Last updated: 25 September 2026

1. Introduction

This Privacy Policy explains how Rocketo (“we“, “us“) collects, uses, shares, stores and protects personal data when you visit https://rocketo.in (the “Website“) or use Rocketo, our online billing, inventory, barcode and GST software for cracker and fireworks shops (the “Service“).

This policy is written to comply with the laws of India, including:

  • the Digital Personal Data Protection Act, 2023 (“DPDP Act“) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules“), as their provisions come into force;
  • the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules“), for as long as they apply;
  • the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, to the extent applicable;
  • the CERT-In Directions dated 28 April 2022 under section 70B of the IT Act; and
  • record-keeping requirements under the Central Goods and Services Tax Act, 2017 and other tax laws.

By using the Website or the Service, you confirm that you have read this policy. Where the law requires your consent, we will ask for it separately and clearly, and you can withdraw it at any time (see Section 5).

This policy is a standalone notice. It is not part of, and does not depend on, our Terms of Service.

2. Definitions and our role

Words such as personal data, Data Principal, Data Fiduciary, Data Processor, consent manager and personal data breach have the meanings given in the DPDP Act.

Rocketo plays two different roles, depending on whose data it is:

Whose dataExamplesRocketo’s roleWho decides how it is used
Website visitors, people who book a demo or contact us, and shop owners who buy the ServiceName, phone, email, shop name, payment recordsData FiduciaryRocketo
Data a shop enters into the Service about its own customers and staffCustomer name and mobile number on a bill, staff login details, bills, stockData Processor acting on the shop’s instructionsThe shop owner (the shop is the Data Fiduciary)

In simple words: if you are a customer of a cracker shop that uses Rocketo, that shop is responsible for your data. Please contact the shop first. We will help the shop answer your request, and you can also write to us (Section 14).

3. Personal data we collect

We collect only what we need to run the Website and the Service.

CategoryWhat we collectWhere it comes from
Website visitorsIP address, browser and device type, pages visited, date and timeYour browser, automatically
Demo, contact and sales enquiriesName, mobile number, email, shop name, city, your messageYou, through our forms, phone, email or WhatsApp
Shop owner accountName, email, mobile number, password (stored only in encrypted, hashed form), shop name, shop address, shop phone, GSTINYou, when your account is set up
Staff accounts (created by the shop owner)Name, email, optional mobile number, login password (hashed), role and permissionsThe shop owner
Shop’s customersCustomer name and 10-digit mobile number (required on every bill), items bought, amounts, payment mode (cash, UPI, card, other), duesThe shop’s staff, while billing
Business recordsItems, MRP, selling and purchase rates, HSN codes, tax rates, stock, bills, receipts, GST reportsThe shop
Activity logName of the user, action taken (create, edit, delete, stock change, payment, login, logout), date, time and IP address (IPv4/IPv6)Recorded automatically for security and audit
Subscription paymentsAmount, date, invoice and the UPI or bank transaction referenceYou, when you pay us directly by UPI or bank transfer. We do not collect card numbers, CVV, UPI PIN or net-banking passwords

Camera. If you scan barcodes with your phone or laptop camera, the video is processed only inside your browser to read the barcode. We do not record, upload or store camera images or video. The camera turns on only after you allow it in your browser.

Sensitive data. Under the SPDI Rules, passwords and financial information such as payment details are “sensitive personal data”. We handle them with the extra care described in Section 10. We do not intentionally collect health, biometric, caste, religion or similar data. Please do not enter such data in the Service.

4. Why we use your data (purpose and legal basis)

We use personal data only for the purposes below. We will not use it for a new, unrelated purpose without telling you and, where needed, taking fresh consent.

PurposeLegal basis under the DPDP Act
Reply to demo, contact and sales enquiriesYour consent (section 6)
Create and run your shop account and staff loginsYour consent, and the use you voluntarily gave the data for (section 7(a))
Provide the Service: billing, printing bills, stock, barcode labels, reportsInstructions of the shop owner (we act as Data Processor)
Send login details to staff by email, when the shop owner chooses toInstructions of the shop owner
Collect subscription fees and issue GST invoices to shop ownersYour consent, and compliance with tax law (section 7(d))
Keep the Service secure, prevent fraud and misuse, keep activity and server logsLegitimate use and compliance with law, including CERT-In Directions (section 7)
Reply to courts, police, tax and other authorities when legally requiredCompliance with law, court orders and lawful requests (section 7)
Send service messages: renewal reminders and security alertsConsent and legitimate use
Send offers or news about RocketoOnly with your separate consent, which you can withdraw anytime

We do not sell personal data. We do not use a shop’s customer data to market our own products to those customers. We do not track or profile children or show targeted advertising to them.

