Privacy Policy

Last updated: September 2, 2026  |  Effective: July 18, 2026

1 Introduction

Bhoraniya Hardware Management System ("we," "our," or "us") respects your privacy. This Privacy Policy explains how we collect, use, share, and protect personal information when authorized personnel use our internal hardware business management platform.

By accessing or using this system, you agree to the collection and use of information in accordance with this policy. This system is intended solely for internal business use by authorized personnel.

2 What Bhoraniya Hardware Management Does

This system helps the Bhoraniya Hardware team manage day-to-day business operations including sales entries, inventory tracking (stock in/out), product cataloging, customer management, vehicle management, and internal communication.

3 Information We Collect

3.1 Information you provide

  • Account details — name, email address, and password when you are registered by an administrator
  • Role and permission assignments within the system
  • Sales entries, invoices, and transaction data you create
  • Customer and party information (names, contact details, addresses)
  • Product catalog data: names, rates, units, and categories
  • Company profiles, logos, and business settings
  • Stock records and vehicle/delivery information
  • Internal chat messages and daily update communications

3.2 Information collected automatically

  • Device browser type, operating system, and IP address at each login
  • Geolocation data (latitude/longitude) captured at login for security auditing
  • Session activity, pages visited, and features used within the system
  • Error logs and system performance data

4 How We Use Your Information

  • Authenticate users and manage secure access to the system
  • Process and record sales invoices, stock movements, and business entries
  • Generate reports, summaries, and analytics for business decisions
  • Manage inventory levels and stock availability in real time
  • Enforce role-based permissions and granular access control
  • Maintain audit trails for accountability and compliance
  • Troubleshoot technical issues and ensure system stability
  • Facilitate internal team communication via the daily update module

Your data is never used for advertising purposes or sold to third-party marketing services. All data processing is limited strictly to legitimate internal business operations.

5 How We Share Information

We do not sell your personal information. We may share it only as needed:

  • Within the organization — authorized staff and management with appropriate role-based permissions
  • Service providers — trusted technology vendors (hosting, database) bound by confidentiality agreements
  • Legal reasons — to comply with law, court orders, or to protect the rights and safety of users and the organization
  • Business transfers — in connection with a merger, acquisition, or reorganization, subject to appropriate safeguards
  • With your consent — wherever you expressly agree to additional sharing

6 Cookies and Similar Technologies

We use cookies and similar technologies to keep you signed in, remember preferences, and maintain secure sessions. The types of cookies used include:

  • Session Cookies — keep you logged in during your active session; deleted when you close the browser
  • CSRF Tokens — embedded in forms to prevent cross-site request forgery attacks
  • Preference Cookies — store your UI preferences such as table filters and display settings

We do not use third-party advertising cookies or tracking pixels. Cookie usage is limited to what is strictly necessary for system operation.

7 Data Retention

We retain personal information only as long as needed for the purposes described in this policy, including account operation, dispute resolution, security, and legal or accounting requirements:

  • User Account Data — retained for the duration of the active account and a reasonable period after deactivation
  • Transaction & Sales Records — retained for a minimum of 7 years to comply with financial and tax regulations
  • Inventory & Stock Records — retained as long as the business requires historical data for reporting
  • System Logs & Audit Trails — retained for up to 2 years for security and accountability purposes

When no longer required, data is deleted or anonymized in a reasonably secure manner.

8 Security

We use reasonable administrative, technical, and physical safeguards to protect personal information:

  • Password hashing using industry-standard bcrypt encryption
  • CSRF (Cross-Site Request Forgery) protection on all forms
  • Session-based authentication with secure cookie handling
  • Role-based access control (RBAC) with granular permission management
  • IP address and geolocation logging at login for security audit
  • Input validation and sanitization to prevent SQL injection and XSS attacks

No method of transmission or storage is 100% secure. Please protect your password and notify your system administrator of any suspected unauthorized access.

9 Your Choices and Rights

Subject to applicable law, you may:

  • Access and request a copy of the personal data we hold about you
  • Request correction of inaccurate or incomplete personal data
  • Request deletion or restriction of processing your data
  • Object to the processing of your data in specific situations

We may need to verify your identity before fulfilling certain requests and may decline requests that are unlawful or would prevent us from meeting legal obligations. We will respond to valid requests within 30 days.

10 Third-Party Services

Our system integrates with a limited number of third-party services to provide core functionality. These include Google Fonts, Font Awesome (CDN), and MySQL via XAMPP for local data storage. All critical business data is stored locally on your own server and is not transmitted to external cloud services by default.

11 Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will change when we do. Continued use of the system after changes means you accept the updated policy, except where consent is required by law.

12 Contact

For privacy questions, data requests, or concerns, contact:

  • Business: Bhoraniya Hardware
  • Contact: System Administrator
  • Location: Gujarat, India

We will endeavour to acknowledge and address genuine concerns within a reasonable time.