Privacy Policy
How StoreOPUS (https://storeopus.com) collects, uses, stores, and shares information when you use our websites, merchant portals, desktop software, and optional WhatsApp Business integrations.
Effective date: 5 August 2026
1. Who we are
StoreOPUS is a point-of-sale and store-operations product operated by Inovitrix (“we”, “us”, “our”), based in India. We are the data fiduciary for account and subscription data we collect to provide the Service. Merchants using StoreOPUS remain responsible for personal data of their own customers and staff that they store or process in the software (including offline desktop databases).
Contact: privacy@storeopus.com or support@storeopus.com.
2. Scope
This policy covers:
- Our public website (https://storeopus.com), registration, download, and activation flows
- Merchant and admin portals hosted under storeopus.com
- Cloud APIs that sync licenses, billing, backups, and optional Marketing / WhatsApp features
- Facebook Login for Business / WhatsApp Embedded Signup when a merchant connects a WhatsApp Business Account through StoreOPUS
It does not replace Meta’s, Razorpay’s, or other third-party privacy policies for services they provide directly to you.
3. Information we collect
Account & business contact. Organization name, contact name, email, phone, GSTIN (if provided), product line (Fashion / Retail), and license / device registration details.
Billing. Plan selection, subscription status, and payment references. Card, UPI, and net-banking credentials are collected and processed by Razorpay; we do not store full card numbers. Merchant of record for settlements: Inovitrix.
Usage & diagnostics. Device registration tokens, sync timestamps, entitlement flags, approximate IP on API requests, and limited application logs needed to operate and secure the Service.
WhatsApp / Meta (Marketing add-on). When you connect WhatsApp via Embedded Signup we receive authorization codes, WhatsApp Business Account (WABA) IDs, phone number IDs, display phone numbers, access tokens (encrypted at rest), message templates metadata, and inbound/outbound message content and delivery statuses required to operate inbox, campaigns, and transactional sends. Meta may also share business portfolio identifiers associated with your Facebook Business login.
Merchant-held customer data. Customer names, phones, loyalty and consent flags stored in your local/offline store database are controlled by you. Cloud processing of that data occurs only when you use features that send it to our servers (for example WhatsApp sends or cloud backups you enable).
4. How we use information
- Create and administer your organization, trial, and licenses
- Deliver downloads, activation keys, and product emails
- Process subscriptions and invoices via Razorpay
- Provide optional WhatsApp Business messaging, templates, inbox, campaigns, and analytics
- Secure the Service, prevent abuse, and troubleshoot issues
- Comply with applicable law and respond to lawful requests
- Improve product reliability and documentation
We do not sell personal data. We do not use WhatsApp message content for advertising to third parties.
5. Legal bases / purposes (India)
We process personal data for lawful purposes including performance of a contract (providing StoreOPUS), compliance with law, and legitimate uses necessary to operate a B2B SaaS product—such as security, billing, and support—consistent with the Digital Personal Data Protection Act, 2023 (DPDP). See our DPDP Notice for data principal rights.
6. Sharing
We share data only as needed with:
- Razorpay — payment processing
- Meta Platforms — when you connect or use WhatsApp Business / Facebook Login for Business features
- Cloud infrastructure providers (for example AWS, email delivery) acting as processors under our instructions
- Professional advisers or authorities when required by law or to protect rights and safety
7. Retention
Account and billing records are retained while your organization is active and for a reasonable period afterward for tax, dispute, and legal compliance (typically up to 8 years for financial records where applicable). WhatsApp connection tokens and message logs are retained while the Marketing add-on is connected and for a limited period after disconnect for delivery troubleshooting, then deleted or anonymized. You may request earlier deletion as described in our Data Deletion Instructions.
8. Security
We use HTTPS, access controls, encrypted storage of WhatsApp access tokens, and least-privilege cloud roles. No method of transmission or storage is 100% secure; merchants must also secure devices, staff accounts, and local databases.
9. Children
StoreOPUS is a business product and is not directed to individuals under 18. We do not knowingly collect children’s data.
10. International transfers
Primary operations and storage are intended for India. Subprocessors may process data in other regions with appropriate safeguards. Meta and Razorpay may process data according to their own locations and terms.
11. Your choices
- Update organization contact details via support or merchant portal
- Disconnect WhatsApp under Marketing → Connect in the desktop app
- Request access, correction, or deletion via privacy@storeopus.com
- Follow Meta-specific deletion steps at /legal/data-deletion
12. Changes
We may update this policy. Material changes will be posted on this page with a revised effective date. Continued use after changes means you accept the updated policy.
13. Contact
Privacy requests: privacy@storeopus.com
General support: support@storeopus.com
Website: https://storeopus.com
These documents describe how StoreOPUS operates. They are not a substitute for independent legal advice. For questions, write to support@storeopus.com.