5. Notice, consent and withdrawal

Clear consent. When we ask for consent, we will do it with a clear action from you, such as ticking a box that is not pre-ticked. We will say what data we need and why. This notice is available in English and, on request, in any language listed in the Eighth Schedule to the Constitution of India.

Withdrawing consent. You can withdraw consent at any time, as easily as you gave it, by emailing info@rocketo.in or using the contact page at https://rocketo.in/contact. After withdrawal:

  • we will stop processing that data within a reasonable time, and ask our processors to do the same;
  • anything we did before the withdrawal stays lawful;
  • we may keep data where the law requires it (Section 9); and
  • if the data is needed to run your account, withdrawing consent may mean we can no longer provide the Service.

Consent managers. You may give, manage, review or withdraw your consent through a consent manager registered with the Data Protection Board of India, once that system is available.

6. Cookies, browser storage and third-party services

TypeUsed forCan you turn it off?
Login cookies (WordPress)Keep you signed in and protect your sessionNo. The Service does not work without them
Browser storage (localStorage, sessionStorage)Remember your settings on your own device, such as the last settings tab, preferred camera and barcode label layout. This stays in your browser and is not sent to usYes. Clear your browser data

We do not use analytics, advertising or cross-site tracking cookies.

The Website loads fonts from Google Fonts, which means your browser connects to Google and shares your IP address with it. Google’s own privacy policy applies to that connection. Links to other websites (for example WhatsApp) are governed by those websites’ own policies.

7. Who we share data with

We share personal data only in these cases, and only as much as needed:

RecipientWhyData shared
Hostinger (hosting and email provider)Store and run the Website and the Service, and send login details, invoices and service emailsAll Service data, stored on their servers; name, email and message content for emails
Your chartered accountant or tax consultantOnly when you export and share GST reportsWhatever you choose to share
Government, courts, police, tax and other authoritiesWhen required by law, court order or a lawful request, including under the IT Act and CERT-In DirectionsOnly what the request legally requires
A buyer or successor of our businessMerger, sale or restructuringAccount and Service data, under this same policy

Our service providers may use the data only to provide their service to us and must keep it secure.

Inside the Service, each shop’s data is kept separate. Other shops cannot see your bills, customers, stock or staff. Our admin screen shows only basic account details (shop name, owner, staff count and bill count). Authorised Rocketo staff open other data only when you ask for support, to fix a technical or security problem, or when the law requires it, and they are bound by confidentiality.

8. Where your data is stored

Your data is stored on Hostinger servers located in India. Security and system logs required by the CERT-In Directions are kept within India.

A few services, such as Google Fonts, may process limited data (like your IP address) outside India. Any such transfer follows section 16 of the DPDP Act: we will not transfer personal data to any country the Central Government has restricted, and we will follow any conditions the Government sets.

9. How long we keep data

We keep personal data only as long as the purpose needs it or the law requires it, then erase it.

DataHow long
Demo and contact enquiries that did not become customersUp to 12 months after our last contact, unless you ask us to delete it sooner
Shop account and Service data (bills, customers, stock, staff)While the subscription is active. After it ends, we keep it for 30 days so you can export it, then erase it within the next 60 days
Our invoices and payment records for your subscription72 months from the due date of the annual GST return for that year (section 36, CGST Act, 2017), or longer if another tax law requires
Server, security and access logs, including IP addressesAt least 180 days (CERT-In Directions) and at least one year where the DPDP Rules require it
Activity log inside the ServiceWhile the account is active, as part of the shop’s records

Shop owners, please note: GST law requires you to keep your own sales and tax records for 72 months. Export your bills and GST reports before your account ends. We are not responsible for keeping them for you after the export period.

Before we erase an account because it has ended or is inactive, we will inform the shop owner at least 48 hours in advance, so there is time to log in or export data.

