Privacy Notice
Last updated: July 30, 2026
Este aviso también está disponible en español.
1. Identity of the Data Controller
SYA Tortillerías (hereinafter “SYA”, “we” or “the Company”), with its address in Puebla, Mexico, is responsible for the processing of the personal data you provide to us, in accordance with the Mexican Federal Law on the Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares, LFPDPPP) and its Regulations.
- Email: info@syatortillerias.com.mx
- Website: https://syatortillerias.com.mx
2. Personal Data We Collect
In order to carry out the purposes described in this privacy notice, we collect the following categories of personal data through our desktop application (Windows), our mobile application (Android/iOS) and our cloud services:
2.1 Business Owner Data (Tenant)
- Full name and business name
- Owner’s email address
- Phone number
- Address of the establishment
- RFC (Mexican taxpayer registration number)
- Google identifier (if you sign in with Google)
- Business account information (service status and configuration)
- Access credentials (password hashed with BCrypt)
2.2 Employee Data
- Full name and username
- Email address (required for access to the mobile app)
- Email verification status
- Role or job position and assigned permissions
- Assigned primary branch
- Mobile application access flag
- Google identifier (where applicable)
- Access credentials (password hashed with BCrypt)
- Account creation and last update dates
2.3 Employee Work Performance Data
For operational management and anomaly detection purposes, we collect daily employee performance metrics:
- Record of activity in the system (sales made, cash counts, shifts)
- Count of suspicious events by severity level (from the Guardian system)
- Success rate and daily classification (Normal, Attention, Alert)
- Scale disconnection metrics (count, duration)
- For delivery drivers: fuel consumption, cost, kilograms delivered and efficiency
- Guardian system trust score per employee
2.4 Data of the Business’s Customers
- Customer name
- Physical address
- Email address (if provided)
- Primary and secondary phone numbers (if provided)
- Notes or remarks
- Credit information: credit limit, outstanding balance, discount type and percentage
- History of changes made to the customer record (who, when, which field changed)
2.5 Transactional and Operational Data
- Sales records: products, quantities, prices, payment method (cash, card, credit), receipt number, employee who made the sale, associated customer, date and time
- Expense records: description, amount, category, employee who recorded it, employee who approved it, receipt image (if attached)
- Cash counts: opening amount, total sales by payment method, expenses, deposits, withdrawals, expected vs. counted amount, difference, notes
- Cash deposits and withdrawals: amount, description, employee, date
- Customer payments: amount, payment method, customer, employee who received it
- Product returns: quantity, reason, employee who processed it
- Sale cancellations: reason for cancellation, employee who cancelled it
- Credit notes
2.6 Delivery Driver and Delivery Data
- Product assignments: quantities, amounts, product, assigned driver, employee who created the assignment
- Driver returns: quantities returned, reason, notes
- Settlements: kilograms assigned vs. sold vs. returned, amounts, deducted expenses, net amount to hand in, cash difference, remarks
- History of edits and cancellations of assignments (who edited, reason, original values)
- Payment method received by the driver (cash, card, credit)
2.7 Guardian System Data (Anomaly Detection)
The Guardian system monitors the activity of the scale connected to the point of sale in order to detect unusual patterns. The data collected includes:
- Suspicious weighing events: event type, weight detected, severity level, risk score, identified fraud scenario
- Trust score per employee and score band
- Scale disconnection records: duration, reason (manual, power failure, cable, unknown), review status
- Review notes written by the administrator
2.8 Location Data
The SYA mobile application does not collect, transmit or store your location on our servers. Real-time GPS tracking of delivery drivers is disabled in the current version of the application.
The only use of location is the following: when you open the delivery zones map inside the application, it queries the device’s location in order to draw your own position on that map and help you locate the customers on the route. This data:
- Is used on the device only, while the screen is open
- Is not sent to our servers and is not saved in any history
- Requires the “While Using the App” permission granted by the operating system, and you may revoke it at any time from your device settings
No location is collected in the background, with the application closed, or outside working hours. The application does not request the “Always” location permission.
2.9 Biometric Data
The mobile application optionally allows the use of biometric authentication (fingerprint or Face ID) for quick access. In that case:
- Biometric data (fingerprint/face) never leaves the device and is never transmitted to our servers
- Only a local reference that the feature is enabled is stored
- The associated access credentials are kept in the device’s encrypted storage (FlutterSecureStorage / Keychain / Keystore)
- When you sign out, the biometric credentials are deleted from the device
2.10 Images and Photographs
- Images of expense receipts captured with the camera or selected from the gallery (compressed to a maximum of 1024x1024 pixels, JPEG quality 75%)
- Product images (optional)
The mobile application requests camera and gallery permission exclusively for these features. No images are captured automatically or in the background.
