MyShop NG is an offline-first point-of-sale and shop-management app. Much of the shop's operational data is stored locally on the user's device. Cloud account, subscription, shop, product-image, notification, referral and limited diagnostic information is processed only as described below. We do not sell personal data or use it for targeted advertising.
1. Who this policy applies to
This Privacy Policy describes how MyShop NG ("MyShop NG", "we", "us" or "our") handles information when you use the MyShop NG mobile application, website and connected services. MyShop NG is a business tool intended for shop owners and people authorised by them. It is not directed to children.
For privacy questions or requests, contact support@myshopng.com.
2. Information you provide
Depending on the features you use, you or an authorised member of your business may provide:
- account information such as name, email address, authentication credentials and verification codes;
- shop information such as business name, contact details, address and optional location coordinates;
- product information including names, codes, barcodes, categories, prices, costs, quantities and optional product images;
- sales and operational information including baskets, sales, pending sales, payment-method categories, receipts, refunds, adjustments, shifts and stock movements;
- optional customer information entered by the business, such as a customer name or phone number;
- staff information including names, roles, permissions and locally protected PIN credentials;
- subscription and transaction references associated with payments;
- promoter information including referral codes, referral relationships, earnings, payout requests and payout-account details;
- feedback, complaints and testing reports, including the subject and message, email address, optional name, rating, app version and device model you submit through our feedback page.
The business using MyShop NG is responsible for having an appropriate basis to enter and use information about its customers and staff.
3. Information stored on the device
MyShop NG is designed to continue supporting shop operations when connectivity is unreliable. Products, inventory, sales, customers, staff, shifts, settings and other operational records may be held in the app's local database. Notification messages and their read or hidden state may also be cached locally so the inbox remains available offline. Staff PINs and cloud session credentials are protected using appropriate local hashing or secure-storage mechanisms.
You may deliberately export, print, save or share backups, receipts, reports, quotes, invoices or product information. Once you send information to another app, person, printer, storage location or sharing service, that recipient's privacy practices also apply.
4. Information processed in the cloud
Cloud services are used to provide account authentication, profiles, owned shops, device registration, subscriptions, notifications, referral and payout functions, encrypted shop-location data, application-update policies, and supported synchronisation features. Product images selected for cloud sync are stored in a private, access-controlled storage area. Local file paths are not uploaded as product data.
Operational shop data that is eligible for cloud synchronisation may be transmitted when you enable or use the relevant cloud feature and an internet connection is available. We process this information to provide continuity, backup, multi-device or multi-shop functionality and account-level services.
5. Location
With your permission, the app may access precise or approximate location while you are using it so you can fill your shop's coordinates. Location access is optional, is not used for background tracking, and is used only for the user-facing shop-location feature. Coordinates sent to our backend are encrypted at rest. You can deny or withdraw location permission through your device settings.
6. Product images, files, printing and sharing
When you choose these functions, the app may use a photo or file picker to select product images, use file access to import or export backups and reports, and invoke device printing or sharing services. The app does not require unrestricted access to all files on your device. A camera may be made available through the system image picker when supported and chosen by the user.
6A. Notifications
If notification support is available, the app creates a random installation identifier and obtains a Firebase Cloud Messaging registration token. We may process that token together with the platform, app version, release channel, notification-enabled status and, when a cloud account is connected, the relevant profile and shop identifiers. Local installations without a cloud account may still receive general MyShop NG announcements.
Notifications may include service announcements and shop-sync activity. A shop-sync notification can identify the staff member who performed the sync, the shop name and a summary count of accepted changes. Notification campaigns, delivery outcomes and sync-notification events may be recorded for reliability, duplicate prevention, administrative auditing and support. Invalid delivery tokens may be marked inactive.
For cloud-connected shops, notification messages are retained in the cloud inbox for up to 90 days. Read and hidden status is maintained separately for each authenticated staff user. Choosing Delete hides an inbox item for that staff user and does not erase it for coworkers. Cached notification information remains on the device until it expires, is hidden or removed, the app's data is cleared, or the app is uninstalled, subject to device backup behaviour.
Notification previews are controlled partly by Android. Depending on your lock-screen settings, a notification may display its title, message, staff name or shop name before the device is unlocked. You can disable notifications or hide sensitive lock-screen content in Android settings. Notification inbox content inside MyShop NG remains protected by normal staff PIN authentication.
7. Diagnostic and usage information
Telemetry-enabled releases may create a random installation identifier and record limited technical or workflow events, such as app route, staff-role category, event time, sign-in result, sale completion, refund or void, shift activity and stock-count progress. Limited event metadata may include a payment-method category, sale line count or whether a discrepancy reason was supplied.
