This page describes the data Tejartk collects and how it is used. The app is a business retail tool, not a children’s product. We do not sell your data and we do not use it for advertising or cross-app tracking.
Who we are
The publisher is Al Osmani Technology (العثماني للحلول الرقمية), Khartoum, Sudan. Email: info@alosmanii.com. Phone: +249912927000.
The store listing name is Tejartk / تجارتك. The in-app name is Tijara / تجارة. The bundle ID is com.alosmanii.tijara.
Camera
Camera access is requested only for store operations. We do not record video in the background and we do not use the camera for advertising identifiers.
- Scan product barcodes at the point of sale and on the product form.
- Capture a product photo to attach to the catalog.
- Capture a staff photo saved as an on-device avatar.
Photos and the device library
You can pick an image from the device library instead of using the camera. Images are compressed to JPEG before they are stored.
- Product photos: compressed, then uploaded to Supabase Storage (bucket product-images) when the account is online. Longest edge 1280px.
- Staff avatars: saved locally in the app documents folder (staff-images). They are not uploaded to the cloud in the current release.
- We do not read the photo library except when you choose an image to attach.
Login and accounts
Store builds run in online mode. Sign-in uses email and password through Supabase Auth. There is no social login, and we do not collect an advertising identifier.
- On sign-up: email, password, display name, and organization name.
- After activation: user ID, organization, branch, and roles are stored with the session (JWT in on-device secure storage).
- Staff rows (email, name, roles, branches, optional compensation) are stored so permissions can work.
- The activation or license code is kept in on-device secure storage so the device can join your organization.
Sync and business data
The app works from a local Drift / SQLite database even when the network is down. When connected, changes sync with the Supabase project (database, storage, and realtime).
- Synced data includes: organization and branches, products and stock, clients and suppliers, sales, purchases, payments, expenses, cash-register shifts, and audit logs.
- Pending local product images are uploaded before changes are pushed to the cloud.
- On iOS and Android, periodic background sync may run when the device is connected.
- SQLite backups and report exports (PDF / CSV / Excel) happen only when you ask, then share through the device’s share sheet.
Data we collect
We collect only what the POS and sync features need:
- Account identifiers: email, name, user ID, session tokens, activation codes.
- Business content you enter: prices, stock, invoices, balances, and client or supplier contact details you type in.
- Photos as defined by Apple: product photos (cloud) and staff photos (on-device only).
- Device preferences: language, theme, active branch, and in-app alert toggles (not push notifications).
What we do not collect
We do not request these permissions and we do not collect these categories:
- Precise or coarse location.
- Microphone.
- The device address book (in-app clients and suppliers are business records you enter).
- Advertising, cross-app tracking, third-party analytics, or crash reporters (no Firebase Analytics, Sentry, or Crashlytics on the store path).
- Children’s data. The app is for business retail use.
Sharing and processors
We do not sell data. The cloud processor for store builds is Supabase (authentication, database, storage, and realtime).
We do not share data with advertising networks. We may disclose data if Sudanese law or the processor’s jurisdiction requires it.
Supabase privacy policyRetention and deletion
Organization data stays in the cloud while the account is active. Signing out or uninstalling the app does not by itself erase the organization’s server-side data.
To request deletion of an account or organization data, email info@alosmanii.com from the registered address. We will verify identity, then delete or de-identify what we can in our systems and at Supabase within a reasonable period.
Security
Cloud traffic uses HTTPS. Remote data access requires authentication. Database access policies scope rows to the organization after sign-in. Session and activation tokens are stored in on-device secure storage, not in plaintext inside the app.
Your rights and contact
You can view and correct your business data in the app. For privacy questions, a copy of your data, or deletion, email info@alosmanii.com or call +249912927000. Public address: Khartoum, Sudan.
Changes to this policy
Last updated: 8 September 2026. If we make material changes, we will post the new version at this same URL. Continued use of the app after publication means you have had a chance to review the update.