HRMS Face Attendance App
This privacy policy applies to the HRMS - Face Attendance app (herein referred to as "Application") created by Bambus Technologies LLP as a Commercial service.
1. Information Collection and Use
The Application collects information when you download and use it.
Camera Access: The Application requires access to your device's camera to perform real-time face detection and recognition for attendance purposes.
Biometric Data: The Application processes facial descriptors (mathematical representations of faces). This data is used solely for identifying employees and marking attendance.
Data Storage: Facial images and descriptors are stored [select one: locally on your device / securely on our company servers] and are not shared with any third-party marketing agencies.
Location information: With the user’s permission, we may collect precise or approximate location to support features such as branch identification, attendance, delivery, service-location confirmation, or location-based security.
We do not collect background location unless this is expressly disclosed in the application, necessary for a feature requested by the user, and permitted by the user.
2. Third-Party Access
Only aggregated, anonymized data is periodically transmitted to external services to help us improve the Application. We use third-party libraries such as:
Capacitor Plugins (for hardware access)
Face-API.js (for facial recognition processing)
3. Data Retention Policy
We will retain User Provided data for as long as you use the Application. If you'd like us to delete User Provided Data, please contact us at info@bambustechnologies.in
4. Children
The Application is not intended for children under the age of 13. We do not knowingly collect personal data from children.
5. Security
We provide physical, electronic, and procedural safeguards to protect information we process and maintain.
6. Consent
By using the Application, you are consenting to our processing of your information as set forth in this Privacy Policy.
7. Contact Us
If you have any questions regarding privacy while using the Application, please contact us via email at info@bambustechnologies.in
Bambus POS
Effective date: 06-08-2026
Last updated: 06-08-2026
Bambus Technologies LLP (“Company,” “we,” “us,” or “our”) operates the “Bambus POS” point-of-sale application and related websites, cloud services, and support services (collectively, the “Services”).
This Privacy Policy explains what information we collect, why we collect it, how we use and disclose it, how long we retain it, and the choices available to users.
By creating an account or using the Services, you acknowledge the practices described in this Privacy Policy.
## 1. Scope of this policy
This policy applies to business owners, administrators, employees, cashiers, and other authorized users who access the Services.
The application is intended for business use. It is not intended for children or for personal household use.
Businesses using our Services may enter information about their customers, employees, suppliers, products, and transactions. In those circumstances, the business generally determines why that information is processed, and we process it to provide the Services.
## 2. Information we collect
Depending on the features you use, we may collect the following categories of information.
### 2.1 Account and business information
We may collect:
* Name;
* Business or trading name;
* Email address;
* Mobile number;
* Business address;
* Tax registration information, such as GSTIN or other applicable identifiers;
* Username, user role, branch, and employee information;
* Subscription and account status; and
* Information provided when contacting customer support.
### 2.2 Authentication information
We collect information necessary to authenticate users, including:
* Registered email address or mobile number;
* One-time-password request and verification records;
* Login timestamps;
* Authentication tokens;
* IP address; and
* Security and failed-login records.
We use one-time passwords to authenticate users. We do not ask users to disclose an email account password to us.
### 2.3 Tenant and technical provisioning information
When a business signs up, our systems may create a dedicated tenant, database, workspace, and domain or subdomain within our SaaS infrastructure.
For this purpose, we may process:
* Tenant and database identifiers;
* Business name and account administrator details;
* Assigned domain or subdomain;
* Provisioning status;
* Server and application logs; and
* Configuration and integration settings.
### 2.4 POS and business-operational information
The Services may process information entered by authorized users, including:
* Products, categories, prices, taxes, discounts, and inventory;
* Sales, returns, refunds, quotations, orders, and invoices;
* Branch, warehouse, register, and shift information;
* Supplier and purchase information;
* Cash movement and payment-method records;
* Employee attendance, commission, or sales information, if enabled;
* Customer names, phone numbers, email addresses, addresses, tax details, and purchase history;
* Notes and documents uploaded by authorized users; and
* Reports and business analytics generated from this information.
The information recorded depends on how the subscribing business configures and uses the Services.
### 2.5 Payment information
The application may record payment-related transaction information, such as:
* Payment method;
* Transaction amount;
* Payment status;
* Payment-provider reference number; and
* Refund or settlement status.
Where electronic payments are processed by an external payment provider, payment credentials are handled under that provider’s privacy and security terms.
