Privacy Policy — Local Plus

Last updated: 7 September 2026 · Made by KiraVerse · support@kirazone.xyz

This policy is written to be read by a merchant, not by a lawyer. Where a sentence could be read two ways, the narrower reading is the one we mean.

The short version

Your sales stay on your phone. Everything the till does — recording sales, counting stock, working out your profit, refunds, expenses, reports — happens on your device and is stored there. We cannot see any of it. There is no server holding your takings.

Five things leave your phone, and only when you choose them:

  1. A report or backup you export and share. It goes wherever you send it, and nowhere else.
  2. An AI menu photo. If you ask for a picture to be made, the dish name goes to the image provider. If you ask for a photo you took to be fixed, that photograph goes to the image provider along with what you asked for. The result comes back and is stored in your account.
  3. A credit purchase. Google Play handles the payment; we are told only that a purchase happened.
  4. Connecting a second phone. If you link phones so an owner can see what staff are selling, a short summary of each sale is sent so the owner's phone can show it. This keeps sending after you set it up, so it has its own section below.
  5. Publishing a Local+ storefront. If you switch your shop on in Local+, your shop's name, its position on the map, and your menu — item names, selling prices and their photos — are put where customers can see them. That is the point of publishing, and it too has its own section below.

If you never use AI photos, never export, never connect a second phone and never publish a storefront, Local Plus sends nothing anywhere.

What we store, and where

On your phone only

WhatNotes
Products, prices, costs, recipes Costs and recipes never leave the device. Item names, selling prices and menu photos leave it in exactly one case: you publish a Local+ storefront, which puts your menu where customers can see it. See "Publishing a storefront".
Every sale, refund, void and expense Stays on the device, with two exceptions you choose. On a shop with connected phones, a short summary of each sale — amount, count, seller, time — is also sent so the owner can see it; refunds, voids and expenses are never sent. And if you are logged in, a copy of your whole shop is saved to your own account so you can get it back on a new phone — see "A copy in your account". Nobody but you can read it.
Stock levels and movements Stay on the device while you are logged out. If you are logged in they are part of the copy of your whole shop described two rows above — see "A copy in your account".
Your settings — currency, exchange rate, language, business-day start The same: on the device while logged out, and part of the copy in your account while you are logged in. This includes your shop's address, phone number, e-mail, tax and registration numbers, and the payment QR codes you saved — a KHQR code carries your bank account identifier, so it travels with them.
Where your shop is Read once, only when you tap "Use my location" on the Local+ storefront screen, and stored on the device. If you publish your storefront, that stored position is part of what is published — a customer finds your shop by where it is. Unpublish and it is no longer served. Never read in the background. It is also read when you press "call for help" or "say where you are" on the Safety screen, which shops in the transport trade have — that is the whole purpose of those two buttons, and the position is put in a text message to the contacts you chose and is not kept by us.
Photos you take with the camera Stay on the device — unless you ask for one to be fixed with AI, which sends that photo. See below.
The menu boards you design Never leave the device. The finished picture goes wherever you send it, and nothing else does — the dish names and prices on a board are never sent anywhere, even when the background under them was bought.

A note on location, because it is the one permission that sounds like tracking: this app asks for it at the moment you press the button that needs it, and never asks again. There is no background location permission in the app at all, so it cannot follow you anywhere even if something went wrong.

It is used for two different things, and which one depends on which app you are holding. As a merchant, it records a single point — where your shop is — and if you never set up a Local+ storefront it is never asked for at all. As a customer on Local+, it is used to find shops near you, which means your rough position is sent to us when you ask for that; and if you drop a pin for a delivery, those coordinates go to the shop you ordered from, because that is how they find your door.

Android's automatic backup is switched off for this app, deliberately. Your trading history is not copied to the Google Drive of whoever owns the phone.

On our servers — only if you use AI photos or buy a board background

WhatWhy
An account identifierTo know whose credits are whose
Your email address Only if you create an account with one, sign in with Google, or sign in with Apple without hiding it. Used to sign you in and to send a password reset. Never used to advertise to you.
Your credit balance, when each pack was bought and when it expires Because a balance the phone controls is a balance anyone can edit
The AI photos you generatedSo you keep them if you change phone
The name of the dish each photo was for To generate the photo, and so you can find it again
A record of each generationSo you can see where a credit went
A photo you asked to have fixed It is sent to the image provider to be worked on, and the result is saved in place of it. The original is not kept on our servers as a separate copy.
The background you bought for a menu board So you keep it if you change phone. One per board: buying another replaces it.
What you asked that background to look like Either which of the ready-made ones you picked, or the words you typed. Nothing else about the board is sent — not your dish names, not your prices, not the layout.

On our servers — only if you publish a Local+ storefront or take orders

WhatWhy
Your published storefront: shop name, description, logo, position, and your menu — item names, selling prices, photos, availability So customers can find your shop and see what it sells. This is public — anyone using Local+ can read it. Unpublishing takes the shop out of discovery.
Each order a customer places: what they ordered, the amounts, and the name, phone number and address they typed So the order can reach you and you can fulfil it. Held on our servers, shown to you in the app. Your costs and margins are not part of an order — a customer never sees what anything cost you.

