Order Manager logo
Order Manager
Enterprise Sales & Order Management

Privacy Policy

Effective date: 20 July 2026 Last updated: 20 July 2026 Applies to: Order Manager (iOS & Android)
Order Manager is an offline-first, enterprise-facing tool for authorized staff of client organizations to manage internal sales, invoices, and inventory. Your business data is stored locally on your device. We do not run advertising, do not sell personal data, and do not use third-party analytics or tracking SDKs.

1Who we are

“Order Manager” (“the App”, “we”, “us”, “our”) is developed and maintained by the App’s publisher. Contact details are provided at the end of this policy. For the purposes of the EU/UK GDPR and comparable laws, the App’s publisher acts as the data controller for the limited data described below; your employing organization (the “Client Organization”) acts as the controller of the business records you enter into the App.

2Scope of this policy

This policy covers the Order Manager mobile application distributed via the Apple App Store and Google Play, and any updates to it. It does not cover third-party services that your Client Organization may separately integrate with, or external websites you may open from the App.

3Data we collect

We follow a strict data minimization principle. The table below summarizes every category of data the App may handle, whether it leaves your device, and why.

Category Examples Stored Shared off-device Purpose
Business records Customers, products, orders, invoices, prices, quantities, notes On-device (SQLite) No App functionality
App preferences Language, theme, currency, tax settings On-device No App functionality
Access credentials Access Key / Security Token issued by your admin On-device secure storage (Keychain / EncryptedSharedPreferences) No Authentication
Technical Reference ID Randomly generated UUID On-device Only when contacting support Security & fraud prevention, support code
Device information OS name and version, device model, app version On-device Only in diagnostic reports you send Troubleshooting
Push notification token Firebase Cloud Messaging (FCM) token Provided by Google / Apple push services Yes (Firebase, if enabled) Administrator notices from your organization
Photo / camera content Facility logo selected by an administrator On-device only No UI customization
Advertising identifiers IDFA, AAID Not collected No Not applicable — we do not run ads

The App does not collect: contacts, precise or coarse location, health data, financial account numbers, biometric identifiers, browsing history, or content of your messages.

4How we use data

  • Operate the App — display, create, edit, and calculate your business records.
  • Authenticate access — validate the Access Key and Security Token issued by your System Administrator.
  • Security & fraud prevention — the on-device Technical Reference ID (a random UUID) is used only to anchor your session and, if you request support, to generate a short support code.
  • Send administrative notices — if push messaging is enabled by your organization, we deliver operational notices (for example, a session revocation notice) via Apple/Google push services.
  • Diagnose issues — when you explicitly export a diagnostic report, basic device and app information is included so support can help you.

We do not use your data to profile you, to serve advertising, or to train machine-learning models.

5Legal basis for processing (EEA / UK users)

  • Performance of a contract — to make the App work for you and your Client Organization.
  • Legitimate interests — securing the service, preventing unauthorized access, and diagnosing faults.
  • Consent — for optional permissions such as camera and photo library, which the operating system requests at the moment of use. You may withdraw consent at any time in your device settings.

6Permissions the App may request

PermissionWhyOptional?
Storage / Files Save PDF invoices, export backups, import spreadsheets you choose Yes — only when you use export/import
Camera Capture a facility logo for UI customization Yes
Photo library Choose an existing facility logo Yes
Notifications Deliver administrative notices from your organization Yes
Internet Validate access, deliver push notices, and download updates Required

You can revoke any optional permission at any time from your device’s system settings.

7Data storage and security

  • Business records are stored on your device in an SQLite database owned by the App.
  • Credentials (Access Key, Security Token) are stored in the platform’s secure storage — Apple Keychain on iOS and EncryptedSharedPreferences on Android.
  • Network traffic uses HTTPS/TLS.
  • Release builds are obfuscated and hardened.
  • You are responsible for physically securing your device and for keeping your Access Key confidential.

8Data sharing and third parties

We do not sell your data. Limited data may be handled by the following processors strictly for the purposes shown:

ProcessorDataPurpose
Apple Push Notification service Push token, notification payload Deliver notifications on iOS
Google Firebase Cloud Messaging FCM token, notification payload Deliver notifications on Android
Your Client Organization’s backend Access Key validation, Technical Reference ID (only during validation and support) Authenticate your session

We may disclose limited information if legally compelled by a valid court order or by law enforcement in the relevant jurisdiction.

9International transfers

Where push notification providers (Apple, Google/Firebase) process data outside your country, they do so under their own compliance frameworks (including EU Standard Contractual Clauses where applicable). Your business records themselves remain on your device and are not transferred by us.

