Back to BTOSC

Privacy policy

What BTOSC collects, why, where it lives and how long we keep it. Self-hosted means your customers' data stays on your server — this covers our records only.

Last updated · 7 August 2026

This policy explains what personal data BTOSC Infotech Pvt Ltd collects about you, why we collect it, who we share it with and what you can ask us to do about it. It covers our website, our client portal, our licence validation service and our dealings with you as a customer or an enquirer.

1. Who we are, and what this policy does not cover

BTOSC Infotech Pvt Ltd, registered office Bhagwati Market, Gali Peepal Mahadev, Hauz Quazi, Delhi 6, Delhi 110006, Delhi, India, is the controller of the personal data described here. That means we decide why and how it is used.

This policy does not cover the data inside your own SnapCart installation. Our software is self-hosted: your store, your customers, their orders and their personal data live on your server, under your control. For that data you are the controller and we are not — we have no routine access to it, and if you ask us to look at it for a support case we act on your instructions. You will need your own privacy policy for your store.

This policy also does not cover the websites of other companies we link to, or the services you connect to your installation.

2. What we collect

Account and contact details. Your name, your company name, email address, telephone number and billing address including city, state or region, postcode and country, and your GSTIN if you give us one for an Indian invoice. If you use the client portal, the credentials for that account.

Order and billing records. What you bought, the price, the currency, the tax applied, the invoice, the payment status and the reference the payment processor gives us. We do not receive or store your full card number, and card details never reach our servers.

Licence and validation data. The licence reference and the domain the licence is issued for. Each time an installation checks its licence with us we record the host name it reported, the IP address the request came from, the result of the check and the time. We also keep a last-seen IP address and a count of checks that came from a domain other than the licensed one.

Support and correspondence. The emails you send us, the enquiry and contact forms you submit, notes from support conversations, newsletter subscriptions, and job applications if you apply to us.

Website usage, if you agree to it. We use Google Analytics 4 to understand how the site is used. It collects information such as the pages you view, the site you arrived from, your approximate location, your device and browser, using cookies and similar technologies. None of that happens unless you accept analytics when we ask: the tag is not in the page until you do, and if you refuse, or accept and later change your mind, it is not loaded and nothing is collected. Section 4 explains how that works.

Your country, for pricing. Separately from analytics, and whatever you decide about it, we use your IP address to work out which country you are in so that we can show prices in the right currency. That lookup sends your IP address to a third-party geolocation service and to nowhere else; we do not store it for that purpose, and the short-lived cache that stops us asking twice is keyed on a one-way hash of the address rather than on the address itself.

Technical logs. Our servers keep ordinary logs of requests, including IP address, time and user agent, for security and troubleshooting.

3. Why we use it, and our lawful basis

For customers in the EU or the UK, the GDPR and UK GDPR require us to have a lawful basis for each purpose. Ours are:

  • To sell and deliver the software, issue licence keys, invoice you and provide support — because it is necessary to perform our contract with you, or to take steps before entering one.
  • To validate licences and detect unlicensed copies — because it is necessary to perform our contract and because we have a legitimate interest in protecting our software from unauthorised use.
  • To keep accounting, tax and invoicing records — because we have a legal obligation to do so under Indian law.
  • To keep our systems and your account secure, and to prevent fraud and abuse — because we have a legitimate interest in doing so.
  • For website analytics — with your consent, which is the only basis that will do for it. We ask before anything is loaded or stored, refusing takes exactly one click just as accepting does, and you can withdraw at any time from any page. Section 4 sets out what we ask and what withdrawing does.
  • For marketing emails such as our newsletter — with your consent, which you can withdraw at any time. Where we email an existing customer about a product they already have, we rely on our legitimate interest, and every message has an unsubscribe link.
  • To defend or bring legal claims — because we have a legitimate interest in doing so.

Where we rely on a legitimate interest, we have considered whether it is outweighed by your rights, and you can object at any time using the contact details in section 9.

4. Cookies and what is stored on your device

We use cookies and similar storage for two things: to make the site and the client portal work — remembering that you are signed in, your language, your currency and whether you prefer the light or dark theme — and, if you agree to it, to measure how the site is used through Google Analytics.

The first kind does not use cookies at all. It is kept in your browser's own local storage, on your device; unlike a cookie it is not attached to requests and is not sent to us, and it is not used to recognise you across sites or to build a profile. It is strictly necessary for a service you have asked for, so we do not ask for consent to it, and it keeps working exactly as it does now whatever you decide about analytics.

The second kind is Google Analytics, and it is the only thing on this site that sets cookies. It is off until you turn it on. When you first arrive you are asked, in a banner, whether we may use it; accepting and refusing are one click each, side by side, with nothing pre-selected and nothing assumed from your carrying on browsing. Until you answer, the Google tag is not requested, no analytics cookie is set and nothing is sent to Google. If you refuse, the tag is never loaded at all.

Your answer is stored on your device, in the same local storage as the settings above, with the date you gave it and a version number for the question it answered. We keep no record of it on our servers, which means it is remembered per browser and per device: clearing your browser's storage, or using another browser, means you will be asked again. If we ever widen what we are asking for — another measurement tool, or using analytics for advertising — the version changes and everyone is asked afresh rather than being held to an answer they gave to a narrower question.

