Privacy Policy
1. Who we are and who this covers
TechCity Inventory (the “Service”) is an online inventory and business-management service, operated by TechCity in Bangladesh (“TechCity”, “we”, “us”). Businesses (each a “Business”) use it to track stock across their warehouses and shops, record purchases and sales (including at the point of sale), manage customers, suppliers, dues, repairs, accounts, VAT and staff, and see reports.
- Business owners and their team — for the accounts you use to sign in and work in the Service, TechCity decides how that information is used.
- People a Business keeps records about — its customers, suppliers and employees. The Business decides what it records about you and why, and TechCity processes that information on the Business’s behalf to provide the Service. If you receive an invoice, payment link, account statement, repair update or reminder from a Business, contact that Business first about your information.
2. Information we collect
| About | What | Where it comes from |
|---|---|---|
| Owner and team accounts | Name, email, phone, profile photo, password (stored only as a one-way hash), your role and which locations you may work in, language preference; if you use Google, the name and email address on your Google account. | You, when you sign up or are invited; Google, if you choose to sign in with it. |
| Business profile and plan | Business name, contact details, country, currency, time zone, logo, locations, the plan you are on and your subscription payments. | The Business. |
| Business records | Products, variants, barcodes, prices and costs, stock at each location, purchases, sales and receipts, transfers and adjustments, expenses and their receipts, accounting entries, VAT records, reports, and spreadsheets imported into the Service. | The Business and its team. |
| A Business’s customers and suppliers | Name, phone, email, address, invoices and payments, amounts owed and account statements; for repairs, the device, the reported fault, the job’s status and your approval of quotes. | The Business; you, if you approve a repair quote or pay through a link the Business sends. |
| A Business’s employees | Where a Business uses the HR features: employee details, attendance, leave and payroll. | The Business. |
| Payments | Payment method, amount, status and the gateway’s reference number. We never receive or store full card numbers — those are entered on the payment provider’s own pages. | The payment gateway used. |
| Messages | The phone number or email address, content and delivery status of messages the Service sends, such as payment reminders, payment links, repair updates and account emails. | The Service, when a Business or the Service sends a message. |
| Technical and activity | IP address, browser and device type, pages and times in server and security logs; and, inside each Business, an activity log of which team member changed what. | Your browser and the Service, automatically. |
We do not use advertising trackers, analytics services or social-media pixels in the Service, and we do not sell personal information.
3. Sign in with Google
If you choose “Sign in with Google”, Google tells us the name and email address on your Google account and whether Google has verified that email. We use these only to find your account, or to create one when you sign up, and to sign you in. We do not receive your Google password, and we do not request access to your Gmail, contacts, Drive, calendar or any other Google data.
TechCity’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google account data for advertising, do not sell it, and do not share it except as needed to provide sign-in or as required by law. You can remove TechCity Inventory’s access at any time from your Google Account’s security settings.
4. How we use information
- To provide the Service: keep stock, sales, purchases, accounts and reports up to date for each Business, show its team live changes, and let its customers view statements, pay and follow repairs.
- To send the messages the Service needs: account and security emails, subscription reminders, and the reminders, payment links and updates a Business chooses to send its customers.
- To bill for subscriptions and keep each Business within its plan.
- To keep the Service secure: detect abuse and fraud, limit sign-in attempts, investigate problems and keep logs.
- To meet legal, tax and accounting obligations, and to enforce our Terms & Conditions.
5. Who we share it with
We share personal information only with the service providers below, only what each needs for its job, or when the law requires it.
| Provider | Why | What they receive |
|---|---|---|
| Our server hosting provider | Runs the Service’s servers, databases, file storage and backups. | All data stored in the Service, under contract. |
| Sign in with Google, if you use it; fonts on these policy pages. | The sign-in request (Google sends us your name and email); your IP address when fonts load. | |
| Payment gateways — bKash, Nagad, SSLCommerz, Stripe | To take subscription payments, and payments through links a Business sends with a gateway it has connected. | Amount and reference, and the contact details the gateway needs. |
| SMS providers — SSL Wireless, BulkSMSBD, Alpha SMS, Twilio | To deliver text messages, through the Service’s provider or one a Business connects. | The phone number and the message. |
| Email delivery provider | To deliver emails from the Service. | The email address and the message. |
| Error monitoring (Sentry) | To find and fix faults in the Service. | Technical details of errors; it is set up not to receive IP addresses, cookies or user details. |
| Authorities | When required by law or a valid legal request, or to protect people’s safety or rights. | Only what is required. |
Each provider handles data under its own terms and privacy policy. If TechCity is ever merged or sold, information may pass to the new owner under this policy.
6. Cookies and browser storage
We only store what the Service needs to work. Nothing is used for advertising or cross-site tracking.
- Sign-in (
sp_token) — keeps you signed in on this device until you sign out, for up to 30 days. - Language and theme (
sp_lang,sp_theme) — remember English or Bangla, and light or dark. - Pricing currency (
sp_currency) — remembers the currency you chose on the pricing page. - Sign-up (
signup-ref,google-signup) — keep an invite code, or a Google sign-up in progress, until you finish creating your account; the Google one is cleared when you close the tab. - Google’s sign-in button — Google may set its own cookies when it shows the button, under Google’s privacy policy.
Clearing your browser’s site data removes them, and you will be signed out.
7. How long we keep it
- Accounts and Business records — while the account is open. When a Business’s account is closed, we delete or anonymise its data within 90 days, except what we must keep by law.
- Invoices, payments and accounting records — as long as tax and accounting law requires, which can be several years.
- Imported spreadsheets — the uploaded file is deleted within a day of the import; the records it created stay with the Business.
- Server and security logs — normally up to 90 days.
- Backups — taken nightly and kept for about two weeks before being deleted.
8. Security
All traffic is encrypted with HTTPS. Passwords are stored only as salted hashes. Payment-gateway credentials that Businesses connect are encrypted. Expense receipts and imported files are stored privately and can be opened only by signed-in team members allowed to see them. Each Business’s data is kept separate from every other Business’s, and inside a Business access is limited by role and location. Sign-in attempts are rate-limited and an account is locked for a while after repeated wrong passwords; sign-ins expire after 30 days and are cancelled everywhere when a password is changed. The database is reachable only from the Service’s own servers. No system is perfectly secure; if a breach affects your personal information, we will notify you and the relevant authorities as the law requires.
9. Your choices and rights
- See and correct your details in your profile at any time.
- Ask for a copy of your personal information, or for it to be deleted — subject to what we must keep by law. Businesses can also export their records and reports from the app.
- Stop reminders and other messages from a Business by asking that Business.
- Withdraw Google access from your Google Account at any time.
Customers, suppliers and employees of a Business: for information a Business holds about you, contact that Business first; we will help it answer you. Everyone else: email [email protected]. We reply within 30 days and may need to confirm who you are first.
10. Where data is processed
The Service’s servers are operated by our hosting provider, and some providers above (such as Google, Stripe, Twilio and Sentry) process data in other countries. When information leaves Bangladesh we rely on those providers’ contractual and security commitments to protect it.
11. Children
The Service is a business tool and is not directed to children. Accounts are for adults able to enter contracts on behalf of a Business. We do not knowingly collect information from children under 13; if you believe a child has given us personal information, contact us and we will delete it.
12. Changes and contact
We may update this policy as the Service changes. The date at the top shows the latest version; for significant changes we will also tell Businesses by email or in the app before they take effect.
Questions or requests: TechCity, Bangladesh — [email protected].
