Privacy Policy - BizDesk
Last updated: 12-Sep-2026
Effective date: 05-Jul-2026
1. Overview
BizDesk is an offline-first business management application for retailers, traders, distributors, service providers, freelancers and small businesses.
BizDesk is provided by [insert legal operator’s name], operating under the Hashtake Labs brand (“we”, “us” or “our”).
This policy explains what information BizDesk processes, where it is stored, how it is used and the choices available to you.
Features vary by app version. Sections describing account registration, mobile verification and cloud profile storage apply when those features are available and used.
2. Information Stored on Your Device
BizDesk stores operational business records locally on your device, including:
-
Products, inventory and stock movements.
-
Sales, purchases, invoices, collections and payments.
-
Staff information and attendance records.
-
Customer, supplier and credit records.
-
Financial reports, settings and selected attachments.
These operational records are not automatically uploaded to our Firestore profile database merely because you verify your number or save your business profile.
If you enable Google Drive backup, your backup may contain these records and other data included by the backup feature.
3. Account and Mobile Verification Information
In versions supporting accounts, BizDesk uses Firebase Authentication to verify your mobile number and sign you in.
Information processed for this purpose includes:
-
Your mobile number, including country code.
-
A unique Firebase account identifier.
-
Authentication status and account-related timestamps.
-
Technical information used by the authentication provider to secure sign-in and prevent abuse.
When you request an OTP, your number is submitted to Google to provide phone authentication. Google also stores and uses phone numbers submitted for this service to improve spam and abuse prevention across Google services, including Firebase.
We request your consent before initiating phone verification. OTP codes are used for verification and are not stored as business-profile fields.
Verifying a mobile number confirms access to that number. It does not verify the legal identity or ownership of a business.
4. Business Profile Information Stored in the Cloud
In versions supporting cloud profiles, selecting Save Profile saves your profile locally and submits the supported profile information to Google Cloud Firestore, linked to your authenticated account.
This information may include the following fields you provide:
-
Business name and owner name.
-
Contact number and email address.
-
Business type.
-
Area, postal code, state and country.
-
Number of staff.
-
Tax identification and business registration numbers.
-
Currency preferences and employee-code prefix.
We also store your account identifier, verified phone number, profile creation and update timestamps, and records of the Terms and Privacy Policy versions acknowledged during setup.
Optional fields are identified in the app. Location details entered in your profile are provided by you; entering them does not give BizDesk access to your device’s GPS location.
A locally selected business logo remains on your device unless a separate upload feature is provided and disclosed. Its local file path is not a publicly accessible image address.
Cloud profile storage is separate from a complete backup of your business records.
5. How We Use Information
We use information to:
-
Verify mobile numbers and provide account access.
-
Save and update your business profile.
-
Provide the business-management features you use.
-
Perform backup and restore operations you request or enable.
-
Respond to support, account-access and deletion requests.
-
Maintain security and investigate misuse.
-
Record acceptance of applicable terms and privacy notices.
-
Meet applicable legal obligations.
We do not sell or rent your personal or business information. We do not use your business records for targeted advertising.
We do not request your OTP through support emails or messages.
6. Internet and Offline Use
Operational features are designed to work primarily offline once any required setup is complete.
Internet access is needed for features such as:
-
Mobile OTP verification and account authentication.
-
Cloud business-profile syncing.
-
Google account connection.
-
Google Drive backup and restore.
-
Opening online policy pages or contacting online services.
Where offline syncing is supported, profile changes may be saved locally and transmitted when connectivity returns. Saving locally does not necessarily mean a cloud sync or backup has completed.
7. Google Sign-In and Drive Access
Connecting Google Drive is separate from verifying your mobile number.
When you connect a Google account for backup, BizDesk processes account information such as your Google email address and account identifier to identify the connected backup account.
BizDesk requests the Google Drive permissions needed to manage its backup files. It does not request access to your Gmail messages or Google Contacts for this functionality.
You can manage or revoke the app’s Google account access through your Google account settings. Revoking access may prevent future backups and restores, but does not necessarily delete existing backup files.
8. Google Drive Backup and Restore
Google Drive backup is optional.
When used:
-
Backup files are stored in the app-specific area of your Google Drive account.
-
BizDesk accesses those files using the permissions granted for backup and restore.
-
Backup files are not deliberately made public by BizDesk.
-
We do not use backup contents for advertising or marketing.
