Effective date: 17 May 2026 Last updated: 17 May 2026
This Privacy Policy describes how BizTrackr (“the app”, “we”, “our”) handles information when you use the mobile application on your Android or iOS device. We are committed to keeping the app simple, transparent, and respectful of your data.
If you do not agree with this Privacy Policy, please do not use BizTrackr.
BizTrackr is published by HNB Software Labs (“we”), based in the Philippines.
You can contact us at:
For matters specifically related to the Philippine Data Privacy Act of 2012 (RA 10173), our designated point of contact is the same email above.
To be unambiguous, BizTrackr does not collect, transmit, or have any ability to read any of the following:
If we add crash reporting in a future version, this policy will be updated and an in-app notice will appear before any reports are sent.
The app stores the following on your device only, when you choose to enter it:
This data is stored in the app’s private storage area on your device. It is not transmitted off the device by the app itself.
When you enable App Lock:
EncryptedSharedPreferences
backed by a hardware-backed key; iOS Keychain with
kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly).The information you enter is used solely to provide the in-app features you actively use:
We do not use this information for any other purpose. We do not analyse it, profile you, or build advertising audiences from it.
BizTrackr asks for the following operating-system permissions. You can revoke any of these at any time in your device settings; the app will continue to work, with the related feature disabled.
| Permission | When it is requested | What we do with it |
|---|---|---|
| Camera | First time you tap the barcode-scanner button in Add Product or POS | Used only to decode product barcodes in real time. No frames are recorded or transmitted. |
| Photo library / Photos | First time you add or edit a product photo | Lets you select an image from your library. The chosen image is copied to the app’s private storage. We do not access photos you have not explicitly picked. |
| Face ID / biometrics | First time you enable “Use biometric unlock” in Settings | Used solely to unlock the app. Matching is performed by iOS / Android; we never receive your biometric data. |
The app does not request location, contacts, calendar, microphone, Bluetooth, notifications, or any other permission.
All BizTrackr data is stored locally on your device:
filesDir/products/ on Android, Documents/ on
iOS), accessible only by BizTrackr.No copy of your data is held by us, by our hosting provider (we have none), or by any cloud service — unless you export or share it as described below.
BizTrackr only ever sends data off your device when you initiate it.
When you tap Share Receipt after a sale, the receipt is rendered as a PNG image and handed to the operating system’s share sheet. You then choose where to send it (Messages, Mail, Save to Files, etc.). BizTrackr has no knowledge of where you send it or who the recipient is.
When you tap Export backup… the app produces a single backup file
(.btb) containing your store profile, products, categories, and sales.
This file is encrypted on your device before it leaves the app. We use AES-256-GCM with a key derived from a passphrase you choose (PBKDF2-HMAC-SHA256, 200,000 iterations). The passphrase is never stored or transmitted; only you can decrypt the backup. If you lose the passphrase, the backup cannot be recovered — not even by us.
You decide where the encrypted backup file goes (Files, Google Drive, iCloud Drive, email, etc.). Once it leaves the app, the destination service’s own privacy policy applies.
When you tap Restore from backup…, you pick a backup file. If the
file is an encrypted .btb, the app prompts you for the passphrase and
decrypts on-device. The contents are then loaded into the local
database. No part of the backup is transmitted off the device.
BizTrackr’s user-visible features are all on-device. The libraries we use are open-source and do not phone home in the configuration we ship.
We do not integrate any advertising SDK, analytics SDK, attribution SDK, A/B-testing SDK, or crash-reporting SDK. If this changes in a future version we will update this policy and clearly disclose the service in advance.
BizTrackr is a business tool intended for adult shopkeepers and entrepreneurs. It is not directed at children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect any information from children. If you believe a child has been using the app, simply uninstall it — there is no online account to delete.
Because all your data is stored locally on the device under your control, you exercise your data rights directly through the app and your device:
.btb for inspection elsewhere.If you have created encrypted backups stored on a cloud service (Drive, iCloud, etc.), please consult that service’s own controls to manage those copies.
We follow security practices appropriate to a local-only application:
EncryptedSharedPreferences with hardware-backed
master keys on Android).No security system is perfect. If you suspect a vulnerability, please email us at henry.dev09@gmail.com.
Because BizTrackr does not collect personal information as a Personal Information Controller (PIC) or Processor (PIP), most provisions of the Data Privacy Act do not impose specific obligations on us. Nonetheless, we publish this policy in keeping with the spirit of the Act and the National Privacy Commission’s transparency principles. If you believe your rights under the Act have been affected by use of the app, you may contact the National Privacy Commission: https://www.privacy.gov.ph/.
If you are in the EEA, UK, or Switzerland, no personal data leaves your device through BizTrackr, so no cross-border transfer occurs. We do not have, and do not act as, a controller or processor for any data about you under the GDPR. Where you have created backups stored on a third-party cloud service, that service is the controller for any data it holds.
We do not sell, share, or otherwise disclose personal information about California consumers. Because we do not collect such information in the first place, your rights to access / delete / opt-out under the CCPA have nothing to act on.
We may update this Privacy Policy from time to time — for example, when we add or change a feature. The “Last updated” date at the top will reflect any change. Material changes will be announced in the app before they take effect. Continued use of the app after an update means you accept the updated policy.
For privacy questions, requests, or concerns:
If you do not receive a satisfactory response, you may also contact the relevant data-protection authority in your country.
This document is provided for transparency. It is not legal advice. Before publishing, have it reviewed by a qualified lawyer familiar with your jurisdiction, especially if you operate in or accept users from the EU, the UK, California, or other regions with specific data-privacy statutes.