Back to home

Privacy Policy

Last updated: August 6, 2026

Business Management AI (the "Service") is operated by Mahmoud Fawzy ("we", "us"). This policy explains what data the Service collects, why, who it's shared with, and the choices you have — for the web app at businessmanagement.space, its Android/iOS apps, and the public storefronts and customer/technician tracking pages it generates for each business.

Two roles: your account, and your customers' data

This distinction matters, so it comes first. When you register a business on the Service, we act as the data controller for your own account details (name, email, login credentials, subscription and billing records) — we decide how that data is used, and this policy governs it directly.

For everything you enter about your own customers, employees, suppliers, or devices (names, phone numbers, sale records, repair jobs, and so on), you are the data controller and we are the data processor: we store and process that data only to run the Service on your behalf, under your instructions. If you're a business owner using the Service, you're responsible for having a lawful basis to collect and store your customers' or employees' data, and for your own privacy notice to them where applicable. If you're a customer or employee of a business that uses the Service, your data was given to that business, not to us directly — contact them first about a data request; we'll support them in fulfilling it.

Data we collect

From you, as an account holder

  • Name, email address, phone number, and a securely hashed password (we never store or can recover your plaintext password).
  • Business details you provide: business name, type, address, phone, tax registration number, logo, and language/currency preferences.
  • Subscription and payment status for your own use of the Service (not your customers' payments — see below).
  • Support messages you send us.

Data you or your staff enter about your business

  • Customers: name, phone, email, address, purchase and loyalty history, notes your staff add.
  • Sales, invoices, expenses, inventory, purchase orders, and accounting records.
  • For repair/mobile-device businesses: device IMEI, brand/model, and repair job status.
  • For businesses with staff accounts: employee names, roles, attendance, and payroll figures you enter.
  • Files you upload: product photos and your business logo, stored via our cloud storage provider.

Payment data

We never see or store full card numbers. Online card payments and in-person card-reader payments are processed directly by Stripe; PayPal payments are processed directly by PayPal. If you connect your own Stripe or PayPal account to accept payments, we store your API keys and webhook secrets encrypted at rest, used only to make the API calls your account authorizes.

AI assistant features

If you use the built-in AI assistant, insights, or auto-reply features, the relevant business data (e.g. a question you ask, or an email thread for auto-reply) is sent to our AI provider, Anthropic, to generate a response. We don't use your business data to train AI models.

Technical data

  • Session cookies used to keep you signed in (not used for cross-site advertising tracking).
  • Basic device/browser information and IP address, for security (e.g. detecting suspicious login attempts) and error logging.
  • If you enable push notifications, a device push token registered with your browser or OS's own push service (e.g. Google, Mozilla, Apple).

Who we share data with

We don't sell your data or your customers' data, and we don't share it for third-party advertising. We share the minimum necessary data with service providers who help us run the Service, each acting under their own privacy commitments:

  • Stripe and PayPal — to process payments you or your customers make.
  • Twilio — to relay WhatsApp/SMS repair-status notifications for businesses that enable that feature.
  • Anthropic — to power the AI assistant, insights, and auto-reply features described above.
  • Our cloud infrastructure providers — for database hosting and file storage, both encrypted at rest and in transit.
  • An email provider (SMTP), used to send account, invoice, and reminder emails on your behalf.
  • If a business connects its own email inbox for AI auto-reply, that business's own email provider (via IMAP), used only to read and reply to that inbox.

We may also disclose data if required by law, to protect the rights, property, or safety of the Service, our users, or the public, or in connection with a merger, sale, or transfer of the business (with notice to affected account holders).

How long we keep data

We keep account and business data for as long as your account is active, plus a reasonable period afterward to comply with tax/accounting record-keeping obligations that apply to your business type and country, and to resolve disputes. You can request deletion of your account at any time — see "Your rights" below.

Security

Passwords are hashed, never stored in plaintext. Sensitive credentials you connect (payment API keys, email account credentials) are encrypted at rest. Data in transit is encrypted (HTTPS). Access to a business's data is scoped strictly to that business's own account and staff — no business can see another business's data. Two-factor authentication is available for your account, and we recommend enabling it.

International data transfers

The Service is used by businesses in multiple countries, and the infrastructure providers above may process or store data in countries other than your own. We choose providers that apply appropriate safeguards for cross-border data transfer.

Your rights

Regardless of where you're located, you can ask us to:

  • Access a copy of the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your account and associated data, subject to the retention needs described above.
  • Export your data in a portable format.
  • Object to or restrict certain processing.
  • Withdraw consent, where processing is based on consent.

To exercise any of these rights, email m.fawzyahmed2004@gmail.com. If you're the customer or employee of a business using the Service rather than the account holder, please contact that business directly first, as described above.

Children's privacy

The Service is intended for business use by adults. We don't knowingly collect data from children, and account registration requires that you be of legal age to enter into a business relationship in your country.

Changes to this policy

If we make material changes to this policy, we'll update the date at the top of this page and, where appropriate, notify account holders by email.

Contact us

Questions about this policy or your data: m.fawzyahmed2004@gmail.com.