Legal

Privacy Policy

Last updated: 29 June 2026

1. Introduction & scope

Yocto POS is a cloud-based, online-only point-of-sale (POS) service for restaurants and retail businesses in India. This Privacy Policy explains how we collect, use, share, and protect personal data when you visit our website, create an account, and use the Yocto POS service (the “Service”). Because the Service is delivered over the internet with real-time synchronisation, the data you and your team enter is stored and processed on our cloud infrastructure. By using the Service, you agree to the practices described here.

2. Information we collect

  • Account & business details: your name, mobile number, email address, and information about your business and outlets (such as business name, outlet names, addresses, and GST details) provided when you register or manage your account.
  • Operational data you enter: the content you and your staff add while running your business, including menus and catalogue items, orders and transactions, customer and loyalty records, and staff accounts and roles.
  • Billing information: subscription and payment details. Payments are processed by our third-party payment processor, Chargebee. Yocto POS does not store full card numbers; sensitive card data is handled by Chargebee.
  • Usage, device & log data: information automatically collected when you use the Service, such as IP address, browser and device type, pages and features used, timestamps, and diagnostic logs, including data collected through cookies and similar technologies.
  • Contact-form submissions: the name, email address, mobile number, and message you provide when you contact us through the website.

3. How we use your information

We use the information we collect to:

  • operate, maintain, and provide the Service to you and your outlets;
  • process subscriptions, add-ons, invoices, and payments;
  • provide customer support and respond to your requests;
  • ensure security, prevent fraud, and protect the integrity of the Service;
  • analyse usage to improve and develop our products and features;
  • comply with applicable laws and legal obligations; and
  • send marketing or promotional communications, only where you have given consent and subject to your right to opt out at any time.

4. Legal bases & your consent

We process personal data in accordance with the Digital Personal Data Protection Act, 2023 (the “DPDP Act”). Where required, we rely on your consent, which you may withdraw at any time. We also process certain data for legitimate uses permitted under the DPDP Act, such as performing our contract with you, providing the Service you have requested, and meeting legal obligations. Withdrawing consent will not affect processing carried out before the withdrawal and may limit your ability to use parts of the Service.

5. Sharing & sub-processors

We share personal data only as needed to run the Service, and with sub-processors who act on our instructions, including:

  • Chargebee, for subscription billing and payment processing;
  • cloud hosting and infrastructure providers that store and run the Service;
  • email and SMS delivery providers for transactional and account messages;
  • analytics providers that help us understand and improve usage.

We do not sell your personal data. We may also disclose information where required by law, to enforce our agreements, or to protect the rights, safety, and property of Yocto POS, our customers, or others.

6. Data retention

We retain personal and operational data for as long as your account is active and as needed to provide the Service. After your subscription ends, we retain data for a reasonable period to allow account reactivation, to resolve disputes, and to meet legal, tax, and accounting requirements, after which it is deleted or anonymised. You may request deletion as described in “Your rights” below.

7. Security

We implement reasonable technical and organisational measures to protect personal data, including encryption in transit, access controls, and role-based permissions. Sensitive actions in the Service can be protected by an App Password. While we work hard to safeguard your data, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your rights

Subject to the DPDP Act, you have the right to:

  • access the personal data we hold about you;
  • request correction and completion of inaccurate or incomplete data;
  • request erasure of your personal data;
  • withdraw consent you have previously given; and
  • seek grievance redressal regarding our handling of your data.

To exercise any of these rights, contact us at hello@yoctopos.in. We may need to verify your identity before acting on a request.

9. Cookies & similar technologies

We use cookies and similar technologies to keep you signed in, remember your preferences, secure the Service, and measure usage. You can control cookies through your browser settings; disabling some cookies may affect how the website and Service function.

10. Children

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from children, and we process any children’s data only in accordance with the requirements of the DPDP Act.

11. Data location / international transfers

Your data is hosted on cloud infrastructure and may be processed by sub-processors, including Chargebee, whose facilities may be located outside India. Where data is transferred across borders, we take reasonable steps to ensure it is handled consistently with this policy and applicable Indian law.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will revise the “Last updated” date above and, where appropriate, notify you. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

13. Contact & Grievance Officer

If you have questions about this policy, wish to exercise your rights, or want to raise a grievance, contact our Grievance Officer at hello@yoctopos.in. This Privacy Policy should be read together with our Terms of Service.