POS, reporting, receipt, and inventory features;
- sync authorized devices and restore encrypted backups;
- provide subscriptions, customer support, and security notices;
- detect abuse, diagnose failures, and improve reliability; and
- comply with applicable legal obligations.
5. Permissions
TindaTrack may request camera access for barcode scanning and product photos, photo access for images you select, Bluetooth and nearby-device access for receipt printers, and location permission on Android versions that require it for Bluetooth discovery. We use these permissions only for the feature you choose.
6. Service providers
TindaTrack uses Supabase for authentication, database, cloud storage, and related backend functions; Google for Google Sign-In and Google Play services; and Expo services for app delivery and updates. These providers process information under their own terms and privacy commitments. We do not sell personal information.
7. Data sharing
We share data only with service providers needed to operate the app, when you direct us to, to protect users and the service, or when required by law. Store owners control which staff accounts and linked devices may access their store data.
8. Security and retention
We use access controls, authenticated sessions, tenant separation, encrypted transport, and encrypted cloud backups. No system can guarantee absolute security. We retain cloud information while your account is active and as needed to provide the service. When you complete a verified deletion request, we delete or de-identify associated cloud data unless limited retention is required for security, fraud prevention, tax, accounting, or legal compliance.
9. Your choices and rights
You may use core POS features offline, decline optional permissions, disconnect cloud features, correct store information in the app, or request account deletion. See our account deletion page for the in-app and web request methods.
10. Children
TindaTrack is a business tool and is not directed to children under 13. We do not knowingly collect personal information from children.
11. Changes to this policy
We may update this policy as the app or legal requirements change. The effective date above will show the latest revision.
12. Contact
Questions or privacy requests may be sent to support@scripthex.com.