AIMS Privacy Policy
UID Solutions Sdn Bhd (925202-M)
Last updated: 4 October 2026
About this policy
This policy explains how UID Solutions Sdn Bhd, Malaysia ("we", "us"), handles information through AIMS mobile applications and their connected services.
AIMS (Barcode) is our device-based inventory application. Its inventory records and local user accounts are stored on the device. It does not automatically upload or synchronise those records to an AIMS inventory server. Where PRO subscriptions are available, online services verify subscription purchases separately from inventory data.
Earlier or organisation-configured AIMS versions may support RFID readers, employee tags and server-connected asset management. Their different processing is described in the section "Earlier and server-connected AIMS versions" below. Features described there do not mean that AIMS (Barcode) uploads inventory or collects RFID information.
1. Information used by AIMS (Barcode)
AIMS (Barcode) processes the information you and other authorised users enter or generate, including:
- Local accounts: usernames, user identifiers, roles, active status and password-verification data. Passwords are stored as salted password hashes rather than readable passwords.
- Inventory: asset codes, names, barcodes, categories, low-stock thresholds and stock balances.
- Customers: customer names and any contact information you choose to enter, such as a phone number, email address or delivery address.
- Activity and reports: receiving, dispatch and stock-count records; quantities; dates; customer or category references; user names and identifiers; and stock-adjustment approvals.
- Application data: local settings, temporary report files, recovery copies created during data-format upgrades, and securely stored subscription-verification information.
Customer details and usernames may identify individuals. Only enter information you are authorised to use for your inventory operations. Creating a local AIMS account does not create an online UID Solutions account.
2. How local inventory information is used
The app uses this information to authenticate local users, enforce permissions, identify assets, calculate stock balances, record movements, compare physical counts, show alerts, and generate reports.
Sysadmin can manage accounts and view all activity on the installation. Other local users can access shared inventory and customer information, while the app limits their activity-history views to their own actions. Saved reports retain the original transaction and operator details for accountability.
We do not receive local inventory, customer records or AIMS passwords through the standard AIMS (Barcode) subscription-verification process. We may receive information if you choose to send us a report or include it in a support request.
3. Camera and barcode scanning
AIMS (Barcode) requests camera access when you choose camera scanning. Camera frames are processed on the device to recognise a barcode. The scanning feature does not save photos or videos, upload camera frames, or use them for facial recognition.
The recognised barcode is used to identify an asset in the selected workflow. You can enter a barcode manually instead. You can manage camera permission in Android settings.
The current Barcode app does not request access to your microphone, address book or precise device location. It does not include advertising or behavioural-analytics SDKs. Basic scanner diagnostics may record camera readiness, frame dimensions or whether recognition succeeded; the app does not put barcode values or camera images in those diagnostic messages.
4. Google Play purchases and PRO verification
Where subscriptions are enabled, Google Play processes purchases and payments under its own terms and privacy policy. We do not receive your payment-card number or Google password.
The app obtains a purchase token from Google Play and sends it over HTTPS to our subscription-verification service. The service checks the purchase with the Google Play Developer API. It processes information such as the subscription product and plan, purchase status, paid-through date and acknowledgement status. Google's response may also contain transaction references and purchase-region information. These checks are used to grant or restore PRO, acknowledge purchases, and handle renewal, cancellation, expiry or revocation. Google may send subscription-change notifications to the verification service through Google Cloud Pub/Sub.
The app stores purchase tokens and the last verified subscription result in Android secure storage. It retains the last verified access status while offline or when a verification request fails, and checks again when online. The verification service does not need asset names, barcode values, customer details, local AIMS usernames or inventory reports to perform these checks.
The current verification service does not maintain a separate subscription database. Its hosting infrastructure may process network and operational information, such as IP addresses, request times, endpoint paths, response codes and service errors, to deliver and protect the service. Purchase tokens, authentication headers and request bodies should not be included in operational logs.
Canceling renewal does not immediately end a paid period. Expiry may restrict use of records above the Free allowance, but it does not automatically delete those records. Restoring a subscription restores access; it does not restore inventory from another device.
5. PDF exports and sharing
Reports and asset registers may include customer information, asset details, stock balances, operator names and transaction history. When you save a PDF, Android lets you choose the destination. When you share a PDF, you choose the receiving app or service.
