Dataflee
Corporate Governance & Compliance

Privacy Policy

Transparency, enterprise data protection, and local-first customer sovereignty for all Dataflee LLP platforms, apps, and services.

Effective Date: August 22, 2026
GDPR, CCPA & DPDP Compliant
Data Ownership
Merchants & clients retain 100% full ownership of their operational business data.
Security & Encryption
Local POS data encrypted with SQLCipher (AES-256); cloud transit secured via TLS 1.3.
Compliance Standards
Aligned with GDPR (EU), CCPA/CPRA (US), DPDP Act 2023 (India), and Google Play Data Safety.

1. Introduction & Entity Scope

Dataflee LLP ("Dataflee", "we", "us", or "our") is committed to protecting the privacy, confidentiality, and security of our users, clients, merchants, and website visitors. This Privacy Policy governs all software applications, digital platforms, and services provided by Dataflee LLP, including:

  • The corporate website (dataflee.com and associated subdomains).
  • Dataflee POS: Our retail Point of Sale system, including the Android application (com.dataflee.pos) and POS Admin Web portals.
  • Dataflee Cloud Sync, SaaS tools, AI sales concierges, and custom software delivery solutions.
  • Consulting, engineering engagements, and pre-sales advisory tools (e.g., Solution Advisor).

By accessing our websites or using any Dataflee software application, you acknowledge and agree to the data collection and processing practices described in this policy.

2. Information We Collect

We collect only the minimum information necessary to provide, secure, and improve our services, categorized as follows:

  • Account & Identity Data: Name, business name, work email address, phone number, physical store address, and tax identification numbers (e.g., GSTIN / VAT) provided during registration or onboarding.
  • Operational & Business Records: Product catalog, inventory counts, pricing, customer ledger balances (Khata entries), transaction summaries, and receipt records generated through Dataflee POS.
  • Hardware & Device Permissions (Android POS): Camera access (strictly used for optical barcode/QR scanning and product catalog photography), Bluetooth & USB Host permissions (used exclusively for communicating with thermal ESC/POS receipt printers and external barcode scanners), and network state checks (for determining offline vs. online synchronization status).
  • Technical & Diagnostics Data: IP address, device model, operating system version, browser type, anonymous telemetry aggregates (with merchant consent), and error logs to maintain system stability.
  • Billing & Payment Metadata: Payment transaction IDs, subscription tier, and invoice records. (Note: Dataflee does not store raw credit card numbers or banking passwords; all online payments are processed by PCI-DSS certified payment gateways such as BillDesk, Razorpay, and Stripe).

3. Local-First Storage & Cloud Sync Architecture

Dataflee POS is engineered with an offline-first architecture to guarantee continuous retail operations even during network outages:

  • On-Device Encrypted Database: All local business records (sales, inventory, customers, logs) are stored directly on the merchant's physical Android device in an encrypted Room SQLite database powered by Keystore-backed SQLCipher (AES-256 encryption at rest).
  • Cloud Sync Engine: For merchants subscribing to Cloud Sync, data modifications enter an encrypted local queue and sync via HTTPS/TLS to Google Cloud Firestore only when an active internet connection and authorized Firebase session are present.
  • Single-Tenant Isolation: Remote multi-tenant data is logically isolated by unique Shop IDs (shops/{shopId}/...), preventing unauthorized cross-merchant access.
  • No Third-Party Ad Tracking in POS: The Dataflee POS retail application contains zero third-party advertising SDKs and does not sell merchant sales data to advertisers.

5. How We Use and Process Information

We utilize the collected information strictly for legitimate commercial and operational purposes, including:

  • Operating, maintaining, and enhancing the features of Dataflee POS, web platforms, and SaaS tools.
  • Processing license activations, subscription renewals, automated trial notifications, and cloud backups.
  • Providing responsive multi-channel customer service, technical debugging, and emergency software recovery.
  • Generating anonymized operational insights and recommendations computed locally for the merchant.
  • Sending critical service announcements, security alerts, and administrative updates.

6. Third-Party Sub-processors & Infrastructure

We partner with reputable enterprise cloud and service providers to support our global delivery. These sub-processors are bound by stringent confidentiality and data protection agreements:

  • Cloud Infrastructure & Databases: Google Cloud Platform / Firebase (Hosting, Firestore, Firebase Authentication, Cloud Functions).
  • Payment Processing: BillDesk (IndiaIdeas.com Limited), Razorpay Software Private Limited, and Stripe Inc. (PCI-DSS compliant payment gateways).
  • Email & Communication Services: Google Workspace / Google Cloud (Google LLC) for enterprise corporate email hosting, account verification relays, and customer support communications.
  • Machine Learning & Vision: Google ML Kit (operates entirely on-device for barcode detection and optical character recognition without transmitting raw images to external servers).
  • Website Analytics & Ads: Google Analytics and Google AdSense (active solely on our public corporate website; strictly excluded from POS transaction apps).

