Privacy Policy
1Who we are
“Order Manager” (“the App”, “we”, “us”, “our”) is developed and maintained by the App’s publisher. Contact details are provided at the end of this policy. For the purposes of the EU/UK GDPR and comparable laws, the App’s publisher acts as the data controller for the limited data described below; your employing organization (the “Client Organization”) acts as the controller of the business records you enter into the App.
2Scope of this policy
This policy covers the Order Manager mobile application distributed via the Apple App Store and Google Play, and any updates to it. It does not cover third-party services that your Client Organization may separately integrate with, or external websites you may open from the App.
3Data we collect
We follow a strict data minimization principle. The table below summarizes every category of data the App may handle, whether it leaves your device, and why.
| Category | Examples | Stored | Shared off-device | Purpose |
|---|---|---|---|---|
| Business records | Customers, products, orders, invoices, prices, quantities, notes | On-device (SQLite) | No | App functionality |
| App preferences | Language, theme, currency, tax settings | On-device | No | App functionality |
| Access credentials | Access Key / Security Token issued by your admin | On-device secure storage (Keychain / EncryptedSharedPreferences) | No | Authentication |
| Technical Reference ID | Randomly generated UUID | On-device | Only when contacting support | Security & fraud prevention, support code |
| Device information | OS name and version, device model, app version | On-device | Only in diagnostic reports you send | Troubleshooting |
| Push notification token | Firebase Cloud Messaging (FCM) token | Provided by Google / Apple push services | Yes (Firebase, if enabled) | Administrator notices from your organization |
| Photo / camera content | Facility logo selected by an administrator | On-device only | No | UI customization |
| Advertising identifiers | IDFA, AAID | Not collected | No | Not applicable — we do not run ads |
The App does not collect: contacts, precise or coarse location, health data, financial account numbers, biometric identifiers, browsing history, or content of your messages.
4How we use data
- Operate the App — display, create, edit, and calculate your business records.
- Authenticate access — validate the Access Key and Security Token issued by your System Administrator.
- Security & fraud prevention — the on-device Technical Reference ID (a random UUID) is used only to anchor your session and, if you request support, to generate a short support code.
- Send administrative notices — if push messaging is enabled by your organization, we deliver operational notices (for example, a session revocation notice) via Apple/Google push services.
- Diagnose issues — when you explicitly export a diagnostic report, basic device and app information is included so support can help you.
We do not use your data to profile you, to serve advertising, or to train machine-learning models.
5Legal basis for processing (EEA / UK users)
- Performance of a contract — to make the App work for you and your Client Organization.
- Legitimate interests — securing the service, preventing unauthorized access, and diagnosing faults.
- Consent — for optional permissions such as camera and photo library, which the operating system requests at the moment of use. You may withdraw consent at any time in your device settings.
6Permissions the App may request
| Permission | Why | Optional? |
|---|---|---|
| Storage / Files | Save PDF invoices, export backups, import spreadsheets you choose | Yes — only when you use export/import |
| Camera | Capture a facility logo for UI customization | Yes |
| Photo library | Choose an existing facility logo | Yes |
| Notifications | Deliver administrative notices from your organization | Yes |
| Internet | Validate access, deliver push notices, and download updates | Required |
You can revoke any optional permission at any time from your device’s system settings.
7Data storage and security
- Business records are stored on your device in an SQLite database owned by the App.
- Credentials (Access Key, Security Token) are stored in the platform’s secure storage — Apple Keychain on iOS and EncryptedSharedPreferences on Android.
- Network traffic uses HTTPS/TLS.
- Release builds are obfuscated and hardened.
- You are responsible for physically securing your device and for keeping your Access Key confidential.
8Data sharing and third parties
We do not sell your data. Limited data may be handled by the following processors strictly for the purposes shown:
| Processor | Data | Purpose |
|---|---|---|
| Apple Push Notification service | Push token, notification payload | Deliver notifications on iOS |
| Google Firebase Cloud Messaging | FCM token, notification payload | Deliver notifications on Android |
| Your Client Organization’s backend | Access Key validation, Technical Reference ID (only during validation and support) | Authenticate your session |
We may disclose limited information if legally compelled by a valid court order or by law enforcement in the relevant jurisdiction.
9International transfers
Where push notification providers (Apple, Google/Firebase) process data outside your country, they do so under their own compliance frameworks (including EU Standard Contractual Clauses where applicable). Your business records themselves remain on your device and are not transferred by us.
10Data retention
- Business records: retained on your device until you delete them or uninstall the App.
- Credentials: retained until you sign out, your administrator revokes them, or you uninstall the App.
- Push token: retained by Apple/Google while the App remains installed; invalidated on uninstall.
11Your rights
Depending on your jurisdiction (including GDPR, UK GDPR, and CCPA/CPRA), you may have the right to:
- Access your data.
- Correct inaccurate data.
- Delete your data — for on-device data, use the delete controls inside the App or uninstall it; for records held by your Client Organization, contact them directly.
- Object to or restrict certain processing.
- Withdraw consent for optional permissions.
- Lodge a complaint with a supervisory authority.
To exercise rights against the App publisher, use the contact details in section 15.
12Children’s privacy
The App is intended for use by authorized adult employees. It is not directed to children under 13 (or 16 in some jurisdictions). We do not knowingly collect personal data from children.
13Account and data deletion
To delete data associated with the App:
- Sign out from within the App to invalidate the local session.
- Uninstall the App from your device to remove all locally stored data, including cached credentials.
- Ask your System Administrator to revoke your Access Key on the server side.
A web-based deletion request form is also available on request from the address in section 15, as required by the Google Play Data Safety program.
14Changes to this policy
We may update this policy to reflect changes in the App or in the law. Material changes will be signaled by updating the “Effective date” above and, where appropriate, by an in-App notice on next launch.
15Contact
For privacy questions, data-subject requests, or Play Store data-deletion requests:
- Email: aloasay191@gmail.com
- Publisher: Order Manager App Publisher
16Store-compliance summary
Apple App Store — App Privacy “nutrition label”
- Data Not Collected: Contacts, Location, Health & Fitness, Financial Info, Sensitive Info, Browsing History, Search History, Advertising Data.
- Data Not Linked to You: Diagnostics (only when you send a report), Product Interaction (crash-only).
- Data Used to Track You: None.
Google Play — Data Safety
- No data sold to third parties.
- No data shared with third parties beyond Apple/Google push infrastructure and your Client Organization’s backend.
- Data is encrypted in transit (TLS) and at rest for credentials (Keychain / EncryptedSharedPreferences).
- Users can request data deletion (see section 13).