Privacy Policy
Last updated: 26 September 2026
Store Soft is an offline-first store-management app for Windows and Android. Products, sales, customers and stock stay on your device unless you enable optional Google Drive backup or multi-device Sync. The app also sends limited installation and usage analytics, including the shop name, phone number and address you enter in Shop info, to our private CRM for support and adoption measurement. Section 8 explains exactly what is sent.
Contents
1. Who we are
Store Soft is a point-of-sale and store-management app for small shops (primarily Algerian épiceries and superettes). It is developed and operated by the Store Soft team. You can reach us at younes.mimene@gmail.com.
2. Scope of this policy
This policy covers the Store Soft desktop and mobile applications and this website. It does not cover third-party services you may separately use (for example, Google), which are governed by their own privacy policies.
Website download requests
If you request access to Store Soft through our website, we collect the name, email address, phone or WhatsApp number, and shop type that you submit. We also record basic campaign information included in the page link (such as source and campaign name) and the submission time. We use this information only to process your request, add the email address you supplied to the Google Play test, send installation instructions, provide follow-up support, and understand the effectiveness of our campaigns.
Download requests are stored in our secure Supabase backend and copied to a private Google Sheet used by the Store Soft team to manage follow-up. We do not sell these details or use them for unrelated advertising. You may ask us to correct or delete a request using the contact details at the end of this policy.
Each request receives a random private link containing only a six-character opaque code. The link contains no name, phone number, or email address. If you use it to open Google Play and then install Store Soft, the code may let us connect the limited trial milestones in Section 8 to your request so we can provide timely setup help.
Meta advertising measurement on the website
The Store Soft download page uses the Meta Pixel to record a page visit and, only after the website successfully saves a request, a standard Lead event. Meta may receive browser and device information, IP address, cookies or similar identifiers, the page URL, and campaign parameters. We use these events to attribute requests to Facebook and Instagram ads, measure campaign performance, and improve ad delivery. We do not explicitly include the name, email address, phone number, or shop type entered in the form in the events we send. Meta processes these events under its own Privacy Policy.
3. Data stored on your device
Store Soft stores the information you enter to run your shop in a local database on your own device only. This may include:
- Shop details you enter (shop name, optional address and phone).
- Products, prices, stock levels, suppliers and purchase costs.
- Sales, receipts, and cash-drawer records.
- Customer and supplier debt (credit / الكريدي) records you create.
- Local user profiles (owner and staff) secured by a username and password, stored only as a salted hash.
4. Multi-device sync (optional)
Multi-device sync is an optional feature for shops that want the same data on more than one device (for example a second till or the owner's phone). It is off by default and is only active if the shop owner creates a Store Soft cloud account and enables it. Most shops run a single device fully offline and never use it.
The store account
- The owner creates an account with an email address and password. This identifies the shop ("the store") and is used to sign in and to enroll devices. We use the email only for authentication and account-related contact — never for advertising.
- Each device you enroll registers under the store using a device fingerprint (the same machine ID / Android ID the license uses), so the number of devices can be limited to your plan and a lost or sold device can be removed.
- Staff (cashier) accounts are created by the owner with a username and a password/PIN that is stored only as a salted hash — never in plain text.
What is uploaded
When sync is enabled, your shop's business records — products, prices, stock, suppliers, sales and receipts, customers, debt (credit / الكريدي) records, repair tickets and staff accounts — are uploaded to our cloud backend so they appear on every enrolled device of the same shop. Unlike Drive backup, these copies are stored on a server we operate (our Supabase backend, hosted in the European Union) for as long as sync is active on your account.
How it is protected
- Data is transferred over encrypted HTTPS connections.
- Each store's data is isolated by row-level security keyed to your store identifier, so one shop can never read or modify another shop's data.
- We use your synced business data only to provide the sync service to you. We do not sell it, share it, or use it for advertising.
You can disconnect a device, disable sync, or ask us to delete your store's cloud data at any time (see Sections 11 and 15).
