Effective date: June 18, 2026
TindaHero ("the app", "we", "us") is a sari-sari store management app built for Filipino store owners. This policy explains what data we collect, why we collect it, how it is stored and protected, and your rights over it.
| Data | Where it is stored | Who can access it |
|---|---|---|
| Products, sales, credits, expenses | On your device (SQLite / Room database) | You only β on your device |
| Same data (when cloud sync is enabled) | Firebase Firestore β scoped to your store ID | You + your authorized staff accounts only |
| Email address, display name | Firebase Authentication + Firestore | You only (store owner sees staff display names) |
| Product photos | Firebase Storage β scoped to your store ID | You + your authorized staff accounts only |
| Shared product photos (only if you opt in) | Firebase Storage β shared "suggested pictures" pool | Other TindaHero merchants, as photo suggestions (see Section 5) |
| Backup files (.json) | Your device's Downloads folder (manual export) | You only |
Cloud sync via Firestore is only active when you are signed in with an account (Pro or Premium plan). Guest / Free users who have not created an account have no data transmitted outside their device.
| Permission | Why it is needed |
|---|---|
| Camera | To scan product barcodes using the device camera. The camera feed is processed entirely on-device by ZXing and is never saved or transmitted. |
| Internet | Required for: (1) Firebase Authentication sign-in / sign-up; (2) Firestore cloud sync when an account is active; (3) downloading the product catalog database from GitHub Releases on first launch; (4) optional barcode lookup via Open Food Facts if a barcode is not found locally. |
| USE_BIOMETRIC / USE_FINGERPRINT | To unlock the app with your fingerprint or face when PIN lock is enabled. Biometric data never leaves your device β it is processed by the Android BiometricPrompt API. |
| RECEIVE_BOOT_COMPLETED | To reschedule the daily auto-backup WorkManager job after the device restarts (Premium plan only). |
| Write External Storage (Android 9 and below only) |
To save exported backup and report files to your Downloads folder. Not used on Android 10 and above. |
TindaHero uses the following third-party services:
| Service | Provider | What it is used for | Data sent |
|---|---|---|---|
| Firebase Authentication | Google LLC | Account sign-up, sign-in, and email verification | Email address, session tokens |
| Firebase Firestore | Google LLC | Cloud sync of store data across owner + staff devices | Your store data (products, sales, credits) β only when signed in |
| Firebase Storage | Google LLC | Storing product photos, and the optional shared "suggested pictures" pool | Product photos β your own (Pro/Premium); shared photos only if you opt in |
| Google Play Billing | Google LLC | Processing Pro / Premium subscription payments | Subscription status only (payment handled entirely by Google Play) |
| Open Food Facts | Open Food Facts (non-profit) | Optional barcode lookup if product is not in the offline catalog | Barcode number only β no personal data |
Firebase services are operated by Google LLC and are subject to Google's Privacy Policy. Open Food Facts is an open-source non-profit project; see their privacy policy. Payment processing through Google Play is subject to Google Payments Privacy Notice.
We do not use any advertising networks, marketing trackers, or analytics platforms.
Pro and Premium users can attach photos to their products. To help other store owners, TindaHero offers an optional "suggested pictures" feature: when you add a product, the app can show photos that other stores have shared for the same product, so you can pick one instead of taking your own.
This sharing is opt-in. We ask you once whether you want to share your product photos. If you choose "No," your photos stay private and are never added to the shared pool. If you choose "Yes":
Shared photos are stored independently of your store, so removing a product from your own inventory does not remove a photo you previously shared. To withdraw your consent or request removal of photos you have contributed to the shared pool, contact us at the email in the Contact section.
To help store owners price competitively, Pro and Premium users see a suggested retail price when adding a product β an average and a typical price range drawn from what other stores charge for the same item.
This figure is an anonymized aggregate. We use the product prices that accounts have saved to their cloud-synced inventory to compute, per product, an average, a minimumβmaximum range, and a count of stores. No individual store's price is ever shown to anyone, and we never reveal which store charges what. The suggestion is optional guidance β you always set your own price.
To request that your data no longer be used for this aggregate, contact us at the email in the Contact section.
All Firestore data is protected by server-side security rules that restrict each store's data to its owner and authorized staff members only. Authentication tokens are managed securely by Firebase. Local data is stored in Android's private app storage and is not accessible to other apps on your device.
TindaHero is not directed at children under 13. We do not knowingly collect any personal information from children. If you believe a child under 13 has created an account, please contact us and we will delete it promptly.
You have the right to:
To exercise any of these rights, contact us at the email address below.
If we update this policy, the new version will be posted at this URL with an updated effective date. Continued use of the app after changes constitutes acceptance of the updated policy. Significant changes will be announced within the app.
Questions or requests about this privacy policy? Contact us at:
lizada.christopher@gmail.com