Backups may run manually or according to automatic backup settings you enable. Restoring a backup may replace local records with the contents of that backup.
Keep access to the Google account containing your backups and periodically check that important data can be restored.
9. Service Providers and Disclosures
We use Google services for relevant features, including:
-
Firebase Authentication for account authentication.
-
Cloud Firestore for cloud business-profile storage.
-
Google Sign-In and Google Drive API for backup access.
-
App-verification services used by Firebase to protect authentication.
These providers process information necessary to deliver and secure their services. Depending on the service, this can include IP addresses, app or device information, request logs and authentication-related identifiers.
Information may also be disclosed when reasonably necessary to comply with applicable law, respond to lawful requests, investigate fraud or protect users and the service.
Google’s practices are described in its Privacy Policy and Firebase privacy information.
10. Permissions
Depending on the feature and Android version, BizDesk may use:
Internet access: for authentication, profile syncing, backup, restore and other online functions described in this policy.
File or media access: for selecting a business logo or attachment, importing or exporting records, and supported backup or restore operations.
Where Android’s system file or photo picker is used, you choose the files made available to the app.
A mandatory in-app permission request, if needed, will explain its purpose. We will disclose additional data collection before introducing features that require it.
11. Security
We use reasonable technical and organisational measures appropriate to the information processed. Cloud access is intended to be restricted to authorised accounts and personnel who need access to operate or support the service.
No app, device or internet service can guarantee absolute security.
Protect your device with a screen lock, keep verification codes private and avoid sharing account access. A restored local backup is not proof of ownership of a Firebase account.
12. Data Retention
Local records remain on your device until you delete them, clear app storage, uninstall the app or replace them through a restore operation. Copies you export or back up may remain separately.
Cloud account and profile information is retained while needed to provide your account and services, unless you request deletion.
After an ownership-verified deletion request, we delete associated information we control, except information that must reasonably be retained for legal obligations, dispute resolution or security purposes. Such information is retained only for the relevant purpose and period.
Support correspondence is retained while needed to resolve your request and meet applicable obligations. If a retention exception applies to a deletion request, we will explain it where legally permitted.
13. Your Choices and Account Deletion
You can:
-
Review and edit supported business-profile fields.
-
Use the supported Change Number process to update a verified number.
-
Enable or disable optional backup features.
-
Revoke Google Drive access through Google account settings.
-
Request access to, correction of or deletion of information we hold about you.
-
Contact us with a privacy concern or request to withdraw consent.
To request account or cloud-data deletion, email hello@hashtakelabs.com / bizdesk@hashtakelabs.com with the subject “BizDesk Account/Data Deletion”. Provide enough information to identify the account, but never send an OTP or password. We may request additional ownership verification.
Account-enabled versions will also provide an in-app route to initiate deletion. Deletion requests can be submitted through this page’s contact email without reinstalling the app.
Deleting an account does not automatically delete independent exports or backups in your own Google Drive. Uninstalling the app does not itself delete your cloud account.
Withdrawing consent for processing necessary to provide authentication or cloud features may prevent continued use of those features. Rights and any applicable exceptions depend on the law governing your request.
14. International Processing
Google and other disclosed service providers may process information on infrastructure outside your country. Applicable safeguards and provider terms govern that processing.
BizDesk does not promise that all information is stored exclusively in India.
15. Children’s Privacy
BizDesk accounts are intended for business users aged 18 or above. The app is not directed at children.
If you believe a child has submitted personal information directly to us, contact us so we can investigate and take appropriate action.
Business users who enter information about employees, customers or other individuals must have appropriate authority and comply with applicable privacy obligations.
16. Future Features
Pro subscriptions, AI features, credits, notifications and additional recovery methods may be introduced in future versions.
Before collecting additional information or using existing information for a materially different purpose, we will update this policy and provide any required notices, permissions or consent choices.
This policy does not mean those features are currently available. Business records will not automatically be submitted to an AI provider simply because you create an account.
17. Changes to This Policy
We may update this policy to reflect changes to features, processing practices or legal requirements.
The revised policy will display its effective date. We will provide appropriate notice of material changes and request additional consent where required.
18. Contact
For privacy questions, corrections, account deletion or complaints, contact:
BizDesk – Hashtake Labs
Email: bizdesk@hashtakelabs.com
Please describe your concern without including passwords, OTPs or unnecessary confidential business records.