Privacy Policy
This Privacy Policy explains how Grozho collects, uses, processes, stores, shares, and protects personal information across our website, desktop billing software, web admin dashboard, and mobile applications.
Key Takeaways
- Grozho provides retail management and POS billing software to Shop Owners, with optional customer ordering and delivery apps.
- We do not sell personal information to advertisers or data brokers.
- Shop Owners control and enter their customer data; Grozho processes this data strictly to provide the SaaS services.
- Card and banking payments for subscriptions are securely processed by Razorpay; Grozho does not store full card numbers or CVV.
1Introduction & Overview
Welcome to Grozho (“we,” “our,” “us,” or “Grozho”), a cloud-synchronized retail store management and delivery platform. Grozho offers an integrated suite of software tools designed for Kirana stores, grocery merchants, and modern retail businesses. This suite includes desktop billing software (for Windows and macOS), a web-based administration dashboard, customer-facing mobile ordering apps (Android and iOS), delivery management applications, and cloud-synchronized backend services.
This Privacy Policy explains in detail how Grozho collects, uses, stores, processes, discloses, protects, and retains personal information when you access our website (including grozho.com), register for an account, subscribe to our software services, or use any of our desktop or mobile applications.
Please read this document carefully to understand our privacy practices. By accessing our website, creating a Grozho account, or using our software applications, you acknowledge that you have read and understood the provisions of this Privacy Policy.
2User Categories & Scope
Because Grozho is a multi-sided Software-as-a-Service (SaaS) platform, this Privacy Policy addresses different categories of individuals whose information we may process:
1. Shop Owners / Businesses
Business proprietors, managers, or retail merchants who subscribe to Grozho to operate store billing, manage inventory, configure delivery zones, and view analytics.
2. Shop Customers / End Users
Individual consumers who place online grocery orders through customer apps or whose contact/billing details are recorded in POS invoices by Shop Owners.
3. Staff & Delivery Personnel
Store employees, billing clerks, and delivery riders created or assigned by Shop Owners to operate billing terminals or navigate and fulfill orders.
3Information We Collect
We collect personal information directly from users, automatically through their interaction with our platform, and as entered by Shop Owners during normal commercial operations.
A. Information Provided by Shop Owners
When a Shop Owner creates an account, activates a store, or configures the Grozho platform, we may collect:
- •Account Details: Full name, owner email address, phone number, and password credentials.
- •Shop Profile: Shop name, store physical address, city, district, state, PIN code, and GPS coordinates (latitude/longitude).
- •Tax & Business Info: GST identification number (if entered) and store operating configurations.
- •Payment Identifiers: Merchant UPI ID, UPI payee name, and UPI QR display settings for point-of-sale customer settlement.
- •Catalog & Inventory Data: Product names, barcodes, purchase prices, selling prices, MRP, stock counts, categories, and batch expiry dates.
- •Staff & Delivery Boy Records: Employee names, phone numbers, roles (e.g. billing, admin), delivery boy names, phone numbers, vehicle types, and vehicle registration numbers.
B. Shop Customer / End User Information
Information relating to store customers may be provided directly by the customer (when using the Grozho customer mobile app) or entered into the desktop POS system by the Shop Owner:
- •Contact Info: Customer full name, mobile phone number, and optional email address.
- •Delivery Addresses: Street address, landmark, city, and geolocation coordinates for accurate doorstep delivery.
- •Order & Invoice History: Line items purchased, order totals, tax amounts, applied discount coupons, and payment method selected (cash on delivery, UPI).
- •Store Ledger (Khata): Outstanding credit balance records, payments made against customer accounts, and store owner ledger notes.
C. Account, Authentication & Verification Data
To protect accounts from unauthorized access, we collect and process authentication data including:
- Password Hashes: Passwords are cryptographically salted and hashed using standard bcrypt algorithms before being stored. Plaintext passwords are never saved or visible.
- Email One-Time Passwords (OTPs): Temporary 6-digit verification codes generated for signup email verification and password reset workflows.
- Session Identifiers & Refresh Tokens: JSON Web Tokens (JWT) and securely hashed refresh tokens stored in database sessions to maintain secure logins.
- Device License Keys: Unique hardware/device identifiers generated for POS desktop terminals to manage multi-device licensing.
D. Transaction & Subscription Records
When a Shop Owner subscribes to a paid Grozho plan:
- We record subscription metadata including chosen plan tier (Starter, Growth, Enterprise), billing cycle (monthly/annual), subscription status, trial period dates, and invoice reference numbers.
- No Card Data Storage: Grozho does not collect, process, or store complete credit card numbers, debit card numbers, or CVV codes on our servers. All subscription payments are processed directly by our PCI-DSS compliant payment gateway provider (Razorpay) under their own privacy policy.