Information you export is then handled by the destination you select, which may include a cloud-storage, email or messaging provider. Review the report before sharing it. PDFs saved outside the app or sent to other people are separate copies and are not removed when you delete a record, clear AIMS data or uninstall AIMS.
6. Earlier and server-connected AIMS versions
If you use an earlier or organisation-configured AIMS version with server-connected features, your organisation determines the enabled features, server and permitted users. Such versions may process:
- Login IDs, employee IDs and names, company, branch, section and access permissions.
- Asset descriptions, serial numbers, models, conditions, assigned locations and organisation-defined fields.
- Barcode and RFID identifiers, including TIDs and EPCs, and employee-to-tag associations when enabled.
- Stocktakes, transfers, loans, returns, disposals, registrations, approvals and related operational history.
- Saved company settings, downloaded records, session information and pending offline work.
These versions may transmit submitted or synchronised records to the organisation's configured AIMS server. Authorised administrators, reviewers and service providers can access information as needed for the configured service and their permissions. Our existing hosted server-connected service uses Google Cloud virtual-machine infrastructure. Your organisation may use a different deployment.
RFID identifiers linked to employees may be personal information. Asset locations, such as a room or warehouse, are inventory records and do not by themselves indicate GPS tracking. Contact your organisation's administrator for details of its configuration, hosting region and retention arrangements. This section does not describe the local-only inventory storage in AIMS (Barcode).
7. Service providers and other disclosures
Google processes information required for Google Play billing and, where configured, subscription notifications. Hosting and infrastructure providers process information needed to operate connected services. Providers you select for exports or sharing process the information you send them. Their handling is also governed by their own terms and privacy policies.
We may disclose information we hold when required by applicable law or when necessary to investigate abuse, protect the service or respond to a lawful request. The current Barcode app does not transmit your inventory to advertising networks.
Connected-service processing may take place outside your country, depending on the hosting deployment and providers involved. Contact us for information about the processing location relevant to your service.
8. Storage, security and retention
Barcode inventory and local account records remain in the app's private device storage until removed through available app functions, Android's clear-storage function or uninstalling the app. Signing out does not delete inventory or local accounts. Private recovery copies may preserve earlier data during an upgrade. The app's current version does not automatically back up your inventory to a UID Solutions cloud service.
Local permissions, password hashing, Android secure storage for subscription information and HTTPS for Barcode subscription checks help protect information. These measures do not guarantee absolute security. Protect access to your device, accounts and exported files.
Saved transaction reports retain historical details even if an associated asset, customer or local user is later changed or deleted. Some deletions are restricted to protect stock integrity. Support correspondence and operational or security records we hold are retained for the purposes for which they were received, including resolving requests, protecting the service and meeting applicable obligations. Contact us for the retention arrangements applicable to your request or deployment.
For server-connected versions, deleting local data or uninstalling the app does not delete records already synchronised to the organisation's server.
9. Your choices, access and deletion requests
You can manage camera permission in Android settings, choose manual barcode entry, control what information you enter, and choose whether and where to export reports. Sysadmin can maintain permitted local accounts and records within the app's stock and audit restrictions.
To remove all app-private Barcode inventory, local accounts and cached subscription information from a device, use Android Settings → Apps → AIMS → Storage → Clear storage, or uninstall the app. Save any reports you need first. These actions cannot be used to recover inventory later and do not cancel a Google Play subscription. Manage cancellation separately in Google Play. Files exported outside app-private storage must be deleted separately.
For access, correction or deletion of information held by us, email jonathan@myuids.com. For organisation-managed server records, also contact your organisation's AIMS administrator. Identify the app version and organisation, if applicable, but do not send passwords, payment-card details or purchase tokens. We may verify your identity and coordinate with your organisation. We cannot remotely retrieve or erase inventory held only on your device. Where records must be retained for applicable legal or operational obligations, we will explain the relevant limitation.
Google manages information held in your Google and Google Play accounts under its own policies and account controls.
10. Children's privacy
AIMS is designed for business and organisational inventory work and is not directed at children. If you believe a child has provided personal information to us through the service, please contact us.
11. Changes to this policy
We may update this policy when features or information-handling practices change. The current version will be published on this page with a revised date. Where required, we will provide additional notice of material changes.
12. Contact us
UID Solutions Sdn Bhd (925202-M)
No. 60-1, Jalan Temenggung 1/9,
Bandar Mahkota Cheras, Section 9,
43200 Cheras, Selangor Darul Ehsan, Malaysia.
Email: jonathan@myuids.com