5. Google account & Google Drive backup (optional)
Google Drive backup is an optional feature. It is off by default and is only used if you choose to sign in with Google from within the app.
What we access
- Basic Google profile — when you sign in, Google provides your email address and display name so the app can show which account is connected. This is used only to display the connected account; it is not stored on our servers.
-
A single, app-private Drive folder — Store Soft requests only the
limited
https://www.googleapis.com/auth/drive.appdatapermission. This grants access exclusively to a hidden application-data folder that the app creates in your own Google Drive.
What we cannot access
The drive.appdata permission technically prevents the app from seeing or
opening any of your other Google Drive content. Store Soft cannot read, list,
modify or delete your documents, photos, spreadsheets or any other files in
your Drive. It can only see the backup files it placed in its own hidden folder.
What we do with it
- Upload encrypted-at-rest copies of your local database backup to that hidden folder.
- List the backups already in that folder so you can choose one to restore.
- Download a backup you select in order to restore it onto your device.
- Delete older backups to keep only the most recent few (rotation).
The backups are stored in your Google account, under your control. We never receive a copy.
6. Google API Services User Data Policy — Limited Use
Specifically:
- We only use Google user data to provide and improve the backup and restore feature you explicitly enabled.
- We do not transfer or sell Google user data to third parties, ad networks, data brokers or for any advertising purpose.
- We do not use Google user data for advertising or for any purpose other than the backup feature.
- We do not allow humans to read your data, except where you give explicit consent for support, where required for security or to comply with law, or where the data has been aggregated and anonymized.
7. Camera
On Android, Store Soft uses the camera only to scan product barcodes in real time (when you open a scanner to add a product or ring up a sale). The camera preview is processed on your device to read the barcode; images are not stored and are not transmitted anywhere. The app does not access your photo gallery.
8. Installation, usage, lead milestones & diagnostics
Store Soft records a random installation ID, a one-way hashed device ID, app version and platform, selected lifecycle milestones, and counts of visits to broad app sections. It also records the shop name, phone number and address entered in Shop info for installation support and adoption measurement. These contact fields are not anonymous. Events are stored on the device first and uploaded in batches when online. Only our administrators can view shop contact fields in the private CRM.
Download page measurement
We save a random visitor ID in your browser's local storage to count distinct download-page visitors, including repeat visits, rather than page loads. We record only this ID, a broad device category (Android, Windows or other), and the first visit time. Clearing browser data or using another browser creates a new visitor. Browsers that block this storage are omitted. The visitor ID is not saved alongside a lead. After you submit a request, its broad device category and Android/Windows download clicks may be attached to that request using its opaque referral code. Repeated clicks count once per request and platform.
Lead-attributed trial milestones
This applies only when an Android installation receives the opaque six-character code from a private website-request link. Store Soft keeps that code in secure device storage and queues delivery offline. We record only: Google Play link opened, app first opened, store setup completed, first real product created, first sale completed, Sync enabled, and staff user added. These milestones are connected to the submitted request and are therefore not anonymous.
We do not send product names, barcodes, prices, stock, customer or supplier data, sale contents, sale or purchase amounts, employee names, or UI clicks. Demo products and the app's hidden repair-service product are excluded. These records are used for onboarding, support, lead follow-up, and aggregate funnel measurement, not advertising delivery.
What is sent
- A random installation ID and one-way hashed device ID to recognise reinstalls.
- Platform, app version, first seen and last active dates.
- Daily opens, first setup/product/sale/customer/backup and activation milestones, and counts of visits to broad app sections.
- Separate Offline licence and Sync status, without prices or sale details.
- Shop name, phone number and address entered in Shop info, stored in our private administrator-only CRM.
What is never sent
Analytics never sends product names, prices, sale contents, customer or supplier records, debts, stock quantities, precise location or advertising IDs. Shop contact fields listed above are the only shop-entered fields in this analytics channel. We do not sell this data or use it for advertising. The Meta Pixel on the website is separate from the installed app.
Separately, the app keeps a full diagnostic error log on your own device for troubleshooting, which you can view and share with our support yourself (for example over WhatsApp).
