Information we process
- Account and store information such as store name, owner/staff name, mobile number, optional email, role, subscription status, and password hash.
- Cash-in and cash-out records such as provider, amount, service fee, reference number, customer/account name, date and time, notes, staff attribution, wallet opening balances, cash adjustments, and daily closings.
- Images voluntarily captured or selected by the user, including transaction proofs and subscription payment proofs.
- Technical records needed for security and operations, such as authentication tokens, request status, limited server logs, and AI receipt usage counts.
How information is used
- To authenticate users and provide transaction tracking, reports, reconciliation, subscriptions, staff controls, and support.
- To read receipt details using on-device OCR and, when enabled by the Superadmin and accepted by the user, AI-assisted receipt reading.
- To detect duplicate references, validate balances, investigate errors, protect accounts, and maintain an audit trail.
AI-assisted receipt reading
Local ML Kit OCR is used first. When OpenAI-assisted reading is enabled in TindahanPay settings, a compressed copy of the selected receipt image and local OCR text may be transmitted through the TindahanPay server to the OpenAI API solely to extract structured receipt fields. The Android app never contains or receives the OpenAI API key. Temporary server copies created for AI processing are deleted after the request finishes. Users can review and edit all extracted fields before saving.
Sharing
Information is shared only with service providers needed to operate the app, such as the hosting provider and, when AI reading is enabled and used, OpenAI as an AI-processing provider. TindahanPay does not sell user data and does not use third-party advertising SDKs in the supplied Android app.
Security and retention
Connections use HTTPS, passwords are stored as one-way hashes, the OpenAI API key is stored only on the server in encrypted form, and access is controlled by account roles. Transaction and subscription information is kept while the account is active and until the user deletes the account, except information that must be retained for fraud prevention, security, dispute resolution, or applicable legal obligations. Account-deletion audit records retain only one-way hashes and deletion timestamps.
Your controls
- Review and correct OCR/AI results before saving.
- Change your password and manage staff access.
- Delete a user account from the app. Store owners can delete the entire store account and associated data.
- Use the public account deletion page even when the app cannot be accessed.
Contact
For privacy questions, account deletion, or data concerns, email support@tindahanpay.online.