Privacy Policy

Last updated: 2026-07-01

Who we are

This Privacy Policy describes how GrowThozhil Solutions, a partnership firm based in Namakkal, Tamil Nadu, India (the “Company”, “we”), collects, uses, stores and protects information when you visit posengine.in, create a POSEngine account or use the POSEngine software (the “Service”).

For the purposes of the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Company is the “Body Corporate” collecting Personal Information from you.

What we collect

We collect only the information needed to operate the Service:

  • Account information — name, business name, email address, mobile number, password (hashed)
  • Business details — GST number, store address, business category, number of outlets
  • Operational data — inventory, vendors, customers, sales invoices, payment records, reports (all entered by you)
  • Payment metadata — transaction ID, amount, method, status, plan purchased. We do not store full card numbers, CVV or net-banking credentials — Razorpay handles payment data directly under PCI-DSS
  • Technical data — IP address, browser/device type, timestamps, error logs (used for security and debugging)

How we use your data

  • To provide and maintain the Service (sync, backup, reporting, billing)
  • To process payments via Razorpay and issue invoices
  • To send transactional emails (account verification, password reset, invoice receipts, payment confirmations, AMC renewal reminders)
  • To send service-critical notices (security alerts, planned maintenance, terms changes)
  • To respond to your support requests
  • To protect the Service against fraud, abuse and unauthorised access
  • To comply with applicable Indian law (e.g. tax authorities, court orders)

We do not send marketing or promotional emails from our transactional email infrastructure. We do not sell, rent or trade your data to third parties for marketing purposes.

Where your data lives

The Service is hosted on Amazon Web Services (AWS) in the Mumbai region (ap-south-1). Daily automated backups are retained for 14 days with point-in-time recovery. All data is stored on AWS infrastructure governed by AWS’ own security and compliance certifications (ISO 27001, SOC 1/2/3, PCI-DSS).

How we protect your data

  • In transit: TLS 1.2 or higher encryption for all browser, POS terminal and API connections
  • At rest: AES-256 encryption on AWS RDS, S3 and EBS volumes
  • Secrets: API keys and credentials are stored in AWS Secrets Manager, never in source code
  • Access control: role-based permissions; multi-factor authentication available; least-privilege IAM roles for our engineering team
  • Audit logs: all administrative actions and data exports are logged for at least 90 days
  • Disaster recovery: tested restore procedure with measured 8-minute Recovery Time Objective (RTO)

Third-party processors

We share limited data only with these sub-processors, each under contract. Data shared is the minimum necessary to deliver the feature you enable — a processor is only involved when you connect it (Shopify / Amazon), send a message (WhatsApp), or generate an e-invoice / file a GST return (Quicko).

ProcessorPurposeData shared
Amazon Web Services, IndiaCore cloud hosting (compute, database, storage)All operational data (encrypted at rest)
Razorpay Software Pvt. Ltd.Payment processing for subscriptionsPayer name, email, phone, amount, plan
Meta Platforms (WhatsApp Business Cloud API)Outbound WhatsApp messages you initiateRecipient phone number, message body
Brevo (Sendinblue SAS)Transactional email delivery (welcome, password reset, security & billing notices)Your email address, message content
Shopify Inc. (optional)Storefront sync when you connect your Shopify storeProduct, inventory and order data for that store only
Amazon Selling Partner API (SP-API) (optional)Marketplace sync when you connect an Amazon seller accountSeller ID, product and order data for that account only
Quicko (Quicko Infosoft Pvt. Ltd.) (optional)e-invoice (IRN) generation and GSTR-1 / GSTR-3B filing when you use our compliance moduleGSTIN, invoice and sales-register data for the return period

Optional processors are only engaged after you explicitly connect / enable the corresponding integration in your admin dashboard. You can revoke any optional processor at any time from Settings → Integrations.

Your rights

  • Access — export your full data as Excel/JSON from the admin dashboard at any time
  • Correction — edit any inaccurate personal data from your profile
  • Deletion — request account closure, after which we delete your data within 30 days (subject to legal retention requirements)
  • Withdraw consent — cancel your subscription or AMC at any time from the portal
  • Grievance — raise a complaint with our Grievance Officer (details below)

For the full DPDP Act 2023 §11–§14 rights — access, correction, erasure, nomination, consent withdrawal — and step-by-step instructions on how to file each, see Your Data Rights.

Data retention

While your account is active, we retain operational data indefinitely so that you can access historical reports. After account closure we delete operational data within 30 days. Financial records (invoices issued to you) are retained for 8 years to comply with Indian tax law.

Cookies

We use first-party cookies strictly to keep you signed in, remember your preferences and measure site performance. We do not use third-party advertising or tracking cookies.

Children

POSEngine is intended for business use by adults. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.

Changes to this Policy

We may update this Policy from time to time. Material changes will be notified by email at least 14 days before they take effect. The “Last updated” date at the top of this page always reflects the current version.

Data Protection Officer & Grievance Officer

In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, the Company has designated a single point of contact for data-protection matters and grievances:

Mohanraj M

Data Protection Officer & Grievance Officer, GrowThozhil Solutions

Designation effective from 2026-07-01.

3 257 B1 Sri Palaniandavar Complex, Kattanachampatty Rasipuram, Namakkal, Tamil Nadu 637408, India

Email (data-protection & grievance): support@posengine.in

We will acknowledge your grievance or data-protection request within 24 hours and respond substantively within 15 days.

If POSEngine is later notified as a Significant Data Fiduciary under Section 10 of the DPDP Act, an independent DPO will be appointed and their details posted on this page.