AesoniONE Manager (“the app”) is published by Aesoni (“we”, “us”). The app is an internal operations tool for branch managers at organizations using the AesoniONE franchise management platform. Accounts are created by your organization’s administrator — the app has no public sign-up.
This policy explains what data the app handles, why, and how it’s protected.
1. Who this app is for
AesoniONE Manager is provided to branch managers by the franchise organization that employs them, as part of that organization’s AesoniONE subscription. It is not directed at, marketed to, or knowingly used by children.
2. Data the app handles
Account and session data
- Login email and password, checked against your organization’s AesoniONE backend to sign you in.
- A session (refresh) token and your basic profile (name, role, assigned branch), stored on-device using the operating system’s encrypted secure storage (Android Keystore-backed). This is what keeps you signed in between app launches.
- Your short-lived access token is never written to disk — it exists only in the app’s memory while the app is open, and is discarded on logout or app close.
Business data
Signing in gives the app access to your employer’s operational data for your assigned branch(es), which you can view and, in limited cases, edit: sales and shift records, expenses, purchase orders and stock/inventory counts, GST and other financial reports, staff rosters (including punch-in PINs, which are stored hashed, never in plain text, by our backend — the app never sees or stores the plain PIN), and customer records limited to name, phone number and email address.
This data belongs to your employing organization, not to an individual user of the app, and is not used by Aesoni for any purpose outside operating the AesoniONE service for that organization.
Report exports
When you export a report (PDF, Excel or CSV), the app generates it on request, writes it briefly to the app’s private cache, and hands it to your device’s share sheet so you can send it via WhatsApp, email, Drive, or wherever you choose. The app does not upload these files anywhere on its own, and does not keep them once you leave the report screen — cache files are reclaimed by the operating system.
Diagnostics
The app includes Sentry, an error-reporting library, for crash and error diagnostics. It is not currently active in this build. If it is enabled in a future release, it would report device model, OS version, and a redacted crash stack trace to help us fix bugs — never business data, credentials, or personal records — and this policy will be updated first.
What the app does not do
The app does not access your location, camera, microphone, contacts, calendar, or SMS. It does not use advertising identifiers, does not contain third-party advertising or tracking SDKs, and does not process in-app purchases or payments.
3. Where data is stored and how it’s protected
Business and account data is stored on Aesoni’s own backend infrastructure: our API runs on Vercel, and our database runs on Supabase (currently hosted in the Asia-Pacific / Sydney region). All communication between the app and our backend is encrypted in transit (HTTPS/TLS) — the app is built to refuse any unencrypted connection.
4. Who we share data with
We do not sell your data, and we do not share it with third parties for their own marketing or advertising purposes. We use a small number of service providers strictly to operate the app on our behalf, under their own security and confidentiality commitments:
- Supabase — database hosting
- Vercel — API/backend hosting
- Sentry — crash diagnostics (only if/when enabled — see §2)
5. Data retention and deletion
Business records (sales, staff, customer data, etc.) are retained according to your employing organization’s own operational and record-keeping needs, since that data belongs to the organization. Your session credentials are removed from your device immediately when you log out. To request access to, correction of, or deletion of data associated with your account, contact your organization’s administrator, or reach us directly at tech@aesoni.in.
6. Your choices
You can log out at any time, which clears your session from the device. Because this is an employer-provisioned account, requests to close an account entirely should go through your organization’s administrator.
7. Changes to this policy
If how we handle data changes materially, we’ll update this page and change the “Last updated” date above.
8. Contact us
Questions about this policy or your data: tech@aesoni.in