Legal

Privacy Policy

Last updated: September 2026

This policy explains how Taprobane Holdings (Private) Limited ("we," "us," "our") collects, uses, and protects information in connection with Infinity Portal (the "Service"). It applies to the businesses that sign up for the Service and to the individuals those businesses authorize to use it.

1. Information we collect

We collect information in a few different ways:

  • Account and business information you provide when signing up - business name, contact details, and the information needed to set up branches, warehouses, and users.
  • Operational data your business generates while using the Service - sales, purchases, inventory, financial records, and similar business data. This data belongs to your business; we process it to provide the Service.
  • Usage data - login activity, feature usage, and device/browser information, used to operate and improve the Service and to power its security and fraud-detection features.
  • Communications you send us directly, such as support requests.

2. How we use information

We use the information above to:

  • Provide, maintain, and support the Service;
  • Operate security and loss-prevention features described on our Security & Fraud Detection page;
  • Send notifications you or your business have configured (for example, receipt, SMS, WhatsApp, or Telegram alerts);
  • Improve and develop the Service; and
  • Meet legal and regulatory obligations.

3. How information is shared

We do not sell personal information. We share information only where necessary to operate the Service -- for example, with payment/card-terminal providers to process transactions you initiate, with messaging providers (SMS, WhatsApp, Telegram) to deliver notifications your business has configured, and with hosting infrastructure providers. We may also disclose information where required by law.

4. Data security

We apply technical and organizational safeguards appropriate to the sensitivity of the data involved, including access controls, authentication requirements (including two-factor authentication and role-based permissions), and a tamper-evident audit trail on system changes.

5. Data retention

We retain business and account data for as long as an account is active, and for a reasonable period afterward as needed for legal, accounting, or legitimate business purposes.

6. Your rights

You may request access to, correction of, or deletion of information we hold about you, subject to our legal and legitimate business retention needs, by contacting us using the details below.

7. Children's privacy

The Service is intended for business use and is not directed at children.

8. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by an updated date at the top of this page.

9. Contact

Questions about this policy can be sent to[email protected].