Legal
Privacy Policy
Effective date: May 7, 2026 · Version 1
This Privacy Policy explains how Nivo One ("we", "us", or "our") collects, uses, stores, and shares information when you install or use the Nivo One Point of Sale application ("the App") and the supporting cloud services we operate at https://nivoone.com ("the Service").
The App is designed to be offline-first: your day-to-day business data — sales, inventory, customers, vouchers — is stored locally on the machine you install it on, and is never uploaded to our servers unless you explicitly enable a cloud-sync feature. This policy describes the limited information we do receive, why we receive it, and what your choices are.
1. Information we collect
1.1 Information you provide directly
- Account information. When you create a Nivo One account or activate a license, we collect your name, email address, and an account password (stored only as a salted hash).
- Business information. The name of your business, business type, and the country or region you operate in. This is used to issue per-business licenses and to apply the correct currency, tax presets, and feature defaults.
- Activation data. When you activate a license, we record the activation key, the plan you are on, the time of activation, and a non-personal hardware fingerprint of the machine that activated it. The fingerprint lets us enforce the per-license terminal cap without revealing your hardware identity.
- Support correspondence. If you contact us for support, we keep the messages, attachments, and email thread so we can respond and follow up.
1.2 Information we receive automatically
- License heartbeat. The App periodically asks our servers whether the license JWT it holds is still valid. The heartbeat carries the license id and the hardware fingerprint — nothing else.
- Diagnostic logs. If a crash or unhandled error occurs, the App may send a de-identified crash report (stack trace, OS version, app version) to our crash-reporting provider. These reports do not contain your business data.
- Application analytics. We collect anonymised usage signals — which screens are opened, feature counters, performance timings — to improve the product. Analytics data is not tied to your identity, your business records, or your customers.
- Server access logs. Our cloud services log standard request metadata (IP address, user-agent, request path, status code, timestamp) for security and abuse prevention.
1.3 Information that stays on your device
The following categories of data are stored only on the local machine where you install the App and are not transmitted to us:
- Sales, vouchers, invoices, receipts, and ledger entries.
- Items, stock balances, batches, warehouses, and stock-movement history.
- Customer records, party balances, and contact details you enter.
- Printer configuration, terminal topology, and worker PINs.
- Any photos, attachments, or documents you save inside the App.
If you choose to enable a future cloud-sync feature, the data that is synced will be clearly scoped at the time the feature is enabled, and you can disable sync at any time.
2. How we use information
- To create and manage your Nivo One account and the businesses linked to it.
- To issue, verify, suspend, and revoke licenses and to enforce per-license terminal caps.
- To send service notices — license expiry warnings, security alerts, important policy updates — and, only when you opt in, product news.
- To diagnose crashes and performance regressions and to improve product reliability.
- To detect, investigate, and prevent fraud, abuse, and unauthorised access.
- To comply with applicable law, lawful requests from authorities, and our internal records obligations.
3. Legal bases for processing
Where data-protection law (such as the GDPR or India's DPDP Act) requires a legal basis, we rely on the following:
- Contract. Most processing is necessary to deliver the App and the Service to you under our Terms of Service.
- Legitimate interest. Crash diagnostics, anonymised analytics, security logging, and fraud prevention.
- Consent. Marketing communications, optional cloud-sync features, and any analytics not strictly necessary for the App to function — you can withdraw consent at any time.
- Legal obligation. Where we must keep records or respond to lawful requests.
4. Sharing and disclosure
We do not sell your personal information. We share data only as described below:
- Service providers. We use carefully chosen processors to operate the Service — cloud hosting, email delivery, crash reporting, and product analytics. They process data only on our instructions and under written data-processing terms.
- Legal and safety. We may disclose information when we have a good-faith belief it is required by law, by a valid legal process, or to protect the rights, property, or safety of users or the public.
- Business transfers. If Nivo One is involved in a merger, acquisition, or asset sale, your information may be transferred subject to this policy or a successor policy that gives equivalent protection.
5. Data retention
We keep account, license, and billing records for as long as your account is active, plus the period required to satisfy legal, accounting, and audit obligations (typically up to seven years after the relationship ends). Crash reports and server logs are retained for up to 90 days. Anonymised analytics may be kept indefinitely. Local data on your machine is retained until you delete it or uninstall the App.
6. Your rights
Subject to local law, you may have the right to:
- Access the personal information we hold about you.
- Correct information that is inaccurate or incomplete.
- Request deletion of personal information we no longer need.
- Object to or restrict certain processing.
- Receive a portable copy of information you provided to us.
- Withdraw consent where processing relies on consent.
- Lodge a complaint with your local data-protection authority.
To exercise any of these rights, email us at [email protected]. We will respond within the timeframes required by applicable law.
7. Security
We use industry-standard safeguards to protect information in transit and at rest, including TLS for all network traffic, hashed and salted passwords, signed JWT licenses, encrypted backups, and least-privilege access controls. No system is perfectly secure, however, so you are responsible for protecting the device the App runs on, your account password, and any worker PINs you set up.
8. Children
The Service is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can remove it.
9. International transfers
Our cloud services may operate in regions different from where you live. Where data-protection law requires it, we use approved transfer mechanisms — such as Standard Contractual Clauses or equivalent — to keep your information protected.
10. Cookies and similar technologies
Our public web pages and the cloud admin console use a small number of cookies that are strictly necessary for sign-in and security (for example, the admin session cookie is HTTP-only and same-site strict). The App itself does not use third-party advertising cookies.
11. Changes to this policy
We may update this policy as the product and the law evolve. When we make material changes, we will increase the policy version, update the effective date above, and require you to accept the new version inside the App before continuing to use it. The previous version remains available on request.
12. Contact us
Questions, complaints, or rights requests can be sent to:
Nivo One
Email: [email protected]
Web: https://nivoone.com
This page is provided for transparency. It does not constitute legal advice. If you have specific questions about your rights or about how we handle your data, please contact us using the details above.