That is the complete list. Not your sales, not your profit, not your costs. Your selling prices are on our servers in exactly one case — a storefront you chose to publish, where they are the menu. What you paid, what you made and your book of sales are in neither list above. There is one place they do go, and only one: if you are logged in, the copy of your whole shop saved to your own account. Nobody else can read it, it is there so a lost phone is not a lost year, and logging out stops it. Logged out, those figures never leave the phone at all.

Your account

You can use the entire till with no account at all.

An account is needed only for credits, and for letting a second phone join the same shop. Local Plus can create an anonymous account — no name, no email, no phone number, just an identifier that says "this device's credits".

If you want those credits to survive a lost phone, you can turn that anonymous account into a real one, four ways:

An account carries your credits. It also carries the copy of your shop described above, for as long as you stay logged in — that is the one thing on this page that changed when backup arrived, and it is why "stays on the phone" now has a condition attached to it wherever it appears.

Messages, reviews and reports on Local+

These three exist only on the Local+ side — the marketplace, where a customer orders from a shop. None of them touches the till. A phone that only sells, and never publishes a storefront, produces none of it.

It is also the one part of this policy written for the customer as much as for the merchant, because on Local+ each of them writes things the other one reads.

The conversation on an order

Once an order is placed, the customer and the shop can write to each other about it — "no ice", "I am at the door". Those messages are stored on our servers, because a server is the only way the other phone can read them. Both already have each other's name and phone number from the order itself, so the thread tells neither of them anything the order had not already.

A message cannot be edited or deleted once it is sent — not by either side, and not by us. It is the record of what was agreed about an order, and a record either side could rewrite would be worth less than no record at all.

Reviews

When an order is finished, the customer can rate the shop out of five and write a comment. The rating and the comment are stored on our servers and shown to that shop. The shop is never told who wrote them: no name, no phone number and no account identifier reaches the merchant. That is deliberate — a merchant who can see who complained is a merchant nobody complains to.

We do not write reviews and we do not edit them.

Reporting something

Either side can report a shop, a person, an order, or the conversation on one.

A report carries the account identifier of whoever sent it, what the report is about, the reason they picked from a fixed list, and anything they chose to type in their own words. It is read by one person: the owner of KiraVerse. The reported party is never told who reported them, and there is no reply — the app says so before the report is sent rather than after.

When the report is about a shop, we also keep a copy of what that shop's storefront said at that moment — its name, its description, and the address of its picture. A shop can be renamed in the time it takes to type, so without the copy a complaint about one name would reach us describing another, and the person deciding it would be reading the wrong thing. The copy is of what the shop published to every customer, and holds nothing about whoever reported it.

That copy is deleted twelve months after the report was filed, unless the case is still open. The report itself stays: it is the record of a decision. What goes is the old shop-front text, because a year later there is no case left for it to be evidence in.

Blocking

When you block a shop, that is kept on your phone only and is never sent anywhere.

When a shop blocks a customer, the shop's list of blocked customers is stored on our server, because an order reaches the shop through us and only we can turn it away. That list holds account identifiers and nothing else — no names, no messages, no reason. Only that shop can read its own list; nobody can read across shops, including us in ordinary operation.

Nobody is told they have been blocked: a blocked order is refused the same way any other refused order is.

Either way, the list belongs to the phone that made it, and that has a cost it is fair that you know: a block does not travel to your other phone, and reinstalling the app clears it — on our side too, because the shop's phone is the copy that counts.

Delivery-order notifications

Not available in the current release. The description below is how the feature is built for when it ships, and it is kept here because a policy that appears after a feature does is a policy nobody re-reads. Today, the switch it describes does not exist on your phone, and nothing of the kind runs.

If you turn this on, Local Plus can see that a delivery app has posted a notification.

It reads which app posted it, and at what time. Nothing else. Not the title, not the message, not the customer's name, not the order, not the amount. This is enforced by how the feature is built, not by a promise: the notification's contents are never read, so there is nothing to store, send or lose.

That information stays on your phone and is used for one thing: showing you "an order arrived at 14:32 — record it?".

The feature is off until you switch it on in your phone's own settings, and you can switch it off there at any time.

Publishing a storefront

Nothing here happens unless you switch your shop on in Local+. An unpublished shop serves nothing, and that is how the app arrives.

Published means public. Your shop's name, description, logo, its position on the map, and your menu — item names, selling prices, photos, what is available — can be read by anyone using Local+. That is what a storefront is for, and it is why this section exists: everywhere else in this policy, prices staying private is the rule.

What is never part of it: your costs, your margins, your recipes, your stock levels, your sales history, your expenses, your staff. A customer sees a menu, not a book.

Orders. When a customer orders, they type a name, a phone number and — for delivery — an address. That reaches our servers and your phone, because you have to fulfil the order. It is theirs: if they delete their account, their name, number and address are stripped out of the order while your record of the sale itself stays.

Turning it off. Unpublish from the storefront screen. The shop leaves discovery immediately. Deleting your account removes the storefront and its orders entirely.

