Kapda Stock is operated by Codemites (“we”, “us”). This policy explains what information we collect when you use the Kapda Stock platform, why we collect it, and the choices you have. It applies to our website, web application and related services, and is designed to comply with the Digital Personal Data Protection Act, 2023 (India).
1. Information we collect
- Account information — business name, owner name, GSTIN, phone number, email address and password (stored as a salted bcrypt hash, never in plain text).
- Business data you enter — products, customers, suppliers, invoices, payments, employee records and similar operational data belonging to your business.
- Usage information — log data such as IP address, browser type, pages visited and actions performed, used for security auditing and product improvement.
- Payment information — subscription payments are processed by Razorpay; we never see or store your full card number, CVV or UPI PIN.
2. How your business data is isolated
Every business on Kapda Stock runs in its own dedicated, isolated database schema. Your data is never shared with, visible to, or mixed with any other business on the platform. Access within your workspace is controlled by the roles you assign to your own staff.
3. How we use information
- To provide, maintain and improve the Kapda Stock service.
- To send transactional messages (invoices, receipts, reminders) that you initiate on WhatsApp, SMS or email.
- To notify you about subscription status, security events and important product changes.
- To prevent fraud, abuse and unauthorized access (rate limiting, audit logs, anomaly detection).
We do not sell your data, mine your business data for advertising, or share it with third parties except as described below.
4. Third-party processors
We rely on a small set of processors to run the service, each receiving only the minimum data required:
- Neon (PostgreSQL) — encrypted database hosting.
- Razorpay / Cashfree — payment processing for subscriptions and, where you configure it, your own customer payments.
- Meta / Twilio / MSG91 / SendGrid — delivery of WhatsApp, SMS and email messages you send.
- Google Drive / Microsoft OneDrive — encrypted backups, only when you connect your own account.
- Cloudinary — storage of images you upload (scanned for malware first).
5. Security
- All traffic is encrypted in transit with TLS; HSTS is enforced.
- Sensitive credentials (payment gateway keys, bank details, 2FA secrets) are stored with AES-256 encryption.
- Two-factor authentication is available for all accounts and mandatory for administrators.
- Financial records are never hard-deleted, preserving a complete audit trail.
6. Data retention & deletion
Your data is retained for as long as your subscription is active. If you cancel, your workspace is retained for 30 days so you can export or reactivate, after which it is permanently deleted. You can request a full export (Excel/PDF) or deletion at any time by contacting us.
7. Your rights
You may access, correct, export or delete your personal data, and withdraw consent for optional processing, by writing to us. We respond to verified requests within 30 days.
8. Changes to this policy
We will notify you of material changes by email and in-app notice at least 15 days before they take effect. Continued use after that date constitutes acceptance.