Privacy Policy & Data Security
How we protect your dealership inventory records, customer privacy, and billing data.
1. Introduction & Commitment to Privacy
Sydx Spares is committed to protecting the privacy and proprietary business data of automobile dealerships, tractor showrooms, and auto-parts retailers. This Privacy Policy outlines how we collect, store, process, and safeguard your data in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act, India) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
2. Information We Collect
When you register for a Sydx Spares workspace or use our platform, we collect:
- Dealership Identity: Business name, registered address, GSTIN number, logo, and authorized dealership brand details.
- Owner & Counter Staff Credentials: Full name, verified mobile number, administrative email address, and encrypted authentication tokens.
- Operational Catalog & Billing Data: Spare part numbers, descriptions, stock quantities, dealer cost prices, retail selling prices, supplier contacts, and customer sales invoices.
- Technical Security Telemetry: IP addresses, browser user agent, login timestamps, and Cloudflare Turnstile bot verification tokens to defend against brute-force attacks.
3. How We Use & Process Your Data
Your business information is strictly used for operational purposes:
- Provisioning and maintaining your dedicated multi-tenant workspace.
- Generating GST-compliant A4 billing invoices and dispatching 1-click WhatsApp customer receipts.
- Calculating dealership KPIs, dead capital ageing analytics, ABC Pareto matrix, and automated purchase recommendations.
- Transmitting transactional notifications, payment receipts, and password recovery links via Resend email infrastructure.
4. Zero Third-Party Selling Guarantee
We never sell, monetize, rent, or trade your dealership data to third-party advertisers, OEM manufacturers, or competitors under any circumstances. Your inventory counts, margins, and sales volumes remain your exclusive commercial trade secret.
5. Data Security & Encryption Standards
- PostgreSQL Row-Level Security (RLS): Universal `tenant_id` scoping prevents any cross-tenant data leakage.
- Encryption in Transit & At Rest: All web traffic is strictly encrypted using TLS 1.3 / HTTPS. Database storage volumes are encrypted with AES-256.
- Payment Safety: We do not store full credit card numbers or UPI PINs on our servers. All transactions are securely routed through PCI-DSS Level 1 certified gateways (Razorpay).
6. Your Rights (Access, Portability & Deletion)
As a registered subscriber, you have the right to access, rectify, or download your entire inventory and billing database via CSV export. Upon account termination, you may request complete permanent purging of your tenant workspace from our cloud database.