Last updated: July 2026
We collect information you provide directly to us, such as when you create an account, use our services, or contact us for support. This includes business information, user details, and operational data.
We use the collected information to provide, maintain, and improve our services, process transactions, send technical notices and support messages, and communicate with you about products, services, and promotional offers.
We do not sell, trade, or otherwise transfer your personal information to third parties without your consent, except as described in this policy. We may share information in response to legal requests or to protect our rights.
We implement appropriate security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. This includes encryption, access controls, and regular security assessments.
We retain personal information for as long as necessary to provide our services and fulfill the purposes outlined in this privacy policy, unless a longer retention period is required by law.
Statutory carve-out: financial and transactional records (invoices, purchase orders, and similar documents) must be retained for the period mandated by the GST Act, the Companies Act, 2013, and the Income Tax Act — currently up to 6-8 years depending on the record type — even after you request deletion of your account. These records are moved to a restricted, read-only archive and are not accessible through the platform once your account is deleted, then purged once the mandated period ends.
After a record is removed from our active systems, a copy may still exist in our routine backups for our standard backup rotation window before it is fully purged from backup storage as well.
You have the right to access, correct, update, or delete your personal information, consistent with the Digital Personal Data Protection Act, 2023 ("DPDP Act"). Specifically:
To exercise these rights, use the self-service Export/Delete options on your Business Profile page, or contact us at privacy@MonitorBizz.com if you're unable to access your account. We aim to acknowledge every request promptly and to act on erasure requests within a reasonable time, and in any case within 90 days.
Personal data vs. business data: the DPDP Act governs personal data about identifiable individuals (e.g. names, phone numbers, email addresses of you, your team, or your customers/vendors as stored in the app). Most day-to-day business/transactional records (stock counts, pricing, order statuses) are not personal data unless they contain identifiable contact details. Where your business stores personal data about your own customers or vendors, MonitorBizz acts as a Data Processor and your business is the Data Fiduciary responsible for that data; for your own account and team member profiles, MonitorBizz acts as the Data Fiduciary directly.
We use cookies and similar technologies to enhance your experience, analyze usage, and assist in our marketing efforts. You can control cookie settings through your browser preferences.
Our service may integrate with third-party services. We are not responsible for the privacy practices of these third parties. Please review their privacy policies.
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your data during such transfers.
We may update this privacy policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
For any questions about this Privacy Policy, or to raise a grievance about how your personal data has been handled, please contact us at privacy@MonitorBizz.com or contact@monitorbiz.com. We aim to acknowledge grievances promptly and resolve them within a reasonable time frame.
We are committed to complying with applicable data protection laws, including India's Digital Personal Data Protection Act, 2023 and its rules, the Information Technology Act, 2000 and the rules made thereunder, and the General Data Protection Regulation (GDPR) where applicable.