This Privacy Policy explains what personal data Nexcod POS ("we", "us") collects through the website nexcodpos.in, the Nexcod POS software and its Android and Windows apps, why we collect it, who it is shared with, and the rights you have. It is written to meet the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 and its rules. By using the Service you agree to the processing described here.
1. Our role and yours
- For the details of the people who hold accounts with us (shop owners and their staff) and of visitors who contact us, we are the Data Fiduciary.
- For the details a shop enters about its own customers, patients, doctors and suppliers, the shop is the Data Fiduciary and we process that data only on the shop's instructions, to provide the Service. A customer who wants to use their rights over such data should first contact the shop; we will help the shop respond.
2. What we collect
- Account details: name, mobile number, e-mail, password (stored only as a one-way hash), store name, address, GSTIN, drug licence number and logo.
- Business records you enter: products, batches, stock, purchases, sales bills, returns, payments, expenses and reports.
- People in your records: names, phone numbers and addresses of customers, patients, doctors and suppliers, prescription details and dues, as entered by the shop.
- Staff records: staff names, phone numbers, attendance, the selfie and location taken when attendance is marked in the app, and salary entries.
- Purchase bills you upload: the PDF or photo of a supplier's bill, so that it can be read into a purchase entry.
- Payments: the plan, the amount, the date and the UTR reference you enter. We never see your UPI PIN, card number or bank password.
- Enquiries: the name, phone number, e-mail and message you send through a form on the website, including a call request.
- Technical data: IP address, browser or device type, app version, sign-in times and an activity log of changes made in the account, kept for security.
- Notifications: a device token, if you allow notifications in the app.
- Google sign-in: your name and e-mail from Google, if you choose to sign in with Google.
3. Why we use it
- To create and secure your account, and to verify you with one-time codes.
- To provide the Service: billing, stock, purchase entry, reports, staff, backups and the messages you choose to send.
- To confirm payments and switch plans on.
- To give support, answer enquiries and call back when you ask us to.
- To send service messages such as sign-in codes, alerts, plan reminders and important changes.
- To detect and prevent fraud, abuse and security incidents, and to meet legal obligations.
- To improve the Service using combined figures that do not identify anyone.
We do not sell, rent or trade personal data, and we do not use your business data for advertising.
4. Who we share it with
Only with the service providers below, each for its own purpose and bound by its own terms, or where the law requires it:
- Hosting provider: stores the Service's database and files on its servers.
- OpenAI: receives a purchase bill you upload, and nothing else from your account, so that its lines can be read. It is used only when you upload a bill.
- WhatsApp: bills and messages you choose to send go from your own linked WhatsApp number to the person you send them to.
- Google: for Google sign-in, for app notifications through Firebase Cloud Messaging, and for Google Drive backups if you connect your own Drive. We can see only the files the Service creates in your Drive.
- E-mail delivery: to send sign-in codes, receipts and service messages.
- Authorities: when required by law, a court order or a lawful request from a government agency.
5. Cookies and storage
We use only the cookies needed for the Service to work: a session cookie that keeps you signed in and a security token against forged requests. The software stores a few preferences, such as the last screen or filter you used, in your browser. There are no advertising cookies and no third-party tracking or analytics scripts on our website.
6. Android app permissions
- Camera: to scan barcodes and pairing QR codes, and for staff to take an attendance selfie. The camera is used only when you open these screens; scanning frames are processed on the device and not stored.
- Internet: to reach your data over a secure connection.
- Location: when a staff member marks attendance, their location at that moment is checked against the shop's location and saved with the attendance entry, so the owner can see it was marked at the shop. The owner also uses it once to set the shop's location. The app does not track location in the background.
- Notifications and vibration: optional, for attendance, salary and store alerts. You can turn them off in your phone's settings.
- Foreground service: lets a store alarm you set keep ringing until you stop it.
The app asks for no other permission.
7. How we protect it
All connections use HTTPS. Passwords are stored only as one-way hashes and app sessions use random tokens that expire and are revoked when you sign out or change your password. Every account can reach only its own store's data, and staff see only what the owner allows. Access to our systems is limited and logged. No system is perfectly secure; if a personal data breach occurs, we will inform the affected users and the Data Protection Board of India as the DPDP Act requires.
8. How long we keep it
- Account and business data: while the account is active. You can delete individual records in the software at any time.
- After an account is closed: kept for 30 days so that an export can be requested, then deleted, except what we must keep by law, such as our own payment and tax records.
- Enquiries and call requests: for as long as needed to answer them, and no longer than two years.
- Security and activity logs: for as long as needed to protect the Service and meet legal requirements.
9. Your rights
Under the DPDP Act you have the right to:
- know what personal data we hold about you and how it is used;
- have it corrected, completed or updated;
- have it erased when it is no longer needed, unless the law requires us to keep it;
- withdraw consent, as easily as you gave it, for any processing that relies on consent;
- nominate another person to exercise these rights if you die or become unable to;
- have a grievance resolved by our Grievance Officer, and if you are not satisfied, to complain to the Data Protection Board of India.
Most details can be seen and corrected in the software itself. For anything else, write to us from your registered e-mail or phone. We may ask you to confirm your identity before acting on a request, and we respond within 30 days.
10. Children
The Service is a business tool for adults and is not meant for anyone under 18. We do not knowingly collect a child's data for our own purposes. A shop that records a child as a patient or customer is responsible for doing so lawfully.
11. Where data is stored
Data is stored on servers operated by our hosting provider and the service providers named above, some of which may be outside India. We do not transfer personal data to any country the Government of India has restricted under the DPDP Act, and we expect every provider to protect it to the standard described here.
12. Changes to this policy
We may update this policy. The date at the top shows the latest version. We will tell you of a material change in the software or by e-mail before it takes effect.
Contact and grievance officer
Questions, complaints and requests about this document go to our Grievance Officer, who acknowledges them within 48 hours and resolves them within 30 days of receipt.
- Grievance Officer: Krishav Kumar Barman, Nexcod POS
- Email: support@nexcodpos.in
- Phone: +91 7319833790
Also read our Terms of Service and Refund and Cancellation Policy. Together with this page they form the whole agreement between you and Nexcod POS.
