We are committed to maintaining the security, integrity, and confidentiality of the operational data processed through our distributed microservices suite. This Privacy Policy outlines how data flows, where it is stored, and who controls it.
1. COMPLIANCE & THE ROLE-BASED DATA SPLIT
Under applicable data protection frameworks (such as GDPR, CCPA, and regional digital privacy acts):
- The Showroom is the "Data Controller": You (the Showroom Owner) collect information directly from your staff and retail customers. You determine what customer names, phone numbers, and addresses are logged into the system.
- VoltOS is the "Data Processor": We act solely on your instruction. We process, store, and route the customer and transaction information within our secure platform perimeter to execute the business logic of the Software.
2. INFORMATION WE COLLECT AND PROCESS
To operate the microservices architecture successfully, we collect two categories of information:
2.1 Showroom Staff (Authorized Users)
- Identity Details: Full name, business email address, active phone number, and system-defined role (Owner, Manager, Salesperson, Technician).
- Session and Security Data: Unique Device IDs (hardware signatures used to enforce device-based session locking), cryptographically hashed One-Time Passwords (OTPs), and API access tokens.
2.2 Showroom Customers (Retail Consumers)
- Contact Information: Name, physical address, and primary/secondary phone numbers.
- Transactional History: Products purchased, service history, device models, repair notes, and parts replacement details.
- Reminders: Scheduled maintenance calendars and automated technician assignment logs.
3. STRICT DATA USAGE POLICIES
Customer and showroom transaction data processed by the Software is subject to strict usage boundaries:
- No Commercial Exploitation: We do NEVER sell, lease, rent, trade, or distribute your showroom's customer data, transaction records, or employee contact logs to any third-party marketing companies, advertisers, or analytics brokers.
- Internal System Actions: Customer data is used strictly to fulfill operations requested by the showroom staff (e.g., executing a checkout transaction, resolving customer history lookups, calculating profit trends, or compiling cron-job service reminders).
4. SECURITY ARCHITECTURE & DATA INTEGRATION FLOW
To process retail checkout operations, user authorization, and maintain detailed customer logs, data flows securely through multiple distinct security layers:
- Client Request Initiation: Showroom client devices connect via secure HTTPS connections to a single, hardened API Gateway, which enforces Cross-Origin Resource Sharing (CORS) rules and blocks unregistered requests.
- Access Token Verification: The API Gateway validates JSON Web Tokens (JWT) and checks user roles. Authorized requests are routed to the Identity Service to verify session permissions and active device locking keys.
- Inventory Lookup & Validation: For any operations involving item listings or stock levels, queries are directed to the Catalog Service to verify catalog metadata.
- Checkout & Financial Logging: Sales receipts, customer payment figures, and GST breakdowns are compiled and written dynamically by the Transaction Service.
- Customer & Service Retention: Repair task logs, technician work histories, and service reminders are securely compiled and retained inside the CRM Service.
Furthermore, we employ these rigorous security standards:
- JWT-Protected Endpoints: All cross-service API requests are routed through a secure Gateway, validated using JSON Web Tokens (JWT) with signature verification.
- Hashed Credentials: Employee login credentials, including passwords and generated
temporary OTP codes, are instantly salted and hashed using
bcryptbefore database storage. - Device-Bound Token Locks: If an employee attempts to reuse an API token or session refresh token from an unregistered hardware device, the Identity service will automatically invalidate the session and force an account lockout.
5. INTRA-PLATFORM MICROSERVICE COMMUNICATION
5.1 Perimeter Isolation
To process retail checkout operations or display comprehensive customer history, data must traverse our internal microservices boundaries:
- Identity Service: Manages staff access, roles, and device keys.
- Catalog Service: Validates product descriptions, prices, and stock counts.
- Transaction Service: Handles sales processing, billing summaries, and GST calculation.
- CRM Service: Compiles service tasks, logs repair notes, and structures chronological maintenance reminders.
5.2 Perimeter Security
All intra-service communication is conducted over a closed virtual private network (VPN) and internal service-to-service endpoints. Data is encrypted in transit and never leaves our secure cloud network perimeter during processing.
6. DATA RETENTION & SUBSCRIBER RIGHTS
We retain personal data and transactional information for as long as your subscription is active.
- Owner Data Deletion Requests: Showroom Owners can submit an official "Purge Request" to delete their tenant database. Upon receiving the validated request, we will permanently destroy all customer contacts, sales history, and employee profiles within 30 days, except where retention is mandated by regional tax or transaction audit laws.
- Customer Inquiry: Retail customers who wish to access, correct, or delete their personal info stored within the showroom records must contact the Showroom (the Data Controller) directly. As the Processor, we will execute data modification queries upon receiving the verified request from the Showroom Owner.
7. COMPANY DETAILS & CONTACT
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us at:
- Company Name: CodingGama
- Office Address: 8th Floor, Harihar Chowk, 807 Star Chambers, Rajkot, Gujarat 360001
- Support Email: info@codinggama.in