Crash & error reports
Error reports sent to our backend contain the installation ID, hashed device ID, platform, OS and app version, error type and broad area. Messages, stack traces, context and action history remain only in the local diagnostic log.
Optional in-app feedback
If you choose to send feedback inside Store Soft, we receive your 1–5 star rating, one issue category for ratings below five, and any comment you choose to write. We also receive a random installation ID, the app version, Android or Windows platform, and submission time. Feedback can wait on your device while offline and is sent to our private backend when online. Only Store Soft administrators can read it. We use it to understand problems and improve the app, including rating and category totals. The optional comment may contain information you choose to enter. This submission works even if optional Analytics is off. Google Play reviews are separate and are handled by Google Play.
9. How we use information
- To let you run your shop: ring up sales, manage stock, and track debt — entirely on your device.
- To create and restore backups when you ask the app to (locally and, if enabled, to your Google Drive).
- To provide the optional multi-device sync service when you enable it (keeping the same shop data on your enrolled devices).
- To process website download requests, provide Google Play access, send installation instructions, and follow up with interested shop owners.
- To measure installation and usage, and support shops using the contact fields described in Section 8.
- To provide onboarding and measure the request-to-trial funnel through the limited lead milestones described in Section 8.
- To show diagnostic logs to you on your own device for troubleshooting (you may choose to share these with our support).
10. Sharing & disclosure
We do not sell, rent or trade your information. We do not share your shop data, your Google data, or your analytics data with third parties for their own purposes. Information may only leave your device when:
- You enable Google Drive backup (data goes only to your own Google account); or
- You enable the optional multi-device sync tier (business data goes to our secure backend solely to sync your own devices, see Section 4); or
- The app sends installation, usage and shop contact analytics described in Section 8 to our private backend; or
- An eligible Android install sends the limited lead-attributed milestones described in Section 8; or
- You choose to submit optional in-app feedback described in Section 8 to our private backend; or
- The website sends page-view and successful-lead events to Meta for advertising measurement as described in Section 2; or
- You manually export, copy or share a backup file or a diagnostic log yourself (for example, sending it to our support over WhatsApp).
We may disclose information if required by law, or to protect the security and integrity of the service. We host our backend with infrastructure providers (Supabase / its cloud provider, in the EU) acting solely as our processors.
11. Data retention & deletion
- On your device: data is kept until you delete it. The app includes a "delete all business data" option, and uninstalling the app removes its local data.
- Google Drive backups: you can delete backups from within the app, or directly from your Google Drive.
- Synced cloud data: if you use the multi-device sync tier, you can remove an enrolled device or disable sync in the app; you can also ask us to delete your store account and its synced data from our backend. Full instructions: Delete your account and data.
- Website download requests and linked milestones: we keep a request and its linked trial milestones while needed for installation support and customer follow-up. You may ask us to correct or delete them at any time using the contact details below.
- Revoking Google access: you can disconnect the account in the app, and you can revoke Store Soft's access at any time from your Google Account at myaccount.google.com/permissions.
- Installation analytics and shop contact fields: contact us using the details below to request deletion of records associated with your shop or installation. Lead-attributed milestones can be deleted with your website request.
- In-app feedback: contact us using the details below to request deletion of a submitted rating or comment associated with your installation.
12. Security
Local PINs and staff passwords are stored only as salted SHA-256 hashes, never in plain text. Data transferred to Google Drive or to our sync backend is sent over encrypted HTTPS connections; synced data is isolated per store by row-level security so one shop cannot access another's. No method of storage or transmission is 100% secure, but we design the app to keep your data on your device and under your control by default.
13. Children's privacy
Store Soft is a business tool intended for shop owners and their staff. It is not directed to children and we do not knowingly collect personal information from children.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Continued use of the app after changes take effect constitutes acceptance of the updated policy.
15. Contact us
Questions about this policy or your data? Message us on WhatsApp (+213 654 33 86 49) or email younes.mimene@gmail.com.