SmartCoupon — Privacy Policy

_Last updated: 12 August 2026_

SmartCoupon is a tool for shopkeepers. This policy describes what the app

collects, why, and how to get rid of it. It is deliberately short, because the

app deliberately collects very little.

You must host this at a public URL and enter that URL in the Play Console.

Google requires a privacy policy link for every app, and an app that collects

an email address or phone number cannot be published without one. A GitHub

Pages URL or a page on your own site is fine.


Who is responsible

SmartCoupon is operated by AxionX Digital, Ahmedabad, Gujarat, India, which

is the data controller for the information described here.

Contact: softwarebelieve@gmail.com

Write to that address for any question about this policy, to request a copy of

your data, or to have it deleted.

What is collected, and why

Your sign-in identifier — a phone number or an email address.

Used only to sign you in and to keep you signed in. Stored by our

authentication provider (Supabase). Without it there is no account.

**Your shop details — name, language, country, category, and the phone number

you choose to print on your cards.**

The name and phone number appear on the vouchers you send, because that is the

point of them. The language and country decide which script and currency the

app uses.

**Your offers and redemptions — the offers you create, the codes issued

against them, and each redemption's amount, time, outlet and staff name.**

This is the shop's own trading record. It is what the console shows you and

what settles an argument at the counter.

Staff names you enter. So a receipt says who took the redemption. Staff do

not have accounts and are not tracked.

What is *not* collected

card is drawn on the phone and handed straight to WhatsApp. The image is

never uploaded. Only the text of a post is recorded.

for them and does not read them.

not ask for them and does not read them.

give a phone number so their code can be found again; that number is stored

against the voucher and nothing else.

Analytics and crash reporting

The app uses Google Firebase Analytics and Crashlytics, and only for

understanding whether the product works: how far a new shop gets in setup,

which offer types are used, and — most of all — which of the redemption

verdicts cashiers actually hit, because that tells us which wording confuses

people at a counter.

What is sent is deliberately narrow:

template, redemption reason, whether the till was offline, language and

country.

takings are its own business and are never sent.

(model, OS version, coarse country), which it collects by default.

What is never sent: your shop name, your phone number, your address, staff

names, voucher codes, customer phone numbers, or any photograph. This is

enforced in code by an allow-list of permitted parameters and covered by an

automated test, not by convention.

Crashlytics receives stack traces when the app fails, so the failure can be

fixed. Those contain no shop or customer data.

If Firebase is not configured for a given build, none of this runs at all.

Permissions

Camera — used only to scan a voucher's QR code at your counter. Nothing is

recorded or uploaded; the camera is read to find a code and closed. The

permission is optional: a shop can type codes by hand and never grant it.

Where the data lives

In a Supabase project (PostgreSQL) operated by the controller named above.

Access is restricted by row-level security so a shop can read only its own

rows. Traffic is encrypted in transit.

How long it is kept

For as long as the shop exists, and then for up to 30 days after you delete

it — see below.

Deleting your data

In the app: Settings → Delete my shop.

Two things happen, at different speeds, and both are deliberate:

cannot sign in again, and the shop, its offers, vouchers, redemptions and

posts disappear from the app entirely.

That 30-day window exists so a shop deleted by mistake can be restored on

request, and so a dispute or a report of abuse raised just before deletion can

still be investigated. During it the records are not used for anything else and

are not visible in any app. After it, they are gone and cannot be recovered by

us or by you.

If you want the records destroyed sooner than 30 days, email the contact

address above and say so; we will action it and confirm.

To request deletion without using the app, email the contact address from the

address the account uses. Requests are actioned within 30 days.

Children

The app is for business use and is not directed at children.

Changes

Material changes will be noted here with a new date at the top.