Privacy Policy
How BizFlow360 collects, uses, stores and protects the data we process on behalf of merchants and their customers.
Effective: 16 May 2026 · Operator: Labhyansh Infotech Pvt Ltd · Contact: support@bizflow360.in
1. Who we are and what this policy covers
BizFlow360 is operated by Labhyansh Infotech Pvt Ltd. We provide business-management software (an ERP) used by merchants to run their sales, purchases, inventory, production and accounting.
This policy applies to the BizFlow360 SaaS platform at biz.labhyansh.com, the marketing site bizflow360.in, and all related integrations (including the Shopify connector).
For data about a merchant's customers and vendors, the merchant is the data controller and BizFlow360 is the data processor. Every merchant's data lives inside its own tenant boundary; we never pool, merge or share data across merchants.
2. The data we collect
We collect only the data needed to run the service. Specifically:
- Business identity at signup — business name, address, contact details and your GSTIN (and the PAN within it). The GSTIN is required to open an account because a free trial is limited to one per business; it is validated locally against the GST format and check digit, and is not sent to any third party at signup.
- Merchant user accounts — username, email, hashed password, contact number, role. Provided by the merchant at signup.
- Customer records — name, email, phone, billing/shipping address, GSTIN (for B2B customers), order history. Entered by the merchant, or imported from connected sales channels (e.g. Shopify orders).
- Vendor records — name, email, phone, address, GSTIN, contact persons. Entered by the merchant.
- Operational data — invoices, purchase orders, inventory, goods-receipt notes, dispatch notes, payments, reports.
- Technical data — IP address, browser, log timestamps, anonymous usage metrics (used only to operate and improve the service).
- Sales enquiries & chat assistant — if you use the chat assistant or the “Book a demo” form on this website, we collect the details you submit (name, work email, phone and company) and the messages you send, solely so our team can answer your enquiry and arrange a demo. This is a sales enquiry you choose to send us — not merchant operational data — and it is never sold or used for advertising.
We do not collect demographic data, behavioural profiles, marketing preferences or any data we do not need for the merchant's operational flow.
3. How we use the data
Customer and vendor data is used solely to operate the service for the merchant:
- Generating GST-compliant invoices (name, address and GSTIN are used to calculate place-of-supply tax splits).
- Matching incoming orders to existing customer records (email is the primary match key).
- Producing dispatch notes and shipping documents (address, phone).
- Recording payments and accounts-receivable balances.
- Reporting and analytics inside the merchant's own tenant.
We do not sell, rent, lease or otherwise transfer personal data to third parties. We do not use this data for marketing, advertising, profiling or automated decision-making.
4. Artificial intelligence
Parts of BizFlow360 use AI: AI Insights (narrative summaries of your sales, purchase and inventory figures), the Atlas assistant (answers questions about your own business data), and Market Intel. Because this processes your commercial data, we are specific about how it works.
- The AI runs on our own infrastructure. We self-host an open-weights language model on a server we control. Your data is not sent to OpenAI, Anthropic, Google or any other AI provider.
- Your data is never used to train any model. The model is used only to generate a response and is not fine-tuned, retrained or improved using your data.
- Prompts are scoped to your own tenant. The figures given to the model are drawn only from your organisation's records. One customer's data is never included in another customer's prompt or answer.
- The numbers are computed before the AI sees them. Totals and metrics are calculated by ordinary code; the model only turns them into readable prose. It is not asked to do the arithmetic.
- AI output is informational. It can be wrong or incomplete and is not accounting, tax or legal advice. Check anything you intend to act on against the underlying records, which are always available in the app.
- No automated decisions about people. We do not use AI to make decisions producing legal or similarly significant effects on any individual.
- Atlas is scoped to business questions about your workspace. It is not a general assistant and is not intended for personal, medical, legal or emotional support.
5. Encryption
- In transit — TLS 1.2 or higher is enforced everywhere; HTTP requests are redirected to HTTPS. Certificates are issued by Let's Encrypt.
- At rest — application databases run on AES-256-encrypted persistent disks. Third-party OAuth access tokens (e.g. Shopify) are additionally encrypted with Fernet (AES-128-CBC + HMAC-SHA256), and the encryption key is stored only in the application environment, never in the database.
- Backups — daily encrypted snapshots, retained per policy.
6. Access control
- Tenant isolation — every database read and write is automatically scoped to a single tenant by a centralised security listener. Cross-tenant reads are limited to platform-admin endpoints and are audit-logged.
- Role-based access (in-app) — merchant users are assigned roles (admin, sales, purchase, warehouse, vendor, etc.) and only see data their role requires.
- Staff access — internal access to production systems is limited to named individuals on a need-to-know basis, authenticated by SSH keys; no shared accounts.
- Authentication — merchant logins use bcrypt-hashed passwords with a forced password change on first login. Session tokens (JWT) are signed and short-lived.
7. Logging and monitoring
BizFlow360 maintains an activity log recording create/update/delete events on customer, vendor, order, invoice, inventory and user records — who did what, when, on which entity. Logs do not contain plaintext passwords, OAuth tokens or full card numbers.
8. Retention and deletion
- Merchant data is retained while the merchant uses the service.
