SHOPCOMM · DHARA TECHNOLOGIES
Privacy Policy
Looking to delete your account? Request deletion without the app, or read what account closure deletes and retains.
1. Scope and developer
This Privacy Policy explains how DhaRa Technologies ("we", "us" or "ShopComm") handles information when shop Owners and staff use the ShopComm mobile application and related services. ShopComm is a business operations tool for recording completed services, calculating staff commissions and tracking offline settlement status. It is not intended to collect customer identity or payment-account information.
2. Data we collect
Account and profile data includes an Owner name and mobile number, address and may include an optional email address, and profile photograph. An Owner supplies shop information and may add staff names, mobile numbers, profile photographs and sign-in PINs. PINs and one-time passwords are protected as hashes where applicable; short-lived authentication authorizations and OTP support records may also be processed for account access and registration assistance.
Business data may include shop memberships, service names, quantities, service values, commission rates and amounts, timestamps, cash or online payment-mode labels, staff settlement amounts, partial-payment records and notes, subscription status, referral codes and rewards, feedback, support records and security/audit events. Cash and online are record-keeping labels only. ShopComm does not collect card numbers, bank-account details, UPI credentials or customer payment credentials.
The app creates a random installation identifier. The server stores a one-way representation to recognize the currently trusted installation, protect accounts and reduce referral misuse. It is not an IMEI, advertising ID or hardware fingerprint. Infrastructure providers may process ordinary technical information such as IP address, device or browser user-agent, request time and error logs to operate, protect and rate-limit the service.
3. Microphone and speech features
ShopComm requests microphone permission only when a user chooses a voice-search feature. Audio is handled by the device speech-recognition service to produce search text. ShopComm does not upload or store microphone recordings on its own servers. Depending on the device and settings, the operating-system or speech-service provider may process audio under its own privacy terms. Text-to-speech uses the device speech engine to read selected service information aloud. Users can use the app without voice search and can deny or revoke microphone permission in device settings.
4. How we use information
We use information to create and secure accounts; authenticate Owners and staff; deliver Admin Web email OTPs and any enabled verification messages; manage trusted sessions; operate role-based shop access; maintain staff and service lists; record services; calculate service totals and staff commissions; record daily, weekly and monthly settlement status and partial payments; synchronize pending offline records; administer subscriptions and referral rewards; provide support; prevent excessive authentication attempts; investigate misuse; maintain security and audit logs; and comply with applicable law.
5. Staff information and Owner responsibility
The shop Owner controls which staff are added and supplies their information. The Owner must have a lawful basis, obtain any required consent and give staff any legally required notice before entering their information. Staff information is used for account access and management within the relevant shop.
6. Administrator and support access
Authorized ShopComm administrators may view and modify shop profiles, Owner contact and account-management information, staff details and access, and configured services, prices and commission rates without an Owner-generated support code. Shop Management remains available to administrators when a shop subscription has expired, a shop is disabled or its Owner is inactive. This is separate from access to individual completed-service transactions, settlement details and private operational activity: those support actions require an Owner-generated one-time code and an active time-limited grant. The current support grant lasts up to 30 minutes and may be revoked by the Owner. Successful Admin changes are recorded with the affected area, action, non-sensitive changed-field names, administrator, reason and timestamp; recent changes are shown in Support access. PINs, OTPs, support codes, mobile numbers and email addresses are excluded from that change summary. Authorized administrators may also process limited system logs or aggregate platform totals for security and service operation.
7. Device and offline storage
The app stores an authentication token, random installation identifier, remembered sign-in mobile number and role, language and feature preferences, cached API responses and pending offline service entries on the device. Pending entries are transmitted to ShopComm when connectivity returns. Signing out clears the token and user-specific cached and pending entries, but the remembered mobile number, role, installation identifier and preferences may remain to support returning users. Use another number changes the sign-in number; clearing app storage removes the remembered sign-in information. Deleting a shop clears that shop's cached data and pending entries on the device performing the deletion. Uninstalling or clearing local storage does not delete the server account.
8. Service providers and disclosure
We use providers for application and database hosting, network security, image storage and enabled message delivery. The current deployment uses Render for hosting and Cloudinary for uploaded profile and shop photographs and hosted catalogue images. Images are delivered through image URLs; do not upload photographs or content that you need to keep confidential. Device camera or photo-picker access is used only when you choose to take or select an image; denying optional photo or microphone access does not prevent core record keeping. Device speech recognition and text-to-speech are supplied by the device or operating-system provider. Providers may process information outside your region according to the configured hosting locations and their terms. If you choose email or WhatsApp support, those providers process your message under their own terms. We may disclose information where legally required, to protect users or the service, or in a business transfer with appropriate safeguards. We do not sell personal data, serve advertising or share data for targeted advertising.
