Privacy Policy
At SmartStore HQ, we believe your business intelligence is strictly yours. This policy explains exactly how we secure your POS transactions, AI chats, and enterprise ledgers.
1. Multi-Tenant Data Collection
SmartStore HQ operates as an Enterprise Business Operating System (EBOS). The data we process is strictly to facilitate your operations:
- Tenant Ledgers: All inventory batches (FEFO), branch telemetry, Khata double-entry ledgers, and staff attendance logs are stored in isolated partitions within our Neon.tech PostgreSQL databases.
- Customer Data (CRM): Leads gathered via POS counters or WhatsApp Webhooks are strictly owned by you. We do not aggregate your customers' phone numbers or purchasing habits.
- Infrastructure Telemetry: We collect non-identifiable system logs (P99 latency, API error rates) to maintain our Render cloud deployment SLAs.
2. AI Employees & Meta Webhooks
SmartStore HQ integrates advanced AI (Gemini LLMs) to process your WhatsApp and Instagram direct messages. Here is how that data is handled:
- Zero AI Training on Your Data: Incoming customer chats are sent to Gemini LLM to generate replies (Draft Orders). Google's Enterprise APIs guarantee that your chat logs are never used to train public AI models.
- Meta Graph API Strict Compliance: Messages received via WhatsApp Business API or Messenger are encrypted in transit. We only decrypt them inside our secure backend to render them in your Unified Inbox and route them to the AI.
- No Ad Targeting: We will never sell your customer chat logs or CRM lists to Facebook/Meta or any other advertising broker.
3. Data Security & Storage
We utilize enterprise-grade architecture to prevent breaches and unauthorized access:
- Row-Level Security (RLS): Our PostgreSQL database enforces strict RLS policies, ensuring that Branch A cannot query the financial ledgers of Branch B, even at the raw database level.
- Encryption: Data is encrypted at rest (AES-256) and in transit (TLS 1.3).
- Automated Backups: Daily snapshots are securely vaulted offsite, ensuring your POS records survive catastrophic hardware failures.
4. Data Portability & Deletion
You are not locked into our ecosystem. You have the absolute right to control the lifecycle of your data.
- Full Export Rights: Account owners can export their entire catalog, Khata ledgers, and CRM contacts in CSV/JSON formats at any time.
- Permanent Deletion (The 30-Day Purge): If you cancel your subscription, we initiate a permanent hard-delete of your entire tenant database partition 30 days after cancellation. Backups containing your data naturally age out and are destroyed within a standard 60-day lifecycle.
5. Payment Processing & PCI Compliance
SmartStore HQ facilitates billing, but we deliberately limit our exposure to sensitive financial instruments:
- No Credit Card Storage: We do not store raw credit card numbers, CVVs, or bank PINs on our servers. All digital payments are tokenized and processed via certified gateways (e.g., Stripe) that hold PCI-DSS Level 1 compliance.
- Khata (Credit) Ledgers: Any manual credit limits or outstanding balances you assign to your customers are stored purely as numerical values against their profile in your isolated tenant database.
6. Employee Data & Workforce Module
As an employer using our Workforce module, you collect data about your staff. SmartStore HQ protects this as strictly as customer data:
- Role-Based Access Control (RBAC): Cashiers cannot view the salaries, commissions, or shift logs of other staff members. Only users with Manager/Owner roles have clearance.
- Audit Logs: Every action taken by an employee on the POS is logged (e.g., voiding a receipt) for internal loss prevention, but this data remains exclusively yours to audit.
7. Cookies, Tracking & Sessions
We use cookies and local storage mechanisms exclusively for platform functionality and security, not for retargeting ads:
- Authentication Tokens: Secure, HTTP-only JWTs are used to keep you logged into the web portal and POS native apps.
- Zero Third-Party Trackers: We do not deploy Meta Pixel, Google Analytics advertising features, or third-party behavioral trackers inside the authenticated EBOS dashboard.
8. Global Privacy Rights (GDPR & CCPA)
SmartStore HQ acts as a Data Processor for the business data you upload, while you remain the Data Controller. Depending on your jurisdiction (e.g., EU, California), you and your customers have rights to:
- Right to Access & Rectification: You can edit any customer profile or inventory record directly through the admin dashboard.
- Right to be Forgotten: You can hard-delete a customer's CRM profile from your database instantly.
- DPA Addendums: Standard Contractual Clauses (SCCs) are available for Enterprise clients routing data outside the EU.
Data Protection Officer (DPO)
If you have any questions regarding SOC2 compliance or data processing agreements (DPA), contact our legal team.
