Privacy Policy
Last updated: June 11, 2026
1. Introduction
Retailer360 is operated by Viaom Technologies Pvt. Ltd. ("we", "our", or "us"). We respect your privacy and are committed to protecting the personal and business data you entrust to us. This policy explains what data we collect, why we collect it, how we use it, and the controls you have over it.
By using Retailer360 — whether via the Android app or the web app at app.retailer360.in — you agree to this policy.
2. Data We Collect
Account & Identity Data
- Your mobile phone number (used as your login identity, stored in E.164 format)
- A bcrypt hash of your optional MPIN (quick-unlock PIN); the PIN itself is never stored in plain text
Shop & Business Data
- Shop name, business type, physical address
- GSTIN (optional; used to pre-fill GST invoices)
- Shop logo image (stored in AWS S3)
- Invoice counter and lifetime revenue aggregates
Invoice & Customer Data
- Invoices you create: customer name, phone, address, email; product names, quantities, prices, HSN/SAC codes, serial numbers, IMEI numbers, tax rates
- Customer records and Khaata (credit) ledger entries
- Payment modes (cash, UPI, card, bank transfer, Khaata)
Voice Data
- When you use the Voice Bill feature, your audio is recorded on-device and sent to Google's Gemini API for transcription
- We store the transcript text and extracted invoice data as part of the voice session record
- Raw audio is not stored on our servers
- Voice session data is deleted when you finalize or abandon the session
Google Drive Integration
- If you connect Google Drive, we store your OAuth 2.0 access token and refresh token, encrypted using AES-256-GCM with a key held securely in AWS Systems Manager (SSM) Parameter Store
- These tokens are used solely to upload invoice PDFs to a "Retailer360" folder in your own Google Drive
- You can revoke access at any time from Settings → Google Drive → Disconnect, which deletes the stored tokens and revokes the Google grant
Subscription & Payment Data
- Your subscription plan (Free, Silver, or Gold), status, and billing period
- Zoho Payments payment ID and payment session ID (to confirm your payment and activate your plan)
- We do not store your card number, bank account details, or UPI credentials — all payment processing is handled by Zoho Payments
Staff Accounts
- If you add staff members, we store their name, mobile phone number, and the permissions you assign to them
Authentication Tokens
- Session refresh tokens are stored in DynamoDB with a unique token ID to enable remote revocation
- OTP codes (sent via Firebase) are stored as bcrypt hashes with a short TTL and are never stored in plain text
3. Microphone Access
Retailer360 requests microphone permission only for the Voice Bill feature. Microphone access is not used for any other purpose. When you open the Voice Bill screen for the first time, the app displays a clear disclosure before requesting the permission. You can revoke this permission at any time via your device settings (Settings → Apps → Retailer360 → Permissions → Microphone). Revoking microphone access disables only the Voice Bill feature; all other features continue to work normally.
4. How We Use Your Data
- To provide, operate, and improve the Retailer360 service
- To generate GST-ready invoices and PDFs on your behalf
- To transcribe voice input into invoice drafts using Google Gemini
- To back up invoice PDFs to your Google Drive (only when you have enabled this)
- To manage your subscription and process payments via Zoho Payments
- To authenticate you via Firebase phone OTP and maintain secure sessions
- To respond to support requests and deletion requests
We do not sell, rent, or share your personal or business data with any third party for marketing or advertising purposes.
5. Third-Party Services
Retailer360 uses the following third-party services, each governed by its own privacy policy:
- Firebase Authentication (Google) — sends and verifies phone OTP codes for login. Firebase Privacy
- Google Gemini API — processes voice audio to produce transcripts for the Voice Bill feature. Audio is not retained by us. Google Privacy
- Google Drive API — stores invoice PDFs in your own Google Drive account when the integration is enabled. Google Privacy
- Zoho Payments — processes subscription payments. Zoho stores payment method details on its PCI-DSS compliant platform. Zoho Privacy
- Amazon Web Services (AWS) — all application data (invoices, customers, shop info) is stored in AWS DynamoDB and S3, hosted in the ap-south-1 (Mumbai) region in India.
6. Data Storage & Security
- All data is stored in AWS DynamoDB and S3 in the ap-south-1 (Mumbai) region
- Data in transit is encrypted using TLS 1.2+
- Google Drive tokens are encrypted at rest using AES-256-GCM with a key held securely in AWS Systems Manager (SSM) Parameter Store
- OTP codes and MPINs are stored as one-way bcrypt hashes and cannot be reversed
- Refresh tokens include a unique token ID (JTI) so individual sessions can be revoked remotely
7. Data Retention
- Business data (invoices, customers, products, voice session drafts): retained until you delete your account
- Voice session records: deleted when the session is finalized or abandoned; raw audio is never stored
- OTP codes: automatically expire via DynamoDB TTL within minutes of issuance
- Refresh tokens: expire per the token lifetime or when you log out from a session
- Deletion requests (submitted without an account): retained for up to 30 days while we process them
8. Your Rights & Data Deletion
You can permanently delete your account and all associated data at any time:
- In the app: Go to Settings → scroll to the bottom → Delete Account. Deletion is immediate and irreversible.
- Without app access: Email us at support@retailer360.in or visit app.retailer360.in/delete-account. We will process the request within 7 business days.
What gets deleted: your shop profile, all invoices and billing history, customer records and Khaata balances, staff accounts linked to your shop, and your phone number and sign-in credentials.
What is not deleted: any files already uploaded to your Google Drive — those exist in your own Google account and are under your control.
9. Children's Privacy
Retailer360 is intended for use by business owners and their staff. We do not knowingly collect data from individuals under the age of 18. If you believe a minor has provided us with personal data, please contact us and we will delete it promptly.
10. Changes to This Policy
We may update this policy from time to time. When we make significant changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you within the app. Continued use of Retailer360 after changes take effect constitutes acceptance of the updated policy.
11. Contact Us
For privacy questions, data deletion requests, or to exercise any other rights, please contact us:
- Email: support@retailer360.in
- Company: Viaom Technologies Pvt. Ltd.
- Data deletion form: app.retailer360.in/delete-account
Retailer360