App name: ZZZ P2Point
Platforms: Android / iOS
This policy explains what information "ZZZ P2Point" (the "App") handles and how it is used. Please read it before using the App.
1. Overview
The App is a serverless, peer-to-peer loyalty point system in which a shop's device and a customer's device connect directly over Bluetooth Low Energy (BLE). No account registration or login is required.
Everything you handle in the App (shop name, user name, device identity keys, point balances, transaction history, and paired counterparties) is stored on your device and on the device of your transaction counterpart. We operate no servers, and none of this content is ever sent to or collected by the developer or any third party.
The App contains no analytics. Point transactions happen exclusively over Bluetooth with the devices you pair with. To sustain its operation, the App may display advertising served by a third-party provider (Google AdMob) and may charge for some shop-side features. Internet communication is used solely for delivering and displaying those ads (see "6. Third-party services").
2. Information handled on your device
The App creates, stores, and uses the following information on your device only.
2.1 Profile (shop name / user name)
- The "shop name" (shop mode) or "user name" (customer mode) you enter on the Settings screen
- It is shown to your paired counterparties so they can identify you, and is transmitted to and stored on their devices via Bluetooth
- The App never asks for your real name, phone number, or email address. We recommend using an arbitrary nickname or trade name
2.2 Device identity keys (public/private keys)
- On first launch, the App automatically generates an Ed25519 key pair (for signatures / authenticity) and an X25519 key pair (for encryption) on your device
- The Ed25519 key signs every point exchange (grants, spends, syncs) so tampering and impersonation can be detected, and derives the ID that identifies your device
- Private keys never leave your device. Only public keys are shared with your counterparties for signature verification
2.3 Point balances, transaction history, paired counterparties
- In shop mode the App stores, per paired customer, the point balance and the latest transactions (up to 5), plus your grant rules (default points, expiry). In customer mode it stores, per paired shop, the point balance and the latest transactions (up to 5)
- The history is used to display balances, automatically remove expired points, and reconcile balances between the shop's and the customer's records
- To complete a transaction, its content (points granted/spent, new balance, expiry) is also transmitted to and stored on your counterpart's device. It is never stored on any server
3. How the information is used
The information above is used solely to:
- Discover nearby devices and pair with them (business-card exchange) to register the shop↔customer relationship
- Send and receive point grant / spend / settlement requests and notices
- Sign and verify every exchange (authenticity and integrity of the counterpart and content)
- Store, display, and automatically expire point balances and history on the device
- Reconcile and force-sync balances when the shop's and customer's records diverge
4. Where the information is stored
All information the App creates is stored only on your device and your counterpart's device.
- ✅ Stored only in the App's private on-device storage
- ✅ Transaction records are mirrored on the counterpart's (shop↔customer) device
- ❌ Nothing is sent to any server operated by us (no such server exists)
- ❌ No cloud backup
- ❌ No mechanism through which the developer could access your data
5. About Bluetooth communication
The defining feature of the App is that shop and customer devices talk to each other directly over Bluetooth, with no server in between. Please note:
- Point exchanges travel only over a direct one-to-one link with a paired counterpart. There is no relaying through third-party devices
- Every packet (grant, spend, sync) is signed with the sender's private key and verified by the receiver. Packets with invalid signatures, or from devices you have not paired with, are discarded
- While online (scanning), your configured shop/user name is visible in the discovery list of nearby devices
Please understand: exchanges are transmitted as Bluetooth radio signals, so some metadata (who communicated and when) can be observed nearby. Do not include sensitive information in your shop or user name.
6. Third-party services
6.1 Advertising
To sustain its operation, the App may display advertising served by Google AdMob (Google LLC), a third-party ad provider. For ad delivery, the provider may collect and use advertising identifiers (the Android advertising ID / the iOS IDFA, etc.) and device information. For details on what is collected and how it is handled, please see Google's Advertising Policies & Terms.
The App uses Internet communication solely for delivering and displaying ads. None of the App's content — point ledgers, shop names, user names, or keys — is ever sent to the ad provider.
6.2 Billing
The App may charge for some shop-side features. Any payment is processed through the App Store / Google Play in-app purchase system, and payment details such as credit-card numbers are handled by the store operators (Apple / Google). We never obtain or store your payment information.
6.3 Services the App does not use
The App uses none of the following:
- ❌ Analytics (Google Analytics, Firebase Analytics, etc.)
- ❌ Crash reporting (Crashlytics, etc.)
- ❌ User authentication / login / accounts
- ❌ Any backend server operated by us
Your counterpart for point transactions is the nearby device running the App — never an external service provider.
7. Required permissions
The App requests the following permissions. On iOS, the system confirmation dialog appears on first use.
| Permission | Purpose |
|---|---|
| Bluetooth (scan / advertise / connect) | To discover and connect to nearby devices and exchange point transactions directly |
| Location (Android 11 and earlier only) | Requested only because Android required the location permission for Bluetooth scanning up to Android 11. The App never obtains, uses, or stores your location (on Android 12+ it runs without the location permission via neverForLocation) |
| Internet | Used solely for delivering and displaying ads. Point transactions themselves happen over Bluetooth only, and none of the App's content is sent over the Internet |
You can revoke these permissions at any time from the device settings. The App requests no microphone, camera, contacts, or photo permissions.
8. Deleting your data
You can delete the App's data at any time.
- Only the latest 5 transactions are kept per counterparty; older entries are removed automatically (folded into a carried-over balance)
- Uninstalling the App permanently deletes everything it stored on your device (keys, profile, balances, history, paired counterparties)
- Records mirrored on a counterpart's device (your balance and history with them) live on their device and are removed by their deletion or uninstall
9. Security
Every packet involved in a point exchange (pairing card, grant, spend, sync) carries an Ed25519 digital signature, and the receiver verifies the sender's authenticity and the content's integrity (preventing impersonation and tampering). Public keys exchanged at pairing are pinned on the device, and any communication claiming a known ID with a different key is rejected. If the shop's and customer's records ever diverge, the App reconciles them with the shop's ledger as the authority.
Please also understand the limits: the App verifies signatures but is intended for casual, short-range point exchanges. Do not use it to manage real money or anything equivalent to legal tender or electronic money.
10. Children's privacy
The developer operates no server that collects or stores personal information. The App is not directed at children under 13 and does not knowingly collect personal information from children under 13. If a child uses the App, we recommend doing so under a guardian's supervision.
11. Changes to this policy
This policy may change without notice. Material changes will be announced together with an app update.
12. Contact
For questions about this policy, please contact us via the store page distributing the App.