2.11 Technical and Telemetry Data
- Unique device identifier (generated by the application; it is not the IMEI)
- Device name (make and model)
- Operating system and platform (Android, iOS, Windows)
- Installed application version
- Usage events: application opening, visual theme change
- Push notification token (Firebase Cloud Messaging)
- Authentication tokens (JWT) stored in encrypted storage
- Synchronization records: status, date, errors
- Internet and server connection status
2.12 Supplier Data
- Supplier name and contact person
- Email address and phone number
- Address
- Payment terms and notes
2.13 Virtual Assistant Data (Website Chatbot)
Our website includes a virtual assistant (“Nixta”) that answers questions about our products and services. When you interact with the chatbot, we collect:
- The content of the messages you write and the replies the assistant generates
- An anonymous session identifier (randomly generated; it does not identify you personally) used to group the messages of a single conversation
- The date and time of the conversation and the domain it originated from
- Your IP address and, derived from it, an approximate location (country, region and city) and your internet service provider — used exclusively for security, abuse prevention (for example, limiting the number of messages per visitor) and statistics. This location is indicative at city level: it does not allow us to identify you personally or to know your home address
We recommend that you do not write personal or sensitive data in the chat. Conversations may be reviewed by SYA personnel in order to better answer frequently asked questions, improve the quality of the assistant and detect misuse. This information is used only for the purposes described; it is not used for advertising and it is not sold to third parties. You may request the deletion of your conversations at any time by exercising your ARCO rights (see section 9).
3. Purposes of Processing
3.1 Primary Purposes (Necessary)
- Providing the point-of-sale software services on desktop and mobile
- Managing user accounts, authentication and role-based access control
- Processing and recording sales transactions, returns and cancellations
- Managing inventory and product control
- Managing delivery driver assignments, settlements and returns
- Managing customer credit, payments and account statements
- Generating reports on sales, expenses, cash counts and income
- Operating the Guardian anomaly detection system to protect the business
- Synchronizing data between the desktop application, the mobile application and the cloud
- Performing automatic backups of information
- Sending real-time push notifications about business events
- Displaying the delivery zones map and the user’s own position on it, processed on the device (real-time route tracking is disabled — see section 6)
- Providing technical support
- Billing and collecting license fees
3.2 Secondary Purposes (Optional)
- Sending communications about software updates
- Notifying you about new features or services
- Collecting usage telemetry to improve the user experience (app opening, visual configuration changes)
- Performing aggregate statistical analysis to improve the service
- Sending promotional information (with your consent)
If you do not wish your personal data to be processed for the secondary purposes, you may tell us at info@syatortillerias.com.mx
4. Data Storage and Security
4.1 Where Data Is Stored
- Desktop application (Windows): Local SQLite database on your device, with automatic synchronization to the cloud server
- Mobile application (Android/iOS): Local SQLite database on the device; sensitive credentials in the operating system’s encrypted storage (Keychain on iOS, Keystore on Android)
- Cloud server: PostgreSQL database hosted on Render.com
- Optional backups: Dropbox, Google Drive, OneDrive or iCloud Drive (depending on the user’s configuration)
- Push notifications: Firebase Cloud Messaging (Google Cloud infrastructure)
4.2 Security Measures
We implement administrative, technical and physical security measures to protect your data:
- Password hashing with BCrypt (work factor 12)
- All communications encrypted with HTTPS/TLS (REST API and WebSocket)
- Authentication with JWT tokens with automatic expiration and secure renewal
- Socket.IO connections authenticated with JWT during the handshake
- Role-based access control with granular permissions
- Encrypted storage for sensitive credentials on mobile devices
- Biometric data processed exclusively on the device (never transmitted)
- Images compressed before transmission to minimize exposure
- Data isolation per branch and per business (multi-tenant architecture)
- Device identifiers generated by the application (no IMEI or hardware identifiers are used)
- Automatic, redundant backups
5. Use of Third-Party Services
For the software to operate, we use the following third-party services:
5.1 Google APIs
- Google Sign-In: For secure user authentication (we receive a unique Google identifier and an email address)
- Google Drive API: For cloud backups (optional, requires explicit authorization)
Use of these services is subject to Google’s Privacy Policy.
5.2 Firebase Cloud Messaging (FCM)
We use Google’s Firebase Cloud Messaging to send push notifications to the mobile application. A device token is registered and associated with your employee record and branch. This token is deleted when you sign out. Subject to the Firebase Privacy Policy.