**We do not intentionally store complete payment-card numbers, CVV codes, online-banking passwords, or UPI PINs.**
### 2.6 Device and usage information
We may automatically collect:
* Device type, manufacturer, and model;
* Operating-system and application version;
* Device or application identifiers;
* IP address and approximate network-derived location;
* Language and time-zone settings;
* Login, feature usage, and interaction records;
* Crash reports, diagnostics, and performance information; and
* Security, fraud-prevention, and audit logs.
### 2.7 Camera, photos, files, and documents
If enabled and permitted by the user, the application may access the camera, selected photos, or selected files to support functions such as:
* Scanning product barcodes or QR codes;
* Adding product or business images;
* Uploading invoices, receipts, or supporting documents; and
* Capturing documents needed for configured business processes.
We access only the information required for the feature selected by the user, subject to the permissions provided through the device.
### 2.8 Bluetooth and local-network information
The application may request access to Bluetooth or nearby devices to connect to compatible POS printers, barcode scanners, card readers, cash drawers, or other business hardware.
Local-network access may be used to discover or communicate with compatible devices. We do not use these permissions to track users for advertising.
### 2.9 Information from integrations
If a business connects a third-party service, we may receive information from that service as authorized by the business. Integrations may include payment providers, accounting services, delivery platforms, messaging services, analytics services, and Odoo modules.
The information received depends on the integration and permissions selected by the business.
## 3. How we use information
We use information to:
* Create, configure, and maintain business accounts and tenants;
* Provision databases and domains or subdomains;
* Authenticate users and deliver OTP messages;
* Process POS transactions and maintain business records;
* Manage products, inventory, customers, suppliers, invoices, payments, and reports;
* Synchronize information between authorized devices and cloud services;
* Provide subscribed features and integrations;
* Generate reports and operational analytics;
* Provide customer support and respond to requests;
* Send service-related and security communications;
* Monitor performance and correct technical problems;
* Detect fraud, misuse, unauthorized access, and security incidents;
* Maintain audit and transaction records;
* Enforce our agreements and protect legal rights;
* Comply with applicable legal, accounting, taxation, and regulatory obligations; and
* Improve the reliability, usability, and security of the Services.
We will not use personal or sensitive information for purposes materially different from those described in this policy without providing appropriate notice and obtaining consent where required.
## 4. Legal grounds for processing
Where applicable law requires a legal basis, we process information:
* To perform our contract with the subscribing business;
* With the user’s consent;
* To comply with legal obligations;
* To protect users, our Company, and the Services; and
* For legitimate business purposes, provided those interests are not overridden by applicable privacy rights.
A subscribing business is responsible for ensuring it has a lawful basis for entering customer, employee, supplier, and other third-party information into the Services.
## 5. How we disclose information
We may disclose information in the following circumstances.
### 5.1 Within the subscribing business
Information may be visible to the business owner, administrators, managers, and other authorized users according to assigned access rights.
### 5.2 Service providers
We may engage service providers for:
* Cloud hosting and database infrastructure;
* Domain and application hosting;
* OTP and transactional email delivery;
* Payment processing;
* Error monitoring and analytics;
* Customer support;
* Backup and disaster recovery; and
* Security and fraud prevention.
These providers are permitted to process information only as necessary to deliver the relevant services and subject to appropriate contractual obligations.
Our current material service providers include:
* Contabo
* RazorPay
### 5.3 Business-requested integrations
We disclose information to third-party applications when an authorized business administrator enables an integration or instructs us to transfer information.
### 5.4 Legal and safety purposes
We may disclose information when reasonably necessary to:
* Comply with applicable law, legal process, or a valid government request;
* Detect or prevent fraud, security threats, or unlawful activity;
* Protect the rights, property, or safety of users, the public, or our Company; or
* Establish, exercise, or defend legal claims.
### 5.5 Business transfers
If we are involved in a merger, financing, acquisition, restructuring, or sale of assets, information may be transferred as part of that transaction, subject to applicable law and appropriate confidentiality protections.
## 6. Sale of personal information and advertising
We do not sell users’ personal information.
We do not share personal information with advertising networks or use POS transaction information for targeted advertising.
## 7. Data retention
We retain information only for as long as reasonably necessary to:
* Provide the Services;
* Maintain transaction, tax, accounting, and audit records;
* Meet contractual and legal obligations;
* Resolve disputes;
* Prevent fraud and security incidents; and
* Enforce our agreements.