4Automatically Collected Technical Data
When you access our website or connect our desktop or mobile applications to our cloud servers, our infrastructure automatically records technical and diagnostic information reasonably required for security, performance, and stability:
- Network & Device Data: Internet Protocol (IP) address, browser type, operating system version (Windows, macOS, Android, iOS), and hardware model.
- Application Telemetry: Application version, device license identifier, platform runtime environment, and active connection status.
- Audit & Security Logs: Timestamps of logins, password reset requests, key administrative configuration updates, and rate-limiting trigger events.
- Diagnostics & Error Logs: System crash reports, server error traces, and request response codes utilized strictly for debugging and service stability.
6How We Use Personal Information
We process personal information for legitimate business purposes necessary to deliver, maintain, and safeguard our retail software platform:
- Account Management:Creating, authenticating, and maintaining Shop Owner, employee, and customer profiles.
- POS Billing & Offline Sync:Generating GST-compliant invoices, processing checkout, and synchronizing offline desktop data with the cloud.
- Inventory & Stock Tracking:Managing catalog items, barcode mapping, supplier records, and batch expiry notifications.
- Order Delivery Management:Routing online customer orders to designated store delivery personnel and updating real-time order tracking.
- Transactional Messaging:Dispatching email verification OTPs, password reset links, and push notifications for order status updates.
- Security & Fraud Prevention:Monitoring audit logs, detecting unauthorized logins, enforcing API rate limits, and defending platform integrity.
- Customer Support:Investigating technical inquiries, troubleshooting billing anomalies, and assisting Shop Owners with store onboarding.
- Legal & Regulatory Compliance:Maintaining statutory accounting records and fulfilling lawful obligations under applicable Indian laws.
7Lawful Processing & Legal Basis
Because Grozho operates primarily in India, we process personal information in compliance with applicable Indian legal standards, including the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (DPDP Act):
- Consent: Where an individual has expressly provided consent to the collection and processing of their data for specified purposes.
- Performance of a Contract: Where processing is necessary to fulfill our software subscription agreement, activate licenses, or process customer orders requested through our software.
- Legitimate Operational Uses: Where permitted by law for maintaining security, preventing fraudulent activity, creating backups, and ensuring business continuity.
- Compliance with Legal Obligations: Where processing or retention is required by Indian statutory provisions, taxation laws, or lawful orders issued by governmental authorities or courts.
8Shop Owner & Customer Data Relationship
Important Distinction of Roles
Grozho operates as a Technology Service Provider / Data Processor with respect to customer information stored by Shop Owners within their respective store accounts.
Grozho → Shop Owner → Shop Customer:
- Shop Owner Authority: The Shop Owner determines which customer details (names, phone numbers, delivery addresses, ledger credit balances) are entered into their Grozho POS or mobile store.
- Shop Owner Responsibilities: The Shop Owner is responsible for ensuring that customer information is collected lawfully, that their store customers are provided with fair notice, and that any required consents are obtained under applicable law.
- Grozho's Role: Grozho hosts and processes this customer information strictly on behalf of the Shop Owner to execute platform features (such as invoice printing, cloud ledger synchronization, and order delivery dispatch).
10Third-Party Service Providers
To operate our cloud infrastructure, Grozho integrates with the following vetted third-party service providers:
Amazon Web Services (AWS SES & S3)
AWS SES delivers transactional emails and OTPs; AWS S3 securely hosts product catalog images and store banners.
Razorpay
Processes Shop Owner SaaS subscription payments, recurring renewals, and webhook verification securely under PCI-DSS standards.
Google OAuth Services
Provides optional single-sign-on (SSO) authentication for users choosing to authenticate using their Google accounts.
Expo Push Notification Service
Delivers real-time mobile push notifications for order placements, delivery status updates, and critical store alerts.
Each third-party service provider operates under its own terms of service and privacy policy regarding data processed through its infrastructure.
11Google Login & Authentication
Users may optionally choose to sign in to Grozho applications using Google OAuth 2.0. When you authenticate via Google:
- Grozho receives only basic public profile information authorized by you, including your name, verified email address, avatar image URL, and unique Google ID identifier.
- No Access to Passwords: Grozho never accesses, requests, or stores your Google account password.
- Data received through Google Login is processed solely for authentication and account profile creation in accordance with Google's API Services User Data Policy.
12Data Security & Storage Practices
Grozho employs reasonable and appropriate administrative, technical, and physical security measures designed to protect personal information against unauthorized access, destruction, loss, alteration, or disclosure:
Disclaimer: While we implement robust, industry-standard safeguards, no method of transmission over the Internet or electronic storage is 100% secure. Grozho cannot guarantee absolute security against all unforeseen vulnerabilities.
