Norilo Privacy Policy

Effective and last updated: 30 August 2026

This policy explains how Norilo, provided by tanzeelsam-code, handles information through the Android application (package com.norilo.app), its optional cloud services, and the direct-ordering and order-tracking experience used by participating businesses. The merchant workspace can be used entirely offline. Direct-ordering customers can check out as guests or optionally create a Norilo customer account.

Information we handle

How information is used

We use information to provide point-of-sale and retail operations, staff access, customer profiles and saved details, online and table-QR ordering, private order history, order preparation and delivery, customer support, receipts and printing, inventory, loyalty and khata records, reports, authentication, cloud synchronization, backup, fraud and abuse prevention, and account or data-deletion support. We do not use third-party advertising SDKs, build advertising profiles, or sell personal information.

Offline and cloud storage

In offline mode, business information stays in the app's private storage on the Android device. Android cloud backup is disabled for the app. If an owner enables a cloud account, the app sends account and selected business-operation data over encrypted HTTPS connections to the production Supabase project so the workspace can synchronize between sessions and devices. If a customer creates an account, Supabase stores the login, profile, saved addresses, favourites and the link to that customer's direct orders. Direct, table-QR, and connected marketplace orders are stored in the merchant workspace so authorized staff can fulfil them.

Service providers and other disclosure

Information may also be disclosed when required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards. We do not share information with data brokers or advertising networks. Service providers may process data in countries other than the user's country, subject to their contractual and security safeguards.

Retention and deletion

Offline data remains on the device until the user deletes it, clears app storage, or uninstalls the app. Cloud workspace and order records remain while needed by the participating business for operations, support, accounting, dispute handling, or legal obligations. Salted storefront request hashes are used only for rate limiting and security and are periodically purged. Hosting and security providers may keep restricted logs and disaster-recovery copies for their normal retention cycles.

An authenticated owner can use More → Settings → Privacy & account → Permanently delete account to delete the login, every workspace owned by that account, and associated synchronized business and direct-ordering data. A request can also be started from the account deletion page. Information controlled separately by Foodpanda or another user-chosen service must be deleted through that provider. Records may be retained only where required for security, fraud prevention, dispute resolution, or applicable law.

An authenticated customer can open Customer ordering → Account → Delete account to remove the customer login, profile, saved addresses and favourites. Completed transaction records that the merchant must retain may remain, but the deleted authentication identifier is detached from those orders. Guest orders remain managed through the receiving business and the support process described on the deletion page.

Security

Norilo uses HTTPS for cloud traffic, Android private app storage for local data, row-level access controls for cloud records, hashed staff PINs, secret-backed integration authentication, rate limiting, opaque public tracking tokens, and release signing. No security system is perfect, so users should protect their devices and credentials and avoid putting unnecessary sensitive information in free-text fields.

Children

Norilo is a business operations service intended for adults and authorized business staff. It is not directed to children under 13, and the Google Play app does not target children.

Your choices and contact

Cloud sync and customer accounts are optional, guest checkout remains available, optional customer fields can be left blank, and a direct-ordering customer can type an address instead of sharing location. Business owners control the operational information entered into their workspace and are responsible for giving staff and customers any additional notice required by local law. A customer can edit account details in the customer portal; for a guest order or a retained transaction record, contact the business that received the order or the support address below.

For privacy questions, access or correction requests, or deletion help, email vconnect0021@gmail.com.