πŸ›’ TindaHero β€” Privacy Policy

Effective date: June 18, 2026

TindaHero ("the app", "we", "us") is a sari-sari store management app built for Filipino store owners. This policy explains what data we collect, why we collect it, how it is stored and protected, and your rights over it.

Short version: Your store data (products, sales, credits) stays on your device. If you create an account, your email address is stored securely with Firebase. Cloud sync is optional and only active when you are signed in with an account. Product photos are private by default β€” sharing them as suggestions to other stores is optional and opt-in. We do not sell or share your data with advertisers.

1. What Data We Collect

A. Data you provide

B. Data collected automatically

2. How Your Data Is Stored

Data Where it is stored Who can access it
Products, sales, credits, expenses On your device (SQLite / Room database) You only β€” on your device
Same data (when cloud sync is enabled) Firebase Firestore β€” scoped to your store ID You + your authorized staff accounts only
Email address, display name Firebase Authentication + Firestore You only (store owner sees staff display names)
Product photos Firebase Storage β€” scoped to your store ID You + your authorized staff accounts only
Shared product photos (only if you opt in) Firebase Storage β€” shared "suggested pictures" pool Other TindaHero merchants, as photo suggestions (see Section 5)
Backup files (.json) Your device's Downloads folder (manual export) You only

Cloud sync via Firestore is only active when you are signed in with an account (Pro or Premium plan). Guest / Free users who have not created an account have no data transmitted outside their device.

3. Permissions We Request

Permission Why it is needed
Camera To scan product barcodes using the device camera. The camera feed is processed entirely on-device by ZXing and is never saved or transmitted.
Internet Required for: (1) Firebase Authentication sign-in / sign-up; (2) Firestore cloud sync when an account is active; (3) downloading the product catalog database from GitHub Releases on first launch; (4) optional barcode lookup via Open Food Facts if a barcode is not found locally.
USE_BIOMETRIC / USE_FINGERPRINT To unlock the app with your fingerprint or face when PIN lock is enabled. Biometric data never leaves your device β€” it is processed by the Android BiometricPrompt API.
RECEIVE_BOOT_COMPLETED To reschedule the daily auto-backup WorkManager job after the device restarts (Premium plan only).
Write External Storage
(Android 9 and below only)
To save exported backup and report files to your Downloads folder. Not used on Android 10 and above.

4. Third-Party Services

TindaHero uses the following third-party services:

Service Provider What it is used for Data sent
Firebase Authentication Google LLC Account sign-up, sign-in, and email verification Email address, session tokens
Firebase Firestore Google LLC Cloud sync of store data across owner + staff devices Your store data (products, sales, credits) β€” only when signed in
Firebase Storage Google LLC Storing product photos, and the optional shared "suggested pictures" pool Product photos β€” your own (Pro/Premium); shared photos only if you opt in
Google Play Billing Google LLC Processing Pro / Premium subscription payments Subscription status only (payment handled entirely by Google Play)
Open Food Facts Open Food Facts (non-profit) Optional barcode lookup if product is not in the offline catalog Barcode number only β€” no personal data

Firebase services are operated by Google LLC and are subject to Google's Privacy Policy. Open Food Facts is an open-source non-profit project; see their privacy policy. Payment processing through Google Play is subject to Google Payments Privacy Notice.

We do not use any advertising networks, marketing trackers, or analytics platforms.

5. Shared Product Photos (Suggested Pictures)

Pro and Premium users can attach photos to their products. To help other store owners, TindaHero offers an optional "suggested pictures" feature: when you add a product, the app can show photos that other stores have shared for the same product, so you can pick one instead of taking your own.

This sharing is opt-in. We ask you once whether you want to share your product photos. If you choose "No," your photos stay private and are never added to the shared pool. If you choose "Yes":

Shared photos are stored independently of your store, so removing a product from your own inventory does not remove a photo you previously shared. To withdraw your consent or request removal of photos you have contributed to the shared pool, contact us at the email in the Contact section.

6. Suggested Retail Prices

To help store owners price competitively, Pro and Premium users see a suggested retail price when adding a product β€” an average and a typical price range drawn from what other stores charge for the same item.

This figure is an anonymized aggregate. We use the product prices that accounts have saved to their cloud-synced inventory to compute, per product, an average, a minimum–maximum range, and a count of stores. No individual store's price is ever shown to anyone, and we never reveal which store charges what. The suggestion is optional guidance β€” you always set your own price.

To request that your data no longer be used for this aggregate, contact us at the email in the Contact section.

7. Data Security

All Firestore data is protected by server-side security rules that restrict each store's data to its owner and authorized staff members only. Authentication tokens are managed securely by Firebase. Local data is stored in Android's private app storage and is not accessible to other apps on your device.

8. Data Retention & Deletion

9. Children's Privacy

TindaHero is not directed at children under 13. We do not knowingly collect any personal information from children. If you believe a child under 13 has created an account, please contact us and we will delete it promptly.

10. Your Rights

You have the right to:

To exercise any of these rights, contact us at the email address below.

11. Changes to This Policy

If we update this policy, the new version will be posted at this URL with an updated effective date. Continued use of the app after changes constitutes acceptance of the updated policy. Significant changes will be announced within the app.

12. Contact

Questions or requests about this privacy policy? Contact us at:
lizada.christopher@gmail.com