Privacy Policy
Last updated: 27 July 2026
This Privacy Policy explains how Store Soft ("Store Soft", "the app", "we", "us") handles information when you use our store-management application on Windows and Android. Store Soft is designed to be offline-first: your business data lives on your own device, and the app works without an account or an internet connection. One optional feature, Google Drive backup (to your own Google account), is off by default and only sends data when you turn it on. A second optional feature, multi-device sync to our secure cloud backend, is a paid tier that is also off by default and only sends data if the shop owner creates an account and turns it on. The app also sends a small amount of anonymous usage analytics that never includes your business data.
Contents
1. Who we are
Store Soft is a point-of-sale and store-management app for small shops (primarily Algerian épiceries and superettes). It is developed and operated by the Store Soft team. You can reach us at younes.mimene@gmail.com.
2. Scope of this policy
This policy covers the Store Soft desktop and mobile applications and this website. It does not cover third-party services you may separately use (for example, Google), which are governed by their own privacy policies.
3. Data stored on your device
Store Soft stores the information you enter to run your shop in a local database on your own device only. This may include:
- Shop details you enter (shop name, optional address and phone).
- Products, prices, stock levels, suppliers and purchase costs.
- Sales, receipts, and cash-drawer records.
- Customer and supplier debt (credit / الكريدي) records you create.
- Local user profiles (owner and staff) secured by a username and password, stored only as a salted hash.
4. Multi-device sync (optional)
Multi-device sync is an optional feature for shops that want the same data on more than one device (for example a second till or the owner's phone). It is off by default and is only active if the shop owner creates a Store Soft cloud account and enables it. Most shops run a single device fully offline and never use it.
The store account
- The owner creates an account with an email address and password. This identifies the shop ("the store") and is used to sign in and to enroll devices. We use the email only for authentication and account-related contact — never for advertising.
- Each device you enroll registers under the store using a device fingerprint (the same machine ID / Android ID the license uses), so the number of devices can be limited to your plan and a lost or sold device can be removed.
- Staff (cashier) accounts are created by the owner with a username and a password/PIN that is stored only as a salted hash — never in plain text.
What is uploaded
When sync is enabled, your shop's business records — products, prices, stock, suppliers, sales and receipts, customers, debt (credit / الكريدي) records, repair tickets and staff accounts — are uploaded to our cloud backend so they appear on every enrolled device of the same shop. Unlike Drive backup, these copies are stored on a server we operate (our Supabase backend, hosted in the European Union) for as long as sync is active on your account.
How it is protected
- Data is transferred over encrypted HTTPS connections.
- Each store's data is isolated by row-level security keyed to your store identifier, so one shop can never read or modify another shop's data.
- We use your synced business data only to provide the sync service to you. We do not sell it, share it, or use it for advertising.
You can disconnect a device, disable sync, or ask us to delete your store's cloud data at any time (see Sections 11 and 15).
5. Google account & Google Drive backup (optional)
Google Drive backup is an optional feature. It is off by default and is only used if you choose to sign in with Google from within the app.
What we access
- Basic Google profile — when you sign in, Google provides your email address and display name so the app can show which account is connected. This is used only to display the connected account; it is not stored on our servers.
-
A single, app-private Drive folder — Store Soft requests only the
limited
https://www.googleapis.com/auth/drive.appdatapermission. This grants access exclusively to a hidden application-data folder that the app creates in your own Google Drive.
What we cannot access
The drive.appdata permission technically prevents the app from seeing or
opening any of your other Google Drive content. Store Soft cannot read, list,
modify or delete your documents, photos, spreadsheets or any other files in
your Drive. It can only see the backup files it placed in its own hidden folder.
What we do with it
- Upload encrypted-at-rest copies of your local database backup to that hidden folder.
- List the backups already in that folder so you can choose one to restore.
- Download a backup you select in order to restore it onto your device.
- Delete older backups to keep only the most recent few (rotation).
The backups are stored in your Google account, under your control. We never receive a copy.
6. Google API Services User Data Policy — Limited Use
Specifically:
- We only use Google user data to provide and improve the backup and restore feature you explicitly enabled.
- We do not transfer or sell Google user data to third parties, ad networks, data brokers or for any advertising purpose.
- We do not use Google user data for advertising or for any purpose other than the backup feature.
