Effective date: [EFFECTIVE DATE] · Operated by [LEGAL ENTITY NAME] ([REGISTERED ADDRESS])
1. What we collect
Shopkeeper account information (provided when your account is created by an administrator): your name, mobile number, shop name, shop address, and GSTIN (if applicable).
Business data you enter in ContoDesk: inventory items, prices, stock levels, bills, payment records, and customer details — including names and mobile numbers of your own customers that you choose to store for billing and udhaar (credit) tracking.
Device and usage information: browser type, app access times, pages or features used, and technical logs needed to operate and secure the service.
Cookies and analytics: we use strictly necessary cookies for session and authentication. We use Google Analytics (tag GT-NBXH9LKH) on public pages only (such as the login and marketing pages) — not on authenticated shopkeeper app screens after sign-in. See our Cookie Policy for details.
2. How we use your information
- To provide and operate ContoDesk for your shop (inventory, billing, customers, GST tools).
- To authenticate you and enforce that each shop's data stays private to that shop.
- To improve reliability, security, and support.
- To comply with applicable law and respond to lawful requests.
- To send service-related communications where permitted.
We do not sell your personal data or business data to third parties.
3. Legal basis and consent (DPDP Act 2023)
ContoDesk is offered to shopkeepers in India. We process personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act), and applicable rules as they come into force.
Where required, we rely on your consent, contractual necessity (to provide the service you request), and legitimate uses permitted under the DPDP Act. By using ContoDesk after being provisioned an account, you acknowledge this Privacy Policy.
You are responsible for having a lawful basis to store your customers' contact details in ContoDesk and for informing your customers as required by law.
4. Data security and tenant isolation
Each shop's data is stored separately and protected by access controls and row-level security so that one shop cannot view or modify another shop's records. Your inventory, bills, and customer ledger are private to your shop and are never shared with other shops on the platform.
We use industry-standard technical and organisational measures to protect data. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
5. Roles: processor vs controller
For your shopkeeper account data (your name, mobile, shop details): [LEGAL ENTITY NAME] is generally the data fiduciary / controller and determines how that account data is processed to operate ContoDesk.
For customer contact data you store(your customers' names, mobiles, and related billing or udhaar records): you are the data controller (data fiduciary) for that information. ContoDesk acts as a data processor — we process that data only on your instructions, to provide the service, and do not use it for our own marketing or share it with other shops.
6. Sub-processors
We use trusted service providers to host and operate ContoDesk, including cloud hosting, database infrastructure, payment processing (if applicable), and message delivery (e.g. email or WhatsApp where enabled). These providers process data only to deliver the service and under contractual obligations consistent with this policy.
A current list of sub-processors may be provided on request to [SUPPORT EMAIL].
7. Data retention
We retain account and business data for as long as your shop account is active and as needed to provide the service, comply with law, resolve disputes, and enforce agreements. Specific retention periods for backups and deleted accounts: [RETENTION PERIODS — TO BE CONFIRMED BY OWNER].
When you or your administrator requests account closure, we will delete or anonymise personal data within [DELETION TIMEFRAME — TO BE CONFIRMED BY OWNER], except where retention is required by law.
8. Your rights
Under the DPDP Act and our policies, you may have the right to:
- Access personal data we hold about you as a shopkeeper.
- Request correction of inaccurate data.
- Request erasure where applicable and not prohibited by law.
- Withdraw consent where processing is consent-based (without affecting prior lawful processing).
- Lodge a grievance with our Grievance Officer (see Contact below).
To exercise these rights, contact [SUPPORT EMAIL]. We will respond within the timelines required by applicable law.
9. Children
ContoDesk is intended for business use by adults (shopkeepers and authorised staff). It is not directed at individuals under 18 years of age, and we do not knowingly collect personal data from children.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the effective date. Material changes may be communicated through the app or by email where appropriate.
11. Contact and Grievance Officer
[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
Email: [SUPPORT EMAIL]
Grievance Officer (DPDP Act)
Name: [GRIEVANCE OFFICER NAME]
Email: [GRIEVANCE EMAIL]