Legal
Privacy Policy
Last updated: On launch
This Privacy Policy explains how SatvScript ("we") handles personal data in OSMS ("the Service"), in line with India's Digital Personal Data Protection Act, 2023 (DPDP Act).
1. Roles
For data a store enters about its own customers (names, phone numbers, ages, prescriptions, purchase history), the store is the data fiduciary/controller and OSMS acts as a data processor on the store's instructions. For account data of the store's own users (name, email), we are the controller.
2. What we collect
- Account data: your name, email, password (hashed), and store details.
- Store operational data: customer records, prescriptions (health-related data), inventory, orders, and payments you enter.
- Billing data: subscription status and payment references (card/UPI details are handled by our payment processor, not stored by us).
- Technical data: logs needed to operate and secure the Service.
3. How we use it
To provide and secure the Service, process subscriptions, provide support, and comply with law. We do not sell personal data.
4. Tenant isolation
Each store's data is logically isolated; one store cannot access another store's records.
5. Sub-processors
- Razorpay — payment processing for subscriptions.
- Hosting provider — infrastructure hosting in India.
6. Retention & deletion
Operational records you delete are soft-deleted and permanently purged after 30 days. When a store closes its account, its data is retained for 30 days (to allow recovery/export) and then permanently deleted, unless a longer period is required by law.
7. Your rights
Subject to the DPDP Act, you may access or correct your account data, and request a copy or deletion of your store's data by contacting us. Store customers should direct such requests to the store; we assist the store in fulfilling them.
8. Security
We use industry-standard measures (encryption in transit, hashed passwords, access controls). No system is perfectly secure; we will notify affected users and the Data Protection Board of material breaches as required.
9. Contact / Grievance Officer
For privacy requests or complaints: Contact us. [Name a Grievance Officer before launch, as required by the DPDP Act.]