You can change your mind at any time using the cookie settings button in the bottom corner of any page, which brings the same banner back. Withdrawing does not merely record a preference: we instruct Google's tag to stop using analytics storage, set Google's own opt-out flag for our property, remove the script from the page, and expire the _ga cookies already on your device. What we cannot do from here is unsend measurements that were already sent while you had accepted, or delete what Google holds — for that, use the rights in section 8 and Google's own controls.

You can also block or delete cookies in your browser, and you can opt out of Google Analytics on every site using Google's own browser add-on.

5. Who we share it with

We do not sell your personal data, and we do not share it for anyone else's advertising. We share it only with the following:

  • Payment processors. Razorpay for payments in Indian rupees and PayPal for payments in US dollars. They process your payment details under their own privacy policies and as controllers in their own right.
  • Email delivery. Our transactional and notification email is sent over SMTP through Google Workspace, which carries our transactional email., which handles your email address and the content of those messages on our behalf.
  • Analytics. Google, as the provider of Google Analytics 4.
  • Geolocation. The country lookup that decides which currency to show you receives your IP address for the moment it takes to answer. It is told nothing else about you, and we keep no record of the lookup.
  • Hosting and infrastructure. DigitalOcean, in its Bangalore (blr1) region in India., which hosts our website, our database and our licence validation service.
  • Professional advisers. Our accountants, auditors and lawyers, where they need it to advise us.
  • Authorities. Where we are required to disclose by law, by a court, or by a regulator with jurisdiction over us.
  • A buyer. If we sell or reorganise our business, the buyer, subject to this policy continuing to apply.

6. Where your data is held, and international transfers

We are an Indian company, and our systems and their data are hosted in India — DigitalOcean’s Bangalore (blr1) region. Some of the providers listed above process data in other countries.

If you are in the EU, the EEA, the UK or Switzerland, your personal data will be transferred to India, which is outside those areas. India is not currently the subject of an adequacy decision by the European Commission or the UK government, so we rely on appropriate safeguards for the transfer: it is made under the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum where the United Kingdom is involved.

You can ask us for a copy of the safeguards we use by writing to the address in section 9.

7. How long we keep it

We keep personal data only as long as we need it for the purpose we collected it for, or as long as the law requires.

  • Account, licence and contract records: for as long as your licence or subscription is live, and then for three years — except where the financial-record period below is longer, in which case that one governs.
  • Invoices, payment records and tax documents: eight years from the end of the financial year they relate to. This one is not ours to choose — section 128 of the Companies Act 2013 requires eight years, and section 36 of the CGST Act 2017 separately requires seventy-two months from the due date of the relevant annual return, which the eight years covers.
  • Licence validation logs, including host names and IP addresses: twenty-four months, after which the individual check records are deleted. The summary we hold against the licence itself — when it was last seen, the last host and IP address it reported, and how many mismatched checks there have been — is kept for as long as the licence record.
  • Support correspondence and enquiries: three years from our last exchange with you.
  • Newsletter subscriptions: until you unsubscribe, and then a minimal record so we do not email you again.
  • Job applications: twelve months from the decision, so that we can come back to you about a later role, unless you ask us to delete them sooner.
  • Server and security logs: twelve months.

8. Your rights

If you are in India, the Digital Personal Data Protection Act 2023 gives you the right to ask for a summary of the personal data we hold about you and how we process it, to have it corrected, completed or updated, to have it erased where we no longer need it and no law requires us to keep it, to nominate someone to exercise your rights if you die or become incapacitated, and to have a grievance dealt with. Where we rely on your consent, you can withdraw it at any time.

Our Grievance Officer for the purposes of that Act is Anshul Agrawal, Director. Write to info@btosc.com with “Grievance” in the subject line. If you are not satisfied with our answer, you may complain to the Data Protection Board of India.

If you are in the EU, the EEA or the UK, the GDPR and UK GDPR give you the right of access to your personal data and to a copy of it, and the rights to rectification, to erasure, to restriction of processing, to data portability, and to object to processing carried out on the basis of a legitimate interest or for direct marketing. You may withdraw consent at any time without affecting processing already carried out. You also have the right to complain to your national supervisory authority, or to the Information Commissioner's Office in the UK.

We do not make decisions that produce legal effects for you, or similarly significant effects, by automated means alone, and we do not profile you for that purpose.

To exercise any of these rights, write to us using the details in section 9. We may need to verify your identity first. We will respond within thirty days, which is inside the one-month deadline the GDPR sets, and we will tell you if we need longer.

BTOSC sells to businesses, not to consumers, in the European Union and the United Kingdom, and has not appointed a representative under Article 27 of the GDPR or the UK GDPR.

9. Security, changes and how to contact us

We protect your data with encryption in transit, cryptographically signed licence keys, access controls on our systems and restricted administrative access. No system is completely secure, but if a breach happens that is likely to put you at risk we will notify you and the relevant authority as the law requires.

Our services are for businesses and we do not knowingly collect personal data from children.

We may update this policy. The date at the top of this page shows when it last changed, and we will tell you about a material change by email or on this site.

To contact us about privacy, or to exercise any right in section 8: legal@btosc.com, which is the mailbox we read for privacy and legal correspondence. By post: BTOSC Infotech Pvt Ltd, Bhagwati Market, Gali Peepal Mahadev, Hauz Quazi, Delhi 6, Delhi 110006, Delhi, India.

Need an answer today?

Ask us directly — we answer licensing questions in writing.