Privacy Policy
Last updated: June 24, 2026
This Privacy Policy explains how {{LEGAL_ENTITY_NAME}} ("we", "us", "our"), the operator of DigiVyapar Pro (the "Service"), collects, uses, shares, and protects personal data. By creating an account or using the Service, you agree to this Policy.
1. Who we are
DigiVyapar Pro is a business-management platform (inventory, orders, billing, payments and related tools) operated by {{LEGAL_ENTITY_NAME}}, {{REGISTERED_BUSINESS_ADDRESS}}. For any privacy question, contact us at privacy@digivyaparpro.com.
2. Two roles: your account vs. data you upload
For your account information (the people who sign in), we act as the data fiduciary / controller.
For the personal data you enter about your own customers, vendors and employees, you are the data fiduciary and we act as a data processor handling that data on your instructions to provide the Service. You are responsible for having a lawful basis (e.g. consent) to upload it. See our Terms of Service.
3. Information we collect
Account data (you provide): name, email, phone number, password, business name and business type.
Data you enter about third parties: customer and vendor details (name, phone, email, billing/shipping address, GSTIN, and for vendors PAN), employee details (name, email, phone, role), and any notes you add.
Business records: products, inventory, orders, invoices, payments, expenses, and reports you create in the Service.
Files you upload: attachments such as bills, receipts and invoices, which may contain personal data.
Payment data: for paid subscriptions, payments are processed by our payment gateway. We do not receive or store your full card details — only transaction metadata (amount, status, date, method, reference).
Device & technical data: push-notification device tokens, device/app/OS version, and basic activity needed to operate and secure the Service. Standard server logs (e.g. IP address) may be processed by our infrastructure providers.
Product analytics (web, consent-based): on the web version of the Service we use Microsoft Clarity to understand how the product is used (for example aggregate usage, navigation flows, and anonymised session replays/heatmaps) so we can improve it. Clarity loads only after you consent and never on the mobile apps. Recordings are privacy-masked: in our configuration all on-screen text is masked, and the contents of input fields and dropdowns are always masked, so your business, customer, vendor, employee and financial data are not captured. We associate analytics only with non-identifying values (a one-way hashed account/workspace identifier, your role, and your subscription plan) — never your name, email, phone, GSTIN/PAN, addresses, amounts or any other personal data. You can decline at the consent prompt; doing so disables Clarity. We do not use advertising SDKs.
4. How we use your data
Provide, operate and maintain the Service and your account.
Authenticate you and keep the Service and your data secure (including fraud/abuse prevention).
Process subscription payments and manage billing.
Send service and transactional notifications (orders, payments, inventory, account, subscription).
Provide customer support and respond to your requests.
Improve reliability and performance, and fix problems.
Comply with legal, tax and regulatory obligations.
5. Sharing & sub-processors
We do not sell your personal data. We share data only with service providers ("sub-processors") that help us run the Service, under appropriate confidentiality and data-protection terms:
Supabase — database, authentication and file storage (hosting of your data).
Razorpay — subscription payment processing.
Google Firebase Cloud Messaging (FCM) — push notification delivery.
Brevo — transactional email (e.g. employee invitations, support).
Cloudflare — Android app (APK) distribution.
Microsoft Clarity — consent-based, privacy-masked product analytics on the web (see Section 3).
We may also disclose data where required by law, to enforce our agreements, or to protect rights, safety and security.
6. International transfers
Some sub-processors may store or process data outside India. Where they do, we rely on those providers' safeguards and applicable legal protections for such transfers.
7. Data retention
We retain personal data for as long as your account is active and as needed to provide the Service. After account closure or a deletion request, we delete or anonymise personal data within 30 days, except where we must retain certain records to comply with law (for example, tax and financial records, which Indian law may require us to keep for up to 8 years) or to resolve disputes and enforce our agreements. Backups are cycled and purged on a rolling basis.
8. Security
We use commercially reasonable safeguards, including encryption in transit (TLS), encryption at rest at our hosting provider, tenant-level data isolation (row-level security), and role-based access controls. No method of transmission or storage is 100% secure, and you are responsible for keeping your login credentials confidential. If a breach affecting your personal data occurs, we will notify affected users and the relevant authority as required by applicable law.
9. Your rights
Subject to applicable law (including the Digital Personal Data Protection Act, 2023), you may:
access and obtain a copy of your personal data (in-app Export my data, or by email);
correct inaccurate data;
request deletion of your account and personal data (in-app Delete my account, or via our Account Deletion page);
withdraw consent (for example, by turning off optional notifications or closing your account); and
nominate, where applicable, another person to exercise your rights.
To exercise these rights, use the in-app controls or email privacy@digivyaparpro.com. We aim to respond within 30 days.
10. Grievance Officer
In accordance with applicable Indian law, our Grievance Officer is:
{{GRIEVANCE_OFFICER_NAME}}
Email: grievance@digivyaparpro.com
Address: {{REGISTERED_BUSINESS_ADDRESS}}
11. Cookies & local storage
The Service uses local storage (and, on the web, equivalent browser storage) strictly to keep you signed in and remember preferences. If you consent to product analytics on the web, Microsoft Clarity may also set cookies/storage to measure usage (see Section 3); you can decline these at the consent prompt. We do not use advertising or cross-site tracking cookies.
12. Children
The Service is intended for businesses and is not directed at individuals under 18. We do not knowingly collect personal data from children.
13. Changes to this Policy
We may update this Policy from time to time. We will post the updated version here with a new "Last updated" date and, where appropriate, notify you in-app.
14. Contact
Questions about this Policy or your data: privacy@digivyaparpro.com · {{LEGAL_ENTITY_NAME}}, {{REGISTERED_BUSINESS_ADDRESS}}.