SalesTeam

Legal

Privacy Policy

What SalesTeam collects, why it collects it, who can see it, how long it is kept, and how to get a copy or have it deleted. Written to describe what the software actually does, not to cover every eventuality in the abstract.

Before this is published

The description of what is collected is accurate and was checked against the code — the sub-processor list below is derived from the hosts the software actually calls, not from memory. Three things to settle:

  1. Have it reviewed against the law that applies to you — India's DPDP Act, and GDPR too if you take an EU customer. The parts worth the time are movement tracking and the controller/processor split, because that split decides who answers a staff member's complaint.
  2. Confirm your hosting provider and region, marked like this below. It is the one sub-processor the code cannot tell me.
  3. Confirm the retention periods. Movement trails are what the software actually enforces; the rest are proposed operational commitments. Both are labelled as such.
Last updated 22 September 2026

Two kinds of relationship

Where you are a customer — a distribution business using SalesTeam — you decide what goes into the system and why. You are the controller of that data; we process it on your instructions.

Where you are a member of a customer's staff — a salesperson, a delivery person, a manager — your employer decides what is recorded about you and is the right first point of contact about it. We hold it for them.

Where you contacted us through this website, we are the controller. That is the one case where the data is ours rather than a customer's.

What is collected

Account details

Name, email address, phone number, role, and the time of your last sign-in. Entered by your administrator when the account is created.

Business records

Shops and their owners' names, phone numbers and addresses; product catalogues and prices; orders and their lines; deliveries; payments and receipts; returns; and shop balances. This is the working content of the service.

Payments are recorded, not processed. Money moves directly between the payer and the distributor's own bank or UPI account. We never see a card number, a bank credential or a UPI PIN.

Location

This is the sensitive one, so it is set out in full. There are three separate cases:

If tracking is on for you, your employer switched it on, chose you specifically, and is accountable for that decision.

Website enquiries

If you use the contact form: your name, email, and the phone number, company and message you choose to give, plus the IP address the submission came from. The IP is kept to recognise automated abuse, not to identify you.

Technical data

Ordinary server logs — IP address, timestamps, which endpoint was called and whether it succeeded — kept to operate and secure the service and to investigate faults.

What is not collected

Why it is collected

We do not use your business data to train models or to build any product other than the service you are using.

Who can see it

Sub-processors

The third parties involved in running the service. This list was checked against the hosts the software actually calls.

We will update this list before adding a sub-processor that handles personal data.

How long it is kept

Business records are kept for as long as your account is active, because they are your trading history. Some are deliberately never edited or deleted in place: payment receipts and ledger entries are append-only, and a correction is a reversing entry beside the original rather than a rewrite.

Movement trails

Enforced by the software. Recorded positions are kept for a period your company sets — 30 days by default, 180 at most — and are then deleted outright overnight, not archived or flagged. Your administrator can see and change the window on the Staff tracking screen, and shortening it deletes the older trails that night.

This is the movement trail only. The single position recorded with an order, a shop registration or a delivery is part of that record and is kept with it.

Everything else

These three are operational commitments rather than something the software enforces on a timer, unlike movement trails above.

Security

Access is authenticated and role-scoped; passwords are stored hashed, never in readable form; data is transmitted over TLS and the mobile app refuses unencrypted connections outright; each customer's data is isolated by tenant on every query. No system is perfectly secure, and we will tell affected customers about a breach that puts personal data at risk without undue delay.

Your rights

Depending on where you are, you may have the right to a copy of your personal data, to have it corrected, to have it deleted, and to object to some processing.

If you are a member of a customer's staff, ask your employer first — they control the data and can usually act immediately. If you ask us directly, we will pass the request to them unless the law requires otherwise.

Requests: meshitsolutions@gmail.com. We will acknowledge within 7 days and answer within 30.

If you are not satisfied with how we handled it, you can complain to the Data Protection Board of India. If you are in the EEA or the UK, you may complain to your local supervisory authority instead.

Children

The service is for business use and is not directed at children.

Changes

We may update this policy. Material changes will be notified to account administrators, and the date at the top of this page will change.

Contact

Meshit Solutions OPC Pvt Ltdmeshitsolutions@gmail.com, WhatsApp +91 92178 25076, or via the contact page.

We have not appointed a Data Protection Officer; privacy requests go to the address above and are handled by the people who run the company.