Mamilat is a bookkeeping app for shopkeepers, published by Mamilat. This policy covers the Mamilat mobile app for Android and iOS and this website. It is written plainly on purpose: you should be able to tell exactly what is held about you and your shop.
1. Information you give us
When you create an account and use Mamilat, we hold:
| What | Why we hold it |
|---|---|
| Your name and email address | To identify your account, sign you in, and contact you about your subscription or a support request. |
| Your password | Only if you choose email sign-in. It is stored hashed — we cannot read it, and neither can anyone with the database. |
| Business name, address, phone number and logo | These are printed on the statements and reports your shop produces, and let our staff reach you. |
| Your bookkeeping records — the accounts you create, the people they represent, transactions, expenses and currencies | This is the ledger itself. It is the thing the app exists to keep, and it is yours. |
| Contact details you enter for your own customers and suppliers | So you can send them a statement. We never contact them, and we never use them for anything of our own. |
2. Information collected automatically
- A device identifier generated by the app itself when it is installed. It is random, it is not your device's hardware ID, and reinstalling produces a new one.
- The device model, operating system and app version, so support can tell what you are running when something goes wrong.
- Sign-in times, so you can see where your account is being used.
Mamilat does not collect your location, does not read your contacts, photos, messages or files beyond a logo or account picture you deliberately choose, contains no advertising, and does no cross-app or cross-site tracking.
3. Signing in with Google or Apple
If you sign in with Google or with Apple, we receive from them your name, your email address, and a unique identifier for your account with that provider. We request no other permissions.
We use this only to create and recognise your Mamilat account. Mamilat's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, we do not transfer this information to others except as needed to run Mamilat, we do not use it for advertising, and no human reads it except where you ask us to help with a support problem or the law requires it.
If you sign in with Apple and choose to hide your email address, Apple gives us a relay address instead of your real one. That works normally, and we never attempt to uncover the address behind it.
4. Where your ledger is stored
Your bookkeeping records are kept on your own device first. That is why Mamilat opens and records with no internet connection.
When your device has a connection, a copy is sent to our servers as a backup, so a lost, broken or replaced phone does not take your books with it. Backups are transmitted over an encrypted connection (HTTPS) and are restored only to an account that has signed in successfully.
5. Who we share information with
We do not sell your information, and we do not share it for advertising. We share it only with:
- Google (Firebase Authentication) and Apple, to verify who you are when you use their sign-in.
- Our hosting provider, which stores the servers the backup runs on.
- Authorities, if we are legally required to — and only to the extent required.
Your customers' and suppliers' details are never shared with anyone.
6. How long we keep it
Your account and its backups are kept for as long as your account is open. If you ask us to delete your account, we remove your account record and your backups from our servers within 30 days. The copy on your own device is removed when you uninstall the app or sign out and clear its data.
7. Your rights
You can, at any time:
- See and correct your business and account details inside the app.
- Export any account's ledger as a PDF statement.
- Ask for a copy of everything we hold about you.
- Ask us to delete your account and your backups.
- Disconnect Google or Apple from your account, or revoke Mamilat's access from your Google account permissions page.
To make any of these requests, write to support@mamilat.com. We answer within 30 days.
8. Security
Traffic between the app and our servers uses HTTPS. Passwords are stored hashed. Your sign-in token is kept in the device's secure keystore rather than in ordinary app storage. You can add a PIN or a fingerprint lock so the ledger does not open on a phone left on a counter. No system is perfect, and we will tell you promptly if we ever learn that your information has been exposed.
9. Children
Mamilat is a tool for running a business and is not directed at children under 13. We do not knowingly collect their information.
10. Changes
If this policy changes we will update this page and change the date at the top. Substantial changes will also be announced in the app.
11. Contact
Email: support@mamilat.com
WhatsApp / phone: +93 745 117 117
Web: https://mamilat.com