1. Who we are and the scope of this policy
Dukanam is owned and operated by Amvention Private Limited (“Amvention”, “Dukanam”, “we”, “us”, or “our”), with its business address at 302, 306, Sree Vishnu Abode, Megha Hills, Swamy Ayyappa Society, Madhapur, Hyderabad, Telangana, India 500081.
This policy applies when you visit dukanam.com, create or use a Dukanam account, use the web application or versioned API, purchase a subscription, submit a testimonial or private product feedback, contact us, or otherwise interact with the Dukanam billing, bookkeeping, inventory, payments, GST-preparation, compliance-guidance, and reporting service (the “Service”). It does not govern a third-party website or service that has its own privacy notice.
2. Our role and the business customer’s role
For account, website, subscription, support, product-security, and service-usage data, Amvention determines why and how the data is processed and acts as the data-responsible entity or Data Fiduciary where applicable.
A business that creates a Dukanam workspace normally decides why it records personal data about its customers, suppliers, staff, and other contacts. For that workspace data, the business is responsible for providing any required notice, obtaining any required permission, respecting individual rights, and ensuring the data is lawful and accurate. Amvention processes that data to provide the Service on the business’s instructions. Workspace owners and authorized users may access and manage it according to their roles.
3. Personal data we handle
The data involved depends on how you use Dukanam. It may include:
- Account and identity data: name, email address, phone number, encrypted password, account role, language, and authentication or password-reset records.
- Business profile data: shop or legal name, contact details, address, logo, tax registrations, GSTIN, PAN, business category, financial year, invoice settings, UPI ID, and compliance profile.
- Workspace records: customer and supplier details, items and photos, invoices and quotations, purchases and returns, payments, expenses, ledger and stock movements, cash-register records, bank-reconciliation information, reminders, notes, and audit history.
- Uploaded material: product-import files, item images, GST-reconciliation files, licences, registrations, and other compliance evidence you choose to upload.
- Subscription and transaction data: selected plan, billing interval, charge amount, tax and invoice information, Razorpay references, payment method category, payment status, and subscription history. Payment-card, bank-account, or UPI credentials entered in Razorpay’s checkout are handled by Razorpay; we do not need the full credentials to operate your subscription.
- Communications: support requests, feedback, security reports, invitation details, and service emails and their delivery status.
- Testimonial submissions and customer-authorized drafts: your name and email, linked workspace, selected shop type, testimonial text, optional shop photo, optional public city or region, publication consent, submission time, moderation status, and private review and permission notes. An administrator may prepare wording from genuine customer feedback on your behalf; it remains unpublished until permission and approval are recorded. Your email and private notes are not published.
- Private product feedback: your signed-in account and workspace, whether the feedback is an improvement request, complaint, or suggestion, the message, any optional supporting image, handling status, submission time, and any response from our team. Product feedback is not published as a testimonial.
- Daily app statistics: the app sends aggregate counts of records and actions, monetary sums, milestone dates, app version and a random installation identifier to improve the product. These reports contain no customer or item contents. Detailed reports are kept for 90 days; daily metrics are retained for at least 25 months and then summarized monthly. Workspace deletion removes these statistics.
- Technical and usage data: IP address, browser and device type, timestamps, requested pages or API routes, session and security events, error information, and diagnostic logs.
- Cookie and local-storage data: session, remember-me, security, language, interface state, and other essential preferences described below.
Please do not upload information that the Service does not request or that you are not authorized to use.
4. How we receive data
We receive data directly from you; from a workspace owner or team member who adds, imports, or invites you; automatically from your browser, device, or API client; and from providers that support the Service. For example, Razorpay sends us subscription and payment-status events so we can activate plans, issue invoices, and reconcile charges.
5. Why we use personal data
- To create accounts and workspaces and provide requested billing, inventory, accounting, export, team, and compliance-guidance features.
- To authenticate users, enforce workspace permissions and plan limits, protect tenant isolation, prevent duplicate operations, and investigate fraud, abuse, or security incidents.
- To process subscriptions, verify payment status, issue receipts or tax invoices, manage renewals and cancellation, and maintain financial records.
- To send account, password, invitation, payment, compliance-reminder, and other service communications. Dukanam does not independently send the customer reminders that you compose for WhatsApp or email; you review and send those through your chosen service.
- To answer support requests, diagnose faults, maintain the Service, understand feature performance, and make proportionate improvements.
- To prepare and review testimonials, contact the customer when necessary, prevent abuse, and—only after approval and with recorded consent for the wording and attribution—publish the name, shop name and type, optional city or region, testimonial text, any authorized shop photo, and publication date on the matching store-type page and through the public API.