10Data retention

  • Business records: retained on your device until you delete them or uninstall the App.
  • Credentials: retained until you sign out, your administrator revokes them, or you uninstall the App.
  • Push token: retained by Apple/Google while the App remains installed; invalidated on uninstall.

11Your rights

Depending on your jurisdiction (including GDPR, UK GDPR, and CCPA/CPRA), you may have the right to:

  • Access your data.
  • Correct inaccurate data.
  • Delete your data — for on-device data, use the delete controls inside the App or uninstall it; for records held by your Client Organization, contact them directly.
  • Object to or restrict certain processing.
  • Withdraw consent for optional permissions.
  • Lodge a complaint with a supervisory authority.

To exercise rights against the App publisher, use the contact details in section 15.

12Children’s privacy

The App is intended for use by authorized adult employees. It is not directed to children under 13 (or 16 in some jurisdictions). We do not knowingly collect personal data from children.

13Account and data deletion

To delete data associated with the App:

  1. Sign out from within the App to invalidate the local session.
  2. Uninstall the App from your device to remove all locally stored data, including cached credentials.
  3. Ask your System Administrator to revoke your Access Key on the server side.

A web-based deletion request form is also available on request from the address in section 15, as required by the Google Play Data Safety program.

14Changes to this policy

We may update this policy to reflect changes in the App or in the law. Material changes will be signaled by updating the “Effective date” above and, where appropriate, by an in-App notice on next launch.

15Contact

For privacy questions, data-subject requests, or Play Store data-deletion requests:

16Store-compliance summary

Apple App Store — App Privacy “nutrition label”

  • Data Not Collected: Contacts, Location, Health & Fitness, Financial Info, Sensitive Info, Browsing History, Search History, Advertising Data.
  • Data Not Linked to You: Diagnostics (only when you send a report), Product Interaction (crash-only).
  • Data Used to Track You: None.

Google Play — Data Safety

  • No data sold to third parties.
  • No data shared with third parties beyond Apple/Google push infrastructure and your Client Organization’s backend.
  • Data is encrypted in transit (TLS) and at rest for credentials (Keychain / EncryptedSharedPreferences).
  • Users can request data deletion (see section 13).

سياسة الخصوصية

تاريخ السريان: 20 يوليو 2026 آخر تحديث: 20 يوليو 2026 تسري على: تطبيق Order Manager (iOS و Android)
تطبيق Order Manager هو أداة مؤسسية تعمل دون اتصال أولاً يستخدمها الموظفون المفوَّضون في المؤسسة العميلة لإدارة المبيعات والفواتير والمخزون داخليًا. تُخزَّن بيانات عملك محلياً على جهازك. نحن لا نعرض أي إعلانات، ولا نبيع البيانات الشخصية، ولا نستخدم أدوات تحليل أو تتبع تابعة لأطراف ثالثة.

١من نحن

يُطوَّر تطبيق «Order Manager» («التطبيق»، «نحن») ويحافظ عليه ناشر التطبيق. ترد بيانات التواصل في نهاية هذه السياسة. لأغراض النظام الأوروبي/البريطاني لحماية البيانات (GDPR) والقوانين المماثلة، يعمل ناشر التطبيق بوصفه المتحكم بالبيانات فيما يخص البيانات المحدودة الموضحة أدناه، بينما تعمل جهة عملك (المؤسسة العميلة) بوصفها المتحكم بالسجلات التشغيلية التي تُدخلها في التطبيق.

٢نطاق هذه السياسة

تغطي هذه السياسة تطبيق Order Manager المتوفر عبر Apple App Store و Google Play وأي تحديثات له. ولا تغطي أي خدمات تكاملية قد تربطها المؤسسة العميلة بشكل مستقل، ولا المواقع الخارجية التي قد تفتحها من داخل التطبيق.

٣البيانات التي نجمعها

نلتزم بمبدأ تقليل البيانات. يوضح الجدول التالي كل فئة من البيانات التي قد يتعامل معها التطبيق، وما إذا كانت تغادر الجهاز، ولماذا.

