Skip to content
SimpleERP

Legal

Privacy policy

What we collect, why, and what you can ask us to do with it.

Updated

In short

This privacy policy explains how SimpleERP handles personal data. We collect what is needed to run your account and your business records, never sell it, use only essential cookies, and you can access, correct, export or delete your data.

Who is responsible

[Company legal name], [Registered address], India, operates SimpleERP and is responsible for your personal data as described here. We follow the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 and its rules.

What we collect

DataExamplesWhy
AccountName, mobile number, password hash, optional emailTo create your login and keep it secure
Business recordsCustomers, products, invoices, employees, payslips, attachmentsTo provide the service you use; this is your data
Session and securityIP address, browser, sign-in times, audit historyTo keep sessions secure, limit abuse and show who changed what
Contact formName, business name, phone, optional email, your message, and the IP address and browser it was sent fromTo reply to you and to keep spam out

Business records often contain personal data about your customers, suppliers and employees. For that data you decide what is entered and why, and we process it on your instructions to provide SimpleERP.

Cookies

SimpleERP uses only essential cookies: a session cookie that keeps you signed in (httpOnly, so page scripts cannot read it) and one that remembers the last business you opened. There are no advertising or tracking cookies.

Who processes it

  • The hosting provider that runs our servers and database
  • An email delivery provider, when email is turned on, to send invitations, password resets and replies
  • Professional advisers or authorities, only where the law requires it

We do not sell personal data or share it for advertising.

How long we keep it

We keep account and business data while your account is open. When you close it, we delete or anonymise it within a reasonable period, except records we must keep by law, such as tax records. Contact form messages are kept for as long as needed to deal with your request.

How we protect it

Each business's data is isolated by database row-level security, passwords are hashed with scrypt, sessions can be revoked, and every change to documents and masters is recorded. The security page explains what is enforced today and what depends on hosting.

Your rights

  • Ask what personal data we hold about you and how we use it
  • Correct or complete it; most of it you can edit yourself in the product
  • Ask us to delete it, subject to what the law requires us to keep
  • Withdraw consent where we rely on it, and nominate someone to act for you
  • Complain to our grievance officer, and then to the Data Protection Board of India

Grievance officer

Write to simpleerpsoftware@gmail.com. We acknowledge complaints within 24 hours and aim to resolve them within 15 days. We will tell you about material changes to this policy by email or in the product before they apply.

Run your whole business from one simple place.

Seven days free. No card. Your first GST invoice in minutes.