Privacy Policy
Effective 24 September 2026 · Applies to the Businessly app on Android
(com.zak.businessly) and on Windows.
Businessly is a digital khata for small shopkeepers. This policy explains what data the app handles, why, who processes it, and how you can delete it. It is written to match what the app actually does.
1Who we are
Data controller: Zubair Ahmed Khan (individual developer). For privacy questions and data-deletion requests: appzubair@gmail.com.
2What we collect and why
Your ledger
Customers, suppliers, sales, purchases, payments, balances, cash, expenses, products, bills, rent, installments, loans, your Zakat worksheet, business names and settings — the records you create.
Stored in an encrypted database on your device. If you sign in, it is also synced to our server, so it is safe if your device is lost or broken and so your other devices can reach it. The app does not ask for access to your Google Drive and stores nothing there.
If you never sign in, none of it leaves your device.
To decide what to build next, we also count, across all accounts, what kinds of businesses people create and which parts of the app they use — for example, how many accounts have an installment plan. These are totals only: they contain no names, no amounts, no phone numbers and nothing you typed. The server adds them up automatically; no person reads your entries to produce them.
Account details
When you sign in, we hold the email address you signed in with, and — for Google sign-ins — your display name and Google user ID, to authenticate you and tie your ledger to your account.
Contacts
Only on Android, and only when you tap Import from contacts. We read just the contact you pick, and it becomes part of your ledger entry. We never upload your contact list. On Windows, contacts are not accessed at all.
Anonymous device count
Once a day the app reports an anonymous device identifier, the platform, the app version and the OS version, so we can count how many devices use Businessly and tell a returning device from a new one.
The identifier is a one-way hash of a value your operating system already assigns to the device. The original value never leaves your device, the hash cannot be reversed, and it is not linked to you, your account or your ledger. It survives reinstalling the app — which is what lets us count devices rather than installs — and changes on a factory reset.
Error reports
When showing the banner advert, or asking for your ad-consent choice, fails (Android only), the app sends a short technical report so we can find and fix the problem. It holds the error code and error message from Google's ad software, the app version, the platform, the operating-system version (on Android this can include the phone's build name), and the same anonymous device identifier described above.
When signing in fails (Android and Windows), the app sends a report that holds codes only: the kind of failure (for example "no internet" or "could not make a secure connection"), the sign-in step, the server's short error code, and for a secure-connection failure the security library's fixed reason (for example "certificate has expired"), plus the same app version, platform, operating-system version and anonymous device identifier. It does not contain the error message or the email address you were signing in with. If the report cannot be sent at the time, the device keeps it for up to 7 days and sends it the next time the app starts.
A report never contains your ledger, your email or your account, and it is not linked to your account. It is sent whether or not you are signed in, because these failures matter most for people who are not signed in. Only the most recent few reports of the same problem are kept; further repeats are only counted. The app also limits how often it sends reports.
Advertising ID (Android only)
Used by Google AdMob when the app shows its banner advert. The banner appears in a band above the main screens, and on a few individual screens. It is deliberately not shown on a customer's statement. Ads may be switched off entirely, in which case no ad requests are made at all.
The Windows app contains no advertising code and shows no ads.
We do not collect location, photos or messages. Apart from the error reports above, the app sends no crash or usage telemetry, and your ledger is never used for advertising. The app contains no third-party analytics SDKs.
3Who processes your data
- Google — Google Sign-In only, to authenticate you. We request just your email address. No Google Drive access is requested or used. Google's Privacy Policy.
- Supabase — our cloud backend, storing your synced ledger isolated per account, the anonymous device count and the error reports. Hosting region: ap-southeast-1 (Singapore). Supabase's Privacy Policy.
- Google AdMob (Android only) — serves the banner advert and may use your advertising ID to show and measure ads. In the EEA and UK you are shown a consent choice first; without consent, ads are limited or non-personalised. You can reset or delete your advertising ID in Android Settings → Privacy → Ads.
- Brevo — sends the sign-in code when you sign in by email, and the welcome email. It receives your email address for that purpose only.
4How your data is protected
- On your device: the database is encrypted at rest (SQLCipher), on both Android and Windows. The key is held in the operating system's secure storage — the Android Keystore, or Windows DPAPI.
- In transit: everything sent to Supabase and Google travels over HTTPS/TLS.
- On the server: encrypted at rest by Supabase, and access-controlled so only your own account can read your rows.
5How long we keep it
Your synced ledger stays on the server while your account exists. The app also keeps a few recent encrypted snapshots on the device itself. When you delete your data, the server copy is removed.
Error reports: the full report is deleted after 14 days. A grouped summary of each problem — the error code and latest error message, how often it happened, when it was first and last seen, and the latest app version — is kept until that problem has not happened for a year.
6Your choices and your right to delete
- Never sign in, and nothing from your ledger ever leaves the device.
- Sign out — your data stays on the device.
- Save a copy of your book as a file at any time, and keep it wherever you choose.
Delete everything: in the app, Settings → Delete all my data. You are offered two options — remove from this device only, or delete everywhere, which permanently erases your local data and your server-side ledger, and signs you out. Deleting everywhere cannot be undone.
If you have uninstalled the app and cannot use the in-app option, email the address above — see the account & data deletion page.
7Permissions the app requests
- Internet — for sign-in, sync, ads, and opening WhatsApp or links you choose to send.
- Contacts (Android) — only when you tap Import from contacts.
- Notifications (Android) — for the reminders you switch on yourself. These are generated on the device; nothing is sent anywhere.
- Advertising ID (Android,
com.google.android.gms.permission.AD_ID) — used only by AdMob for the banner described above.
8Children
Businessly is a business tool intended for users 18 and over. It is not directed at children.
9Changes to this policy
We update this page and its effective date when the app's data practices change. Material changes are reflected here before the corresponding app version is released.
Note on the Pakistan Personal Data Protection Bill (PDPB): once enacted, this policy will be reviewed for consent, data-subject rights and data-residency alignment.