GoldShopper

Privacy Policy

How GoldShopper collects, uses, and protects your business data — clearly explained.
Privacy Policy – GoldShopper

GoldShopper ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our cloud-based ERP platform for jewellers — including our website at goldshopper.in, Business App, B2B App, B2C App, and any related services (collectively, the "Services").

By using GoldShopper, you agree to the practices described in this policy. If you do not agree, please discontinue use of our Services. This policy is compliant with the Information Technology Act, 2000, the IT (Amendment) Act 2008, the Digital Personal Data Protection Act, 2023 (DPDPA), Google Play Store policies, and Apple App Store guidelines.

Effective Date: June 1, 2026  |  Last Updated: June 1, 2026  |  Version: 1.0

01

Who We Are

GoldShopper is India's #1 Cloud ERP platform purpose-built for the jewellery industry. We are incorporated under the laws of India and operate from India. Our registered email for all privacy-related matters is support@goldshopper.in.

As a Data Fiduciary under the Digital Personal Data Protection Act, 2023, we determine the purpose and means of processing your personal data and are responsible for its lawful processing.


02

Information We Collect

We collect information in the following categories:

Category Examples Source
Account & Identity Name, business name, email address, mobile number, GST number, PAN, HUID You (during registration)
Business Data Inventory records, sales & purchase invoices, gold rates, customer ledgers, karigar records, stock details You (during use)
Financial Data Payment amounts, transaction IDs, billing plans, EMI records, GST returns data You & payment gateways
Device & Usage Data Device type, OS version, IP address, browser type, app version, pages visited, session duration, crash logs Automatically collected
Location Data Approximate or precise location (only when you grant permission, for store-finder or karigar tracking features) Your device (with consent)
Communication Data Messages sent via our contact forms, support emails, chat logs You
Media Product/jewellery images uploaded by you for digital catalogues You (with permission)
📌 Note We do NOT collect sensitive personal information such as passwords in plaintext, biometric data, or credit/debit card numbers. Payment transactions are processed by certified third-party gateways.

03

How We Use Your Information

We use the information we collect for the following purposes:

  • To create, manage, and maintain your GoldShopper account and subscription
  • To provide and operate all ERP features including billing, inventory, accounting, and GST compliance modules
  • To display real-time gold rates and sync them across your account
  • To generate HUID, barcode, and BIS-compliant tagging reports
  • To send transactional communications such as invoices, receipts, and support replies
  • To send service updates, feature announcements, and usage tips (you can opt out)
  • To process payments and manage subscriptions
  • To detect, investigate, and prevent fraud, security incidents, and abuse
  • To improve our platform through analytics, crash reporting, and user feedback
  • To comply with legal obligations under Indian law (GST Act, IT Act, DPDPA)
  • To provide customer support and onboarding assistance
✅ We Do Not Sell Your Data GoldShopper does not sell, rent, or trade your personal or business data to any third party for commercial or marketing purposes — ever.


05

Data Sharing & Disclosure

We do not share your personal data with third parties except in the following limited circumstances:

  • Service Providers: Trusted vendors who help us operate (e.g., cloud hosting on AWS/Azure, SMS gateways for OTPs, payment processors). These parties are bound by data processing agreements and cannot use your data for other purposes.
  • Government & Regulatory Bodies: When required by law, court order, or a valid government request under Indian law.
  • Business Transfers: In the event of a merger, acquisition, or asset sale, your data may be transferred. You will be notified in advance.
  • With Your Consent: For any other sharing not listed here, we will ask for your explicit consent first.
ℹ️ B2C White-Label Partners If your jewellery business uses our B2C white-label app, your customers' data entered through that app is processed on your behalf. You are the Data Fiduciary for your customers; GoldShopper acts as a Data Processor.

06

Third-Party Services & Integrations

Our Services may integrate with third-party platforms. Each of these has its own privacy policy which we encourage you to review:

  • Google Analytics / Firebase: For usage analytics and crash reporting
  • Payment Gateways (Razorpay / PayU / Others): For processing subscription payments securely
  • SMS / WhatsApp Providers: For OTPs, invoices, and notifications sent to your number
  • Cloud Hosting (AWS / Azure / GCP): For secure, encrypted data storage within India
  • GST Portal API: For auto-filing and data validation with government systems

We vet all third-party service providers for security and compliance before integration. We are not responsible for the privacy practices of external websites you may navigate to from our platform.


07

Data Retention

We retain your data for as long as your account is active and for a period thereafter as required by law or our legitimate business needs:

  • Account Data: Retained for the duration of your subscription plus 3 years after account closure (for legal/tax purposes under GST Act)
  • Business / Transaction Data: Retained for 7 years as mandated under Indian accounting and tax regulations
  • Support & Communication Logs: Retained for 2 years
  • Device & Usage Logs: Retained for 90 days for security and debugging
  • Deleted Data: Removed from active systems within 30 days of account deletion; backup purge within 90 days

08

Data Security

We implement industry-standard technical and organizational measures to protect your data:

  • All data transmitted between your device and our servers is encrypted using TLS 1.2 / TLS 1.3
  • Data at rest is encrypted using AES-256 encryption
  • Access to production systems is restricted to authorized personnel only, with multi-factor authentication (MFA) enforced
  • We conduct regular security audits and vulnerability assessments
  • Automated daily backups with geo-redundant storage within India
  • Role-based access controls (RBAC) for your team members within GoldShopper
⚠️ Security Incident Reporting In the unlikely event of a data breach affecting your personal data, we will notify you and the relevant regulatory authority (CERT-In / Data Protection Board) within the timelines prescribed by law. Please report any security concerns to support@goldshopper.in.

