Shop Manager Privacy Policy
Read the latest version embedded in the app before completing signup to Shop Manager App.
Last updated: 10 August 2026 | Version 2.0.0
This policy explains what Shop Manager collects, why, who it is shared with, how long it is kept, and how to delete it. Shop Manager is provided by Zubair Shahzad, who is the data controller for the information described below. Contact: contact@softlearnhub.com.
We do not sell your personal information, and we do not use your business data to target advertising.
1. Information you give us
- Account details — your name, email address, profile photo and a unique account identifier, created when you register with an email and password or with Google Sign-In. We never see or store your Google password.
- Shop details — shop name, logo, phone number, address, country, currency and tax settings.
- Business records — products, stock levels and prices, sales and invoices, purchases, expenses, payments, banks and wallets you set up, and the balances calculated from them.
- Customer and supplier details you enter — names, phone numbers and addresses of the people and businesses you trade with. See section 7.
- Team details — the email address, name, role and permissions of members you invite to your shop.
- Support and feedback — support tickets and replies you send us, and any rating or comment you submit through Rate the App.
2. Information collected automatically
- Notification token — if you allow notifications, a device messaging token so we can send you alerts such as low-stock warnings and team requests.
- Activity timestamps — when you last opened the App, used to decide whether to send reminder notifications, and an in-app activity log of actions taken in your shop (such as recording a sale) so shop owners can see who did what.
- Advertising identifier — where banner ads are shown, Google AdMob may access your device’s advertising ID and limited technical information to serve and measure ads. See section 6.
- Usage and diagnostic data — basic app-usage and stability measurement collected through Google Analytics for Firebase (such as platform, app version, and which screens are opened), used to keep the App working and to understand which features are used. This never includes the contents of your business records.
- The App does not collect your precise location, and does not request any location permission.
3. Device permissions and what they are for
Every permission below is requested only at the moment you use the feature that needs it — never at launch — and the App remains usable if you decline.
- Camera — to read product barcodes. Scanning is performed on your device. No photo or video is taken, saved, or sent anywhere; only the decoded barcode text is used.
- Contacts — only for the “Import from Contacts” button on the Add Customer and Add Supplier forms. Your device’s own contact picker opens, you choose one contact, and only that contact’s name and first phone number are copied into the form. We do not read your contact list, upload it, or create, change or delete any contact on your device.
- Bluetooth — to connect to a receipt printer you have already paired in your Android settings, so receipts can be printed. The App does not scan for or discover nearby devices.
- Notifications — to show the alerts described above.
- File storage (older Android versions only) — to save an invoice, receipt or report you choose to export as a PDF.
- Fingerprint / biometric unlock (optional) — if you turn it on, your device confirms it is you. The check happens entirely on your device; your fingerprint or face data is never available to the App and never leaves your device.
4. Why we use your information
- To provide the App: store your records, calculate stock, costs, profit and balances, and produce your reports and documents.
- To create and secure your account, including sending one-time passwords for manual login and account deletion.
- To manage shop membership and enforce the roles and permissions an owner sets.
- To send you notifications you have allowed, including reminders to return to the App. You can turn these off in your device settings at any time.
- To answer your support tickets and act on your feedback.
- To process and verify paid plan purchases.
- To show advertising, where applicable.
- To keep the Service secure, prevent abuse, and comply with our legal obligations.
- Where the law requires a legal basis, we rely on performance of our contract with you (providing the App), your consent (notifications, contacts, camera, ads personalisation), and our legitimate interests (keeping the Service secure and improving it).
5. Who your information is shared with
We do not sell your information and we do not share it with third parties for their own marketing. We use the following service providers, who process data on our behalf:
- Google Firebase (Authentication, Cloud Firestore, Cloud Functions, Cloud Messaging) — sign-in, storing your business records, and delivering notifications.
- Google Analytics for Firebase — aggregate usage and stability measurement, and linking ad revenue to the app. It does not receive your business records.
- Google Play Billing — processing paid plan purchases. Google handles your payment details; we never receive your card or bank information.
- Google AdMob — serving and measuring banner advertising.
- Google ML Kit — barcode recognition, which runs on your device.
- Our own support and administration service — hosted for us on Fly.io, handling one-time password emails, support tickets, purchase verification and app configuration.
- Within your shop, the business data you enter is visible to the other members of that shop, according to the role and permissions the owner grants them. Our administrators can see support tickets and submitted feedback in order to help you.
We may also disclose information where we are legally required to, or to establish or defend legal claims.
6. Advertising choices
Banner ads may be shown in the App and are supplied by Google AdMob. Ads are never targeted using your business records. You can limit ad personalisation or reset your advertising identifier at any time in Android: Settings > Google > Ads (the exact path varies by device). Google’s handling of ad data is described in its own privacy policy.
7. Data about your customers and suppliers
The customer and supplier details you enter are personal information about other people. For that information you are the controller and we act on your instructions as your processor: we store it, show it back to you and your team, and include it on the documents you generate. We do not use it for any purpose of our own. You are responsible for having a proper basis to record it and for responding if one of those people asks to see, correct or remove their details — which you can do directly in the App.
8. International transfers
Our providers operate data centres in several countries, so your information may be processed outside the country you live in. Where information is transferred internationally, we rely on our providers’ safeguards, including the contractual protections offered by Google and Fly.io.
9. How long we keep your information
- Your account and business records are kept for as long as your account is active.
- If you delete a shop, that shop’s records are removed.
- If you request account deletion, a 30-day grace period begins; logging in during that period cancels the request. After it passes, your account and the data linked to it — including the shops you own and their products, sales, purchases, expenses and ledgers — are permanently deleted.
- Deleted content may persist for a short period in routine backups before being overwritten, and cannot be restored to you once deletion has completed.
- We may keep the minimum records we are legally required to keep, such as transaction records for tax purposes.
10. How to delete your data
In the App, go to Settings > Account > Delete Account. You will be asked to confirm with a one-time password sent to your email. To delete a single shop instead, use Settings > Delete Store. If you cannot access the App, email contact@softlearnhub.com from your registered address and we will process your request.
11. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, to have it corrected, to have it deleted, to object to or restrict how we use it, to receive a copy in a portable form, and to withdraw consent you have given. You can exercise most of these directly in the App, or by emailing contact@softlearnhub.com. We will respond within the time the applicable law allows. You also have the right to complain to your local data protection authority.
12. Security
Sign-in is handled by Firebase Authentication. Data is transmitted over encrypted connections and stored by our providers using encryption at rest. Access to each shop’s data is restricted by server-side security rules to the members of that shop, sensitive actions are confirmed by one-time password, and our support endpoints are rate-limited and size-capped to reduce abuse. No system can be guaranteed completely secure, so please protect your device, use a strong password, and review who has access to your shop.
13. Children’s privacy
Shop Manager is a business tool intended for adults and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, email contact@softlearnhub.com and we will delete it.
14. Changes to this policy
We may update this policy as the App changes or the law requires. The effective date at the top always reflects the current version, and material changes will be brought to your attention in the App.
15. Contact us
Zubair Shahzad — contact@softlearnhub.com. You can also open Settings > Customer Support inside the App.