الفئة أمثلة مكان التخزين هل تُشارَك خارج الجهاز؟ الغرض
سجلات العمل العملاء، المنتجات، الطلبات، الفواتير، الأسعار، الكميات، الملاحظات على الجهاز (قاعدة SQLite) لا تشغيل التطبيق
تفضيلات التطبيق اللغة، النمط، العملة، إعدادات الضريبة على الجهاز لا تشغيل التطبيق
بيانات الوصول مفتاح الوصول ورمز الأمان الصادران من مسؤول النظام تخزين آمن على الجهاز (Keychain / EncryptedSharedPreferences) لا المصادقة
معرّف تقني مرجعي UUID مولَّد عشوائيًا على الجهاز فقط عند طلب الدعم الفني الأمان ومنع الاحتيال وتوليد رمز دعم
معلومات الجهاز اسم النظام وإصداره، طراز الجهاز، إصدار التطبيق على الجهاز فقط في تقارير التشخيص التي ترسلها معالجة الأخطاء
رمز إشعارات الدفع Firebase Cloud Messaging (FCM) token لدى خدمات Apple/Google للإشعارات نعم (Firebase عند تفعيلها) إشعارات إدارية من مؤسستك
الصور / الكاميرا شعار المنشأة الذي يختاره المسؤول على الجهاز فقط لا تخصيص واجهة الاستخدام
معرّفات الإعلانات IDFA و AAID لا تُجمَع لا غير قابل للتطبيق — لا نعرض إعلانات

لا يجمع التطبيق: جهات الاتصال، الموقع الدقيق أو التقريبي، البيانات الصحية، أرقام الحسابات المالية، البيانات البيومترية، سجل التصفح، أو محتوى رسائلك.

٤كيف نستخدم البيانات

  • تشغيل التطبيق — عرض السجلات وإنشاؤها وتعديلها وإجراء الحسابات المرتبطة بها.
  • المصادقة على الوصول — التحقق من مفتاح الوصول ورمز الأمان الصادرين من مسؤول النظام.
  • الأمان ومنع الاحتيال — يُستخدم المعرّف التقني المرجعي (UUID عشوائي) على الجهاز فقط لتثبيت جلستك، وعند طلب الدعم لتوليد رمز دعم قصير.
  • إرسال إشعارات إدارية — عند تفعيل إشعارات الدفع في مؤسستك، نُرسل إشعارات تشغيلية (كإشعار إلغاء جلسة) عبر خدمات Apple/Google.
  • تشخيص الأعطال — عند تصدير تقرير تشخيص طوعاً، يتضمن معلومات أساسية عن الجهاز والتطبيق لمساعدة فريق الدعم.

نحن لا نستخدم بياناتك لبناء ملف تعريفي عنك، ولا لخدمة الإعلانات، ولا لتدريب نماذج تعلم آلي.

٥الأساس القانوني للمعالجة (لمستخدمي المنطقة الأوروبية/المملكة المتحدة)

  • تنفيذ عقد — لتقديم التطبيق لك ولمؤسستك.
  • المصلحة المشروعة — تأمين الخدمة ومنع الوصول غير المصرّح به وتشخيص الأعطال.
  • الموافقة — للأذونات الاختيارية مثل الكاميرا ومكتبة الصور، حيث يطلبها نظام التشغيل عند الحاجة. ويمكنك سحب الموافقة في أي وقت من إعدادات جهازك.

٦الأذونات التي قد يطلبها التطبيق

الإذنالسبباختياري؟
التخزين / الملفات حفظ فواتير PDF، تصدير النسخ الاحتياطية، استيراد الجداول التي تختارها نعم — فقط عند التصدير/الاستيراد
الكاميرا التقاط شعار المنشأة لتخصيص الواجهة نعم
مكتبة الصور اختيار شعار موجود مسبقًا للمنشأة نعم
الإشعارات استلام الإشعارات الإدارية من مؤسستك نعم
الإنترنت التحقق من الوصول، إرسال الإشعارات، وتنزيل التحديثات مطلوب

يمكنك سحب أي إذن اختياري في أي وقت من إعدادات نظام جهازك.

٧تخزين البيانات والأمان

  • تُخزَّن سجلات العمل على جهازك في قاعدة بيانات SQLite خاصة بالتطبيق.
  • تُخزَّن بيانات الاعتماد (مفتاح الوصول ورمز الأمان) في التخزين الآمن للنظام — Apple Keychain على iOS و EncryptedSharedPreferences على Android.
  • تستخدم حركة الشبكة تشفير HTTPS/TLS.
  • تُنشَر إصدارات الإنتاج بعد التمويه وتقوية الأمان.
  • أنت مسؤول عن حماية جهازك ماديًا وعن الحفاظ على سرية مفتاح الوصول.

٨مشاركة البيانات والأطراف الثالثة

نحن لا نبيع بياناتك. قد تُعالَج بيانات محدودة من قِبل الجهات التالية للأغراض الموضحة فقط:

الجهة المعالجةالبياناتالغرض
خدمة Apple للإشعارات رمز الإشعارات ومحتواها تسليم الإشعارات على iOS
Google Firebase Cloud Messaging رمز FCM ومحتوى الإشعارات تسليم الإشعارات على Android
الخادم الخلفي للمؤسسة العميلة التحقق من مفتاح الوصول، والمعرّف التقني المرجعي عند التحقق أو طلب الدعم المصادقة على جلستك

قد نُفصح عن معلومات محدودة إذا اقتضى ذلك أمر قضائي صحيح أو طلب قانوني في الاختصاص المعني.

