A Ai Matic
Home Privacy Policy Terms of Service Data Deletion Get in touch
Legal

Privacy Policy

Last updated: 15 July 2026

This Privacy Policy explains how Ai Matic ("Ai Matic", "we", "us") handles data in connection with our website (aimatic.tech) and our software: Aimatic POS, Aimatic Sales, Aimatic Shopping, and Aimatic Restaurant. It's written to describe what each application actually does, not a generic template.

The short version

Every Aimatic app connects directly to your own ERPNext server. We do not operate a central server that collects your sales, customer, or catalog data. That data is created, stored, and synced entirely between the app and the ERPNext instance your business controls.

Who controls your data

If your business uses any Aimatic app, your ERPNext instance is the data controller for the sales, customer, and inventory data the app creates — not Ai Matic. Ai Matic builds and, where contracted, maintains the software and, in some cases, hosts the ERPNext server on the business's behalf, but the business itself decides what data is collected from its customers and how long it's retained.

Aimatic POS

Depending on how a given installation is configured, the app handles:

  • ERPNext account credentials or an OAuth2 session — used to authenticate the terminal or the signed-in cashier against your ERPNext server. Passwords are verified by ERPNext itself and are never stored by the app.
  • A randomly generated device identifier — created locally on first install to distinguish physical terminals and prevent duplicate sales during sync. It is not derived from any hardware serial number, advertising ID, or other identifier that could track the device across apps.
  • Sales, catalog, and customer data synced from and to your ERPNext server — item lists, prices, stock levels, customer records, and completed or queued sales — cached locally so the terminal keeps working when the connection drops, and synced back once it's restored.
  • An offline cashier PIN, stored locally as a one-way hash (never in plain text), used only to allow a previously-verified cashier to keep operating the terminal while it's offline.

The Android version requests Camera access, used only to scan a one-time device enrollment code when setting up a new terminal — not used at any other time, and no images are stored or transmitted — plus network access to reach your ERPNext server. It does not request contacts, location, microphone, SMS, or file access outside its own storage.

Aimatic Sales

Aimatic Sales is an employee-facing app for our business customers' own sales staff (Sales User / Sales Manager roles), not a consumer app. A salesperson signs in with their individual ERPNext account through a secure login flow (OAuth2 with PKCE) — there is no shared password or API key built into the app. Once signed in, the app handles:

  • The signed-in employee's own ERPNext session, stored securely on the device and never shared with or derived from any other Aimatic app's login.
  • Customer, pricing, and stock data the salesperson is permitted to see in ERPNext — customer names, outstanding balances, credit limits, item prices, and warehouse stock — used to build draft orders.
  • Draft orders kept on the device so a salesperson can keep working without a connection, synced to ERPNext once back online.

The Android version requests Camera access to scan a product barcode when searching for items — never for photos of people — and network access to reach your ERPNext server. It does not collect location/GPS data.

Aimatic Shopping

Aimatic Shopping is a consumer app that lets a business's own customers browse its catalogue and place orders. Creating an account uses ERPNext's own sign-up process; it never links to, or reuses, an existing customer record by guessing from a name, email, or phone number — a new account only ever creates a new customer record. Depending on what you do in the app, it handles:

  • Your account session (a secure OAuth2 login, separate from the POS/Sales apps' own logins), stored in the device's encrypted storage or, on the web version, in your browser's session storage.
  • Your cart, delivery address, and order history — the delivery address is text you type in (a street address), not GPS location tracking.
  • Payment method selection — the first version of Shopping only supports Cash on Delivery and Store Pickup. The app itself never collects card numbers or other online payment details; there is no payment gateway integrated yet.

See "Requesting deletion of your account or data" below for how to have your Shopping account and personal data removed.

Aimatic Restaurant

Aimatic Restaurant is an internal pilot for restaurant waiter order-taking, currently used only for internal testing against sample data. It is not yet distributed on any public app store; if and when it is, this policy will be updated to describe what it collects in production use.

What we don't do

  • We do not include advertising SDKs in any Aimatic app.
  • We do not include third-party analytics or tracking SDKs.
  • We do not sell or share data with third parties.
  • We do not operate a central database of your customers' or your business's sales data.

Requesting deletion of your account or data

This section applies to Aimatic Shopping, the app with real end-customer accounts (Aimatic POS and Sales are used by our business customers' own staff, whose accounts are managed by that business's ERPNext administrator).

You can request deletion of your Shopping account and personal data at any time, three ways:

  • In the app, under Account → Privacy & data → Request Account Deletion.
  • By emailing nabeelmehmood448@gmail.com.
  • Via the dedicated page at aimatic.tech/data-deletion.html.

Submitting a request logs it for the business to review — it is not instant, automatic deletion. Here's honestly what happens: your personal profile data (name, email, phone number, saved addresses) is removed or anonymized. Order and invoice records connected to your account may need to be kept for a period even after your account is deleted, because businesses in Pakistan are legally required to retain sales and tax records for a minimum period regardless of whether the customer who placed the order still has an account. This is the same reason a paper receipt doesn't disappear from a shop's books just because a customer asks — the record-keeping obligation belongs to the business, not to your account.

This website

aimatic.tech does not use tracking cookies or third-party analytics. Our web server keeps ordinary access logs (IP address, requested page, timestamp) for security and troubleshooting, retained for a limited period, and not used for profiling or advertising.

Security

All communication between Aimatic POS and your ERPNext server is required to use HTTPS. On Android, authentication tokens and the offline cashier PIN hash are stored using the device's hardware-backed secure storage (Android Keystore), not in plain application storage.

Data retention and deletion

Locally cached data on a terminal can be cleared by uninstalling the app or repointing it to a different ERPNext server. Data held on your ERPNext server is retained and deleted according to your business's own policies — contact your ERPNext administrator to request deletion of specific records.

Changes to this policy

If this policy changes, we'll update the "last updated" date above. Material changes will be reflected here before they take effect.

Questions about this policy or how a specific installation handles data: nabeelmehmood448@gmail.com

A Ai Matic

ERPNext implementation & custom POS development.

Home Privacy Policy Terms of Service Data Deletion nabeelmehmood448@gmail.com

© Ai Matic. All rights reserved.