← Back to VeriStock Pro Terminal
Privacy Policy — VeriStock Pro Cloud & POS Services
Effective Date: September 8, 2026 | Version 2.7.2 | Applicable to Android App & Desktop Web Application
1. Introduction
VeriStock Pro ("we", "our", or "us") provides retail inventory management systems, Android POS terminal software, and cloud desktop web applications designed for retailers, business managers, technicians, and Chartered Accountants. This Privacy Policy outlines our strict commitment to data confidentiality, encryption, multi-tenant cloud storage, and statutory regulatory compliance.
2. Data Collection & Synchronization
To enable real-time multi-terminal checkout, cloud inventory synchronization, statutory KYC docket generation, and ledger audit capabilities, VeriStock Pro processes the following categories of data:
- Account & Membership Credentials: Full name, authorized email address, business mobile number, store location, and cryptographically verified role permissions (Owner, Manager, Staff, Cashier, Technician, CA Auditor).
- Financial & Transactional Records: Point-of-sale invoices, quotations, return credit notes, inward purchase bills, supplier khata ledgers, operating expenses, and tax aggregates (CGST, SGST, IGST) formatted in Integer Paise.
- Statutory Second-Hand KYC Evidence: Customer identity proofs (Aadhaar / Voter ID / Driving Licence), digital biometric fingerprints, device IMEI verification photos, and SHA-256 digital hash digests created under Bharatiya Nyaya Sanhita (BNS) & Indian Penal Code (IPC) statutory mandates.
- Hardware & Terminal Telemetry: Device identifiers used solely for multi-device sync conflict resolution, audit logs, and hardware driver connections (ESC/POS thermal printers, barcode scanners).
3. Cloud Infrastructure & Security Controls
All cloud synchronization is hosted on Google Cloud & Firebase Enterprise Infrastructure (Project: veristock-ad58d) enforcing zero-trust principles:
- Encryption in Transit: Mandatory TLS 1.3 / HTTPS for all communication between Android terminals, browser sessions, and Google Cloud Firestore.
- Encryption at Rest: Local Android Room databases utilize 256-bit AES SQLCipher (`android-database-sqlcipher`). Cloud Firestore documents and Cloud Storage assets are secured via Google zero-trust server-side encryption.
- Role-Based Access Control (RBAC): Multi-tenant isolation enforced directly at the Firestore rule level. No tenant can read or write documents belonging to another business identifier (`businesses/{bizId}`).
- Article 45 Media Asset Isolation: KYC photos and document proofs are stored strictly in private Firebase Storage buckets (`kyc_photos/...`) with signed URL access, never stored as unencrypted Base64 text in database tables.
4. Staff Invitations & Communication
When an Owner invites team members or CA auditors, VeriStock Pro triggers transactional emails via secure 2nd Generation Firebase Cloud Functions (`sendStaffInviteEmail` in `asia-south1`). Contact information is processed strictly for authentication and authorization.
5. Data Retention & Account Deletion
Merchants retain complete ownership of their data. Business owners can initiate account and workspace deletion anytime directly from the mobile app settings or via our dedicated web portal: Account & Data Deletion Portal. Upon verification, a 72-hour grace period applies, followed by permanent purge of workspace data, subject to statutory GST retention rules (Section 36, CGST Act 2017).
6. Third-Party Sharing Disclaimers
VeriStock Pro does NOT sell, rent, monetize, or disclose user data or merchant transactional records to third-party advertisers, data aggregators, or marketing brokers under any circumstance.
7. Compliance Contact
For privacy queries, security audits, or compliance requests, contact our engineering desk at privacy@veristockpro.com.