Privacy

Your shop’s data is yours.

Plainly what we collect, why we need it, and who else ever sees it. No dark patterns, no selling your customer list.

Last updated 5 September 2026

Who we are

Overall Retailer CRM (“Overall”, “we”) is retail management software for independent Indian shops. This policy covers the Overall web application and the marketing site you are reading now.

Two different roles matter throughout this page. For your own account details we decide what is collected and why. For the customer and sales records you enter into Overall, you decide — we only hold and process them so the software works for you.

What we collect

Your account

  • Name, email address, and phone number
  • A password, stored only as a bcrypt hash — never in a form we can read
  • If you sign in with Google: your Google account identifier, email, and name. We never receive your Google password.

Your business

  • Business name, type, and category
  • PAN, and GSTIN if you provide one
  • Business address, city, state, and pincode

PAN and GSTIN are collected because GST-compliant invoicing requires them. They are not used for anything else and are never shared for marketing.

The records you create

  • Your customers’ names, phone numbers, addresses, and purchase history
  • Products, stock levels, suppliers, and pricing
  • Orders, invoices, quotations, payments, and ledger entries
  • Photographs you upload of your products

Technical

  • Server logs including IP address, browser type, and the pages requested
  • Timestamps of sign-in attempts, kept to detect abuse

AI product photos and descriptions

When you use the AI photoshoot feature, the product photograph you selected and the product details you entered are sent to Google’s Gemini API so it can generate a new image and written description. This is the only feature that sends your content to a third party for processing.

  • Nothing is sent unless you press Generate. The feature is never automatic.
  • Your customer records, orders, and invoices are never sent to the AI service — only the product photo and the product fields.
  • The generated image and text are stored in your own store’s data and shown only to you until you choose to use them.

Google processes this content under its own terms. If you would rather not have a photo leave our servers, do not use the AI feature — every other part of Overall works without it.

Who else touches your data

We do not sell your data, and we do not share it for advertising. We use a small number of service providers, each for one specific job:

  • Hostinger — hosting and database. All of your data lives here.
  • Google — sign-in with Google, and the Gemini API for the AI feature described above.
  • Razorpay — payment processing when you buy AI credits. Card and UPI details go directly to Razorpay; we never see or store them.
  • Email delivery — for verification and password-reset messages only.

We may also disclose data where the law requires it, or to protect the safety and rights of our users.

Cookies

Overall uses cookies only to keep you signed in and safe. There are no advertising or tracking cookies.

  • A sign-in cookie that keeps your session active. It is httpOnly, so scripts in your browser cannot read it.
  • A security token used to verify that requests genuinely came from you, and not from another site acting in your name.

Clearing these cookies signs you out. Nothing else depends on them.

What stays on your own device

So the counter keeps working when the internet does not, Overall stores some information in your browser:

  • A copy of your product catalogue, so you can still ring up a sale offline
  • Sales made while offline, held until they can be uploaded
  • An identifier for this device, used to number offline invoices without collisions

This never leaves your device except as the ordinary sale data it represents, uploaded to your own account when the connection returns. Clearing your browser storage removes it — along with any sale that had not yet been uploaded, so let the queue empty first.

How long we keep it

Your business records are kept for as long as your account is open, because they are your books — invoices and ledgers you may be legally required to retain.

If you close your account, tell us and we will delete your data within 30 days, except where we are required to retain records under Indian tax law. Server logs are kept for a short period for security and troubleshooting.

Your rights

Under India’s Digital Personal Data Protection Act, 2023, you may ask us to:

  • Tell you what personal data we hold about you
  • Correct anything inaccurate
  • Delete your data, subject to the retention rules above
  • Nominate someone to exercise these rights if you cannot

Write to contact@overall.co.in and we will respond within 30 days.

If your customers ask you to remove their details, you can do that yourself inside Overall — those records are yours to manage.

Security

Traffic is encrypted with HTTPS. Passwords are hashed with bcrypt. Sign-in endpoints are rate-limited, sessions use httpOnly cookies, and every write is checked against a cross-site request token.

No system is perfect. If you find a security problem, please tell us at contact@overall.co.in before disclosing it publicly, and we will work with you to fix it.

Changes to this policy

If we change how we handle your data in a way that matters, we will update the date at the top of this page and tell you inside the app before the change takes effect.

A note on this document. It describes honestly how Overall works today, but it has not been reviewed by a lawyer. Because Overall handles PAN, GSTIN and your customers’ personal data, have a legal professional check it against the DPDP Act before you rely on it commercially.

Questions about your data?

Write to contact@overall.co.in — a person reads it.

Read the Terms