Rasda · رصدةOfficial legal pages

Privacy Policy

Privacy Policy · سياسة الخصوصية

Version: 3.3 Last updated: 19 September 2026

English

1. Introduction

Rasda helps small and medium businesses manage sales, inventory, and receipts. Store and customer records stay on your device. If you choose to send feedback from the rating prompt, only that feedback is stored in Firebase for review and product improvement.

This policy explains the data the app handles, where it is stored, who can access it, and your rights. Displaying this policy is a processing notice, not blanket consent; we ask separately before enabling optional analytics or app news.

2. Operator and data controller

Omar Alkhatib
Karl-Imhoff-Weg 24
30165 Hannover
Germany

For privacy, rights, or complaint enquiries: kh249918@gmail.com.

3. Data processed locally

The app processes data you enter and stores it locally in the app's isolated storage:

  • Store and owner names, mobile number, email, address, country, and currency.
  • Tax number, commercial registration number, and VAT rate.
  • Products, categories, sale and cost prices, quantities, and barcodes.
  • Suppliers, purchase orders, inventory movements, expenses, cash register, and quotations.
  • Orders and receipts, including items, amounts, payment methods, status, and dates.
  • Customer data you enter, such as name, mobile or WhatsApp number, social account, shipping address, and deferred amounts.
  • Interface preferences, user role, and business sector.

4. Optional and technical data

  • Feedback: only after you select and confirm “Send feedback”, Firebase Firestore stores the feedback text, app version, operating-system type, and a review status. We do not request your name or customer data.
  • Optional analytics: Firebase Analytics remains disabled until you make a separate explicit choice to allow it. If allowed, it processes fixed screen names and general events about feature usage, onboarding, Free limits, and the Pro funnel, plus an installation identifier, sessions, platform and version data, and an approximate region that may be inferred from the network address. We do not send customer names or phone numbers, product names, order or invoice contents, store sale amounts, profits, debts, or free text. The SDK may automatically collect supported Pro purchase events with the Pro product identifier, price, and currency.
  • Optional app news: when enabled, Firebase Cloud Messaging uses an installation identifier, receiving token, and technical data to deliver general notifications through Google and APNs. We do not upload the token to our own database.
  • Update checks: Firebase Remote Config supplies Android version numbers and a general update message.
  • Security: Firebase App Check processes app/device integrity information and verification tokens to protect Firebase connections.
  • Pro: Google Play or Apple and RevenueCat process the product identifier, purchase record, and entitlement data needed to complete and restore the purchase.

5. What we do not collect

  • No Rasda account or password.
  • No precise location or device coordinates.
  • No access to contacts, photos, or files unless you explicitly select an item or function.
  • No payment-card data; payment method is stored only as text such as cash, card, transfer, or deferred.
  • No advertising, advertising identifiers, advertising personalisation, Firebase setUserId, or custom user identifier. Limited analytics is off before your decision and remains off if you decline.
  • No transfer of your products, customers, receipts, or business amounts to Firebase, RevenueCat, Google, or Apple.

6. Storage, backups, and sharing

Sales, inventory, and settings data is stored locally in isolated app storage. This is currently the only source of those records; there is no hidden cloud copy. The Rasda operator cannot view, retrieve, or restore them for you. Automatic Android backup is disabled. A manual backup is encrypted using a password that you choose and the app does not retain.

Limited external processing may involve Google/Firebase, Apple, and RevenueCat as described above. When you share a receipt, debt reminder, or encrypted backup, the system share sheet lets you choose the destination app. The shared content then falls under that app's privacy policy.

7. Legal basis, retention, and international transfers

Consent settings and data required to operate the app and fulfil a Pro purchase are processed to perform the contract or take steps at your request. App Check and security tools are used for our legitimate interest in protecting the service. Optional analytics, app news, and feedback rely on your choice and consent.

  • Local records remain until you delete them, the app, or its storage. We have no copy to restore.
  • Firestore feedback currently has no guaranteed automatic deletion period. It remains until deleted after review or after an identifiable deletion request.
  • Analytics, FCM, App Check, and Remote Config retention follows Firebase project settings and Google policies. Purchase records follow Apple, Google, and RevenueCat policies and legal duties.
  • Google, Apple, and RevenueCat may process technical or purchase data outside your country under their infrastructure, contracts, and legal safeguards.

8. Your responsibility for customer data

When you enter customer data, you are the data controller for that data and Rasda is a tool operating on your device. You are responsible for complying with applicable privacy law, obtaining consent where required, using data only for its stated purpose, and deleting it when lawfully requested.

9. Your rights and controls

  • You can view and edit records in the app. Some final transactions cannot be changed to protect accounting consistency.
  • You can export a complete encrypted backup and readable CSV files for products and customers.
  • You can archive products and customers; a product linked to an order cannot be hard-deleted.
  • Full deletion removes local data, settings, images, and temporary files, but not copies saved outside the app, content shared elsewhere, purchase records, or feedback held by external services.
  • You may request deletion of the RevenueCat customer record by email, subject to purchase records Apple or Google may retain under their policies.
  • Feedback has no account or name attached. To request deletion, email its approximate text and sending time so it can be located.
  • You can allow or decline analytics separately and change that choice at any time under Settings → Privacy. Declining or withdrawing consent does not restrict any Rasda feature. Withdrawal stops future optional analytics but does not automatically delete historical Analytics data processed lawfully before withdrawal.
  • You may separately disable app-news consent in Preferences at any time for future processing.
  • If you are in the EU or EEA, you may complain to the data-protection authority for your place of residence or work.

10. Device permissions

The app requests the minimum permissions only when you use the relevant feature: sharing, the system file picker, the system photo picker, camera access for barcode scanning, optional notifications, and optional biometric device locking. The app does not receive your biometric template. A barcode can be entered manually. You can refuse a permission and continue using the remaining features.

11. Children, changes, and contact

The app is intended for business owners and staff and is not directed to anyone under 16. We do not knowingly collect children's data.

We may update this policy when features change data handling. Material changes, such as cloud synchronisation or a new processing purpose, will be announced in the app before implementation, and fresh consent will be requested where required by law.

For a privacy request, email kh249918@gmail.com. We will respond within a reasonable period.