Privacy Policy
Effective September 19, 2026
CStoreNexus is software a store owner uses to run their own business. Almost everything in it is your business data — your registers' files, your invoices, your price book. We hold it so the software can show it back to you. We do not sell it, we do not advertise against it, and we do not use it to train anything.
1. Who we are
CStoreNexus is operated by EGY Management, Memphis, Tennessee, United States. If you have a question about anything on this page, write to egycstore@gmail.com.
2. What this policy covers
The CStoreNexus web application at app.cstorenexus.com, the CStoreNexus mobile app for iPhone and Android, the collector software that runs on a store's office PC, and this website. It does not cover anything your register manufacturer, fuel supplier or card processor does with your data under their own agreements with you.
3. What we collect
Account information
- Your name and email address.
- Your role (Owner, Admin, Supervisor, Manager or Employee) and the list of locations you may see.
- A password, which is held by Google Firebase Authentication and is never visible to us in readable form.
Your business data
The whole point of the product. This is created by your own equipment and your own staff:
- Register files. Transaction journals and day-close movement documents written by your Gilbarco Passport or Verifone Commander, collected from the register's own network share.
- Sales, shift and fuel data derived from those files — department totals, hourly sales, tenders, lottery, gallons by grade, tank readings.
- Invoices you or your staff upload, including the photographs and PDFs themselves, and everything read out of them: vendor, item numbers, costs, quantities.
- Your price book — items, costs, retails, categories, vendors, promotions and the price changes you queue to your registers.
- Records of what people did in the software: who accepted a shift, who accepted an invoice, who changed a price and when.
Register journal files may contain payment details in the truncated, masked form the register itself writes — typically a card type and the last four digits. We store the register's file as it was written. We never collect, and the register never gives us, a full payment card number, PIN or magnetic stripe data. We do not process payments.
Photographs and files you upload
Invoice photographs, PDFs and spreadsheets you send from the web app or the phone. These are stored against the location they belong to. Uploads are capped at 15 MB and limited to images, PDFs, CSV and Excel files.
What the mobile app asks for, and why
| Permission | Why | What leaves the phone |
|---|---|---|
| Camera | Photograph an invoice; scan a barcode for a price check. | An invoice photo you choose to send. Barcode scanning happens on the phone — no image from a scan is uploaded. |
| Photos / Files | Attach an invoice you already photographed or received as a PDF. | Only the file you pick. The app cannot browse your library on its own. |
| Face ID / Touch ID / fingerprint | Unlock the app after your first sign-in. | Nothing. Your device tells the app yes or no. No biometric data is ever sent to us or stored by us. |
| Notifications | Tell you something is waiting for you to accept. | A device token, so a notification can reach that phone. |
Technical data
Server logs of requests to the service (time, IP address, which function ran, whether it succeeded), and error reports when something breaks. Kept so the service can be operated and debugged.
4. What we do not do
- We do not sell, rent or share your data with data brokers or advertisers.
- We do not show ads, and we run no advertising or cross-site tracking code.
- We do not use your invoices, price book or sales data to train machine-learning models of our own.
- This website sets no cookies and runs no third-party analytics. Signing in to the application does store a session on your device, because that is what keeps you signed in.
5. How we use what we collect
- To run the software: read your register files, build your reports, read your invoices, hold your price book.
- To decide who may see and do what, using your role and your location list.
- To notify you when something needs your attention.
- To support you when you ask for help, and to find and fix defects.
- To bill you, and to keep the records a business is required to keep.
- To comply with the law where we must.
6. Who else touches it
We use a small number of service providers. They act on our instructions and may not use your data for their own purposes.
| Provider | What it does | Where |
|---|---|---|
| Google (Firebase) | Hosting, sign-in, database, file storage and the scheduled jobs that build your reports. | United States |
| OpenRouter, and the model provider it routes to (currently Google Gemini) | Reads the text off an invoice photograph you upload. The image and the text read from it are sent for that purpose only. | United States |
| Apple, Google | Deliver push notifications to your phone, and distribute the mobile app. | United States |
We will also disclose data if the law requires it, and we will tell you unless we are forbidden to. If the business is ever sold, your data moves with it and you will be told before anything changes.
7. Where it lives, and for how long
In Google Cloud data centres in the United States. We keep your business data for as long as your account is open, because a back office with a deleted history is not a back office. Server logs are kept for up to 90 days.
Your register's own files never leave your store on our account. The collector copies them up; it never deletes the originals from the store PC. Whatever happens to us, the files on that machine are still yours and still there.
8. Security
- Everything travels over HTTPS/TLS and is encrypted at rest by Google Cloud.
- Access is enforced on the server by rules tied to your account and your location list — not by hiding buttons in the interface.
- Read-only roles (Manager, Employee) cannot accept a shift, accept an invoice, send a price to a register, or add a user, and the server refuses those writes regardless of what a client asks for.
- No system is perfectly secure. If a breach affects your data we will tell you promptly and say what we know.
9. Your choices and your rights
You may ask us to show you what we hold, correct it, export it, or delete it. Write to egycstore@gmail.com from the address on the account and we will answer within 30 days. Depending on where you live you may have rights under laws such as the California Consumer Privacy Act or the GDPR; we apply the rights described here to everyone regardless.
10. Deleting your account and your data
You can have your account and its data deleted in either of two ways:
- Ask the Owner on your account to remove you in Users & Access. That revokes your access immediately.
- Email egycstore@gmail.com from your account address with the subject Delete my account.
Your sign-in record and personal details are deleted within 30 days. Business records that the account owner must keep — accepted shift reports, accepted invoices, the audit trail of who changed a price — are retained for up to 7 years where tax or accounting law requires it, or deleted sooner on the account owner's written instruction. Backups roll off within 90 days.
11. Children
CStoreNexus is business software and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has an account, write to us and we will remove it.
12. Changes to this policy
If we change something that matters, we will change the date at the top and tell account owners by email before it takes effect. The current version always lives at cstorenexus.com/privacy.
13. Contact
CStoreNexus · EGY Management · Memphis, Tennessee, United States
egycstore@gmail.com