Back to Home

Privacy Policy & Data Processing Agreement

Last Updated: July 2026

At RetailBrain, protecting your data and the data of your employees and customers is our highest priority. This Privacy Policy outlines how we collect, use, process, and protect your information when you use our Point of Sale and AI Forecasting platform ("Service").

1. Our Role: Data Processor

1.1 When processing Personally Identifiable Information (PII) submitted to our platform by your Organization (including staff names, shift logs, customer purchase histories, and contact information), RetailBrain acts strictly as a Data Processor. 1.2 Your Organization is the Data Controller. You are solely responsible for ensuring you have obtained explicit consent and established a lawful basis under applicable laws (e.g., the Digital Personal Data Protection Act, 2023) to collect and process this data using our Service.

2. Information We Collect

2.1 Account Information: Names, emails, and authenticated profiles used to access the platform. 2.2 Operational Data: Inventory levels, supplier details, sales transactions, and waste logs. 2.3 Usage Data & Telemetry: System logs, IP addresses, browser types, and device identifiers necessary to secure the platform and audit Role-Based Access Control (RBAC) violations.

3. How We Use AI and LLMs

3.1 The AI Advisor: We utilize third-party Large Language Models (LLMs) to generate business insights. 3.2 Data Anonymization: We do not send raw PII (like customer names, employee shift logs, or credit card numbers) to these external LLMs. We only transmit anonymized inventory schemas, product velocity metrics, and aggregate sales data required to generate forecasts. 3.3 No Model Training: RetailBrain strictly prohibits our third-party LLM partners from using your operational data to train their foundational models. Your data remains your data.

4. Data Security and Isolation

4.1 Multi-Tenant Security: RetailBrain utilizes strict multi-tenant isolation. Your operational data is cryptographically protected and logically segregated. 4.2 Role-Based Isolation: Our application-level security engine ensures that Store Managers and Cashiers cannot access data across physical branch boundaries (the "Store Scope"), while Organization Admins retain global visibility.

5. Cookies and Local Storage

5.1 Strictly Necessary Cookies: We use cookies and local storage to maintain session states and enforce platform security. These are essential for the platform to function securely and cannot be opted out of. 5.2 Analytics: We use anonymized analytics to monitor system performance. We do not use third-party marketing trackers on the core dashboard.

6. Data Breach Notification SLA

6.1 Incident Response: In the unlikely event of a security breach that exposes your unencrypted data, RetailBrain commits to notifying the Organization Admin within 48 hours of confirming the breach. 6.2 Remediation: We will provide full transparency into the scope of the breach and the immediate remediation steps taken to secure the platform.

7. Sub-processors

7.1 Third-Party Vendors: We engage third-party sub-processors to provide necessary infrastructure and services (e.g., cloud hosting providers, payment gateways, and AI inference engines). 7.2 Data Protection Agreements: All sub-processors are vetted for strict compliance with the Digital Personal Data Protection Act, 2023, and are bound by Data Processing Agreements (DPAs) that mandate security standards equivalent to or greater than our own.

8. Cross-Border Data Transfers

8.1 International Processing: To ensure global availability, your data may be transferred to and processed in jurisdictions outside India where our sub-processors maintain facilities, provided such transfers are not restricted by the Central Government of India under the DPDP Act. 8.2 Data Localization: Core financial transaction records and payments data processed via our payment gateways are maintained within India in compliance with RBI guidelines on payment data localization.

9. Data Retention and Deletion

9.1 Active Subscriptions: Data is retained for the lifetime of your active subscription. 9.2 Termination: Upon termination of your subscription, we will retain your data for a grace period of 30 days to allow for export. After this period, your data will be permanently and irrevocably destroyed from our active databases.


For data subject access requests (DSARs) or privacy inquiries, please contact our Data Protection Officer at privacy@retailbrain.online.