- To receive, investigate, respond to, and resolve private improvement requests, complaints, and suggestions submitted by signed-in users.
- To comply with law, respond to lawful requests, establish or defend legal claims, and enforce our agreements.
Where the law requires consent, we ask for it and allow it to be withdrawn. In other cases, processing may be necessary to provide a service you requested, for specified legitimate uses permitted by law, or to meet legal obligations. Withdrawing consent does not affect processing already lawfully completed and may make a requested feature unavailable.
6. When data is shared
We do not sell or rent personal data, and we do not use a business’s customer or supplier list for independent advertising. We may disclose only the data reasonably needed to:
- Authorized workspace users: owners, administrators, accountants, and staff according to configured permissions.
- Operational providers: infrastructure and object storage, database and cache hosting, transactional email, security and error logging, and customer support providers acting for us.
- Payment providers: Razorpay and relevant banking or payment-network participants when you authorize or pay for a subscription.
- User-directed services: a browser, email application, WhatsApp, printer, scanner, or other destination you deliberately open or use from Dukanam.
- Professional advisers and authorities: auditors, insurers, legal or tax advisers, courts, regulators, or law-enforcement bodies where reasonably necessary or legally required.
- Corporate transactions: a buyer, investor, or successor in a merger, financing, restructuring, or sale, subject to confidentiality and appropriate safeguards.
When a testimonial is approved, the submitted name, shop name, shop type, testimonial text, shop photo, and publication date become public and may be indexed by search engines. The submitter’s email, moderation status, and review notes remain private. Improvement requests, complaints, suggestions, optional supporting images, and our responses remain available only to the submitter and authorized Dukanam administrators; they are never added to public testimonial pages or the public testimonial API.
Providers are expected to process data under contractual and security obligations and only for the service they supply.
7. Storage location and international transfers
Dukanam is operated from India and is configured to use durable cloud storage in India for core production files. Some providers or their support operations may process limited information in another country. Where personal data is transferred, we apply contractual, technical, and organizational safeguards and follow transfer restrictions that apply under Indian law.
8. Retention
We keep account and workspace data while the account or workspace is active and for a reasonable period afterward to support recovery, resolve disputes, enforce agreements, prevent abuse, and meet tax, accounting, payment, security, and other legal obligations. Different records require different periods: financial and subscription records may need to be kept longer than routine logs or support correspondence.
When deletion is appropriate, data is removed or de-identified from active systems and expires from backups under the applicable backup cycle. Legal holds, outstanding payments, fraud prevention, and statutory recordkeeping may delay deletion. Aggregated or de-identified information that no longer identifies an individual may be retained.
Pending and rejected testimonial submissions are kept only as long as reasonably needed for moderation, abuse prevention, dispute handling, and legal compliance. Approved testimonials remain published until withdrawn, removed by us, or no longer needed. A submitter may ask us to withdraw a testimonial using the contact email below; we may verify the request against the private email supplied with the submission.
Private product feedback and administrator responses are kept while reasonably useful for support, product improvement, complaint handling, abuse prevention, and legal compliance, then deleted or de-identified under our retention process.
You can ask us to delete your account at any time from Profile → Delete account in the app, or by email. A request is held for 7 days so it can be cancelled, after which your account, the workspaces you own and their uploaded files are permanently erased. Two categories of record survive: the GST tax invoices Amvention issued you for paid subscriptions, which Indian tax law requires us to keep for 8 years from the end of the relevant financial year, and security and audit records with your user account detached so they no longer identify you. The account deletion page sets out the steps and the full list of what is deleted and what is kept.
9. Security
We use safeguards designed for the nature of the Service, including encrypted connections, hashed passwords, role-based authorization, tenant-scoped access controls, private storage for sensitive uploaded evidence, expiring download links where supported, audit records, rate limits, backups, and monitoring of security-relevant events. No online system is completely secure. Keep credentials private, use appropriate team roles, and notify us promptly if you suspect unauthorized access.
If we become aware of a personal-data breach, we will take reasonable steps to contain and investigate it and will notify affected individuals and the competent authority when and as required by applicable law.
10. Your rights and choices
Subject to your role, applicable law, and necessary identity verification, you may ask us to:
- confirm whether we process your personal data and provide a summary of it and relevant sharing;
- correct, complete, or update inaccurate personal data;
- erase personal data that is no longer needed, unless it must be retained for a specified purpose or by law;
- withdraw consent where consent is the basis of processing;
- address a privacy grievance; and
- record a nomination to exercise applicable data rights in the event of death or incapacity, when this right and its procedure apply.
