1 Overview & Service Scope
This Privacy Policy describes how Hiba Technologies, owned and operated by Oasis India IT Store ("Company", "we", "us", or "our"), collects, processes, stores, and protects personal and business information when you use our Point of Sale (POS) software (Oasis POS), restaurant dining management software (Oasis Table), website (oasispos.in), hardware counter peripherals, and integrated communication services.
We provide billing, POS counter operations, inventory management, GST e-invoicing, barcode generation, weighing scale synchronization, and business communication workflows tailored for retail shops, supermarkets, restaurants, apparel stores, and enterprise merchants across Chennai, Tamil Nadu, and India.
2 Meta Platform & WhatsApp Business API Integration
Our software integrates with the Meta Platforms, Inc. / WhatsApp Business Platform (Cloud API / On-Premises API) to provide merchant-authorized automated transactional communications.
When a business merchant administrator connects and authorizes the WhatsApp Business integration, our systems process messaging payloads solely to deliver merchant-initiated transactional notifications to end-customers, such as:
- Digital GST Tax Invoices & Billing Receipts: Instant PDF links, invoice summaries, and tax breakdown notifications upon checkout completion.
- Order & Kitchen Status Updates: Restaurant dining table orders, Kitchen Order Ticket (KOT) confirmations, takeaway order ready alerts, and home delivery dispatch notices.
- Payment Confirmations: Transaction status, UPI payment receipts, and balance settlement acknowledgments.
- Khata & Ledger Statements: Customer credit ledger balances, payment reminder alerts, and loyalty point updates.
- Direct Support & Technical Setup: Authorized merchant-to-customer communication and technical support conversations initiated by users.
We adhere strictly to the Meta Developer Terms, Meta Commercial Terms, and WhatsApp Business Messaging Policies. We do not use WhatsApp Business messaging for unsolicited bulk spam, unauthorized marketing, or prohibited content.
3 Information We Collect & Process
We process information categorized into the following streams:
| Category | Data Elements Processed | Source & Purpose |
|---|---|---|
| Meta / WhatsApp Integration Data | Meta Business Account ID (WABA ID), Phone Number ID, App Scopes, Access Tokens, Webhook delivery status receipts (Sent, Delivered, Read, Failed). | Received via Meta Graph API upon merchant authorization to execute and verify messaging dispatch. |
| Transactional Messaging Data | Customer mobile numbers (E.164 format), customer name (optional), invoice number, itemized product names, quantities, billing totals, CGST/SGST amounts. | Generated during the retail checkout workflow to compose and transmit the requested digital receipt. |
| Merchant Account & Setup Data | Business name, GSTIN, owner/contact person name, business email address, billing phone number, physical shop address, counter hardware serial numbers. | Provided by the merchant during software onboarding, licensing, hardware provisioning, and warranty registration. |
| Website Enquiries & Demo Requests | Name, phone number, business type (supermarket, restaurant, retail, etc.), city, and optional requirements. | Voluntarily submitted via our website lead forms to request consultation, 1:1 on-site demo, or product quotations. |
4 How We Use Information
We use the collected information strictly for legitimate commercial and technical purposes:
- To provide, operate, maintain, and enhance the core capabilities of Oasis POS.
- To transmit digital receipts, invoices, and transactional WhatsApp alerts requested by merchants and their customers.
- To manage software license activations, version updates, counter hardware driver installations, and troubleshooting.
- To provide dedicated 1:1 technical support and customer onboarding across Tamil Nadu and India.
- To detect, prevent, and remediate technical faults, security incidents, unauthorized access, or API abuse.
- To comply with statutory accounting, Goods and Services Tax (GST) invoicing, and legal obligations under Indian law.
5 Explicit Non-Sale Guarantee & Data Sharing
Oasis India IT Store does NOT sell, rent, trade, lease, monetize, or broker Meta Platform data, WhatsApp customer phone numbers, or merchant transactional records to third-party data brokers, marketing agencies, or advertising networks.
We share information only under the following limited, legally regulated circumstances:
- Platform Infrastructure & Delivery Partners: Meta Platforms, Inc. (to deliver WhatsApp messages via the official WhatsApp Business API), secure cloud hosting infrastructure providers, and SMS gateway vendors where applicable.
- Merchant Discretion: When an end-customer transacts at a retail shop, their receipt details are shared with the merchant from whom they made the purchase.
- Legal & Statutory Compliance: When required by a valid court order, government subpoena, tax authority directive, or applicable law in the Republic of India.
6 Security & Access Controls
We implement rigorous organizational, technical, and administrative safeguards to protect your personal and business data against unauthorized access, alteration, disclosure, or destruction:
- Encryption in Transit & at Rest: All data transmitted between clients, POS endpoints, and servers is encrypted using industry-standard TLS/HTTPS 1.3 encryption. Sensitive tokens are encrypted at rest.
- Restricted System Access: Access to production databases, Meta API tokens, and webhook infrastructure is restricted strictly to authorized technical personnel under the principle of least privilege.
- Offline Continuity & Local Storage: Oasis POS operates with local database isolation on the counter terminal, allowing continuous billing without unnecessary cloud data leakage.
- Multi-Factor Authentication & Audit Logs: Administrative access requires multi-factor authentication (MFA) and maintains immutable security audit logs.
7 Data Retention & Storage
We retain personal data and integration logs only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by statutory law:
- Meta / WhatsApp Integration Tokens: Retained for the duration of the merchant's active software subscription and deleted immediately upon integration disconnection or account termination.
- Transient Messaging Delivery Logs: Retained for up to 90 days for delivery verification, debugging, and receipt delivery status checks, after which they are automatically purged.
- Tax & Financial Invoices: Historical sales invoices and tax records generated by merchants are retained in accordance with Indian statutory tax requirements (such as Section 36 of the Central Goods and Services Tax Act, 2017).
8 Your Rights & User Data Deletion Instructions
Under applicable data protection regulations (including the Digital Personal Data Protection Act, 2023 and Meta Platform Terms), you have the right to access, rectify, restrict, or request the deletion of your personal data held by us.
If you are a business administrator or an individual wishing to delete information associated with our Meta / WhatsApp Business API integration or your account records, please review our dedicated instructions:
View Data Deletion Instructions
You can also submit a data deletion request directly by emailing support@oasispos.in with the subject line Meta Data Deletion Request.
9 Contact & Grievance Redressal
If you have questions, feedback, or concerns regarding this Privacy Policy, our Meta WhatsApp Business API integration, or data protection practices, please contact our designated Privacy and Compliance Officer:
Hiba Technologies — Privacy & Compliance Office
Operated by Oasis India IT Store