Legal
Privacy Policy
Last updated: [REVIEW: date of publication]
1. Who we are
[REVIEW: registered legal entity name] ("iTrack SCM", "we") provides retail supply-chain planning software. Our registered office is [REVIEW: registered office address, city, state, PIN].
2. Our role: controller and processor
Where a customer uploads its business data to the platform, that customer decides why and how the data is processed. The customer is the Data Fiduciary (controller) and we act as a Data Processor on its documented instructions, under the Data Processing Agreement forming part of its contract.
Where we handle data about our own account holders, prospects and website visitors, we are the Data Fiduciary. This policy covers both, and says which is which in each section.
3. Personal data we process
Account data (we are the fiduciary)
[REVIEW: confirm the list.] Name, work email address, role and workspace membership of users created on the platform, plus authentication records and session activity.
Customer business data (we are the processor)
Sales, stock, product and store records uploaded by customers. This is commercial data rather than personal data, but store and employee identifiers within it may constitute personal data. [REVIEW: confirm with a sample of real uploads what personal data, if any, they actually contain — this determines how much of the DPDP regime applies.]
Technical data
[REVIEW] Server logs including IP address, request time and user agent, retained for security and reliability purposes.
4. Why we process it, and on what basis
[REVIEW: map each category to a purpose and a lawful basis — for the DPDP Act, consent or a legitimate use; state which applies to each.]
5. Cookies
[REVIEW: keep this accurate and keep it short. The platform sets a session cookie that is strictly necessary for authentication. If you later add analytics or advertising tags to the marketing site, this section must list them and you will need a consent banner — which is a good reason to think twice before adding them.]
6. Sub-processors
We use a small number of vendors to run the service. [REVIEW: publish and maintain the current list with each vendor's purpose and processing location — enterprise procurement asks for this by name, and the DPA usually commits you to notifying customers before you add one.]
7. Where data is held
Platform data — including databases, uploaded files and backups — is hosted in India. [REVIEW: confirm at publication, and list any vendor that processes data outside India, together with the safeguards applied.]
8. How we protect it
[REVIEW: confirm each statement still describes the deployed system before publishing.]
- Tenant data is separated at the database using row-level security, so isolation is enforced by the database itself rather than by application-side filtering.
- Data is encrypted in transit, and encrypted at rest by the managed database and object storage.
- Access to the platform is authenticated and role-based; administrative database credentials are separate from the credentials the application runs under.
- Managed database backups support point-in-time recovery.
- [REVIEW: add breach detection, logging and incident response commitments.]
9. How long we keep it
[REVIEW: retention period per category, and what happens on termination — export window, then deletion, including deletion from backups and the timeline for that. Enterprise reviewers ask specifically about backups.]
10. Your rights
Under the Digital Personal Data Protection Act, 2023, data principals have the right to access a summary of their personal data and its processing, to correction and erasure, to nominate another person to exercise their rights, and to grievance redressal.
Where we act as a processor for a customer, requests should be directed to that customer as the Data Fiduciary; we will assist them in responding. [REVIEW: state the response window you commit to.]
11. Grievance officer
The DPDP Act requires a contactable grievance officer. Ours is:
[REVIEW: grievance officer name]
privacy@itrackscm.com
[REVIEW: registered legal entity name], [REVIEW: registered office address, city, state, PIN]
12. Children
The platform is a business tool and is not directed at children. [REVIEW: confirm — the DPDP Act imposes additional obligations where children's data is processed.]
13. Changes to this policy
[REVIEW: how changes are notified, and where previous versions can be found.]
14. Contact
Questions about this policy, or about how we handle data, can be sent to privacy@itrackscm.com. Our Terms of Service govern use of the platform.