5.3 Dropbox
We use Dropbox for automatic backups of your database. This feature requires your explicit authorization and is subject to the Dropbox Privacy Policy.
5.4 Render.com
Our backend server and cloud database are hosted on Render.com, which complies with international infrastructure security standards.
5.5 Anthropic (Claude)
The virtual assistant on our website runs on Claude, Anthropic’s artificial intelligence technology. The messages you write in the chat are processed through their API in order to generate the replies. Subject to the Anthropic Privacy Policy.
5.6 Cloudflare
We use Cloudflare services to host the virtual assistant service, to store chatbot conversations and to measure the use of our website anonymously and without cookies (Cloudflare Web Analytics). Subject to the Cloudflare Privacy Policy.
5.7 Commitment to Equivalent Protection
Every third party with which SYA shares user data —including analytics services, cloud infrastructure, artificial intelligence providers and the software development kits (SDKs) integrated into our applications, as well as any parent company, subsidiary or related entity that might have access to that data— is required to afford your personal data protection equal or equivalent to that established in this privacy notice. We select these providers by verifying that they have privacy policies and security measures compatible with the commitments made here, and we do not authorize them to use your data for purposes other than providing the contracted service. In particular, we do not share your data with advertising networks or data brokers.
6. Location Tracking
Real-time GPS tracking of delivery drivers is disabled in the current version of the SYA mobile application. This section explains what that means in practice and which conditions would apply if the feature were reactivated in the future.
6.1 Current Situation: No Location Is Collected
The application does not collect, does not transmit and does not store location data of any employee. Specifically:
- There is no tracking of a driver’s location during their working day
- The business administrator cannot see the location of their employees from the application
- No route history is generated or kept
- No location is collected in the background or with the application closed
- The application does not request the “Always” location permission
The only use of location is to draw your own position on the delivery zones map, while you have that screen open. That data is processed on the device and never reaches our servers. You may revoke the location permission at any time from your device settings and the application will keep working (it will simply stop showing your position on the map).
6.2 Conditions for a Possible Reactivation
If we reactivate route tracking in the future, we will announce it in advance in accordance with section 14 of this notice, and the following conditions will apply, in compliance with the principle of proportionality of the LFPDPPP:
- Express, free and informed consent from the employee before any location data is collected. A refusal will not result in any labor retaliation or unfavorable condition
- A visible control in the application to turn tracking on and off at any time, without justification, and a permanent indicator while it is active
- Only during the active working day: never outside working hours
- Minimum data: latitude, longitude and timestamp; no other device data
- Restricted access for the business administrator and the employee themselves. No sharing with third parties, no sale, no advertising and no profiling
- Maximum retention of 90 days, with automatic deletion afterwards and the option to request early deletion through ARCO rights (section 9)
7. Device Permissions (Mobile Application)
The mobile application requests the following permissions, depending on the platform:
7.1 Android
- Internet: To connect to the server and synchronize data
- Network state: To detect connection availability
- Biometrics: For fingerprint authentication (optional)
Note: The application does NOT request camera permission directly on Android; images are captured through the operating system’s image picker.
7.2 iOS
- Camera: To capture images of expense receipts
- Photo library: To select existing images
- Face ID: For biometric authentication (optional)
- Remote notifications: To receive push notifications
- Location (While Using the App only): To show your own position on the delivery zones map. The application does not request the “Always” location permission and does not collect location in the background (see section 6)
- Bluetooth: To connect to thermal receipt printers. It is used exclusively for printing; nearby devices are not tracked and it is not used to infer your location
All permissions require the user’s explicit authorization through the operating system. You may revoke any permission in your device settings at any time.
8. Data Transfers
Your personal data may be transferred and processed inside and outside the country, only for the following purposes:
- Backend server on Render.com for central storage and processing
- Firebase Cloud Messaging (Google) for delivery of push notifications
- Backup services (Dropbox, Google Drive) with your explicit consent
- Competent authorities when required by law
We do not sell, rent or share your personal data with third parties for marketing or advertising purposes.
9. ARCO Rights
Under Mexican law you have the right to know what personal data we hold about you, what we use it for and the conditions of that use (Access). You also have the right to request the correction of your personal information when it is out of date, inaccurate or incomplete (Rectification); to request that we delete it from our records or databases when you consider that it is not being used in accordance with the principles, duties and obligations set out in the applicable regulations (Cancellation); and to object to the use of your personal data for specific purposes (Opposition). Together these are known in Mexico as your ARCO rights.
