GemSphere
GemSphereTechnology That Transforms

Privacy Policy

Last Updated: June 2026

1. Introduction & Scope

GemSphere Technologies Private Limited ("GemSphere AI," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy governs the data collection, processing, and storage practices for:

  • Our corporate website located at www.gemsphere.ai.
  • Our software platforms, API portals, and the GemSphere Commerce mobile application (available on the Google Play Store).

This policy has been updated to fully align with global data protection regulations, including the European Union's General Data Protection Regulation (GDPR) and Google Play Store App Developer Policies.

2. Data Controller

The Data Controller responsible for processing your personal data is:
GemSphere Technologies Private Limited
Garuda BHIVE Workspace, BTM Layout, Bengaluru, Karnataka 560076, India.
CIN: U62011KA2025PTC211975
Inquiries regarding this policy or data protection can be sent directly to Contact@gemsphere.ai.

3. Information We Collect

We collect information directly provided by you, automatically through your interaction with our platforms, and via device permissions enabled inside our mobile application.

A. Personal Information (Forms and Authentication)

  • Account Credentials: Full name, business email address, phone number, company/store name, password, and job title used to authenticate and create admin or cashier profiles.
  • Customer & Billing Information: Billing name, email address, phone number, shipping address, and GSTIN/tax identification numbers used to process transactions, invoice details, and loyalty rewards.
  • Communication Data: Inquiry details, feedback, chat history with support services, or email correspondence.

B. Mobile Application Permissions & Collected Data

To perform core Point of Sale (POS) and ordering tasks, the GemSphere Commerce app requests the following device integrations:

  • Camera Access: Utilized exclusively when the user activates the barcode scanner to scan product barcodes and add items directly to the checkout cart. No images or videos are saved, stored, or sent to external servers.
  • Storage & Files: Needed to download, save, and share PDF invoices and thermal receipt files locally on the device or share them via external communication channels (e.g., WhatsApp).
  • Device & Notification Identifiers: Unique device IDs (UUIDs), operating system metadata, and Push Notification Tokens to deliver critical system updates and transaction alerts.

C. Usage & Website Analytics

  • IP address, browser type, referral source, time spent on pages, and navigation paths collected through secure, anonymized analytics cookies.

4. GDPR Legal Basis for Processing

Under the GDPR, we only process your personal data where there is a valid legal basis:

  • Contractual Necessity: To set up your account, process orders, issue invoices, redeem loyalty rewards, and deliver POS services.
  • Consent: Where you have explicitly opted in, such as allowing analytics cookies or subscribing to marketing emails.
  • Legitimate Interests: To secure our systems, prevent fraudulent transactions, analyze system usage patterns, and optimize app performance.
  • Legal Obligation: To comply with tax laws, accounting regulations, and statutory reporting requirements.

5. Data Sharing & Third-Party SDKs

We do not sell your personal data. We only share information with trusted third-party service providers who conform to strict confidentiality standards, including:

  • Hosting and Backend Services: Secure cloud providers hosting our database, microservices, and media storage.
  • App Utilities & SDKs: Core libraries (such as React Native, Expo, and Reanimated) for rendering UI, and notification relays to deliver push notifications.
  • Legal Disclosures: When required to comply with binding court requests, tax audits, or statutory laws.

6. Data Security & Encryption

All data collected via our website and the GemSphere Commerce mobile application is encrypted in transit using industry-standard Transport Layer Security (TLS/HTTPS) and encrypted at rest in our cloud databases. We implement strict internal access controls to ensure that only authorized personnel can access account details.

7. International Data Transfers

If personal data originating in the European Economic Area (EEA) is transferred to servers located outside the EEA, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses approved by the European Commission) to maintain equivalent data protection standards.

8. Your Rights Under GDPR & Data Protection Regulations

Depending on your location, you hold the following rights regarding your personal information:

  • Right of Access: Obtain a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data under certain conditions.
  • Right to Restrict Processing: Request that we limit how your data is processed.
  • Right to Data Portability: Obtain your data in a structured, commonly-used, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests or direct marketing.
  • Right to Withdraw Consent: Withdraw consent at any time without affecting prior lawful processing.

9. Account & Data Deletion Requests

In compliance with Google Play Store developer policies, we offer a straightforward mechanism for users to delete their account and associated personal data:

You can request deletion of your account and all associated transactional/personal records by:

  • Submitting a request inside the Account Settings screen of the GemSphere Commerce mobile application.
  • Sending an email directly to Contact@gemsphere.ai with the subject line "Account Deletion Request".

Upon request, we will permanently delete or anonymize your personal information, unless we are legally required to retain specific transaction data for financial, tax, or local accounting compliance.

10. Data Retention

We retain your personal data only as long as your account remains active or as needed to provide our services. Once the purpose for data collection is fulfilled, we securely delete or anonymize it, unless retention is required to fulfill statutory audit and tax reporting obligations.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be published directly on this page with an updated revision date.

12. Contact Information

For any questions, clarifications, or to exercise your privacy rights, please reach out to us at:

GemSphere Technologies Private Limited

Garuda BHIVE Workspace, BTM Layout, Bengaluru, Karnataka 560076, India

Email: Contact@gemsphere.ai

Phone: +91 7892585801

CIN: U62011KA2025PTC211975