PhoneRepairPOS

Privacy Policy

Last updated: 20 August 2026

Who we are

PhoneRepairPOS is a trading name of VoxBot Ltd ("we", "our", "us"), a company registered in Northern Ireland under company number NI736457, registered office 24 Rhanbuoy Park, Holywood BT18 0DX. You can contact us at support@phonerepairpos.app.

PhoneRepairPOS is an app for phone repair businesses. This policy explains what data the app handles, where it goes, and what rights you and your customers have.

The two kinds of data, and who is responsible for each

This distinction matters, so we state it plainly.

1. Your shop's business data — your customers' names and contact details, device details, repair notes, tickets, and payment records.

For this data you are the data controller and we are a data processor acting on your instructions. You decide what to collect and why; we only store and transmit it so the app works. Our processing obligations to you are set out in the Data Processing Terms in our Terms of Use.

2. Your account and usage data — your sign-in identity, shop settings, device identifiers, diagnostic data, and analytics about how the app is used.

For this data we are the data controller. Our lawful basis is legitimate interests: operating, securing, supporting, and improving the app.

Where your data is stored

Data you enter is stored on your device and, where cloud sync is active, in our Firebase project hosted on Google Cloud Platform. This is our infrastructure, not your personal iCloud account.

We can technically access this data, because we administer the database. We access it only where necessary to operate the service, investigate a fault, or comply with a legal obligation — never to read, mine, or sell your business data, and never for advertising.

The following collections are stored in our Firestore database: shops, tickets, customers, devices, payments, moneyEvents, and invites.

Sub-processors

We use the following third parties. Each is bound by its own data protection terms.

ProviderPurposeLocation
Google (Firebase / Google Cloud)Database, authentication, crash reporting, remote configuration, analyticsEU / US
MixpanelProduct analytics, and masked session replayUnited States
AppleApp distribution, and device-level servicesEU / US

Where data is transferred outside the UK, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or another safeguard permitted under UK GDPR.

We will give you reasonable notice before adding or replacing a sub-processor that handles your shop's business data.

Analytics and diagnostics

The app sends usage and diagnostic events to Firebase Analytics, Crashlytics, and Mixpanel so we can understand how features are used and fix crashes.

These events describe app usage, not your customers. No event we send carries a customer name, phone number, repair note, or payment amount. Error reports include technical error codes only, never message content or personal details.

Session replay

To understand where people get stuck — an abandoned repair ticket tells us that it happened, but not why — the app also sends Mixpanel a masked replay of a sample of sessions.

A replay is not a recording of your screen as you see it. The app takes periodic screenshots of its own interface, and before any image leaves your device it masks every piece of text, every photo, every web view and every map. Anything typed into a field is masked and cannot be unmasked. What reaches us shows the shape of a screen, which controls were tapped, and in what order — not what your tickets say.

Because a replay depicts the app's own screens, it is usage data that we control. But it is captured while your shop's business data is on screen, which is precisely why the masking happens on the device, before anything is uploaded, rather than afterwards.

Three things we think you should know:

  • Replays are taken from roughly 1 in 10 sessions, not all of them.
  • They upload over mobile data as well as Wi-Fi, so they count towards a metered connection.
  • We can switch session replay off for every device remotely, without waiting on an app update. The masking is automatic, and if we ever find a screen it has not masked correctly, that is what we will do: switch it off, delete the affected replays, and fix it before it goes back on.

How long we keep data

Your shop's business data is retained for as long as your shop uses the app. If you stop using it, contact us and we will delete your shop's records. Analytics and diagnostic data, including session replays, is retained for up to 14 months.

Security

We protect data in transit and at rest using the encryption and access controls provided by Google Cloud Platform, restrict administrative access to those who need it, and enable point-in-time recovery and delete protection on the production database.

No system is perfectly secure. If a breach affects your shop's data, we will notify you without undue delay and give you the information you need to meet your own reporting duties.

Your rights, and your customers' rights

If you are in the UK or EU you have the right to access, correct, erase, restrict, or port your personal data, and to object to processing. To exercise these rights over your account data, contact us.

If one of your customers makes a request about their data, that request is yours to answer — you are their data controller. We will assist you promptly and at no charge, and can extract or delete specific records on your instruction.

You may also complain to the Information Commissioner's Office at ico.org.uk.

Children's privacy

PhoneRepairPOS is a business tool and is not directed at children under 13. We do not knowingly collect data from children.

Changes to this policy

We may update this policy from time to time. Changes will be posted here with an updated date. Where a change materially affects how we handle your shop's business data, we will give you notice.

Contact us

Questions about this policy: support@phonerepairpos.app.