1. Introduction
VoKart POS ("the App", "we", "us") is a point-of-sale application built for Indian retail merchants. This Privacy Policy explains what data we collect, how we use it, and your rights as a user.
By using the App, you agree to this policy.
2. Data We Collect
2.1 Account & Identity Data
- Name, email address, and phone number (provided during registration)
- Business name, GSTIN (optional), and shop address
- Login credentials (stored securely via Keycloak OAuth2; passwords are never stored in plaintext)
2.2 Business / Transaction Data
- Products, categories, prices, and stock levels you enter
- Sales transactions, payments, and receipts you create
- Customer names, phone numbers, and credit balances you record
- Supplier information and purchase invoices
2.3 Device & Technical Data
- Device model, OS version, and app version (for crash diagnostics)
- Push notification token (FCM) — used only to deliver in-app alerts to your device
- IP address at login time (for security audit logs)
2.4 Camera Access
We access the device camera only when you initiate a barcode or QR code scan (e.g., to add a product by scanning its barcode during billing or inventory management). We do not capture, store, or transmit photos or video.
2.5 Microphone Access
We access the device microphone only when you use the voice order feature to place an order by speaking. Audio is processed solely to convert speech to an order — it is not stored, shared, or used for any other purpose. You can revoke microphone permission at any time in device settings.
2.6 Data We Do NOT Collect
- We do not collect location data
- We do not access your contacts
- We do not collect biometric data
- We do not serve ads or share data with advertising networks
3. How We Use Your Data
| Data | Purpose |
|---|---|
| Account data | Authentication, account recovery |
| Business data | Core POS functionality (billing, inventory, reports) |
| Customer data | Checkout, credit accounts, receipt sharing |
| Device token | Push notifications for new orders and alerts |
| Technical data | Bug fixes, performance improvements |
We do not sell your data to third parties.
4. Data Storage & Security
- All data is stored on servers located in India.
- Data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Access is controlled by role-based permissions — employees see only what their role allows.
- We conduct periodic security reviews.
5. Data Sharing
We share data only in the following limited cases:
| Recipient | Reason |
|---|---|
| Firebase (Google) | Push notifications via FCM |
| Keycloak (self-hosted) | Authentication and session management |
| Payment gateway (if enabled) | Processing UPI/card payments |
| Legal authorities | Only when required by Indian law (IT Act 2000) |
We do not share your business data or customer data with any other third parties.
6. Data Retention
- Active account data is retained for as long as your account is active.
- If you delete your account, we delete your data within 30 days, except where retention is required by law (e.g., GST records under Indian tax law).
- Transaction records may be retained for up to 7 years for tax compliance purposes.
7. Your Rights
As a user, you have the right to:
Access
View the data we hold about you
Correct
Fix inaccurate data
Delete
Remove your account and associated data
Export
Get your data in CSV format
Withdraw Consent
Disable push notifications anytime via device settings
To exercise any of these rights, email: privacy@vokart.in
8. Children's Privacy
VoKart POS is intended for use by adults (18+) operating a business. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us at privacy@vokart.in and we will delete it promptly.
9. Push Notifications
We send push notifications to inform you about:
- New orders or pending voice orders
- Low stock alerts
- Payment and credit account updates
You can disable push notifications at any time in your device settings or in the App under Settings → Notifications.
10. Changes to This Policy
We may update this policy periodically. We will notify you of significant changes via:
- In-app notification
- Email to your registered address
Continued use of the App after changes constitutes acceptance of the updated policy.
12. Governing Law
This Privacy Policy is governed by the laws of India, including:
- Information Technology Act, 2000
- Digital Personal Data Protection Act, 2023 (DPDPA)
Any disputes arising from this policy shall be subject to the jurisdiction of courts in India.