Privacy Policy
PhoneStock mobile application
Last updated: August 5, 2026
1. Introduction
PhoneStock ("we", "us", or "our") provides a subscription software service
for second-hand and refurbished mobile phone retailers. The PhoneStock Android app helps shop
owners and staff manage inventory, record purchases and sales, generate invoices, maintain
dealer and cash ledgers, assign tasks, and export business reports.
This Privacy Policy explains what information we collect, how we use it, how we protect it,
and the choices available to you. By creating an account or using the app, you agree to this
policy. If you do not agree, please do not use PhoneStock.
PhoneStock is operated by Asquare Tech Lab. For privacy-related questions, contact us using
the details in Section 12.
2. Information We Collect
2.1 Account and authentication data
- Mobile phone number — used for one-time password (OTP) sign-in via Firebase Phone Authentication.
- Staff user profiles — names, mobile numbers, role assignments, and permission settings created by the store owner.
- Session tokens — stored securely on your device to keep you signed in.
2.2 Store and business profile data
- Store name, address, city, state, pincode, and optional logo.
- Owner name and owner mobile number.
- GSTIN, GST billing preferences, invoice prefix, and invoice terms text.
- Bank account details (bank name, account number, IFSC, account holder name) used on invoices when you choose to display them.
- Branch details, including branch names, addresses, contact email, and print template settings.
2.3 Transaction, inventory, and ledger data
- Purchase and sale records, including phone brand/model, RAM, storage, colour, condition, and IMEI numbers.
- Invoice numbers, dates, amounts, payment modes, margins, tax calculations, and accessories information.
- Customer names, mobile numbers, and addresses entered by you at the time of a transaction.
- Dealer balances, cash ledger entries, cash receipts, and cash payments.
- Stock levels, recycle-bin (soft-deleted) records, and exported backup files you generate.
- Task assignments, comments, checklists, and status updates when the Tasks module is enabled for your store.
2.4 Photos, documents, and signatures
When you choose to attach media, we collect and store the files you upload, such as:
- Customer photographs.
- Identity proof images and ID proof numbers you enter.
- Digital signatures captured in the app.
- Store or branch logos and optional invoice attachments.
These files are uploaded to secure object storage (Cloudflare R2) and linked to your business
records. We do not access this content for advertising or marketing.
2.5 Device and technical data
- Firebase Cloud Messaging (FCM) device token — to deliver push notifications such as subscription reminders and task alerts. You can disable notifications in your device or app settings.
- App version and basic device information — as needed to operate the service and troubleshoot issues.
- Camera access — used only when you scan barcodes/IMEI or take photos within the app. We do not access the camera in the background.
- Biometric authentication — if you enable App Lock, fingerprint or face unlock is processed locally on your device by the operating system. Biometric data is not transmitted to or stored on our servers.
2.6 Payment and subscription data
- Subscription plan, renewal dates, and payment status for your PhoneStock license.
- Razorpay order and payment identifiers when you pay through the in-app payment flow.
- UPI or other payment references you provide for manual subscription renewal, if applicable.
We do not store full credit or debit card numbers. Card and UPI processing is
handled by Razorpay and their banking partners according to their own privacy policies.
2.7 Data you do not need to provide
Many fields are optional. You decide what customer, dealer, and business information to
enter. You are responsible for ensuring that you have a lawful basis to collect and store
customer and identity information under applicable law.
3. How We Use Your Information
We use collected information solely to:
- Authenticate users and manage store and staff accounts.
- Provide inventory, invoicing, ledger, reporting, backup export, and task management features.
- Generate PDF invoices and business reports you request.
- Send service-related push notifications and subscription reminders.
- Process subscription payments and maintain billing records.
- Protect the security of the platform, prevent abuse, and enforce subscription access rules.
- Respond to support requests and improve reliability of the service.
We do not sell your personal data. We do not use customer
contact details or uploaded ID proofs for third-party marketing.
4. How We Share Information
We may share information only in the following circumstances:
-
Service providers — with vendors that help us run PhoneStock, including
cloud hosting, database providers (MongoDB), object storage (Cloudflare R2), Firebase
(authentication and messaging), and Razorpay (payments). These providers process data on
our instructions and for the purposes described in this policy.
-
Within your store — staff users you invite can access data according to
the permissions assigned by the store owner (for example, view-only vs. manage access).
-
Legal requirements — when required by law, regulation, court order, or
governmental request, or to protect the rights, safety, and security of users and the
service.
-
Business transfers — in connection with a merger, acquisition, or sale of
assets, subject to continued protection of your information.
We do not share your business data with advertisers or data brokers.
5. Data Storage, Location, and Security
Your account and business data are stored on secure servers accessed through authenticated
APIs. Uploaded media is stored in encrypted object storage. API requests require an
application key and a valid authenticated session token.
Store app accounts and our internal admin operations use separate authentication systems.
Admin staff access to production data is limited to operational and support needs.
While we use industry-standard safeguards, no method of transmission or storage is completely
secure. You are responsible for keeping your device secure and not sharing OTP codes or
session access with unauthorised persons.
6. Data Retention and Deletion
-
Active business records remain available while your subscription is active or during any
read-only grace period after expiry, as described in our Terms of Service.
-
Deleted purchases and sales are placed in the Recycle Bin (soft delete) until permanently
removed by an authorised user.
-
Backup exports you generate are downloaded to your device; we do not retain copies solely
because you exported a backup.
-
We retain payment and billing records as needed for accounting, tax, and legal compliance.
You may request deletion of your store account and associated data by contacting support.
We will honour deletion requests subject to legal retention obligations and any outstanding
payment or dispute resolution needs.
7. Your Choices and Rights
- Account data — update store profile, branch settings, and staff permissions in the app.
- Notifications — manage push notification permission on your device.
- App Lock — enable or disable biometric lock in app settings.
- Backups — export your ledger and stock data at any time using the backup tool.
- Deletion — contact us to request account or data deletion.
Depending on your location, you may have additional rights under applicable privacy laws
(such as access, correction, or objection). Contact us to exercise these rights.
8. Children's Privacy
PhoneStock is a business application intended for shop owners and adult staff. We do not
knowingly collect personal information from children under 13 (or the minimum age required
in your jurisdiction). If you believe a child has provided us personal information, contact
us and we will take steps to delete it.
9. Third-Party Services
The app integrates with third-party services that have their own privacy policies:
Links opened from the app (for example, WhatsApp, email, or phone dialer for support) are
handled by those third-party apps and services.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will
update the "Last updated" date at the top of this page and, where appropriate,
notify you through the app or by other reasonable means. Continued use of PhoneStock after
changes become effective constitutes acceptance of the revised policy.
11. Contact Us
For privacy questions, data access requests, or account deletion requests, contact: