Overview
This Privacy Policy describes how Patrido Multimedia ("we," "us," or "our") collects, uses, and protects your information when you use the Pocket Shop Manager mobile application.
We are committed to ensuring your business data remains private and secure, in alignment with global best practices and the Nigeria Data Protection Regulation (NDPR).
1 Data Ownership (Offline-First Philosophy)
We believe your business data belongs exclusively to you. Pocket Shop Manager is designed as an offline-first application.
All inventory records, sales transactions, debt lists, and staff records are stored locally on your mobile device. Patrido Multimedia does not host, view, or process your primary business ledgers on our servers.
Single Business Profile
Each Pocket Shop Manager account is designed around one business profile. Your inventory, sales history, staff records, and tax records are stored together as a single entity on your device. If you operate more than one shop, each location requires its own separately registered account.
2 Information We Collect
A. User Account Information
When you choose to use cloud backup or Pro features, we collect your email address via Google OAuth solely to identify your backup identity. No other personal data is collected for this purpose.
B. Security Verification Data
To facilitate Master Code recovery, we collect answers to three user-selected security questions — the process by which a business owner can regain access to their account if they forget their 6-digit Master Code.
- These questions and answers are chosen voluntarily by the business owner during setup or in Settings.
- Your answers are hashed and stored locally on your device and are not visible to or accessible by any staff members under your account.
- They are synced via a highly encrypted
security_vault.jsonfile to both your Firebase profile and your private Google Drive, solely for emergency account recovery and multi-device authentication. - They are not used for marketing, shared with third parties, or used for any purpose beyond account recovery.
C. Business Compliance Data
Based on your selected business structure, you may optionally input your CAC Registration Number and Tax Identification Number (TIN). This data remains locally encrypted and is only used to format your invoices and local tax computations.
D. Device Identity Metrics
We generate and store a stable, anonymous Device ID in your phone's local storage. This is used exclusively to enforce the 14-day trial period limit and prevent fraudulent trial extensions.
E. Device Permissions
- Camera: Used to scan barcodes and capture images of products and receipts.
- Storage / Media: Required to save PDF business reports and manage local database files on your device.
- Network: Used only for voluntary cloud sync, app updates, and license verification. The app functions fully without network access.
3 Customer Data for Invoicing
Voluntary Collection
The app allows you, as the shop owner, to optionally record customer names and phone numbers for the purpose of issuing digital invoices via WhatsApp. Providing this information is entirely voluntary — customers are never required to share their contact details.
Storage
All customer contact data collected through the app is stored locally on your device. Patrido Multimedia does not have access to your customers' names or phone numbers at any time.
Usage
Customer phone numbers are used strictly for invoice delivery via WhatsApp and internal debt tracking. You, as the business owner, are responsible for ensuring your customers are comfortable with providing this information and for using it appropriately.
4 AI Business Advisor
How the AI Advisor Works
Pocket Shop Manager includes an AI Business Advisor feature that analyzes your shop's data — sales trends, inventory levels, expense patterns, and debt records — to generate actionable business insights directly on your dashboard.
Data Privacy in AI Features
- All AI analysis is performed on-device using locally stored data.
- No customer names, transaction amounts, or financial data are transmitted externally.
- AI-generated insights are displayed only to the logged-in business owner (Master Code holder).
- Staff members logged in with their individual PINs do not have access to AI insights.
Accuracy Disclaimer
AI-generated insights are recommendations only and are based entirely on the data you have entered into the app. The quality of insights is directly dependent on the accuracy and completeness of your records. These insights should be used as a management aid, not as definitive financial or business advice.
4 External Hardware (Printers)
Bluetooth & Network Access
The app requires permission to access Bluetooth and your Local Area Network (LAN) specifically to discover and communicate with thermal or wireless printers connected to your device or shop network.
Pocket Shop Manager supports standard ESC/POS Bluetooth thermal printers and Wi-Fi network printers. The app does not store your network credentials or transmit any data outside your local network during printing.
5 Google OAuth & Drive Integration
If you enable Google Drive Backup, the app requests permission to access only the specific files and folders it creates within your Drive.
- We cannot see your personal photos, documents, or any other files in your Google Drive.
- Data synced to your Drive is transferred via secure HTTPS encryption.
- Your encrypted backup exists in your personal Google Drive — not on Patrido Multimedia servers.
6 Staff Personnel Data
What We Store
Pocket Shop Manager allows business owners to create staff accounts containing the following information: staff name, assigned role or position, optional profile photo, and a unique login PIN. This data is used solely to enable staff access control within the app and to attribute sales transactions to individual employees for accountability purposes.
Storage
All staff personnel data is stored locally on your device and, if cloud backup is enabled, encrypted within your private Google Drive. Patrido Multimedia does not access, process, or store staff information on our servers.
Business Owner Responsibility
As the business owner and the data controller for your staff's information, you are responsible for obtaining appropriate consent from each staff member before entering their personal details into the app. This includes informing them that their name, role, and photo (if added) will be stored on the device used to manage your business and may be included in backup files stored in your personal Google Drive.
7 Security Question Verification
Your three security questions and answers are a private, owner-only security credential that enables Master Code recovery in the event that a business owner loses access to their account.
- Your answers are visible only to the account owner — not to staff, and are hashed before being stored.
- They are accessed by Patrido Multimedia only upon a formal, user-initiated recovery request submitted via our support channel.
- We recommend choosing questions and answers that only you would know, rather than facts easily guessed by staff or family.
- You are responsible for remembering your answers. Forgotten security answers may result in permanent loss of access to your account if your Master Code is also forgotten.
8 Data Retention and Deletion
Because your data is stored locally on your device, deleting the application will delete all local business records unless you have performed a cloud backup to your Google Drive.
If you choose to delete your account, we will remove any stored identifiers (email address / UID) from our authentication server within 30 days of your request.
9 Security Measures
We use industry-standard encryption for data in transit to protect your information during cloud sync operations.
However, you are responsible for the physical and digital security of your device. We provide a secondary 6-digit master code feature, protected by strict lockout limits and strong PBKDF2 hashing, for shop protection — please ensure this code remains confidential and is not shared with unauthorized individuals.
10 Your Rights (NDPR)
Under the Nigeria Data Protection Regulation (NDPR), Nigerian users have the following rights regarding their personal data:
- The right to access your data
- The right to object to processing of your data
- The right to request correction of inaccurate data
- The right to deletion of your account identifiers
As your business data is stored locally on your device, you can fulfill most of these rights yourself by manually editing or exporting your records directly within the app.
To exercise your rights regarding any data held on our authentication servers, please contact us using the details below.
Contact Information
For questions, concerns, or requests regarding this Privacy Policy or your data rights, please reach out to our support team: