1Introduction
Recido is a business management application operated by Zintle Technology and developed by Terry Amagboro (Rukkiecodes). We are committed to protecting your privacy and handling your personal data with transparency, integrity, and in full compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other international privacy standards.
This Privacy Policy explains in detail what personal information we collect, why we collect it, how we use it, how we protect it, who we share it with, and what rights you have regarding your data. By using Recido, you acknowledge that you have read, understood, and agreed to the practices described in this policy.
2Information We Collect
Recido collects only the minimum information necessary to provide you with our business management services. We collect the following categories of information:
2.1 Account and Authentication Information
- Email Address: Used for account creation, authentication, password recovery, and important service communications.
- Password: Securely hashed and encrypted using industry-standard cryptographic algorithms. Passwords are never stored in plain text and are not accessible to Recido staff.
- Google Account Information (if using Google Sign-In):
- Google User ID (unique identifier)
- Email address associated with your Google account
- Display name from your Google profile
- Profile photo URL (used temporarily during account setup)
2.2 Business Profile Information
To enable professional document generation, we collect and store the following business information that you provide:
- Business Name: The official name of your business or trading name
- Business Phone Number: Primary contact number (with country code) for customer communication
- Business Address: Physical location, registered address, or operational address of your business
- Business Logo: Image file uploaded by you and stored securely in Firebase Storage (PNG or JPG format)
- Custom Messages: Thank-you notes, greetings, or promotional messages that appear on your business documents
- Business Disclaimer: Legal notices, return policies, terms of sale, or other custom text you wish to include on documents
2.3 Customer Information (User-Generated)
You may add customer information to Recido for the purpose of creating business documents and maintaining customer relationships. This information includes:
- Customer Full Name: Name of the customer or client (required)
- Customer Email Address: Email for sending documents or communications (optional)
- Customer Phone Number: Contact number for follow-ups or delivery coordination (optional)
- Customer Business/Residential Address: Location information for billing or reference (optional)
- Customer Shipping Address: Delivery address if different from primary address (optional)
All customer data you enter is stored securely and is only accessible by you and any sales representatives you authorize. Customer data is private and is never shared with third parties for marketing or advertising purposes.
2.4 Inventory and Product Information
To support your business operations, Recido allows you to manage inventory. We collect and store:
- Product Name: Name or description of the item
- Product Code/SKU: Optional identifier for tracking purposes
- Price: Selling price or cost of the product
- Available Quantity: Stock levels and inventory counts
- Product Description: Additional details or specifications (optional)
2.5 Transaction and Document Data
Recido stores all business documents you create, including:
- Receipts: Transaction records for completed sales
- Invoices: Payment requests with due dates and itemized charges
- Quotations: Cost estimates provided to customers
Each document includes metadata such as document ID, issue date, due date (for invoices), selected items, applied taxes, discounts, shipping fees, and associated customer information.
2.6 Usage and Analytics Data
We may collect limited, anonymized usage data to improve app performance and user experience, including:
- App version and device type
- Operating system version (Android version)
- Crash reports and error logs (anonymized)
- Feature usage patterns (which features are used most frequently)
This data is aggregated, anonymized, and cannot be traced back to individual users.
2.7 Payment Information (if applicable)
If Recido introduces paid subscriptions or premium features in the future, payment processing will be handled by trusted third-party payment processors such as Stripe, Google Play Billing, or Apple App Store. Recido does not collect, process, or store your credit card numbers, bank account details, or other sensitive payment information. We only receive confirmation of successful transactions and subscription status from the payment processor.
2.8 Information We Do NOT Collect
3How We Use Your Information
Recido uses your personal information solely to provide, maintain, and improve our business management services. Specifically, we use your data for the following purposes:
3.1 Core App Functionality
- Account Creation and Authentication: To create your account, verify your identity, and allow you to securely log in to Recido
- Document Generation: To create professional receipts, invoices, and quotations with your business branding and customer information
- Inventory Management: To track product stock levels, monitor sales performance, and provide inventory insights
- Customer Relationship Management: To store customer data you provide, track purchase history, and enable personalized customer interactions
- Business Insights: To generate reports, analytics, and AI-powered suggestions based on your sales and inventory data
3.2 Communication and Support
- Service Communications: To send you important updates about your account, service changes, security alerts, or technical issues
- Customer Support: To respond to your inquiries, troubleshoot problems, and provide technical assistance
- Policy Updates: To notify you of changes to this Privacy Policy, Terms and Conditions, or other legal agreements
3.3 Security and Fraud Prevention
- To detect, prevent, and respond to security incidents, fraud, or unauthorized access
- To protect the rights, property, and safety of Recido, our users, and the public
- To enforce our Terms and Conditions and other policies
3.4 App Improvement and Development
- To analyze anonymized usage patterns and improve app features, performance, and user experience
- To develop new features based on user needs and feedback
- To fix bugs, optimize performance, and ensure app stability
3.5 Legal Compliance
- To comply with applicable laws, regulations, and legal processes
- To respond to lawful requests from government authorities, law enforcement, or courts
- To protect our legal rights and defend against legal claims
4Legal Basis for Processing (GDPR)
For users in the European Union (EU), European Economic Area (EEA), and United Kingdom (UK), we process your personal data based on the following legal grounds under GDPR:
| Processing Activity | Legal Basis |
|---|---|
| Account creation and authentication | Contract performance (providing the service you signed up for) |
| Document generation and business management features | Contract performance |
| Customer support and service communications | Legitimate interest (providing support and maintaining service quality) |
| Security and fraud prevention | Legitimate interest (protecting our users and platform) |
| Anonymized analytics for app improvement | Legitimate interest (improving user experience) |
| Legal compliance and responding to legal requests | Legal obligation |
| Marketing communications (if you opt in) | Consent (which you can withdraw at any time) |
5Data Sharing and Third-Party Services
Recido does not sell, rent, trade, or share your personal information with third parties for their marketing purposes. We only share data with trusted service providers who help us operate the app, and only to the extent necessary. Here's how we share your data:
5.1 Service Providers and Subprocessors
We use the following third-party service providers to help deliver our services:
Google Firebase (Google Cloud Platform)
- Purpose: Cloud infrastructure, database storage (Cloud Firestore), file storage (Firebase Storage), user authentication (Firebase Authentication), and app analytics
- Data Shared: User account data, business information, customer records, inventory data, document data
- Location: Data may be stored on Google Cloud servers in various regions, including the United States and European Union
- Compliance: Google Firebase is GDPR-compliant and certified under ISO 27001, ISO 27018, SOC 2, and SOC 3
- Privacy Policy: https://firebase.google.com/support/privacy
Google Authentication (OAuth 2.0)
- Purpose: Secure sign-in with Google account
- Data Shared: Google User ID, email address, display name, profile photo URL (only basic profile information)
- Privacy Policy: https://policies.google.com/privacy
OpenAI API (for AI features)
- Purpose: AI-powered inventory suggestions and business insights
- Data Shared: Anonymized sales data, inventory trends (no personally identifiable customer information)
- Privacy Policy: https://openai.com/privacy
Google Gemini API (for AI features)
- Purpose: Alternative AI provider for inventory analysis and recommendations
- Data Shared: Anonymized sales and inventory data
- Privacy Policy: https://ai.google.dev/gemini-api/terms
Stripe (if payment features are introduced)
- Purpose: Payment processing for subscriptions or premium features
- Data Shared: Transaction amount, currency, payment confirmation (Stripe processes payment details directly)
- Privacy Policy: https://stripe.com/privacy
Expo Platform Services
- Purpose: App development, updates, and push notifications (if enabled)
- Data Shared: Device tokens, app version, crash reports
- Privacy Policy: https://expo.dev/privacy
5.2 Legal Requirements and Law Enforcement
We may disclose your personal information if required to do so by law or in response to valid legal requests, such as:
- Court orders, subpoenas, or other legal processes
- Requests from law enforcement or government authorities
- Investigations of fraud, security breaches, or violations of our Terms and Conditions
- Protection of the rights, property, or safety of Recido, our users, or the public
We will notify you of such requests unless prohibited by law or court order.
5.3 Business Transfers
If Zintle Technology is involved in a merger, acquisition, asset sale, bankruptcy, or other business transaction, your personal information may be transferred to the successor entity. In such cases, we will notify you via email or prominent notice in the app before your data is transferred and becomes subject to a different privacy policy.
5.4 With Your Consent
We may share your information with other third parties if you explicitly consent to such sharing, and we will clearly explain what information will be shared and for what purpose before obtaining your consent.
6International Data Transfers
Recido is operated by Zintle Technology in the United States, and our infrastructure is powered by Google Firebase, which operates data centers globally. This means your personal information may be transferred to, stored in, and processed in countries outside your country of residence, including the United States, European Union, and other regions where Firebase operates.
6.1 Safeguards for Data Transfers
When we transfer personal data internationally, we ensure adequate protection through the following safeguards:
- Standard Contractual Clauses (SCCs): We rely on European Commission-approved Standard Contractual Clauses for transfers from the EU/EEA to countries outside the European Economic Area
- Adequacy Decisions: We transfer data to countries that have been recognized by the European Commission as providing adequate data protection
- Data Processing Agreements: We have Data Processing Agreements (DPAs) in place with all subprocessors that handle personal data
- Google Cloud Compliance: Google Firebase complies with the EU-U.S. Data Privacy Framework and has implemented appropriate safeguards for international data transfers
7Data Security
We take the security of your personal information seriously and implement industry-standard technical and organizational measures to protect your data from unauthorized access, disclosure, alteration, or destruction.
7.1 Technical Security Measures
- Encryption in Transit: All data transmitted between your device and our servers is encrypted using HTTPS with TLS 1.2 or higher
- Encryption at Rest: All data stored in our databases and file storage systems is encrypted using AES-256 encryption or equivalent
- Password Security: User passwords are hashed using bcrypt or similar secure hashing algorithms with salt. Passwords are never stored in plain text
- Secure Authentication: We use Firebase Authentication, which implements OAuth 2.0 and other industry-standard protocols
- Access Controls: Role-based access control (RBAC) ensures that only authorized users can access specific data. Business owners have full access, while sales representatives have restricted access
- Firewall and Network Security: Our cloud infrastructure is protected by firewalls, intrusion detection systems, and DDoS mitigation
7.2 Organizational Security Measures
- Limited Access: Only authorized personnel with a legitimate business need have access to user data, and all access is logged and monitored
- Multi-Factor Authentication (MFA): Internal administrative accounts require MFA to prevent unauthorized access
- Security Audits: We conduct regular security audits, vulnerability assessments, and penetration testing
- Code Reviews: All code changes undergo security reviews to identify and fix potential vulnerabilities
- Incident Response Plan: We have an incident response plan in place to quickly detect, contain, and respond to security breaches
- Employee Training: Our team is trained on data protection best practices, GDPR compliance, and secure development principles
7.3 Data Breach Notification
In the unlikely event of a data breach that affects your personal information, we will:
- Notify affected users within 72 hours of becoming aware of the breach
- Notify relevant data protection authorities as required by law (e.g., GDPR)
- Provide details about the nature of the breach, the data affected, and steps we are taking to address it
- Offer guidance on how you can protect yourself (e.g., changing passwords)
8Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements.
8.1 Retention Periods
| Data Type | Retention Period |
|---|---|
| Account data (email, password, profile) | Retained as long as your account is active, or until you request deletion |
| Business information (name, logo, address) | Retained as long as your account is active |
| Customer data, inventory, and documents | Retained as long as your account is active, or until you manually delete them |
| Transaction records and invoices | Retained for 7 years for tax and accounting purposes, or as required by law |
| Anonymized usage analytics | Retained indefinitely (cannot be traced back to individuals) |
| Support communications | Retained for 3 years for customer service quality and dispute resolution |
8.2 Inactive Accounts
Accounts that have been inactive for 12 consecutive months (no login or app activity) may be scheduled for automatic deletion. We will send you an email reminder 30 days before deletion, giving you the opportunity to log in and keep your account active.
8.3 Deletion Upon Request
You can request immediate deletion of your account and all associated data at any time by contacting us at privacy@recido.app. Upon receiving your request, we will delete your data within 30 days, except where retention is required by law (e.g., tax records).
9Your Privacy Rights
You have significant control over your personal information. Depending on your location, you may have the following rights under applicable data protection laws:
9.1 Rights Under GDPR (EU/EEA/UK Users)
- Right of Access: You can request a copy of all personal data we hold about you
- Right to Rectification: You can request correction of inaccurate or incomplete personal data
- Right to Erasure ("Right to be Forgotten"): You can request deletion of your personal data, subject to legal retention requirements
- Right to Restriction of Processing: You can request that we limit how we use your data in certain circumstances
- Right to Data Portability: You can request your data in a structured, commonly used, machine-readable format to transfer to another service
- Right to Object: You can object to certain types of processing, such as direct marketing or profiling
- Right to Withdraw Consent: If processing is based on consent, you can withdraw consent at any time without affecting the lawfulness of processing before withdrawal
- Right to Lodge a Complaint: You can file a complaint with your local data protection authority if you believe we have violated your privacy rights
9.2 Rights Under CCPA (California Users)
- Right to Know: You can request information about what personal data we collect, use, disclose, and sell
- Right to Delete: You can request deletion of your personal data, subject to certain exceptions
- Right to Opt-Out: You can opt out of the sale of your personal information (Recido does not sell personal data)
- Right to Non-Discrimination: You cannot be discriminated against for exercising your CCPA rights
9.3 How to Exercise Your Rights
To exercise any of these rights, please contact us at:
- Email: privacy@recido.app
- Subject Line: "Privacy Rights Request - [Your Request Type]"
- Mailing Address: Zintle Technology, Attn: Privacy Team, 7420 Unity Ave N #211, Brooklyn Park, MN 55443, USA
We will respond to your request within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before processing your request to protect your data from unauthorized access.
10Children's Privacy
Recido is not intended for use by individuals under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child without parental consent, we will take steps to delete that information promptly.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@recido.app so we can take appropriate action.
12Third-Party Links and Integrations
Recido may contain links to third-party websites, services, or integrations (such as payment processors, customer support platforms, or social media sharing). This Privacy Policy does not apply to those third-party services.
When you interact with third-party services:
- You are subject to their own privacy policies and terms of service
- We are not responsible for their data collection or privacy practices
- We encourage you to review their privacy policies before providing any personal information
Examples of third-party services you may encounter:
- Google Sign-In: Governed by Google's Privacy Policy
- Stripe (if payment features are added): Governed by Stripe's Privacy Policy
- Email service providers: When you share documents via email, your email provider's terms apply
- Social media platforms: When you share documents on WhatsApp, Facebook, or other platforms, their privacy policies apply
13AI and Automated Decision-Making
Recido uses artificial intelligence (AI) to provide enhanced features such as inventory suggestions and business insights. Here's how we use AI and what it means for your data:
13.1 AI-Powered Features
- Inventory Suggestions: Our AI analyzes your sales history and inventory patterns to recommend when to restock products
- Sales Insights: AI identifies trends such as fast-moving products, seasonal patterns, and customer preferences
- Document Automation: AI may assist with auto-filling document fields based on previous entries
13.2 Data Used by AI
The AI features analyze:
- Your sales data (receipts, invoices, quotations)
- Inventory levels and product performance
- Customer purchase patterns (anonymized)
Important: All AI processing is performed on anonymized or aggregated data. No personally identifiable information (PII) about your customers is sent to AI service providers (OpenAI, Google Gemini). Customer names, emails, phone numbers, and addresses are excluded from AI analysis.
13.3 No Fully Automated Decisions
Recido does not make fully automated decisions that have legal or similarly significant effects on you. All AI-generated suggestions are recommendations only. You maintain complete control over all business decisions, including:
- Whether to restock inventory based on AI suggestions
- Pricing decisions
- Customer interactions and marketing
13.4 AI Transparency and Fairness
We are committed to using AI responsibly:
- AI recommendations are based solely on your business data, not external datasets or biased sources
- We regularly audit AI outputs for accuracy and fairness
- You can always disable AI features if you prefer manual management
14Your California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
14.1 Categories of Personal Information We Collect
| Category | Examples | Collected |
|---|---|---|
| Identifiers | Email address, name, Google User ID | Yes |
| Commercial information | Purchase records, transaction history | Yes |
| Internet or network activity | App usage patterns, device information | Yes (anonymized) |
| Geolocation data | GPS coordinates, IP address location | No |
| Biometric information | Fingerprints, facial recognition | No |
| Sensitive personal information | Social security numbers, precise geolocation, health data | No |
14.2 Do We Sell Personal Information?
No. Recido does not sell your personal information to third parties for monetary or other valuable consideration. We have not sold personal information in the past 12 months.
