Privacy Policy
Last updated: September 17, 2026
1. What this covers
This policy explains what osStore collects when you use Retailerpros, why, and what your rights are. In short: we collect what’s needed to run the Service, we don’t sell personal data, and your business records belong to you.
2. Information you give us
- Account details — your name, work email, password (stored only as a hash), and business/store names.
- Business records you create — products, inventory (including IMEIs), sales, invoices, repairs, and the customer records your business keeps in the Service. For that data your business is the controller; we process it on your behalf.
- Payment details — collected and stored by Stripe, our payment processor. Your full card number never touches our servers.
3. Information collected automatically
- Sign-in and security data — session tokens, sign-in timestamps, and failed-attempt counts, used to protect accounts.
- Service logs — standard technical logs (IP address, browser type, requests) kept for security and troubleshooting.
We use browser storage only to keep you signed in and remember preferences like your selected store — not for advertising, and we don’t use third-party advertising trackers.
4. How we use information
- To provide and secure the Service — the only reason your business records are processed.
- To bill you (via Stripe) and send transactional email like password resets and receipts (via Resend).
- To respond to support requests and to notify you about your account or material changes to the Service.
We do not sell personal data, and we don’t use your business records for advertising.
5. Who we share it with
Only service providers necessary to run the product, each bound to use data solely to provide their service to us:
- Stripe — subscription payments.
- Resend — transactional email delivery.
- Google — when you use the mobile register’s “Snap IMEI photo” button, the photograph is sent to Google’s Gemini API to read the IMEI printed on it. The image is used only to return that text and is not used to train Google’s models.
- Expo — push-notification delivery and over-the-air app updates for the mobile apps.
- Cloud hosting and storage providers — running the Service and storing its database, backups, and uploaded images.
We may also disclose information if the law requires it, or in a merger or acquisition (your data stays under this policy or one at least as protective).
6. Supplier Restock Alerts
If Supplier Restock Alerts is on (the default), the platform operator — your supplier — can see your low-stock rows: product name, brand, quantity on hand, and your threshold, along with your business name and the account owner’s name and email so they can reach you. Nothing else from your records is included — not sales, customer lists, costs, or prices. Turn it off anytime in Settings and the sharing stops immediately.
7. The mobile apps
Our iOS apps collect the same account and business data described above, and three things specific to a phone:
- Camera — the register can scan the IMEI barcode on a handset or its box. Scanning happens on the device. If you tap “Snap IMEI photo” instead, the photograph is uploaded and passed to Google’s Gemini API to read the IMEI out of it, then discarded once the text is returned. The camera is never used in the background, and photographs are not added to a library or shared with anyone else.
- Notification token — if you allow notifications, the device registers a push token so we can send the day’s summary, low-stock alerts and new dealer applications. The token identifies the device, not you personally, and is deleted when you sign out. Declining notifications changes nothing else in the app.
- Customer details you enter at the register — when your staff ring up a walk-in sale they may record the customer’s name, phone number and email so the invoice can be sent. Those records belong to your business; we process them on your behalf, exactly as with the rest of your business records.
The apps contain no advertising, no analytics or attribution SDK, and no tracking of any kind across other companies’ apps or websites.
8. Security
Data is encrypted in transit (HTTPS), passwords and reset tokens are stored only as cryptographic hashes, each business’s data is isolated from every other tenant’s, and staff access within your business is limited by the roles you assign. No system is perfectly secure, but we treat your records as what they are: the operating history of your business.
9. Retention and deletion
Your data is kept while your account is active, and retained after cancellation so you can resubscribe without losing anything. You can request full deletion of your account and its data at any time via support@phillyphonesdistributor.com; we’ll complete it within 30 days, except records we must keep by law (for example, billing records).
10. Your rights
You can view and correct your information directly in the app, and export your sales, repair, and inventory reports to CSV. For a copy of your remaining records, or to have them deleted, contact us and we’ll take care of it. Depending on where you live you may have additional statutory rights; we honor requests regardless of geography.
11. Children
The Service is for businesses and isn’t directed at children under 16; we don’t knowingly collect their data.
12. Changes and contact
If we make material changes to this policy we’ll notify you by email or in-app before they take effect. Questions or requests: support@phillyphonesdistributor.com.