Privacy Policy
1. Information We Collect: We collect business contact information (Full Name, verified Email Address, Phone Number, Indian GSTIN, Business Name, Address) upon account registration for identity verification and tax-compliant invoice generation.
2. Cryptographic Credential Protection: Account passwords are encrypted using bcrypt (12 rounds). API keys are stored solely as one-way SHA-256 hashes. Secondary security PINs are protected with hashed comparisons.
3. Message Content & Data Retention: Outbound and inbound messages passing through our API gateways are temporarily stored in database logs for delivery confirmation, auditing, and error inspection. We never sell or share customer contact lists or message content with third parties.
4. Session & Security Auditing: For account defense, we record IP addresses, user-agent signatures, and device metadata during authentication to power our real-time "Recent Login Activity" audit table and "Logout All Devices" session revocation capabilities.
5. Contact Information: For privacy inquiries or data access requests, contact our Data Protection Officer at privacy@bigmis.in.