- We do not allow humans to read your data, except where you give explicit consent for support, where required for security or to comply with law, or where the data has been aggregated and anonymized.
7. Camera
On Android, Store Soft uses the camera only to scan product barcodes in real time (when you open a scanner to add a product or ring up a sale). The camera preview is processed on your device to read the barcode; images are not stored and are not transmitted anywhere. The app does not access your photo gallery.
8. Anonymous analytics & diagnostics
To understand how many shops install and open the app and which versions and platforms are in use, Store Soft sends a small amount of anonymous usage data on startup. This helps us fix bugs and prioritise improvements. It contains no business data and nothing that identifies you personally.
What is sent
- A one-way hashed device identifier (so a reinstall on the same machine isn't double-counted; it cannot be reversed to identify you).
- Platform (Windows or Android), operating-system version, and app version.
- The app's interface language (for example Arabic or French).
- Anonymous "install" and "app opened" events (the open event at most once per day).
What is never sent
We never send your products, prices, sales, customers, suppliers, debts or any other business records, and we do not collect your name, email, phone number, contacts, precise location, or any advertising identifier. Store Soft contains no advertising and no third-party tracking SDKs; this data is not sold, not shared, and not used for advertising.
Separately, the app keeps a full diagnostic error log on your own device for troubleshooting, which you can view and share with our support yourself (for example over WhatsApp).
Crash & error reports
When the app encounters an error, it also sends a stripped, anonymous crash report to our own backend so we can find and fix problems. Each report contains only: the one-way hashed device identifier, platform, OS and app version, the error type, a trimmed error message and stack trace, and the last few in-app actions (as short labels). It does not include your customer list, product catalogue, prices or sales. A trimmed error message can, in rare cases, contain a small fragment of business text; we use it only to fix the app, never for advertising, and never share it with third parties.
9. How we use information
- To let you run your shop: ring up sales, manage stock, and track debt — entirely on your device.
- To create and restore backups when you ask the app to (locally and, if enabled, to your Google Drive).
- To provide the optional multi-device sync service when you enable it (keeping the same shop data on your enrolled devices).
- To understand install/usage counts through the anonymous analytics described in Section 8.
- To show diagnostic logs to you on your own device for troubleshooting (you may choose to share these with our support).
10. Sharing & disclosure
We do not sell, rent or trade your information. We do not share your shop data, your Google data, or your analytics data with third parties for their own purposes. Information may only leave your device when:
- You enable Google Drive backup (data goes only to your own Google account); or
- You enable the optional multi-device sync tier (business data goes to our secure backend solely to sync your own devices, see Section 4); or
- The app sends the anonymous, non-business analytics described in Section 8; or
- You manually export, copy or share a backup file or a diagnostic log yourself (for example, sending it to our support over WhatsApp).
We may disclose information if required by law, or to protect the security and integrity of the service. We host our backend with infrastructure providers (Supabase / its cloud provider, in the EU) acting solely as our processors.
11. Data retention & deletion
- On your device: data is kept until you delete it. The app includes a "delete all business data" option, and uninstalling the app removes its local data.
- Google Drive backups: you can delete backups from within the app, or directly from your Google Drive.
- Synced cloud data: if you use the multi-device sync tier, you can remove an enrolled device or disable sync in the app; you can also ask us to delete your store account and its synced data from our backend. Full instructions: Delete your account and data.
- Revoking Google access: you can disconnect the account in the app, and you can revoke Store Soft's access at any time from your Google Account at myaccount.google.com/permissions.
- Analytics: analytics records are anonymous and cannot be tied back to you, so we cannot single them out for individual deletion.
12. Security
Local PINs and staff passwords are stored only as salted SHA-256 hashes, never in plain text. Data transferred to Google Drive or to our sync backend is sent over encrypted HTTPS connections; synced data is isolated per store by row-level security so one shop cannot access another's. No method of storage or transmission is 100% secure, but we design the app to keep your data on your device and under your control by default.
13. Children's privacy
Store Soft is a business tool intended for shop owners and their staff. It is not directed to children and we do not knowingly collect personal information from children.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Continued use of the app after changes take effect constitutes acceptance of the updated policy.
15. Contact us
Questions about this policy or your data? Message us on WhatsApp (+213 654 33 86 49) or email younes.mimene@gmail.com.