Privacy Policy
Last updated: 2026-07-01
Who we are
This Privacy Policy describes how GrowThozhil Solutions, a partnership firm based in Namakkal, Tamil Nadu, India (the “Company”, “we”), collects, uses, stores and protects information when you visit posengine.in, create a POSEngine account or use the POSEngine software (the “Service”).
For the purposes of the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Company is the “Body Corporate” collecting Personal Information from you.
What we collect
We collect only the information needed to operate the Service:
- Account information — name, business name, email address, mobile number, password (hashed)
- Business details — GST number, store address, business category, number of outlets
- Operational data — inventory, vendors, customers, sales invoices, payment records, reports (all entered by you)
- Payment metadata — transaction ID, amount, method, status, plan purchased. We do not store full card numbers, CVV or net-banking credentials — Razorpay handles payment data directly under PCI-DSS
- Technical data — IP address, browser/device type, timestamps, error logs (used for security and debugging)
How we use your data
- To provide and maintain the Service (sync, backup, reporting, billing)
- To process payments via Razorpay and issue invoices
- To send transactional emails (account verification, password reset, invoice receipts, payment confirmations, AMC renewal reminders)
- To send service-critical notices (security alerts, planned maintenance, terms changes)
- To respond to your support requests
- To protect the Service against fraud, abuse and unauthorised access
- To comply with applicable Indian law (e.g. tax authorities, court orders)
We do not send marketing or promotional emails from our transactional email infrastructure. We do not sell, rent or trade your data to third parties for marketing purposes.
Where your data lives
The Service is hosted on Amazon Web Services (AWS) in the Mumbai region (ap-south-1). Daily automated backups are retained for 14 days with point-in-time recovery. All data is stored on AWS infrastructure governed by AWS’ own security and compliance certifications (ISO 27001, SOC 1/2/3, PCI-DSS).
How we protect your data
- In transit: TLS 1.2 or higher encryption for all browser, POS terminal and API connections
- At rest: AES-256 encryption on AWS RDS, S3 and EBS volumes
- Secrets: API keys and credentials are stored in AWS Secrets Manager, never in source code
- Access control: role-based permissions; multi-factor authentication available; least-privilege IAM roles for our engineering team
- Audit logs: all administrative actions and data exports are logged for at least 90 days
- Disaster recovery: tested restore procedure with measured 8-minute Recovery Time Objective (RTO)
Third-party processors
We share limited data only with these sub-processors, each under contract. Data shared is the minimum necessary to deliver the feature you enable — a processor is only involved when you connect it (Shopify / Amazon), send a message (WhatsApp), or generate an e-invoice / file a GST return (Quicko).
| Processor | Purpose | Data shared |
|---|---|---|
| Amazon Web Services, India | Core cloud hosting (compute, database, storage) | All operational data (encrypted at rest) |
| Razorpay Software Pvt. Ltd. | Payment processing for subscriptions | Payer name, email, phone, amount, plan |
| Meta Platforms (WhatsApp Business Cloud API) | Outbound WhatsApp messages you initiate | Recipient phone number, message body |
| Brevo (Sendinblue SAS) | Transactional email delivery (welcome, password reset, security & billing notices) | Your email address, message content |
| Shopify Inc. (optional) | Storefront sync when you connect your Shopify store | Product, inventory and order data for that store only |
| Amazon Selling Partner API (SP-API) (optional) | Marketplace sync when you connect an Amazon seller account | Seller ID, product and order data for that account only |
| Quicko (Quicko Infosoft Pvt. Ltd.) (optional) | e-invoice (IRN) generation and GSTR-1 / GSTR-3B filing when you use our compliance module | GSTIN, invoice and sales-register data for the return period |
Optional processors are only engaged after you explicitly connect / enable the corresponding integration in your admin dashboard. You can revoke any optional processor at any time from Settings → Integrations.
Your rights
- Access — export your full data as Excel/JSON from the admin dashboard at any time
- Correction — edit any inaccurate personal data from your profile
- Deletion — request account closure, after which we delete your data within 30 days (subject to legal retention requirements)
- Withdraw consent — cancel your subscription or AMC at any time from the portal
- Grievance — raise a complaint with our Grievance Officer (details below)
For the full DPDP Act 2023 §11–§14 rights — access, correction, erasure, nomination, consent withdrawal — and step-by-step instructions on how to file each, see Your Data Rights.
Data retention
While your account is active, we retain operational data indefinitely so that you can access historical reports. After account closure we delete operational data within 30 days. Financial records (invoices issued to you) are retained for 8 years to comply with Indian tax law.
Cookies
We use first-party cookies strictly to keep you signed in, remember your preferences and measure site performance. We do not use third-party advertising or tracking cookies.
Children
POSEngine is intended for business use by adults. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.
Changes to this Policy
We may update this Policy from time to time. Material changes will be notified by email at least 14 days before they take effect. The “Last updated” date at the top of this page always reflects the current version.
Data Protection Officer & Grievance Officer
In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, the Company has designated a single point of contact for data-protection matters and grievances:
Mohanraj M
Data Protection Officer & Grievance Officer, GrowThozhil Solutions
Designation effective from 2026-07-01.
3 257 B1 Sri Palaniandavar Complex, Kattanachampatty Rasipuram, Namakkal, Tamil Nadu 637408, India
Email (data-protection & grievance): support@posengine.in
We will acknowledge your grievance or data-protection request within 24 hours and respond substantively within 15 days.
If POSEngine is later notified as a Significant Data Fiduciary under Section 10 of the DPDP Act, an independent DPO will be appointed and their details posted on this page.