Account and tenant information is normally retained while the business account is active.
Following an account-deletion request, we will delete or anonymize eligible information within 30 days, unless it must be retained for legal, taxation, accounting, fraud-prevention, dispute-resolution, or security purposes.
Backup copies may remain for up to 7 additional days before being overwritten through our normal backup cycle. Information that must legally be retained will be isolated, access-restricted, and deleted when the applicable retention period ends.
A subscribing business may establish separate retention requirements for business records stored through the Services.
## 8. Data security
We use reasonable administrative, organizational, and technical measures designed to protect information, including, where appropriate:
* Encryption of information in transit;
* Access controls and role-based permissions;
* OTP-based authentication;
* Tenant and database separation;
* Security logging and monitoring;
* Restricted production-system access;
* Backups and recovery procedures; and
* Software and infrastructure maintenance.
No electronic system is completely secure. We cannot guarantee that unauthorized access, loss, misuse, or disclosure will never occur. Users must protect their devices and authentication details and promptly notify us of suspected unauthorized access.
## 9. International processing
Our Company and service providers may process information in countries other than the user’s country. Where required, we use appropriate contractual or legal safeguards for international transfers.
Our primary hosting location is Europe.
## 10. User choices and rights
Depending on applicable law and the relationship with the subscribing business, a person may have the right to:
* Access personal information;
* Correct inaccurate or incomplete information;
* Request deletion;
* Withdraw consent;
* Object to or restrict certain processing;
* Request a copy of eligible information; and
* Submit a complaint to an appropriate data-protection authority.
Business users may be able to update information through account settings. Requests concerning information controlled by a subscribing business should ordinarily be directed to that business first.
We may need to verify the requester’s identity and authority before completing a request.
## 11. Account and data deletion
Users can request deletion through email: info@bambustechnologies.in
Deleting an application user may not automatically delete the subscribing business’s entire tenant, database, invoices, or legally required transaction records. Business owners or authorized administrators may request closure of the full business account and deletion of eligible tenant data.
When information must be retained for legal, tax, accounting, fraud-prevention, dispute, or security purposes, we will explain the applicable limitation where legally required.
Account deactivation or suspension is not treated as a completed deletion request.
## 12. Permissions
The application may request only permissions needed for enabled features, such as:
* Camera access for barcode or document scanning;
* Photo or file access for user-selected uploads;
* Notifications for OTP, transaction, security, or service updates;
* Bluetooth or nearby-device access for POS hardware and
* Biometric authentication to secure local access, if enabled.
Users may manage permissions through Android settings. Some features may not work when their required permission is denied.
Any collection of personal or sensitive information that users would not reasonably expect will be explained through an in-app disclosure before the relevant permission or consent is requested.
## 13. Children’s privacy
The Services are intended for use by businesses and authorized adult users. They are not directed to children under the minimum age applicable in their jurisdiction.
We do not knowingly permit children to create business accounts or intentionally collect personal information directly from children. If you believe a child has provided information through the application without appropriate authorization, contact us at info@bambustechnologies.in
## 14. Responsibilities of subscribing businesses
Businesses using the Services are responsible for:
* Providing appropriate privacy notices to their customers, employees, and suppliers;
* Collecting information lawfully;
* Obtaining required permissions and consents;
* Configuring user roles and access rights appropriately;
* Keeping account information accurate;
* Securing devices and user accounts; and
* Responding to applicable privacy requests concerning information they control.
Users should not enter unnecessary sensitive information into free-text fields or upload it unless required for a legitimate business purpose.
## 15. Third-party services and links
The Services may contain links to or integrations with third-party services. Their privacy practices are governed by their own terms and privacy policies. We are not responsible for independently operated third-party services.
## 16. Changes to this policy
We may update this Privacy Policy when our practices, technology, legal obligations, or Services change.We will publish the updated version at https://bambustechnologies.in/privacy-policy and revise the “Last updated” date. Where required, we will provide additional notice through the application, email, or another appropriate channel.
## 17. Contact us
For privacy questions, requests, or complaints, contact:
Bambus Technologies LLP
422, Red Rose Towers, D.B Road,
R.S Puram,
Coimbatore – 641002
Tamil Nadu,
India
Email: info@bambustechnologies.in
Phone: 9894568371
Website: www.bambustechnologies.in