9.1 How to Exercise Your ARCO Rights
To exercise your ARCO rights, send a request to info@syatortillerias.com.mx including:
- Your full name and the email address on file
- A clear description of the data concerned and the right you wish to exercise
- Documents proving your identity (a copy of official identification)
We will respond within a maximum of 20 business days. If the request is granted, it will take effect within the following 15 business days.
10. Withdrawal of Consent
You may withdraw the consent you have given us to process your personal data by sending a request to info@syatortillerias.com.mx. In the specific case of location tracking there is no consent to withdraw, because the application does not collect location data (section 6); if you still wish to prevent the app from querying your position in order to draw it on the zones map, remove the location permission from your device settings. For biometric authentication, you can disable it from the application settings, which deletes the credentials stored on your device. However, for other types of data, please bear in mind that we may not always be able to grant your request immediately, as a legal obligation may require us to continue processing your personal data.
11. Account Deletion, Signing Out and Uninstalling
11.1 Deleting Your Account from the App
The business owner can delete the account and all business data directly from the mobile application, without having to contact us: menu “More” → “Delete account”. The action asks for double confirmation because it is irreversible.
Upon confirmation, the data of the business and its branches, employees, customers, suppliers and associated operational records are deleted from our servers, as are the backups we manage. This deletion is permanent and cannot be undone. We will retain only the information that a legal obligation requires us to keep (for example, records with tax effects, for the period stated in section 13).
Employees who are not owners may request the deletion of their personal data from their business administrator, or directly from us through their ARCO rights (section 9).
11.2 When You Sign Out (Mobile App)
- The device is unregistered from push notifications (FCM)
- Authentication tokens are deleted from encrypted storage
- Stored biometric credentials are deleted
- The local SQLite database remains on the device for offline access
11.3 When You Uninstall the Application
- All local information (database, preferences, tokens, credentials) is automatically deleted by the operating system
- Data stored on our backend server remains. To erase it, use “Delete account” inside the app (section 11.1) or request its Cancellation through your ARCO rights (section 9)
12. Cookies and Local Storage
Our website may use cookies to keep your session active and remember your preferences (such as the light/dark theme). The mobile application uses local storage (SharedPreferences) to save non-sensitive preferences such as:
- Selected visual theme
- User avatar (emoji, image or chosen color)
- Connectivity status
You can configure your browser to reject cookies, although this may affect some website features.
To measure the use of our website we use Cloudflare Web Analytics, a tool that respects your privacy: it does not use cookies and does not collect data that identifies you personally. It only records aggregate, anonymous metrics (such as pages visited and device type) to help us improve the site.
We also record, without cookies, some uses of the site itself — for example whether the video on the home page was played and how much of it was watched — in order to know whether our content is useful. To group those actions within a single visit we use a random number kept in your browser’s temporary memory (sessionStorage), which is erased when you close the tab and does not allow us to identify you or recognize you on later visits.
13. Data Retention
We keep your personal data for the following periods:
- Account data: While you hold an active license and for up to 2 years after its cancellation
- Transactional data: 5 years, to comply with tax obligations
- Guardian system data: 1 year, for analysis and audit purposes
- Activity logs and telemetry: 1 year, for security and support purposes
- Location data: Not applicable — we do not currently collect location (see section 6). If the feature were reactivated, maximum retention would be 90 days with automatic deletion afterwards
- Website virtual assistant conversations: For as long as they are necessary for the service improvement and security purposes described, or until you request their deletion (ARCO rights)
- In-app assistant conversations: A maximum of 90 days, with automatic deletion afterwards
- Push notification tokens: Until the device is unregistered (on sign-out)
- Backups: According to the configuration set by the user (the last 15 backups by default)
Note on deletion: The system uses logical deletion (soft delete) for most records, which means that data is marked as inactive but remains in the database for referential integrity and audit purposes. You may request definitive deletion through your ARCO rights.
14. Changes to This Privacy Notice
We reserve the right to make amendments or updates to this privacy notice. Any amendments will be made available on our website at https://syatortillerias.com.mx/en/privacy-policy and we will notify you of significant changes through the software or by email.
15. Data Protection Authority
If you believe your rights have been infringed, you may file a complaint with the Mexican National Institute for Transparency, Access to Information and Protection of Personal Data (INAI): www.inai.org.mx
16. Contact
For any questions or clarifications regarding the processing of your personal data:
- Email: info@syatortillerias.com.mx
- Website: https://syatortillerias.com.mx