This policy explains how Saskey Innovations ("we", "us", "Saskey") handles personal information in the StockGenie Pro web application (stockgeniepro.com) and the StockGenie Field mobile app (Android package in.saskey.stockgenie.field; iOS, when released). Together these are referred to as the "Service".
The Service is a business-to-business product. We provide it under contract to automotive dealerships (each, a "Dealer"). Dealer employees, sales reps, and back-office staff access the Service to manage their dealership's inventory, sales orders, dispatches, attendance, and expenses. End consumers do not use the Service directly.
For most data processed through the Service, your employer Dealer is the data controller — they decide what data to collect, how to use it, and how long to keep it. Saskey acts as a data processor on the Dealer's behalf under our service agreement.
For account-level data (your login credentials and session metadata), Saskey acts as the controller.
If you have questions about how your specific Dealer uses Service data, contact your Dealer's administrator directly. For Saskey-controlled data, contact us using the details at the bottom of this page.
| Category | What it contains | Why we collect it | Where it lives |
|---|---|---|---|
| Account info | Your work email address, display name, role, Dealer ID | To sign you in, route you to the correct Dealer, and apply role-based permissions | Firebase Authentication, Firestore |
| Session metadata | Last login time, IP address (transient), device type | Security and fraud detection | Firebase Authentication |
| Inventory and sales data | Parts, stock movements, customer records, sales orders, invoices, dispatch labels, returns — all created or referenced by you while using the Service | Core app functionality | Firestore (per-Dealer isolated collections) |
| Field rep work logs (StockGenie Field app only) | Attendance check-ins with timestamp, GPS coordinates if you grant location permission, customer visit records, expense claims, photos you attach | Track field activity for the Dealer's back office; you must grant location permission explicitly | Firestore (per-Dealer isolated collections) |
| Item catalogue cache (StockGenie Field app only) | A copy of your Dealer's part catalogue stored on your device for offline access | Avoid re-downloading large catalogues on every app open | Your device's app sandbox (private, app uninstall removes it) |
| Zoho integration data (Dealers with the integration enabled) | OAuth tokens for the Dealer's Zoho account, customer + item identifiers used to push invoices and credit notes | Sync sales orders, invoices, and credit notes between StockGenie and the Dealer's Zoho Books / Inventory account | Firestore (Dealer-scoped); tokens are short-lived and refreshed automatically |
We do not collect or process:
The Android app may ask for these permissions at runtime. You can deny any of them — the affected feature will simply be unavailable, but the rest of the app keeps working.
| Permission | Why | Optional? |
|---|---|---|
| Internet | Talk to Firebase and stockgeniepro.com | No — required |
| Storage / Files | Cache the item catalogue on the device | Yes — disabling means the catalogue re-downloads every session |
| Location (when in use) | GPS-tag attendance and customer visits | Yes — disabling means location fields stay blank |
| Camera | Attach photos to complaints and expense claims; scan barcodes | Yes — disabling means no photo attachments or barcode scans |
Account info and inventory/sales data are retained for as long as your Dealer subscribes to the Service, plus 90 days after the subscription ends to allow data export.
Session metadata (logs, IP addresses) is retained for up to 90 days for security and abuse investigation.
Device-local item-catalogue cache is retained until you tap "↻ Refresh Items" (which clears and re-pulls) or uninstall the app.
Backups of all Firestore data are retained for 30 days for disaster recovery.
We do not sell your data. We share it only with the parties below, and only as needed to operate the Service:
We do not transfer data to advertisers, analytics resellers, or any party for commercial purposes other than operating the Service.
Firestore data is hosted in Asia (Mumbai) Google Cloud region. Some Firebase services (Authentication, Hosting CDN) replicate metadata globally for performance and availability — this is standard for Firebase and you can read the details in Google's Firebase data processing terms.
All data in transit between your device, our hosting, and our processors is encrypted using TLS 1.2 or higher. Firestore data at rest is encrypted by Google using AES-256.
Account passwords are never seen or stored by us — Firebase Authentication hashes them using bcrypt before storage and we only ever receive the resulting session token.
OAuth tokens for Zoho integration are stored encrypted in Firestore and only accessible from the authenticated Dealer's session.
We restrict employee access to the Firestore admin console to the minimum number of people needed for support, and we log every admin action. Access requires hardware-key two-factor authentication.
Under the Digital Personal Data Protection Act, 2023 (India) and, where applicable, the EU/UK GDPR, you have the right to:
To exercise any of these rights, email support@saskey.in with the subject "Privacy request" and a description of what you want. We respond within 30 days under DPDP Act §11.
If your Dealer is the controller for the data in question (most inventory/sales data), we will route your request to the Dealer's administrator and assist them in fulfilling it.
To delete your StockGenie account:
companyUsers — this is the fastest path because they control your role assignment.Account deletion clears: Firebase Authentication record, your row in users and companyUsers collections, your work logs, your attendance records, and the device-local catalogue cache (next time you launch the app). It does not clear records owned by the Dealer (sales orders you created, invoices you scanned, etc.) — those belong to the Dealer and are governed by the Dealer's own retention policy.
The Service is not directed to and not intended for use by anyone under 18. We do not knowingly collect data from minors. If you believe a minor has provided personal data through the Service, contact us and we will delete it.
The web app at stockgeniepro.com uses browser localStorage and sessionStorage for:
We do not use third-party tracking cookies or any advertising / analytics cookies.
The StockGenie Field mobile app uses Android's app sandbox storage equivalent (Capacitor Filesystem) for the catalogue cache. There are no browser-style cookies in the app.
The Service may contain links to third-party websites (Zoho, our support WhatsApp). Once you leave the Service, this policy no longer applies. We encourage you to read the privacy policies of any site you visit from within our app.
We may update this policy from time to time. When we make material changes, we will notify you through the app (banner on next sign-in) and update the "Last updated" date at the top.
Older versions of the policy are available on request.
For any privacy-related question, data-subject request, or to report a data incident:
Our designated Grievance Officer under the DPDP Act §10(8) is the founder of Saskey Innovations. Reach out at the email above and your message will be routed appropriately.