10. Security and data breaches

We follow reasonable security practices as required by section 43A of the IT Act, the SPDI Rules and Rule 6 of the DPDP Rules. These include:

  • HTTPS encryption for all data sent between your device and our servers;
  • passwords stored only in salted, hashed form, never in plain text;
  • separate data for every shop, and role-based permissions inside each shop;
  • an activity log of changes and logins, with user name and IP address;
  • restricted access for our own staff, on a need-to-know basis, under confidentiality; and
  • regular backups and security updates.

No system is completely secure. Please use a strong password, do not share logins, and remove staff access as soon as a person leaves your shop.

If a breach happens, we will:

  1. inform affected people without delay, in plain language, including what happened, the likely impact, what we are doing and what you can do;
  2. report it to the Data Protection Board of India as the DPDP Rules require, with a detailed report within 72 hours of becoming aware of it;
  3. report cyber security incidents to CERT-In within 6 hours of noticing them, as the CERT-In Directions require; and
  4. inform the affected shop owner at once when the breach involves data we process for that shop, and help them meet their own duties.

11. Your rights

Under the DPDP Act you have the right to:

RightWhat it means
Access (section 11)Get a summary of your personal data we process, what we do with it, and who we have shared it with
Correction, completion and update (section 12)Fix data that is wrong, incomplete or out of date
Erasure (section 12)Ask us to delete data that is no longer needed, unless the law requires us to keep it
Withdraw consent (section 6)Stop processing that is based on your consent
Grievance redressal (section 13)Complain to us and get a response
Nominate (section 14)Name a person who can use these rights for you if you die or become unable to act

How to use your rights. Email info@rocketo.in with the subject “Privacy request”, your name, registered mobile or email, and what you want. We may ask you to confirm your identity before acting. There is no fee.

Our response time. We will acknowledge your request within 7 days and resolve it within 30 days, and in any case within the 90 days allowed by the DPDP Rules.

Customers of a shop: if the shop entered your details (for example your name and mobile number on a bill), send your request to that shop. If you write to us instead, we will pass it to the shop and help them respond.

Your duties. The DPDP Act also asks you not to give false information, not to impersonate anyone, and not to file frivolous complaints (section 15).

12. Children and persons with disability

The Website and the Service are meant for businesses and adults. We do not knowingly create accounts for anyone under 18 years of age. If we learn that we hold the data of a child without verifiable consent of a parent or lawful guardian, we will delete it, as section 9 of the DPDP Act requires.

Shops should not create staff accounts for anyone under 18. Where a shop enters a minor’s name as a customer, the shop is responsible for getting the parent’s consent.

For a person with a disability who has a lawful guardian, the guardian may give consent and use the rights in Section 11 on their behalf, after we verify the guardianship.

13. Responsibilities of shop owners

For the customer and staff data you enter in Rocketo, you are the Data Fiduciary and we process that data on your instructions. By using the Service, you agree to:

  • collect only the customer details you need for billing, GST and dues, and tell customers why you are taking them (for example with a notice at the counter or on the bill);
  • take consent where the law requires it, and not use customer numbers for marketing without separate consent;
  • keep staff logins private, give each person only the permissions they need, and remove access when they leave;
  • answer your customers’ and staff’s requests to access, correct or delete their data (we will help you); and
  • keep your own copies of GST and tax records for the period the law requires.

We will process your shop’s data only to provide the Service, keep it confidential, protect it as described in Section 10, tell you about any breach without delay, and delete or return it when your subscription ends (Section 9).

14. Grievance Officer and contact

For any question, request or complaint about your personal data, contact our Grievance Officer:

Rocketo
Address: Morbi, Gujarat, India
Email: info@rocketo.in
Phone: +91 63527 25325 (Monday to Saturday, 10 am to 6 pm IST)
Contact page: https://rocketo.in/contact

We will acknowledge your complaint within 24 hours and resolve it within 15 days of receiving it.

If you are not satisfied with our response, you may complain to the Data Protection Board of India under the DPDP Act, after first using our grievance process as section 13(3) of the Act requires.

15. Changes to this policy

We may update this policy when the law or the Service changes. The latest version will always be on this page with its “Last updated” date. Where a change needs your consent, we will ask for it again.

This policy is governed by the laws of India.

Scroll to Top