Privacy Policy
Last Updated: July 19, 2026This policy explains how Mechia collects, uses, stores, discloses, and deletes information when you use the Mechia mobile application, public storefronts, and related cloud services. Mechia is designed for business operators and is not directed to children.
1. Information We Collect
The information collected depends on the features you choose to use:
- Account and profile information: name, email address or phone number, account identifier, profile image, authentication records, role, and notification preferences.
- Business, staff, and customer information: business name and address, contact details, branding, staff roles, customer or guest details, bookings, notes, and support messages entered by you or an authorized business user.
- Operational and financial information: inventory, purchases, sales, payment references, expenses, receivables, payables, payroll, audit history, appointments, reservations, and other records needed to provide the selected business modules.
- Sensitive module information: optional records entered in features such as clinic or pharmacy workflows may include patient, prescription, or other health-related information.
- Location: precise or approximate location when you use a location-dependent feature, such as attendance verification, and network-derived location used for security or service configuration.
- Photos and files: optional logos, profile images, product images, support attachments, prescriptions, or business documents that you choose to upload.
- Device and diagnostics: app installation identifiers, push-notification tokens, device and operating-system information, app interactions, crash reports, performance diagnostics, IP address, and security logs.
2. How We Use Information
- Provide authentication, account management, cloud synchronization, storefronts, bookings, payments, reports, notifications, and customer support.
- Protect accounts, enforce tenant isolation, prevent abuse and fraud, and maintain audit trails.
- Diagnose crashes, measure app reliability, configure features, and improve the service.
- Meet legal, tax, accounting, and regulatory obligations that apply to us or to a business using Mechia.
We do not sell personal data and do not use personal data for cross-app advertising or tracking.
3. Storage and Security
Mechia stores offline working data in the app's protected device storage and synchronizes eligible records to our cloud services when cloud features are enabled. Network traffic is encrypted in transit using TLS. Cloud records are protected by tenant-scoped access controls, including database row-level security. Authentication secrets and tokens use operating-system protected storage where supported.
4. Service Providers and Disclosures
We use service providers only to operate requested features. These may include Supabase-compatible infrastructure for authentication, database and Edge Functions; Cloudflare services for network protection and object storage; Google Firebase for analytics, crash reporting, remote configuration and push notifications; payment providers such as Flutterwave or Mobile Money operators; and email, SMS, or WhatsApp providers selected for communications. Payment information sent to a payment provider is handled under that provider's privacy terms. We may also disclose information when required by law or to protect users and the service.
5. Retention and Account Deletion
We retain active account and business information while the account is in use and as needed to provide the service. Security logs, deletion-verification records, and records subject to legal obligations may be kept for a limited period. Routine encrypted backup copies are isolated from normal use and expire under a rolling retention schedule.
Account owners can initiate deletion inside Mechia under Settings > Account > Delete account. People who no longer have the app can use our web account-deletion page. After identity verification, we delete the account and associated cloud data unless a specific record must be retained by law. Deleting cloud data does not remove copies previously exported by the user or independently held by a payment or communications provider.
6. Your Choices and Rights
Depending on your location, you may request access, correction, export, restriction, objection, or deletion of personal data. You can change many account and business records directly in the app, control optional device permissions in system settings, and disable push notifications through the app or device settings.
7. International Processing
Our service providers may process information in countries other than the country where it was collected. Where required, we use appropriate contractual and technical safeguards for international transfers.
8. Changes and Contact
We may update this policy when our services or legal obligations change. The date above identifies the latest version. For privacy questions, use the support channel in the app or visit our support page. For account deletion, use the dedicated deletion request page.