9. Operational-data retention
Detailed completed-service records, settlements and payment history are kept for the current calendar month. The immediately preceding month remains available through the fifth day of the current month; it becomes eligible for automatic permanent deletion at 00:05 India Standard Time on the sixth day. Cleanup is applied by the configured retention job or when retained data is processed; this is not a promise of deletion from every provider system at that exact minute.
When detailed records expire, unpaid commission may be carried forward as a staff-level balance with staff reference, source month, due and paid amounts, status, payment-mode label, notes and update time, without the expired transaction details. Owners may manually delete eligible fully settled days, weeks or months. These operations permanently delete the selected detailed records; they are not a recoverable archive.
10. Other retention
Account, shop, staff, catalogue, subscription and referral information is retained while needed to operate the service. Short-lived authorizations and support grants have expiry rules. Audit entries linked to deleted service records may be removed with those records; general admin, security and support logs are not all subject to a one-month deletion rule.
When an account is closed, we permanently erase the profile's email, address, profile photograph and any images uploaded by that user on Cloudinary, PIN and login credentials, OTP records and trusted device sessions. We retain only the name and mobile number of a closed account, for up to one year after deletion, solely to identify the account if a support query or dispute is later raised about it; after one year these are permanently erased too. You may request earlier erasure of this retained name and mobile number at any time by contacting us below. Internal non-login record references may remain where needed to preserve the shop's operational history; they do not restore the closed account. Provider infrastructure logs and backups follow separate, standard retention and rotation settings. Contact shopcomm.dr@gmail.com for requests concerning retained information; we may verify identity and consider applicable legal obligations.
11. Account and shop deletion
You can request deletion without installing ShopComm, signing in or having a registered email address. Requests sent by email are handled through ShopComm support, not automatically by the website. Email shopcomm.dr@gmail.com with the subject "ShopComm account deletion". Include your registered mobile number and whether you want account closure, erasure of retained personal information, or both. Your shop name can help us locate the account. We may ask for reasonable identity verification and communicate next steps through the support conversation. We complete verified requests within 7 business days. Do not send a PIN, OTP, support-access code or payment credentials.
In the app, open Settings > Delete account, review the confirmation, type DELETE and confirm. If you cannot reach Settings because your shop is expired or you cannot sign in, use the email method.
For every deleted account, email, address, profile photo and images uploaded by that user, PIN and login credentials, OTP records and trusted device sessions are permanently erased. The limited retention of name and mobile number is described in Section 10.
Owner account deletion also permanently removes owned shops and their associated service transactions, settlements, memberships and operational data. Staff accounts are not deleted merely because the shop is removed. Staff account deletion removes personal details and active access but retains that staff member's existing service transactions, settlements and other shop operational records under the shop's normal retention rules. Historical references may remain so the shop's totals and settlement history are not changed by staff account deletion. The Owner, shop details, configured services and other staff are not deleted.
Registering again with the same mobile number creates a brand-new account. It is not connected to the deleted account, and none of the previous records, subscription or access is restored.
Delete this shop is a separate Owner action available in Settings or the expired-plan dialog. It removes only that shop, its uploaded shop images, operational data and memberships, while keeping user accounts and other shops. Approved shared catalogue definitions and images may remain; they are not private user uploads. Deleting one shop does not close your account or settle money owed between the shop and staff. Leaving a shop, signing out and uninstalling are not account deletion.
12. Security
We use authenticated requests, short-lived signed authorizations, Admin Web email OTPs, hashed PINs and installation identifiers, authentication rate limits, role-based access controls, time-limited support consent, audit records and HTTPS for hosted service traffic. Mobile OTP checks are currently disabled; mobile registration, PIN reset and device movement therefore rely on the controls described in the applicable flow, including the registered mobile number, PIN where required, installation binding and short-lived authorization. No method of storage or transmission is completely secure. Users must protect their PIN and device and notify us if they suspect unauthorized access.
13. Choices, rights and grievances
Subject to applicable law, users may request access to or correction or deletion of personal information, withdraw consent where consent is the processing basis, and raise a privacy grievance. Contact shopcomm.dr@gmail.com. We may request reasonable identity verification before responding.
14. Children and changes
ShopComm is intended for business users and is not directed to children. Owners must not create staff access for a child where prohibited or without required authorization. We may update this policy when features, providers or legal requirements change. We will update the effective date and provide reasonable notice of material changes.
Contact ShopComm
Privacy, grievance and account-deletion requests: shopcomm.dr@gmail.com
Phone: +91 99087 81521