7. Data Security, Protection & Storage

Dataflee implements robust administrative, technical, and physical safeguards to prevent unauthorized access, loss, or alteration of data:

  • End-to-end transport encryption utilizing modern Transport Layer Security (TLS 1.3 / HTTPS).
  • Local cryptographic storage using SQLCipher 256-bit AES encryption with hardware-backed Android KeyStore key derivation.
  • Role-Based Access Control (RBAC) and least-privilege principles enforced across all backend infrastructure.
  • Regular vulnerability assessments, dependency auditing, and strict environment credential isolation.

8. Merchant Responsibilities for Local Device & Physical Security

Because Dataflee POS operates with a local-first encrypted database directly on your hardware, the merchant bears distinct security responsibilities:

  • Physical Device Protection: You are solely responsible for securing physical POS tablets, phones, and terminals against theft, unauthorized cashier usage, or physical tampering on your business premises.
  • Credential & Backup Security: You are solely responsible for setting strong lock screen PINs/biometrics, managing cashier permissions, and storing portable backup ZIP files securely. Dataflee LLP accepts zero liability for data exposure or data loss resulting from unsecured physical devices, stolen hardware, malware on unverified devices, or credential sharing among store staff.
  • Third-Party Software & Unofficial Hardware: Dataflee LLP is not responsible for security vulnerabilities introduced by side-loaded third-party applications, rooted Android firmware, or unverified hardware peripherals on the merchant's device.

9. Data Retention, Account & Data Deletion

We retain personal and business data only as long as necessary to fulfill the operational purposes for which it was collected or to comply with statutory legal and accounting obligations:

  • Active Accounts: Merchant data is retained for the duration of the active subscription or trial.
  • Local Device Wipe: Merchants can instantly wipe all local master data, sales, and products from their Android device at any time via Settings > Master Data > Wipe Data.
  • Account & Cloud Data Deletion (Google Play Compliance): You may request the permanent deletion of your account, authentication records, and associated cloud backups by emailing support@dataflee.com with your registered Shop ID / Auth Email. Deletion requests are verified and completed within 30 days.
  • Backup Purging: Archived database snapshots and cloud sync queues are purged following standard retention lifecycles.

10. Your Data Protection Rights (GDPR, CCPA & DPDP)

Depending on your geographic jurisdiction, you hold specific legal rights regarding your personal data:

  • Right to Access & Portability: You have the right to request copies of your stored data and export complete business records via our portable ZIP backup export feature.
  • Right to Rectification: You can update inaccurate or incomplete store profile details directly in the application settings or by contacting our team.
  • Right to Erasure ("Right to be Forgotten"): You may request complete erasure of your personal data where retention is no longer legally necessary.
  • Right to Restrict or Object to Processing: You can withdraw consent for telemetry or marketing communications at any time.
  • Non-Discrimination (CCPA): Dataflee will never discriminate against you for exercising any of your statutory privacy rights.

11. Children's Privacy

Our applications, platforms, and commercial services are strictly designed for businesses and adult professionals. We do not knowingly collect, solicit, or process personal data from individuals under the age of 18. If we discover that personal data of a minor has been collected without verified parental consent, we will promptly delete such information.

  • All services and software are intended solely for users aged 18 and older.
  • Report any inadvertent submission involving a minor to hello@dataflee.com for immediate remediation.

12. International Data Transfers

As a global technology provider, Dataflee may store and process data in secure Google Cloud data centers located in India, the United States, and the European Union. Whenever data is transferred internationally, we ensure adequate protection through standard contractual clauses (SCCs) and enterprise data processing addenda.

  • Data transfers adhere to internationally accepted data protection safeguards.
  • Cross-border cloud infrastructure complies with ISO/IEC 27001, SOC 2, and GDPR standards.

13. Grievance Officer & Contact Information

In compliance with the Indian Information Technology Act 2000, the Digital Personal Data Protection Act 2023, and global privacy regulations, if you have any questions, concerns, or grievances regarding this Privacy Policy or our data practices, please contact our designated Grievance Officer:

  • Entity: Dataflee LLP
  • Grievance Officer: Grievance Redressal Officer / Data Protection Team
  • Email: hello@dataflee.com
  • Support Desk: support@dataflee.com
  • Helpline & WhatsApp Support: +91 9747994266
  • Headquarters: Kochi, Kerala, India — Global Remote Delivery

Have privacy or data safety inquiries?

For any questions regarding your data privacy rights, merchant record deletion requests, or regulatory compliance, reach out directly to our Data Protection team.

Book Audit