Privacy Policy
Last updated 2 September 2026
Short version: we hold your shop account and billing status, the file passes through and is deleted after it prints, payments go through Razorpay, and we don't sell anything.
This policy covers [PrintSets legal entity name] (“PrintSets”, “we”). For a print shop’s own customers, the shop is the data controller and PrintSets is a processor acting on the shop’s instructions — a customer with a question about their print job should ask the shop first.
What we collect
your account + billing status, plus the minimum to run a print job
Shop account. Email, a hashed password, shop name and slug, your pricing, and metadata about the PCs you connect (hostname, app version, last-seen time, IP address). Device tokens are stored hashed.
Billing. Your plan, subscription status and the Razorpay subscription/customer IDs. Payment instruments (UPI ID, card numbers, bank details) are handled entirely by Razorpay — we never receive or store them.
Print jobs. The uploaded PDF (transient — see below), its page count, the chosen options (colour, copies, pages, sides), a contact detail only if the customer chooses to enter one, and the order / pickup / reconciliation codes.
Technical. Server logs with IP address, timestamps, request paths and error details, kept for a short period for security and debugging.
How the PDF is handled
uploaded, pulled once by the shop PC, printed, deleted — nothing kept
- The file is stored only until the job is done.
- The shop’s PC downloads it once to print it.
- It’s deleted immediately after printing. A background job also removes files from orders that were never paid or were abandoned.
- We do not keep, index, read or train anything on the contents.
How we use what we collect
run the service, take payment, support you, keep it secure
- Provide the queue, printing and dashboard.
- Set up and collect your subscription through Razorpay.
- Answer support requests and send service notices.
- Detect and prevent abuse, fraud and security problems, and meet legal obligations.
- Understand usage in aggregate to improve the product (counts and trends, not the content of files).
Who we share it with
Razorpay for payments, our hosting provider, and no one else unless the law compels it
- Razorpay — to create and charge your subscription.
- Infrastructure providers — [hosting / database / email provider] that run the servers and storage on our behalf, under contract.
- Authorities — if we’re legally required to, or to protect rights and safety.
We do not sell personal data or share it for advertising.
How long we keep it
account data while you're active; order history per your plan; PDFs not at all
- Account & billing: while your account is open, then up to [90] days after closure, plus anything we must keep for tax/accounting law.
- Order / day-book history: the last 30 days on Counter, full history on Campus, until you delete it or close the account.
- Uploaded PDFs: deleted right after printing; not retained.
- Server logs: about [30] days.
Your choices and rights
access, correct, export or delete — from the dashboard or by email
You can view and update your account details, export your order history, and delete your account from the dashboard. You can also email us to ask what we hold about you, to correct it, or to have it deleted, subject to records we must keep by law.
If you’re a customer of a shop, contact that shop about your order data — they control it. We’ll help them respond.
Security
encryption in transit, hashed secrets, least privilege
- All traffic is over HTTPS/WSS.
- Passwords are hashed; device tokens are stored hashed.
- The shop PC connects outbound only — no inbound ports are opened on it.
- Access to production data is limited to what’s needed to run and support the service.
No system is perfectly secure, but this is how we reduce the risk.
Cookies and tracking
a sign-in token in your browser, nothing for ads
The dashboard keeps your sign-in token in your browser so you stay logged in. The customer flow uses only what it needs to run an order. We don’t use third-party advertising or cross-site tracking cookies.
Children
PrintSets is a tool for businesses and isn’t directed at children. The shop is responsible for its own counter and customers.
Changes and contact
We’ll post any changes here and, for material changes, notify you by email or in the dashboard. For any privacy question or request, email [privacy@printsets.in].
Email [legal@printsets.in] and a person will get back to you.
This document is a starting template. Replace every [bracketed] value and have it reviewed by a lawyer before you rely on it.