- Shopify privacy webhooks are wired — when Shopify sends
customers/redactwe anonymise and soft-delete matching customer records; when it sendsshop/redact(48 hours after uninstall) we delete the sales-channel connection and destroy the stored OAuth token.customers/data_requestevents are logged and acted on within the required window. - Statutory records (for example, Indian GST invoices) are retained for the legally required period as the merchant's own accounting records.
- On request, a merchant can have their account closed and personal data deleted within 30 days, subject to legal retention obligations.
- Free trials — if a 14-day trial ends without a subscription, the workspace is suspended and all of its data is permanently deleted 30 days later. Nothing is charged and no card is held.
- Trial fraud-prevention record — because a free trial is limited to one per business, we keep a small record after a trial workspace is deleted so the same business cannot repeatedly claim new trials. It holds one-way cryptographic hashes of the GSTIN, its PAN, the contact phone and email, plus the email domain, the business name and the date. It contains none of the merchant\'s business records, cannot be reversed to recover the original values, and is used for no purpose other than enforcing that limit.
9. Your rights
If you are an end customer of a merchant who uses BizFlow360, the merchant is the controller of your data. Requests to access, rectify, port or delete your personal data should be sent to the merchant in the first instance; we will assist the merchant in fulfilling those requests.
Where you have a direct relationship with us (for example, as a BizFlow360 user), you may write to support@bizflow360.in to exercise rights of access, rectification, deletion, portability or objection.
10. Sub-processors
We use the following sub-processors to operate the service:
- Google Cloud Platform — compute, storage and encrypted persistent disks.
- Shopify — when a merchant connects a Shopify store, order and product data flows from Shopify; we are a processor for that data.
- Brevo (Sendinblue) — delivery of our own emails to you: invoices, renewal reminders, password resets and the daily operations summary. Only the recipient's email address and the content of that message are shared. Your customers' and suppliers' contact details are never sent to Brevo.
- ICICI Bank — payment processing when you pay a subscription invoice online. Your name, email, mobile number and the invoice amount are shared so the payment can be taken. Card details are entered on ICICI's own payment page and never reach our servers.
- Sandbox (Quicko) GSP — the GST Suvidha Provider through which we file e-invoices and generate IRNs with the government's Invoice Registration Portal, and through which GSTIN lookups are performed. Invoice data required by GST law, and your entity's GSTIN and IRP API credentials, pass through this route.
- Microsoft — only if you choose to connect a Microsoft 365 mailbox to send your own business email. Nothing is shared with Microsoft unless you connect it.
- Google Analytics and Google Tag Manager — visitor analytics on the public marketing site (bizflow360.in) only. See section 11 on cookies. These are not loaded inside the BizFlow360 application or the admin console, so your business data and your logged-in activity are never sent to them.
- Let's Encrypt — TLS certificate issuance only; no personal data shared.
- GoDaddy — DNS for the bizflow360.in marketing domain; no merchant data.
We do not share personal data with any other third party.
Not on this list, deliberately: no advertising network, no data enrichment or lead-scraping service, and no third-party AI provider. We do not sell or rent personal data, and we do not share it for anyone else's marketing.
11. Cookies and analytics
We treat the marketing site and the application differently, on purpose.
- The application (biz.labhyansh.com) and the admin console load no analytics, no tag manager and no advertising scripts. The only browser storage used is what signs you in and remembers your preferences — your session token, your selected entity and your theme. None of it is shared with anyone.
- The public marketing site (bizflow360.in) uses Google Analytics via Google Tag Manager to understand which pages people find useful. This sets Google cookies and records the usual visitor information — pages viewed, approximate location derived from IP, browser and device type, and the site that referred you. It runs only on the public pages; it is not present once you log in.
Analytics do not run until you agree. On your first visit to the marketing site a banner asks you to choose. Google Analytics and Tag Manager are not present in the page at all until then — they are loaded only if you pick "Accept all cookies", so declining means no analytics cookie is ever created rather than one being set and then ignored. Your three options are:
- Accept all cookies — Google Analytics loads and sets its cookies.
- Essential cookies only — nothing analytics-related loads. Only what the site needs to function is used.
- Reject — as above, and any Google Analytics cookies already on your device from a previous visit are deleted.
Your choice is remembered in your browser's local storage, not in a cookie. You can change it at any time: review your cookie choices. You can also block these with any browser cookie control or tracker-blocking extension, and the site will continue to work normally. We do not use cookies for advertising and we do not run retargeting or ad-network pixels.
12. Incident response
If a security incident is detected, we follow a written incident-response process: containment, investigation, notification, remediation. Affected merchants are notified by email within 72 hours of confirmation, with a description of the incident, the data affected and recommended actions. Regulatory notifications are made where required by applicable law.
13. Vulnerability reporting
We welcome responsible disclosure. Please report any security issue to support@bizflow360.in with steps to reproduce. We will acknowledge receipt within two business days.
14. Changes to this policy
We will update this policy when our practices change or as required by law. Material changes will be communicated to merchants by email and posted on this page. The "Effective" date at the top reflects the current revision.
15. Contact
For any privacy question or request, contact:
Labhyansh Infotech Pvt Ltd
Email: support@bizflow360.in
Phone: +91 85951 51521 · +91 120 313 1251
Questions about your data?
Email us — we read everything that lands in support@bizflow360.in.