Legal

Privacy Policy

This Policy explains what data StoreMitr collects, why we use it, and the choices you have.

Effective 10 September 2026

1. Scope

This Policy covers the StoreMitr websites and apps (including storemitr.com and storemitr.shop) and our API.

It does not cover third-party sites you link to (for example Meta WhatsApp or Razorpay checkout pages), which have their own policies.

2. Data we collect

Account data: name, email, password hash (or Google sign-in identifiers), phone number when verified, and role (Owner / Manager / Cashier).

Business data: legal/trade name, GSTIN/PAN if provided, category, HQ location, and Store addresses and settings you enter.

Operational data you create in the product: products, stock movements, sales, customers, Khata balances, team invites, and similar shop records.

Technical data: session cookies, device/browser basics, IP address, and logs needed for security and debugging.

Billing data: plan code, trial dates, and payment references from Razorpay (we do not store full card numbers).

3. How we use data

To provide and secure the service (auth, Stores, inventory, POS, invoices, team access).

To send one-time passwords for phone/email verification and password reset.

To send WhatsApp invoice messages when you request them and when WhatsApp is configured.

To process Owner subscription upgrades and enforce plan caps.

To improve reliability, prevent fraud/abuse, and respond to support requests.

4. Legal bases (India)

We process personal data to perform our contract with you, for legitimate interests such as security and product improvement, and where required by law.

Where consent is required (for example certain communications), we will ask for it in the product.

5. Sharing

We share data with processors who help us run StoreMitr: hosting, email/SMS delivery, WhatsApp Cloud API (Meta) when you send invoices, and Razorpay for subscription payments.

We may disclose information if required by law or to protect rights, safety, or the integrity of the service.

We do not sell your personal data.

6. Retention

We keep account and business data while your account is active and for a reasonable period afterward for backups, disputes, and legal obligations.

Owner-initiated deletion (when available) may include a hold window before permanent erasure of primary account data, subject to legal retention needs.

7. Security

We use industry-standard measures such as encrypted transport (HTTPS), hashed passwords, and access controls. No method of transmission or storage is 100% secure.

8. Your choices

You can update profile and Store information in the app. Owners control team invites and Store data.

For access, correction, or deletion requests, email support@storemitr.com. We may need to verify your identity.

9. Children

StoreMitr is intended for business use by adults. We do not knowingly collect personal data from children under 18 for the purpose of creating Owner accounts.

10. Changes

We may update this Policy and will post the new version with an updated effective date on this page.

11. Contact

Privacy questions: support@storemitr.com.