Diagnostic events are designed not to contain customer or staff names, phone numbers, PINs, passwords, verification codes, receipt text, product images, database files, prices, costs, profits, quantities or transaction amounts. We use this information for security, reliability, fault investigation, support and product improvement—not advertising or credit decisions.
8. How we use information
We use information to:
- create and secure accounts and verify identity;
- provide POS, inventory, reporting, receipt, staff and shop-management functions;
- support offline operation, synchronisation, backup and account recovery;
- manage subscriptions and verify payment status;
- operate the promoter programme, calculate qualified rewards and process payout requests;
- review feedback, investigate complaints and testing reports, improve the product, and contact you when you permit follow-up;
- provide support, communicate service information and send transactional emails;
- protect the service, prevent abuse, diagnose failures and improve features;
- comply with legal obligations and enforce applicable terms.
9. Service providers and disclosure
We use service providers that process information on our behalf to operate MyShop NG:
- Supabase for authentication, PostgreSQL database services and private product-image storage;
- Render for hosting the MyShop NG backend;
- Firebase Cloud Messaging, provided by Google, for Android push-token registration and notification delivery;
- Paystack for subscription-payment processing and transaction verification;
- Google services where a telemetry-enabled release sends limited diagnostic events to a restricted developer-controlled resource;
- email-delivery providers to send verification codes, account notices and subscription messages.
We may also disclose information when required by law, to protect users or the service, in connection with a business reorganisation subject to appropriate safeguards, or when you direct us to share it. We do not sell personal information and do not share it with data brokers or for cross-context behavioural advertising.
Payment-card details are entered into and handled by Paystack's payment environment. MyShop NG receives transaction references and payment status needed to activate and administer subscriptions; we do not store complete card details.
10. Retention
Local operational records remain on the device until they are deleted through the app, removed by clearing app storage, or removed when the app is uninstalled, subject to device or operating-system backup behaviour. Cloud notification inbox messages expire after 90 days. Push-installation records are updated as devices register and may be deactivated when a token becomes invalid or notifications can no longer be delivered. Other cloud information is retained while your account is active and for as long as reasonably necessary to provide the service, resolve disputes, prevent fraud, meet accounting or legal obligations, and enforce agreements.
Diagnostic information is periodically deleted or anonymised when it is no longer needed for the purposes described above. Notification campaign and delivery audit records may be retained as reasonably necessary for security, support, duplicate prevention and service accountability. Payment and payout records may be retained where required for financial, tax, fraud-prevention or legal compliance. When retention is legally required, the information is restricted to the relevant purpose.
11. Security
We use safeguards appropriate to the nature of the information, including HTTPS in transit, access controls, private storage policies, secure token storage, protected local PINs, encryption of shop-location and payout-account information, and restricted administrative access. Firebase service-account credentials are kept on the backend and are not included in the mobile app. No storage or transmission system can be guaranteed to be completely secure.
12. Your choices and rights
Depending on applicable law, you may ask to access, correct or delete information associated with your account, object to or restrict certain processing, or withdraw consent where processing relies on consent. You may manage notification and location permissions in Android settings, hide sensitive notification previews through Android lock-screen settings, and choose whether to use optional cloud, image, export, printing or sharing functions.
Send privacy requests to support@myshopng.com. We may need to verify that you are authorised to act for the relevant account or business.
13. Account and data deletion
Shop owners can initiate complete cloud-account deletion from Settings → Security in the MyShop NG app after completing fresh email verification. The deletion process removes the Supabase authentication account, cloud product images and profile-owned cloud database records. Local POS records are retained as an offline Free workspace so that deleting a cloud identity does not unexpectedly erase the business's on-device books; those local records can be removed separately by clearing app data or uninstalling the app.
Promoters who do not have a shop account can delete their promotion details from the promoter dashboard. When the same profile also owns a shop, complete deletion must be initiated in the mobile app so the user can review the effect on both parts of the account.
If you cannot access the in-app deletion tools, email support@myshopng.com with the subject “MyShop NG account deletion request.” We will verify the request before deleting associated cloud information, subject to the limited retention obligations described above.
13A. Notification data deletion
Complete cloud-account deletion also removes associated push installations and notification inbox records. Limited campaign, delivery, security, payment or audit records may be retained where reasonably necessary or legally required as described above. Local notification cache can be removed by clearing the app's data or uninstalling the app, subject to device backup behaviour.
14. International processing
Our service providers may process information in countries other than the country where you use MyShop NG. Where required, we use contractual and technical safeguards intended to protect information during such processing.
15. Changes to this policy
We may update this policy when MyShop NG, its service providers or applicable requirements change. We will revise the effective date and provide additional notice through the app, website or store listing when a change is material.
16. Contact us
Questions, complaints and data requests can be sent to:
MyShop NGsupport@myshopng.com
https://myshopng.com