You can edit supported profile and business fields in the Service, and delete your account and its data from Profile → Delete account. Authorized owners or administrators can download the supported business-data portability export from Reports. For other requests, email us using the details below. If your request concerns records controlled by a Dukanam business customer, we may direct it to that business or assist the business in responding. We may ask for information needed to verify identity, authority, and workspace scope.
11. Cookies, local storage, and external resources
Dukanam uses cookies and browser storage that are necessary for sign-in, security, session continuity, language selection, remember-me choices, and core interface state. The language cookie may remain for up to one year; session and remember-me cookies follow their configured duration or end when cleared. Blocking essential storage may prevent the Service from working.
Our pages may request fonts or other static resources from a delivery provider, which can receive basic connection data such as IP address and browser information.
When you open our app download link (dukanam.com/app) or one of our store-type pages (such as dukanam.com/billing-software-for-pharmacy), we record that open on our own servers so we can see which promotions work: the campaign tags in the link, the site or app that sent you, your device, operating system, browser and screen size as your browser reports them, your approximate city and region derived from your IP address by our network provider, your browser language, and whether you were sent to Google Play or the App Store. On store-type pages we also record how long the page was on screen, how far you scrolled, and which link you followed, such as sign-up or the app. A first-party cookie with a random identifier, kept for up to one year, tells a repeat visit from a new one. We do not store your IP address itself, only a keyed one-way hash of it, and we do not record your name, phone number, or email. These records are kept for up to 400 days and are not shared with advertisers.
When Google measurement is enabled, Google Analytics and the Google Ads tag run on public marketing pages, registration, and the first account-setup page. We do not interrupt you with a banner to ask first; this notice is how we tell you. Google Analytics receives privacy-filtered page locations and referrers and a completed-registration event. Google Ads may also receive validated advertising click identifiers and a completed-registration event with a random identifier used to prevent duplicate counts. We do not send names, email addresses, phone numbers, passwords, form contents, or shop records. Enhanced measurement, enhanced conversions, Google signals, and advertising personalization are disabled.
Google's measurement cookies follow Google's retention settings. Read how Google uses information from sites that use its services. Your browser's privacy settings, a content blocker, or Google's own Analytics opt-out add-on will stop this measurement, and none of that prevents registration or use of the Service. Versioned API responses load no measurement at all, and neither does the mobile app.
When Meta measurement is enabled, the Meta Pixel runs on public marketing pages, the language-specific login landing page, registration, and the first account-setup response after a successful new signup. It measures page visits and a completed-registration event; an OTP request or an existing-user login is not counted as a new registration. Meta receives browser and connection information, the public page address and referrer, advertising click identifiers and its measurement cookies. A completed registration carries a random event identifier to prevent duplicate counts. We do not pass names, email addresses, phone numbers, passwords, form contents, or shop records as event parameters. Automatic event collection and advanced matching are disabled. The integration does not load on workspace, password-login, OTP-verification, reset, admin, API or shared-document pages. It also skips URLs with unexpected query parameters or fragments and respects browser Global Privacy Control and Do Not Track signals. Browser privacy settings or content blockers can prevent measurement without preventing sign-in or registration. Read Meta’s cookie policy for its measurement-cookie practices.
Inside your workspace, Google Analytics records which screen you opened so we can see which parts of Dukanam are used. It is told the screen, never the record: the address sent to Google is the route pattern — /invoices/{invoice}, not /invoices/4821 — and the search terms in the address bar, the part after the #, and the page title, which carries your shop's or your customer's name, are all removed before anything is sent. No invoice, customer, item, or workspace identifier, and no account details or shop records, reach Google from inside your workspace. The Google Ads tag is not loaded there at all, and neither is anything on a shared invoice, ledger, or quote link you send to a customer.
12. Children
Dukanam is a business service and is not intended for anyone under 18 to open or administer an account. Do not create an account for a child. If a business records data about a minor in a legitimate transaction, that business is responsible for the lawful basis, parental or guardian permission where required, data minimization, and the child’s well-being. Contact us if you believe a child opened an account without authorization.
13. Changes to this policy
We may update this policy as the Service, providers, or law changes. We will post the revised version here, update the effective date, and provide additional notice through the Service or email when a change materially affects your rights or requires fresh consent.
14. Privacy contact and grievance redressal
Grievance Officer / Privacy and Grievance Desk
Amvention Private Limited
302, 306, Sree Vishnu Abode, Megha Hills, Swamy Ayyappa Society, Madhapur, Hyderabad, Telangana, India 500081
Email: [email protected]
Use the subject “Dukanam privacy request” and include your account email, workspace name, the right or issue involved, and enough detail to locate the relevant data. Do not send passwords or unnecessary identity documents. We will acknowledge and handle the request within the period required by applicable law. Where available, you should first use this grievance process before escalating a complaint to the competent data-protection or consumer authority.