14.3 Do We Share Personal Information?
We share personal information only with service providers (such as Google Firebase) for business purposes as described in Section 5 of this Privacy Policy. These service providers are contractually prohibited from using your data for any purpose other than providing services to Recido.
14.4 How to Exercise Your CCPA Rights
California residents can exercise the following rights:
- Right to Know: Request disclosure of personal information we collect, use, disclose, or sell about you
- Right to Delete: Request deletion of personal information we have collected from you
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out: Opt out of the sale of personal information (not applicable as we don't sell data)
- Right to Limit Use of Sensitive Personal Information: Limit our use of sensitive personal information (not applicable as we don't collect sensitive personal information)
To exercise these rights, contact us at privacy@recido.app with "CCPA Request" in the subject line. We will respond within 45 days as required by law.
14.5 Authorized Agent
You may designate an authorized agent to make CCPA requests on your behalf. The authorized agent must provide:
- Proof of authorization (written permission signed by you)
- Verification of your identity
14.6 Non-Discrimination
We will not discriminate against you for exercising your CCPA rights. You will not be:
- Denied goods or services
- Charged different prices or rates for services
- Provided a different level or quality of services
15European Users - Additional GDPR Information
15.1 Data Controller
For the purposes of GDPR, the data controller is:
Zintle Technology 7420 Unity Ave N #211 Brooklyn Park, MN 55443 United States Email: privacy@recido.app
15.2 EU Representative
If required under GDPR Article 27, we will appoint an EU representative. Contact information will be provided here when applicable.
15.3 Data Protection Officer (DPO)
While we are not currently required to appoint a DPO, you can contact our privacy team with any data protection concerns at privacy@recido.app.
15.4 Supervisory Authority
If you are located in the EU/EEA/UK and have concerns about how we handle your personal data, you have the right to lodge a complaint with your local data protection authority:
- EU Member States: Find your national authority at https://edpb.europa.eu/about-edpb/about-edpb/members_en
- United Kingdom: Information Commissioner's Office (ICO) - https://ico.org.uk
15.5 Data Retention Justification
Under GDPR Article 5(1)(e), we retain personal data only for as long as necessary. Our retention periods are based on:
- The duration of our contractual relationship with you
- Legal and regulatory requirements (e.g., tax laws requiring 7-year retention of financial records)
- Legitimate business interests (e.g., fraud prevention, dispute resolution)
- Your consent (which can be withdrawn at any time)
16Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or app features. When we make changes, we will:
- Update the "Last Updated" date at the top of this policy
- Notify you through the app with an in-app notification or banner
- Send you an email notification if the changes are material and significantly affect your rights
- Request your consent if required by applicable law
We encourage you to review this Privacy Policy periodically. Your continued use of Recido after changes are posted constitutes your acceptance of the updated policy.
16.1 Version History
| Version | Date | Changes |
|---|---|---|
| 1.0 | July 26, 2025 | Initial privacy policy |
| 2.0 | November 5, 2025 | Removed device contact access; added detailed GDPR and CCPA sections; enhanced transparency; updated package name to com.rukkiecodes.recidoapp; clarified AI data usage; added comprehensive security measures |
17Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal information, please contact us:
18Governing Law and Jurisdiction
This Privacy Policy is governed by and construed in accordance with the laws of the State of Minnesota, United States, without regard to its conflict of law provisions. However, we recognize and comply with the data protection laws applicable in your jurisdiction, including:
- General Data Protection Regulation (GDPR) for EU/EEA/UK users
- California Consumer Privacy Act (CCPA) for California residents
- Nigeria Data Protection Regulation (NDPR) for Nigerian users
- Other applicable regional and national privacy laws
Any disputes arising from this Privacy Policy will be resolved in the appropriate courts based on your location and applicable law, with due regard for international data protection agreements.
19Summary - Key Takeaways
20Acknowledgment and Consent
By creating an account and using Recido, you acknowledge that you have read, understood, and agree to this Privacy Policy. You consent to the collection, use, storage, and disclosure of your personal information as described herein.
If you do not agree with any part of this Privacy Policy, please do not use Recido. You can withdraw your consent at any time by deleting your account or contacting us at privacy@recido.app.