What BTOSC collects, why, where it lives and how long we keep it. Self-hosted means your customers' data stays on your server — this covers our records only.
Last updated · 7 August 2026
This policy explains what personal data BTOSC Infotech Pvt Ltd collects about you, why we collect it, who we share it with and what you can ask us to do about it. It covers our website, our client portal, our licence validation service and our dealings with you as a customer or an enquirer.
BTOSC Infotech Pvt Ltd, registered office Bhagwati Market, Gali Peepal Mahadev, Hauz Quazi, Delhi 6, Delhi 110006, Delhi, India, is the controller of the personal data described here. That means we decide why and how it is used.
This policy does not cover the data inside your own SnapCart installation. Our software is self-hosted: your store, your customers, their orders and their personal data live on your server, under your control. For that data you are the controller and we are not — we have no routine access to it, and if you ask us to look at it for a support case we act on your instructions. You will need your own privacy policy for your store.
This policy also does not cover the websites of other companies we link to, or the services you connect to your installation.
Account and contact details. Your name, your company name, email address, telephone number and billing address including city, state or region, postcode and country, and your GSTIN if you give us one for an Indian invoice. If you use the client portal, the credentials for that account.
Order and billing records. What you bought, the price, the currency, the tax applied, the invoice, the payment status and the reference the payment processor gives us. We do not receive or store your full card number, and card details never reach our servers.
Licence and validation data. The licence reference and the domain the licence is issued for. Each time an installation checks its licence with us we record the host name it reported, the IP address the request came from, the result of the check and the time. We also keep a last-seen IP address and a count of checks that came from a domain other than the licensed one.
Support and correspondence. The emails you send us, the enquiry and contact forms you submit, notes from support conversations, newsletter subscriptions, and job applications if you apply to us.
Website usage, if you agree to it. We use Google Analytics 4 to understand how the site is used. It collects information such as the pages you view, the site you arrived from, your approximate location, your device and browser, using cookies and similar technologies. None of that happens unless you accept analytics when we ask: the tag is not in the page until you do, and if you refuse, or accept and later change your mind, it is not loaded and nothing is collected. Section 4 explains how that works.
Your country, for pricing. Separately from analytics, and whatever you decide about it, we use your IP address to work out which country you are in so that we can show prices in the right currency. That lookup sends your IP address to a third-party geolocation service and to nowhere else; we do not store it for that purpose, and the short-lived cache that stops us asking twice is keyed on a one-way hash of the address rather than on the address itself.
Technical logs. Our servers keep ordinary logs of requests, including IP address, time and user agent, for security and troubleshooting.
For customers in the EU or the UK, the GDPR and UK GDPR require us to have a lawful basis for each purpose. Ours are:
Where we rely on a legitimate interest, we have considered whether it is outweighed by your rights, and you can object at any time using the contact details in section 9.
We are an Indian company, and our systems and their data are hosted in India — DigitalOcean’s Bangalore (blr1) region. Some of the providers listed above process data in other countries.
If you are in the EU, the EEA, the UK or Switzerland, your personal data will be transferred to India, which is outside those areas. India is not currently the subject of an adequacy decision by the European Commission or the UK government, so we rely on appropriate safeguards for the transfer: it is made under the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum where the United Kingdom is involved.
You can ask us for a copy of the safeguards we use by writing to the address in section 9.
We keep personal data only as long as we need it for the purpose we collected it for, or as long as the law requires.
If you are in India, the Digital Personal Data Protection Act 2023 gives you the right to ask for a summary of the personal data we hold about you and how we process it, to have it corrected, completed or updated, to have it erased where we no longer need it and no law requires us to keep it, to nominate someone to exercise your rights if you die or become incapacitated, and to have a grievance dealt with. Where we rely on your consent, you can withdraw it at any time.
Our Grievance Officer for the purposes of that Act is Anshul Agrawal, Director. Write to info@btosc.com with “Grievance” in the subject line. If you are not satisfied with our answer, you may complain to the Data Protection Board of India.
If you are in the EU, the EEA or the UK, the GDPR and UK GDPR give you the right of access to your personal data and to a copy of it, and the rights to rectification, to erasure, to restriction of processing, to data portability, and to object to processing carried out on the basis of a legitimate interest or for direct marketing. You may withdraw consent at any time without affecting processing already carried out. You also have the right to complain to your national supervisory authority, or to the Information Commissioner's Office in the UK.
We do not make decisions that produce legal effects for you, or similarly significant effects, by automated means alone, and we do not profile you for that purpose.
To exercise any of these rights, write to us using the details in section 9. We may need to verify your identity first. We will respond within thirty days, which is inside the one-month deadline the GDPR sets, and we will tell you if we need longer.
BTOSC sells to businesses, not to consumers, in the European Union and the United Kingdom, and has not appointed a representative under Article 27 of the GDPR or the UK GDPR.
We protect your data with encryption in transit, cryptographically signed licence keys, access controls on our systems and restricted administrative access. No system is completely secure, but if a breach happens that is likely to put you at risk we will notify you and the relevant authority as the law requires.
Our services are for businesses and we do not knowingly collect personal data from children.
We may update this policy. The date at the top of this page shows when it last changed, and we will tell you about a material change by email or on this site.
To contact us about privacy, or to exercise any right in section 8: legal@btosc.com, which is the mailbox we read for privacy and legal correspondence. By post: BTOSC Infotech Pvt Ltd, Bhagwati Market, Gali Peepal Mahadev, Hauz Quazi, Delhi 6, Delhi 110006, Delhi, India.