Privacy Policy & DPA(Version 2.4 (Enterprise SLA))

Privacy & Data Protection Policy

Comprehensive guidelines on how MSMS Enterprise gathers, cryptographically processes, and protects your retail store databases and employee identities.

Effective Date:
August 4, 2026
Executive TL;DR Summary (In Plain English):
You (the Store Owner) retain 100% intellectual and physical ownership of all POS invoices, customer directories, and device IMEI records.
MSMS operates strictly as a Data Processor. We NEVER sell, share, or broker your store revenue ledgers or customer phone lists to third-party advertisers.
When registering via Google OAuth, we only fetch your name, verified email address, and profile photo icon to provision your Super Admin profile.
Staff employee passwords generated by store admins are hashed using industry-standard Bcrypt before database storage.
Section 01

1. Information We Collect & Account Setup

Mobile Shop Management System ("MSMS Enterprise", "we", "us", or "our") delivers specialized retail operational software for mobile showrooms, electronics distributors, and service centers. To operate this software, we collect two distinct categories of information:

Admin & Owner Profiles

When creating an administrative account via Google OAuth 2.0, we receive your basic Google profile profile, including your full name, verified email address, and Google avatar URL. We use this exclusively to authenticate your identity as the verified Store Owner.

Staff Employee Profiles

Store administrators have the authority to provision staff employee profiles across multiple branches. During setup, admins input an employee full name, designated email, login password, monthly salary, and commission parameters.

Bcrypt Password Security: All custom passwords generated by store admins for staff logins are processed through one-way Bcrypt cryptographic hashing algorithms before being recorded in our database. Neither our internal engineering team nor server administrators can decrypt or read employee raw passwords.

Section 02

2. Customer POS & IMEI Inventory Data Ownership

In the course of daily retail operations, your store employees will input end-customer personal data into the MSMS software—such as customer names, mobile telephone numbers, billing addresses, GSTIN numbers, purchased device model numbers, dual SIM IMEI serial codes, and technical repair diagnostic notes.

📌 Data Controller Designation: You (the Store Owner) are exclusively designated as the Data Controller under global privacy frameworks. MSMS operates strictly as your Data Processor. We exercise no ownership rights, liens, or claims over your showroom sales ledgers or customer contact lists.
Section 03

3. Zero Advertising & Data Brokerage Guarantee

We derive our commercial revenue solely from subscription software licensing and enterprise support SLAs—never from surveillance monetization or data trafficking.

  • No Ad Targeting: We will never expose your store customer lists, IMEI warranty histories, or wholesale purchase order costs to ad platforms (such as Meta Ads, Google Ads, or commercial marketing agencies).
  • No Competitor Aggregation: Your showroom's daily revenue figures, inventory sell-through velocity, and profit margins are never pooled into public trade benchmarks or shared with competing electronics retailers.
Section 04

4. Alignment with Indian DPDP Act & GDPR

MSMS Enterprise is built from the ground up to support modern statutory privacy standards, specifically aligned with the Digital Personal Data Protection Act (DPDP Act, 2023) of India and the General Data Protection Regulation (GDPR).

Store administrators are empowered with self-service tools within the dashboard to execute customer data modification requests, update consent records for SMS/WhatsApp warranty notifications, and export branch database archives upon termination of service.

Section 05

5. Cookies, JWT Sessions & Auth Telemetry

We employ strictly necessary operational browser cookies and cryptographic JSON Web Tokens (JWT via NextAuth.js v5) to maintain secure user login sessions across page navigations.

When an administrator switches operating store branches, we set a temporary session cookie (active_branch_id) to synchronize UI views. We do NOT use invasive tracking pixels or cross-site fingerprinting trackers.

Section 06

6. Contacting Our Data Protection Officer (DPO)

If you have legal queries, require formal Data Processing Addendums (DPA) for your enterprise compliance records, or wish to report potential security vulnerabilities, please communicate directly with our dedicated Data Protection Office:

MSMS Enterprise Privacy Legal Desk
Email: privacy@msms-enterprise.local
Compliance HQ: Tech Park Level 4, Metropolitan Commercial Hub