13Data Retention Policy
We retain personal information only for as long as reasonably necessary to fulfill the purposes for which it was collected:
- Active Accounts: We retain account, shop profile, and catalog records for as long as your Grozho subscription or account remains active.
- Financial & Invoice Records: Invoices, tax summaries, and subscription transaction logs are retained for statutory periods required under Indian tax, GST, and corporate accounting regulations.
- Audit & Security Logs: Security audit logs and session histories are retained for reasonable periods to monitor platform integrity and investigate potential security incidents.
- Backup Lifecycles: Data retained within disaster-recovery backups is overwritten and purged according to routine backup rotation schedules.
14Data Deletion & Account Closure
Users and Shop Owners may request the deletion of their accounts and associated personal data:
- Shop Owner Account Deletion: Shop Owners may submit an account termination request by emailing [email protected]. Upon verification, store access will be disabled and non-statutory data scheduled for deletion.
- Customer Data Deletion: Customers wishing to delete their profile or address data may delete saved addresses via the customer app settings or contact the relevant Shop Owner or Grozho support.
- Exceptions: Certain records (such as completed billing invoices, statutory GST logs, and unresolved dispute documentation) may be retained as required by applicable law or legitimate legal defense.
15User Rights & Choices
Subject to applicable laws, individuals may exercise specific privacy rights regarding their personal information:
- Right to Access: Request a summary of personal information processed by Grozho.
- Right to Correction: Request the correction or updating of inaccurate, outdated, or incomplete personal records.
- Right to Erasure: Request the deletion of personal information where no overriding legal retention obligation exists.
- Right to Withdraw Consent: Withdraw consent previously provided for discretionary data processing activities.
- Right to Grievance Redressal: Submit inquiries or complaints to our designated Grievance Officer.
16Shop Owner Responsibilities
Because Grozho empowers Shop Owners to record and manage customer and employee records, Shop Owners agree to adhere to the following responsibilities:
- Collect customer details lawfully and provide appropriate notice to store patrons regarding how their contact and purchase records are used.
- Ensure the accuracy of customer names, mobile numbers, and ledger entries entered into the platform.
- Maintain strict credential confidentiality for admin, employee, and delivery boy login accounts, avoiding shared or insecure passwords.
- Comply with all applicable Indian data privacy regulations, consumer protection mandates, and local trade laws.
17Children's Privacy
Grozho is a commercial business software platform and online retail ordering application designed for business operators and adults capable of entering into legally binding contracts. Grozho is not intended for use by children under 18 years of age. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal information without parental consent, please contact us at [email protected] so we may promptly take appropriate corrective action.
18Cross-Border Data Processing
Grozho utilizes enterprise cloud infrastructure and third-party services (such as Amazon Web Services). Depending on the geographical architecture of these cloud vendors, personal data may be processed or stored in secure servers located within India or in other jurisdictions where our cloud infrastructure providers maintain data centers, subject to reasonable security safeguards and applicable law.
19Communications & Notifications
We send communications through our integrated systems:
- Transactional Notifications: Email OTPs for account verification, password recovery emails, subscription invoices, order status push updates, and critical security notices. These messages are required for platform functionality.
- Notification Preferences: Users may manage mobile app push notification settings directly within the app or through their mobile device system preferences.
20Security Incidents & Breach Response
Grozho maintains incident detection, containment, and response procedures to promptly address potential security incidents. Where required by applicable law, Grozho will report qualifying cybersecurity incidents to relevant regulatory authorities (such as the Indian Computer Emergency Response Team - CERT-In) and notify affected users in accordance with statutory requirements.
21Account Termination & Inactivity
When a Shop Owner subscription expires or an account is terminated:
- Active cloud synchronization and dashboard access are suspended after the applicable grace period.
- Shop data may be queued for scheduled deletion or anonymization, except where statutory financial retention obligations apply.
22Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect enhancements to our platform, changes in our architecture, or updates in legal and regulatory requirements. When revisions occur, we will update the “Last Updated” date at the top of this document. Material changes may be communicated through notifications on the Grozho website or web dashboard.
23Contact Information
If you have questions, feedback, or requests regarding this Privacy Policy or our handling of personal information, you may reach our team at:
Platform: Grozho
Email: [email protected]
Website: https://grozho.com
Address: Ganpati Mandir, Arni, Maharashtra, India
24Grievance Redressal (India)
In accordance with the Information Technology Act, 2000, the Rules made thereunder, and the Digital Personal Data Protection Act, 2023, the details of our designated Grievance Officer / Privacy Contact are provided below:
Name: Mohan Tayade
Designation: Grievance Officer / Privacy Contact
Organization: Grozho
Email: [email protected]
Postal Address: Ganpati Mandir, Arni, Maharashtra, India
We will acknowledge and respond to received grievances in accordance with statutory timelines prescribed under applicable law.