Who we are
My Shop Diary is published by Ultimate Software Private Limited, Chhutmalpur, Saharanpur, Uttar Pradesh, India 247662. For any question about this policy, write to supportmasihigroup@gmail.com or call 9719969828.
Grievance officer under India's Digital Personal Data Protection Act: Draft name to be added. Until then, complaints go to the email address above.
What stays on your device
The app keeps your business records in your browser or app storage on the device you use (technically, IndexedDB):
- Your shop details, GSTIN, logo, signature and payment QR
- Customers and suppliers, their phone numbers and balances
- Items, rates, batches and expiry dates
- Bills, purchases, payments and expenses
- Patient records in Doctor, Hakeem or Clinic mode
If you uninstall the app or clear your browser data without a backup, these records are gone. That is why the app reminds you to take a backup.
What reaches our server, and why
| Information | When | Why |
|---|---|---|
| Email address; name from Google if you sign in with Google | Every sign-in | To sign you in and to send you a 6-digit sign-in code |
| Shop name, phone, email, city, state, whether GST is on, app version and language | Only if you switch on usage sharing in Settings (off by default) | To know which shops use the app and to support them |
| Daily counts of bills, entries, items and parties (numbers only) | Only if you switch on usage sharing | To understand how much the app is used |
| Your books: all records listed above | Only if you switch on Cloud sync or Cloud backup | So that devices joined to your shop see the same books, and so you can restore them |
| A catalogue order: items, quantities, your note, shop name, phone and city | Only when you place an order from the supplier catalogue | So the supplier can fill your order |
| An Enterprise enquiry: company, contact details and message | Only when you send the enquiry form | To reply to you |
Your mobile number is saved on your device as your shop's identity. It reaches our server only through usage sharing, a catalogue order or an enquiry.
Our server is a Supabase database in Mumbai, India. Database rules allow only the devices joined to your shop to read your cloud books. We do not sell your data and we do not open your books, except to help you when you ask for support.
Outside services
- Supabase stores sign-in accounts, the shared information above and, if you turn them on, your cloud books and backups.
- Google delivers the sign-in code email (through Gmail), handles Google sign-in if you choose it, and serves the website's fonts, so Google sees your device's IP address when the page loads.
- Netlify hosts the website and the app files.
- Meta (WhatsApp Cloud API) and Groq are used only if you add your own keys in the CRM settings of Ultra Advance. Messages, customer phone numbers and the text you send to the AI assistant then go from your device to those services. The keys stay on your device.
- When you share a bill, the app opens WhatsApp, SMS or your UPI app with the message filled in. Those apps follow their own privacy policies.
Backups
A backup file is created by you and kept wherever you choose: your phone, your computer, WhatsApp or Google Drive. If you put a password on it, it is encrypted (AES-GCM) and cannot be opened without that password. Cloud backup, when you turn it on, keeps a copy in a private storage area of our server that only devices joined to your shop can read.
Permissions the app asks for
- Photos and files: only when you pick a logo, a receipt photo or a price list to import. The file is read on your device.
- Fingerprint or face unlock: optional. Your fingerprint never leaves the phone; the app stores only a device-issued credential ID.
- Camera: optional, only when you tap Scan to read a barcode. The picture is read on the phone and is not saved or sent.
- Contacts: optional. The phone shows its own picker and only the contact you choose is filled in.
- Notifications: optional daily reminders about money due or patient visits, made on the phone itself.
- The app does not ask for your location or microphone.
Advertising and tracking
There are no ads, no advertising networks, no analytics SDKs and no third-party trackers in My Shop Diary.
How long we keep it
- Records on your device: until you delete them or clear the app.
- Your sign-in account and anything linked to your number or email on our server: until you ask us to delete it. Deletion requests are handled as described on the Delete account page.
- Usage counts and events: Draft retention period to be decided.
- Cloud books and cloud backups: until you delete them, sign out of the cloud and ask us to remove them, or close your account. Draft period after an account is closed to be decided.
Children
My Shop Diary is a tool for running a business and is not intended for anyone under 18.
Your rights
- See and export your data: it is all inside the app. Settings, Backup gives you the whole file, plus CSV exports.
- Withdraw consent: switch off usage sharing in Settings at any time, and sign out of the cloud to stop sync.
- Delete: Settings, Erase all data removes everything from the device. To remove what our server holds, email us from the address you signed in with.
- Complain: write to the email above. If you are not satisfied, you may approach the Data Protection Board of India.
Keeping it safe
The app and website are served only over HTTPS with a strict Content-Security-Policy. You can lock the app with a PIN or fingerprint. Server access is limited by database rules for each shop, and administrator access uses a separate sign-in. No app can promise it is unbreakable. Draft How and when users are told about a data breach is to be confirmed.
Changes
If this policy changes, the date at the top changes with it, and the new version appears at this same address.