Privacy Notice
Last updated: July 12, 2026
This notice describes how KounterPOS collects, uses, and protects your personal data in compliance with India's Digital Personal Data Protection Act, 2023 (DPDP Act).
1. Data We Collect
When you use KounterPOS, we collect the following categories of personal data:
• Account information: name, email address, and password (stored in hashed form only).
• Business data: customer names, invoices, inventory items, and financial records you create within the application.
• Usage data: pages visited, features used, and interaction patterns within the application.
• Device/browser data: IP address, browser type, and operating system for security and fraud prevention.
2. How We Use Your Data
We process your data for the following purposes:
• To provide and maintain the ERP service, including invoicing, customer management, and financial reporting.
• To authenticate your identity and protect your account.
• To send service-related communications (account security alerts, billing notices).
• To improve our product through aggregated, anonymized usage analysis.
• To comply with legal obligations under Indian law, including the DPDP Act 2023.
3. Legal Basis for Processing
We process your data under the following bases:
• Consent: You explicitly consent to data collection during signup and for each specific processing purpose (see Section 6).
• Contractual necessity: Processing required to deliver the service you subscribed to.
• Legal obligation: Retaining records as required by Indian tax and financial regulations.
• Legitimate interest: Fraud prevention, security monitoring, and product improvement.
4. Data Retention
• Account data: Retained while your account is active, deleted within 30 days of account closure.
• Financial records: Retained for 7 years as required by Indian tax law (Income Tax Act, GST Act).
• Consent records: Retained for 3 years after the consent is withdrawn, as required by DPDP Rules.
• Usage logs: Retained for 90 days for security purposes.
• Support tickets: Retained for 2 years after resolution.
5. Data Sharing
We share your data only in the following circumstances:
• Legal compliance: We may disclose data if required by Indian law, court order, or regulatory authority.
• Service providers: Infrastructure providers (hosting, database) who process data on our behalf under strict contractual obligations.
• We do NOT sell your personal data to third parties.
• We do NOT share your data for advertising or marketing purposes.
6. Your Consent Rights
Under the DPDP Act 2023, you have the right to:
• Give or withdraw consent at any time for each specific purpose.
• Withdraw consent as easily as it was given — visit Settings > Privacy or contact our Grievance Officer.
• Be informed about what data is collected and why, before consenting.
• No pre-ticked boxes — all consents are opt-in and granular.
Withdrawing consent may limit your ability to use certain features of the service.
7. Your Data Subject Rights
You have the right to:
• Access: Request a copy of all personal data we hold about you.
• Correction: Request correction of inaccurate or incomplete data.
• Erasure: Request deletion of your personal data (subject to legal retention requirements).
• Data portability: Request your data in a structured, machine-readable format.
• Grievance: File a complaint with our Grievance Officer if you believe your rights have been violated.
To exercise any of these rights, visit our Data Rights page or contact our Grievance Officer.
8. Data Security
We implement industry-standard security measures:
• Encryption in transit: All data is transmitted over TLS 1.2+ (HTTPS).
• Encryption at rest: Database encryption provided by our infrastructure provider (PostgreSQL with encrypted storage).
• Access control: Tenant-level row-level security ensures complete data isolation between customers.
• Authentication: Argon2id password hashing; JWT-based session management.
• Backups: Automated daily backups with encrypted storage.
• Monitoring: Real-time security monitoring and alerting.
9. Grievance Officer
In accordance with the DPDP Act 2023 and the Information Technology Act 2000, our Grievance Officer is:
Name: [Grievance Officer Name]
Email: grievance@kounterpos.digital
Address: [Registered Office Address]
Response time: Within 24 hours of receipt; resolution within 30 days.
For more details, visit our Grievance Officer page.
10. Changes to This Policy
We may update this Privacy Notice from time to time. Material changes will be communicated via email and in-app notification at least 30 days before they take effect. The "Last Updated" date at the top indicates the most recent revision.
Continued use of the service after the effective date constitutes acceptance of the updated policy.
11. Contact Us
For questions about this Privacy Notice or our data practices:
Email: privacy@kounterpos.digital
Grievance Officer: grievance@kounterpos.digital
Data Rights Requests: Use the Data Rights page or email privacy@kounterpos.digital
If you have questions about this policy, contact our Grievance Officer or email privacy@kounterpos.digital.