Privacy policy
Last updated: July 4, 2026
Who we are
Boother is a point-of-sale, stock, and pre-order app for artists selling at conventions, operated by an independent developer based in Malaysia (“we”, “us”). For anything in this policy, contact support@bootherapp.com.
This policy covers the Boother mobile app (used by sellers) and the public order forms hosted on bootherapp.com (used by their customers).
What we collect from sellers (app account holders)
- Account data: your email address, display name, and an optional profile photo.
- Business data you create: products, product photos, prices, stock counts, booth records, sales, expenses, and settlement figures.
- Payment instructions you choose to publish: bank or transfer details and QR images you attach to your order forms so customers can pay you.
- Crash reports: if the app crashes, technical error data is sent to Sentry (a crash-reporting service). These reports do not include your email or other personal details.
What we collect from customers (order forms)
When you place an order through an artist’s public form, we collect the details you enter — your name, contact, delivery address (if asked), an optional note, and an optional payment-proof image. This information is collected on behalf of the artist you ordered from and is visible only to them: it is their business record of your order. Payment-proof images are stored in a private bucket and are never publicly accessible.
To ask about, correct, or remove an order you placed, contact the artist you ordered from. You can also contact us at support@bootherapp.com.
How your data is used and shared
Data is used only to run the service. We do not sell your data and we show no ads.
- Booth members you share with: when you join a booth, the other members of that booth can see your display name, photo, the products you allocate to the booth, and the booth’s shared sales and expense records.
- Your customers: see the payment instructions you choose to publish on your forms.
- Service providers (processors): Supabase (database, authentication, file storage), Vercel (web hosting), and Sentry (crash reporting). They store and process data solely to provide the service.
How long we keep data, and account deletion
Your data is kept for as long as your account exists. You can delete your account at any time from the app’s Profile screen or at bootherapp.com/delete-account. Deletion takes effect immediately. When you delete your account:
- Removed: your email, display name, profile photo, product and item photos, published payment instructions (bank details and QR images), and your customers’ order details (names, contacts, addresses, notes, and payment-proof images). Your sign-in credentials are permanently disabled.
- Retained: sales, stock, and expense records of booths you shared with other sellers, shown under the name “Deleted user”. These are the other members’ accounting records and contain nothing that identifies you.
Your rights
In line with Malaysia’s Personal Data Protection Act 2010 (and equivalent rights elsewhere), you can access and correct your account data directly in the app, delete your account as described above, and contact us at support@bootherapp.com with any request or complaint about your data.
Security
Data is encrypted in transit, payment-proof images live in a private bucket accessible only through short-lived signed links, and payment writes go through server-side checks rather than trusting the app. No system is perfectly secure, but we design so that a lost phone or a leaked link exposes as little as possible.
Age requirement
Boother accounts are for users aged 18 and over. The service is a business tool and is not directed at children.
Changes
If this policy changes, we will update this page and its “last updated” date. Material changes will be flagged in the app.