٩عمليات النقل الدولية

عندما يعالج مقدمو خدمات الإشعارات (Apple و Google/Firebase) البيانات خارج بلدك، فإنهم يفعلون ذلك ضمن أطر الامتثال الخاصة بهم (بما فيها البنود التعاقدية القياسية للاتحاد الأوروبي عند الحاجة). أما سجلات عملك فتبقى على جهازك ولا نقوم بنقلها.

١٠مدة الاحتفاظ بالبيانات

  • سجلات العمل: تُحفظ على جهازك حتى تحذفها أنت أو تحذف التطبيق.
  • بيانات الاعتماد: تُحفظ حتى تسجّل الخروج أو يُلغيها المسؤول أو تُلغى بإزالة التطبيق.
  • رمز الإشعارات: يحتفظ به مزود الخدمة (Apple/Google) طالما بقي التطبيق مثبّتاً ويُبطَل عند إزالته.

١١حقوقك

وفقًا لاختصاصك القضائي (بما في ذلك GDPR و UK GDPR و CCPA/CPRA)، قد تحق لك الحقوق التالية:

  • الوصول إلى بياناتك.
  • تصحيح البيانات غير الدقيقة.
  • حذف بياناتك — بالنسبة للبيانات على الجهاز استخدم أدوات الحذف داخل التطبيق أو أزل التطبيق، وبالنسبة للبيانات لدى مؤسستك تواصل معها مباشرة.
  • الاعتراض على معالجة معينة أو تقييدها.
  • سحب الموافقة على الأذونات الاختيارية.
  • تقديم شكوى إلى سلطة رقابية.

لممارسة حقوقك تجاه ناشر التطبيق، استخدم بيانات التواصل في القسم 15.

١٢خصوصية الأطفال

التطبيق مخصص للاستخدام من قِبل موظفين بالغين مفوَّضين. وهو غير موجَّه للأطفال دون سن 13 عاماً (أو 16 في بعض الاختصاصات). ولا نجمع عن قصد أي بيانات شخصية من الأطفال.

١٣حذف الحساب والبيانات

لحذف البيانات المرتبطة بالتطبيق:

  1. سجّل الخروج من داخل التطبيق لإبطال الجلسة المحلية.
  2. أزل التطبيق من جهازك لإزالة كل البيانات المخزنة محليًا، بما فيها بيانات الاعتماد المخزنة.
  3. اطلب من مسؤول النظام إلغاء مفتاح الوصول الخاص بك على الخادم.

يتوفر أيضاً نموذج طلب حذف عبر الويب عند التواصل مع العنوان الوارد في القسم 15، وفقاً لمتطلبات برنامج Google Play Data Safety.

١٤التغييرات على هذه السياسة

قد نُحدّث هذه السياسة لتعكس التغييرات على التطبيق أو تغيرات القانون. ستُشار التعديلات الجوهرية بتحديث «تاريخ السريان» أعلاه، ومن خلال إشعار داخل التطبيق عند التشغيل التالي إذا لزم الأمر.

١٥التواصل

للأسئلة المتعلقة بالخصوصية أو طلبات أصحاب البيانات أو طلبات الحذف الخاصة بمتجر Play:

  • البريد الإلكتروني: aloasay191@gmail.com
  • الناشر: ناشر تطبيق Order Manager

١٦ملخّص الامتثال للمتاجر

Apple App Store — بطاقة خصوصية التطبيق

  • بيانات لا تُجمَع: جهات الاتصال، الموقع، بيانات الصحة واللياقة، البيانات المالية، البيانات الحساسة، سجل التصفح، سجل البحث، بيانات الإعلانات.
  • بيانات لا تُربط بك: بيانات التشخيص (فقط عند إرسال تقرير)، وتفاعل المنتج (تعطلات فقط).
  • بيانات تستخدم لتتبعك: لا شيء.

Google Play — قسم Data Safety

  • لا تُباع أي بيانات لأطراف ثالثة.
  • لا تُشارك بيانات مع أطراف ثالثة سوى بنية إشعارات Apple/Google وخادم مؤسستك العميلة.
  • تُشفَّر البيانات أثناء النقل (TLS) وتُشفَّر بيانات الاعتماد أثناء الخزن (Keychain / EncryptedSharedPreferences).
  • يمكن للمستخدم طلب حذف بياناته (انظر القسم 13).