Privacy Policy
This policy explains what information we collect, how we use it, and your choices. Replace the contact details below with your bakery’s real email before publishing.
1. Who we are
The Cake Spot / CakeHub apps are operated by The Cake Spot (“we”, “us”). Contact: malihasameer.235@gmail.com
2. Apps covered
- The Cake Spot — package
com.ovais.thecakespot— ordering for customers - CakeHub — package
com.ovais.thecakespot.admin— staff operations (authorised bakery team only)
3. Information we collect
Depending on which app you use and the permissions you grant, we may process:
- Account data — name, email, phone number, and sign-in identifiers when you register with email/password or Google Sign-In (Firebase Authentication).
- Order & profile data — cart/wishlist contents, delivery addresses, order history, notes, payment status flags, and (for CakeHub) customer contact details needed to fulfil orders.
- Location — approximate or precise location when you set or confirm a delivery address on a map (Android location permission).
- Device & push data — device identifiers and push notification tokens via OneSignal so we can send order updates and (for staff) new-order alerts.
- Diagnostics — crash logs and performance data via Firebase Crashlytics; limited analytics via Firebase Analytics (app usage events).
- App configuration — bakery settings such as currency, bank transfer instructions, and social links stored in Firebase Firestore / Remote Config.
We do not process card payments inside the apps. Checkout shows bank-transfer details configured by the bakery.
4. How we use information
- Create and manage your account
- Place, track, and fulfil bakery orders
- Show the menu, banners, and delivery options
- Send transactional push notifications (order status, new orders for staff)
- Improve reliability (crash reporting) and understand basic product usage
- Secure the apps and prevent abuse (including staff-only access checks in CakeHub)
5. Legal bases (where applicable)
We process data to perform the contract (orders and account), with your consent where required (e.g. notifications, location), and for legitimate interests such as security and app stability.
6. Sharing
We share data with service providers who process it on our behalf:
- Google Firebase — Authentication, Cloud Firestore, Analytics, Crashlytics, Remote Config
- OneSignal — push notification delivery
- Google Sign-In — if you choose to sign in with Google
Bakery staff using CakeHub can see customer order details needed for fulfilment (name, phone, address, items, notes). We do not sell personal information.
7. Data retention
Account and order data are kept while your account is active and as needed for bakery records, legal obligations, and dispute handling. Crash and analytics data are retained according to Firebase / OneSignal provider defaults unless we configure shorter retention.
8. Security
We use industry-standard protections provided by Firebase and Android, including encrypted transit (HTTPS). No method of transmission or storage is 100% secure.
9. Children’s privacy
The apps are not directed at children under 13 (or the minimum age in your country). We do not knowingly collect personal information from children.
10. Your rights & choices
- Update profile details in the app where available
- Revoke location or notification permissions in Android settings
- Request access, correction, or deletion by emailing us
- Delete your account by contacting support (we will remove or anonymise personal data where legally allowed)
11. International transfers
Firebase and OneSignal may process data in data centres outside your country. Their safeguards apply under their respective terms and privacy policies.
12. Changes
We may update this policy. The “Last updated” date will change when we do. Continued use after an update means you accept the revised policy where permitted by law.
13. Contact
Privacy questions: malihasameer.235@gmail.com
Support: malihasameer.235@gmail.com