Connecting a second phone

This section exists because it is the only part of Local Plus that keeps sending after you set it up, and because the rest of this policy would be misleading without it.

Nothing here happens unless you connect phones. An unlinked shop sends nothing, and that is how the app arrives.

What is sent when phones are linked

WhatWhen
Your shop's nameOnce, when you create the link
A staff member's name and role When you make an invite code for them
For each sale: the amount, the currency, how many items, who sold it, and the timeAs it happens

What is not sent, ever

What you sold. Your costs, your margins or your profit. Your stock. Your expenses. Your reports. Your photos. Anything about your customers. The owner's phone shows a running feed of sales — an amount, a seller and a time — and nothing underneath it.

Turning it off. Disconnect the phone, or revoke it from the owner's Connected phones list. Sales stop being sent immediately. What was already sent stays until it is deleted; ask us and we will delete it.

One deliberate behaviour worth naming: if the owner revokes a phone while it is mid-shift, that phone keeps selling normally and its sales simply stop appearing in the owner's feed. The till never refuses a customer because of something the owner did an hour ago, and the sale is still recorded in full on the phone that made it.

Verifying a store

Before a shop is shown to customers on Local Plus, a person at KiraVerse checks who is behind it. This is optional in exactly the sense that publishing is: you only meet it if you ask for your store to be verified.

What you send. Four photographs and a few details: the front of a government ID, a photo of your face holding that ID, your shopfront, the inside of your shop; your full name as on the ID, a phone number, the shop's address, the pin you already placed on the map, and — if you have one — a business registration number.

Who sees it. The photographs and details go to our servers and are shown to one person: the owner of KiraVerse, who reviews them by eye. No automated face matching is performed, and nothing is sent to any third-party identity service. Customers never see any of it; they see a "verified" mark on your shop, and nothing else.

What we do not keep. We do not store your ID number as text — the photograph is the record. We keep the photographs and details for as long as your store is verified, so a later question about the shop can be answered.

Turning it off. Deleting your account deletes the photographs, the details and the verification record with it. Ask by email if you want a verification withdrawn without deleting the account.

Who else receives anything

WhoWhat they getWhen
Google Firebase Your account identifier, your email address if you gave one, your credit records, your generated photos Only if you make an account or use AI photos
Google Firebase Your shop's name, your staff members' names and roles, and a summary of each sale — amount, count, seller, time Only if you connect a second phone
Google Firebase Your published storefront — shop name, position, menu with prices and photos — and each order's contents, with the name, phone number and address the customer typed Only if you publish a Local+ storefront / take orders through it
Google Firebase Your store verification — the four photographs and the details you typed Only if you ask for your store to be verified
Anyone using Local+ Your published storefront, exactly as above. It is public by design Only while your shop is published
The other phones on your shop The owner sees the sale summaries above. A staff phone sees only its own shop name and role Only if you connect a second phone
The person on the other end of an order What you write in the thread on that order Only while an order is open between you
A shop you ordered from Your rating out of five and any comment you wrote, with nothing that says who you are Only after you review a finished order
The owner of KiraVerse A report: who sent it, what it is about, the reason, and anything they typed. Nobody else can read one Only when somebody reports something
The AI image provider The name of the dish you asked for a picture of, or — if you are fixing a photo — that photo. The provider is fal.ai today; the app can be switched to OpenAI, and both are named here so that switching it never makes this page wrong Only when you press generate or fix
Google Firebase (your own account copy) The copy of your whole shop: items, prices, costs, stock, sales, expenses, settings, your shop's contact and registration details, your saved payment QR codes, your staff's names, and the emergency contacts you entered on the Safety screen. Only you can read it Only while you are logged in
Google (sign-in) That you signed in to Local Plus, and your email address Only if you choose to sign in with Google
Apple (sign-in) That you signed in to Local Plus Only if you choose Sign in with Apple
Google Play The purchase itself. We never see your card Only when you buy credits
Whoever you send an export to Whatever is in that file Only when you export and share it

We do not sell your data. We do not share it for advertising. There is no analytics or tracking SDK in this app.

Children

Local Plus is a tool for running a business and is not directed at children.

Your choices

Changes

If this policy changes in a way that affects what leaves your phone, the app will tell you in the app before the change takes effect — not only here.

A note on what "we cannot see it" means

It is the ordinary meaning. Your sales are written to a database file inside the app's private storage on your own device. No copy of that file is sent anywhere, no key is held by us, and there is no mechanism by which we could request one.

One precision, because a policy that is nearly true is worse than one that is plain: if you have connected a second phone, the sale summaries described above do reach Firebase, because that is the only way the owner's phone can show them. That is a few numbers per sale and a seller's name. Your book — what you sold, what it cost you, what you made, your stock, your expenses — is still only on your device, and is still not something we can read. If your phone is lost, we still cannot help you — there is nothing on our side to restore from. That is the trade this design makes on purpose, and it is why the backup exists and why it is yours to keep: the file is the only copy there will ever be, and where it lives is your decision rather than ours.