09

Your Rights & Choices

Under the DPDPA 2023 and applicable law, you have the following rights regarding your personal data:

  • Right to Access: Request a copy of the personal data we hold about you
  • Right to Correction: Request correction of inaccurate or incomplete data
  • Right to Erasure: Request deletion of your data (subject to legal retention requirements)
  • Right to Data Portability: Request your data in a machine-readable format
  • Right to Withdraw Consent: Withdraw consent at any time for optional processing (e.g., marketing emails); withdrawal will not affect prior lawful processing
  • Right to Grievance Redressal: Lodge a complaint with our Grievance Officer (see Section 15)
  • Right to Nominate: Nominate another individual to exercise your rights in case of incapacity

To exercise any of these rights, email us at support@goldshopper.in with the subject line "Data Rights Request". We will respond within 30 days.

ℹ️ Marketing Opt-Out You may unsubscribe from promotional emails at any time by clicking "Unsubscribe" in any marketing email, or by contacting us directly. Note: transactional communications (receipts, OTPs, critical alerts) cannot be opted out of while your account is active.

10

Children's Privacy

GoldShopper is a business ERP platform intended solely for adults (persons aged 18 and above) operating jewellery businesses. We do not knowingly collect personal data from individuals under the age of 18.

If you believe a minor has provided us with personal information, please contact us immediately at support@goldshopper.in and we will delete such information promptly. Under the DPDPA 2023, processing of children's data requires verifiable parental consent, which our platform does not solicit.


11

App Permissions (Mobile App)

Our Business App, B2B App, and B2C App (available on Google Play Store and Apple App Store) may request the following device permissions. All permissions are optional unless explicitly stated, and you can manage them in your device settings at any time:

Permission Purpose Required?
Camera Scan barcodes, HUID tags; capture product photos for digital catalogue Optional
Storage / Photos Upload jewellery images; save invoices and reports to device Optional
Location Multi-store management; showroom check-in for karigar tracking (only when enabled by business owner) Optional
Notifications Order alerts, billing reminders, low-stock warnings, GST filing deadlines Optional
Internet Core app functionality — syncing data with cloud Required
Contacts Auto-fill customer details from phonebook (only with explicit permission) Optional
✅ Play Store & App Store Compliance We comply with Google Play's Data Safety requirements and Apple App Store's App Privacy disclosure requirements. Our data practices are accurately reflected in our store listings. We do not use any permissions for purposes beyond those disclosed here.

12

Cookies & Tracking Technologies

Our website (goldshopper.in) uses cookies and similar tracking technologies:

  • Essential Cookies: Required for the website and app to function (session management, authentication). Cannot be disabled.
  • Analytics Cookies: Help us understand how visitors use our site (e.g., Google Analytics). You can opt out via browser settings or the Google Analytics opt-out extension.
  • Preference Cookies: Remember your settings and preferences (e.g., language, theme).
  • Marketing Cookies: Used for retargeting ads on third-party platforms. We only use these if you consent. You can opt out at any time.

You can control cookies through your browser settings. Disabling essential cookies may affect website functionality. Our mobile apps use Firebase SDK for crash analytics and performance monitoring — this does not use browser cookies.


13

International Data Transfers

GoldShopper is an India-first platform. We store all primary customer and business data on servers located within India, in compliance with RBI and SEBI data localisation guidelines where applicable.

Certain third-party service providers (such as analytics platforms) may process data outside India. When this occurs, we ensure that adequate contractual protections are in place and that the transfer complies with applicable Indian data protection law, including the DPDPA 2023.


14

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make changes:

  • We will update the "Last Updated" date at the top of this page
  • For material changes, we will notify you via email or an in-app notification at least 14 days before the change takes effect
  • For minor changes, posting the updated policy on this page constitutes sufficient notice
  • Your continued use of the Services after the effective date constitutes your acceptance of the updated policy

We encourage you to review this page periodically. All previous versions of this policy are available upon request.


15

Grievance Officer

In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the Digital Personal Data Protection Act, 2023, we have appointed a Grievance Officer:

Grievance Officer Details

Name: Grievance Officer, GoldShopper
Email: support@goldshopper.in
Subject Line: "Privacy Grievance – GoldShopper"
Response Time: Acknowledged within 48 hours, resolved within 30 days

If you are not satisfied with our resolution, you may escalate to the Data Protection Board of India once constituted under the DPDPA 2023.


16

Contact Us

For any questions, requests, or concerns about this Privacy Policy or our data practices, reach out through any of the following channels:

🛡️
Support & Privacy
support@goldshopper.in
⚙️
Admin
admin@goldshopper.in
🌐
Website
goldshopper.in