Norilo Privacy Policy
This policy explains how Norilo, provided by tanzeelsam-code, handles information through the Android application (package com.norilo.app), its optional cloud services, and the direct-ordering and order-tracking experience used by participating businesses. The merchant workspace can be used entirely offline. Direct-ordering customers can check out as guests or optionally create a Norilo customer account.
Information we handle
- Owner and customer account information: email address or phone number, authentication records handled by Supabase Auth, account and workspace identifiers, business name supplied by an owner, and an optional customer profile name and phone number.
- Business and staff information: business name, contact details, address, tax or food-license identifiers, menu or catalogue, pricing, staff names and contact details, roles and PIN hashes, inventory, suppliers, printer settings, expenses, cash sessions, reports, and storefront or integration settings.
- Customer and order information: customer or recipient name, phone number, optional email, saved or one-time delivery address and landmark, favourite stores, reservations, order contents and history, table number, scheduled time, notes, promotions, loyalty or khata activity, feedback, rider details, order status, and an opaque order-tracking token.
- Optional location: a direct-ordering customer may press Use my location and grant permission to add precise latitude and longitude to a delivery order. The Android app does not request Android location permission, and a typed delivery address can be used instead.
- Transaction information: prices, discounts, tax, tips, fees, totals, refunds, payment-method labels, payment status, and optional payment references. Norilo does not collect payment-card or bank-account credentials and does not itself move money. Cash, Raast, Easypaisa, JazzCash, and card labels record or present the merchant's chosen method only.
- Marketplace information: for a business that connects Foodpanda, the service receives the customer, delivery, item, instruction, payment-method label, and order-status information that Foodpanda supplies for that marketplace order. It returns the external order identifier and fulfilment, cancellation, and delivery status required to operate that order.
- Technical and security information: a random local installation identifier, authentication session data, synchronization timestamps and status records, integration events, and error information. The direct-ordering API converts a request IP address into a secret-salted one-way hash for abuse prevention; it does not store the raw address in its application request log.
How information is used
We use information to provide point-of-sale and retail operations, staff access, customer profiles and saved details, online and table-QR ordering, private order history, order preparation and delivery, customer support, receipts and printing, inventory, loyalty and khata records, reports, authentication, cloud synchronization, backup, fraud and abuse prevention, and account or data-deletion support. We do not use third-party advertising SDKs, build advertising profiles, or sell personal information.
Offline and cloud storage
In offline mode, business information stays in the app's private storage on the Android device. Android cloud backup is disabled for the app. If an owner enables a cloud account, the app sends account and selected business-operation data over encrypted HTTPS connections to the production Supabase project so the workspace can synchronize between sessions and devices. If a customer creates an account, Supabase stores the login, profile, saved addresses, favourites and the link to that customer's direct orders. Direct, table-QR, and connected marketplace orders are stored in the merchant workspace so authorized staff can fulfil them.
Service providers and other disclosure
- Supabase provides authentication, hosted database, Edge Functions, and synchronization infrastructure and processes data on our behalf.
- Website hosting and content-delivery providers serve the support and customer-ordering pages. They may process ordinary HTTP information, such as IP address, browser type, requested page, and security logs, under their service terms.
- Foodpanda is an independent marketplace, not an advertising provider for Norilo. When a merchant enables the integration, Foodpanda supplies marketplace-order information and receives the status of those Foodpanda orders. Direct-store customer orders are not sent to Foodpanda. Foodpanda handles information under its own privacy policy.
- User-chosen services may receive content only when a user deliberately opens a WhatsApp/share action or follows instructions to pay with an external bank or wallet. Those services process information under their own terms.
Information may also be disclosed when required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards. We do not share information with data brokers or advertising networks. Service providers may process data in countries other than the user's country, subject to their contractual and security safeguards.
Retention and deletion
Offline data remains on the device until the user deletes it, clears app storage, or uninstalls the app. Cloud workspace and order records remain while needed by the participating business for operations, support, accounting, dispute handling, or legal obligations. Salted storefront request hashes are used only for rate limiting and security and are periodically purged. Hosting and security providers may keep restricted logs and disaster-recovery copies for their normal retention cycles.
An authenticated owner can use More → Settings → Privacy & account → Permanently delete account to delete the login, every workspace owned by that account, and associated synchronized business and direct-ordering data. A request can also be started from the account deletion page. Information controlled separately by Foodpanda or another user-chosen service must be deleted through that provider. Records may be retained only where required for security, fraud prevention, dispute resolution, or applicable law.
An authenticated customer can open Customer ordering → Account → Delete account to remove the customer login, profile, saved addresses and favourites. Completed transaction records that the merchant must retain may remain, but the deleted authentication identifier is detached from those orders. Guest orders remain managed through the receiving business and the support process described on the deletion page.
Security
Norilo uses HTTPS for cloud traffic, Android private app storage for local data, row-level access controls for cloud records, hashed staff PINs, secret-backed integration authentication, rate limiting, opaque public tracking tokens, and release signing. No security system is perfect, so users should protect their devices and credentials and avoid putting unnecessary sensitive information in free-text fields.
Children
Norilo is a business operations service intended for adults and authorized business staff. It is not directed to children under 13, and the Google Play app does not target children.
Your choices and contact
Cloud sync and customer accounts are optional, guest checkout remains available, optional customer fields can be left blank, and a direct-ordering customer can type an address instead of sharing location. Business owners control the operational information entered into their workspace and are responsible for giving staff and customers any additional notice required by local law. A customer can edit account details in the customer portal; for a guest order or a retained transaction record, contact the business that received the order or the support address below.
For privacy questions, access or correction requests, or deletion help, email vconnect0021@gmail.com.