O
onestopERP

Support Desk: support@onestopERP.com

Mon to Sat, 9AM to 9PM IST

arrow_back Back to Home Legal Documentation
shield Trust & Data Protection

Privacy Policy

event Last updated: August 2026 domain Entity: onestopERP (onestoperp.com) verified_user Jurisdiction: India (DPDP Act & IT Rules Compliant)

01 Introduction

Welcome to onestopERP (accessible at onestoperp.com, "we", "our", or "us"). We are committed to protecting the privacy, confidentiality, and security of all personal and enterprise information entrusted to us by our clients, developers, and platform visitors.

This Privacy Policy outlines how onestopERP collects, processes, stores, discloses, and protects your information when you browse our website, create a customer account, purchase cloud VM sandbox plans, or interact with our Oracle Cloud instance infrastructure (including Oracle Fusion Cloud, Oracle Integration Cloud [OIC], VBCS, ATP Database, APEX, and EBS practice environments).

By accessing or using onestopERP, you acknowledge that you have read, understood, and agreed to the data practices described in this Privacy Policy, structured in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), and the Digital Personal Data Protection Act, 2023 (DPDP Act) of India.

02 Information We Collect

We collect information strictly necessary to provide, verify, secure, and bill our cloud instance provisioning services:

person A. Personal & Account Identification Data

  • Full Name and business/organization name
  • Work or personal email address
  • Telephone or WhatsApp contact number (for urgent provisioning and renewal alerts)
  • Account credentials (salted and cryptographic password hashes — we never store plaintext passwords)

receipt B. Transaction & Billing Information

  • Transaction reference IDs, order numbers, and invoice generation details
  • Billing addresses and GSTIN numbers (for corporate tax invoicing in India)
  • Plan duration, purchased modules, and instance provisioning metadata

dns C. Technical & Diagnostic Data

  • Internet Protocol (IP) address, browser user-agent, operating system, and referral headers
  • Session timestamps, portal telemetry, and security access logs
  • Instance reachability diagnostics and technical support interaction tickets

03 How We Use Your Information

onestopERP utilizes collected data for lawful, operational, and service-fulfillment purposes:

  • check_circle Instance Provisioning & Delivery: Generating secure URLs, allocating credentials, setting up requested database/sandbox environments, and managing subscription terms.
  • check_circle Customer Support & Architect Assistance: Resolving configuration queries, answering module questions, and providing technical guidance during support hours (Mon–Sat, 9AM–9PM IST).
  • check_circle Billing & Invoicing: Generating tax-compliant invoices, processing payments, handling verified refund requests, and recording transaction audit trails.
  • check_circle Platform Security & Abuse Prevention: Guarding against unauthorized access, bot attacks, fraudulent transactions, and violations of our Acceptable Use Policy.
  • check_circle Transactional Communications: Dispatching login credentials, service maintenance notices, subscription expiry reminders, and critical security advisories.

04 Payment Processing (Razorpay)

lock Zero Sensitive Payment Data Stored on onestopERP Servers

onestopERP does not collect, process, capture, or store sensitive card numbers, CVVs, card expiration dates, netbanking passwords, or UPI MPINs on our infrastructure.

All financial transactions on onestopERP are handled exclusively through our certified payment processing partner, Razorpay Software Private Limited ("Razorpay"). Razorpay is fully compliant with the Payment Card Industry Data Security Standard (PCI-DSS Level 1) and operates under Reserve Bank of India (RBI) payment guidelines.

When initiating payment via UPI, Credit/Debit Cards, Net Banking, or Wallets, your financial information is transmitted directly across encrypted SSL/TLS channels to Razorpay. Razorpay's handling of transaction data is governed by the Razorpay Privacy Policy.

05 Cookies & Tracking Technologies

We use browser cookies and local storage tokens exclusively to deliver essential website functionality and improve your user experience:

Category Purpose Requirement
Essential Session Cookies User login authentication, active token validation, and CSRF security protection. Strictly Mandatory
Functional & Cart Tokens Persisting selected subscription items in the cart, currency toggle (INR / USD), and promo codes. Functional
Security & CDN Telemetry Mitigating DDoS attacks, load balancing, and rate limiting via Cloudflare. Strictly Mandatory

You can configure your browser to decline non-essential cookies. However, disabling session storage may prevent you from logging into your dashboard or completing checkout.

06 Data Retention & Security Safeguards

We retain personal and business records only for as long as necessary to fulfill the purposes for which they were collected or to comply with statutory legal and tax obligations:

  • Active Subscription & Profile Data: Retained throughout the duration of your active client engagement.
  • Billing & Invoicing Records: Preserved for up to seven (7) years in compliance with Indian GST, taxation, and company accounting regulations.
  • Instance Credentials & Ephemeral Data: Sandbox instance passwords, access credentials, and temporary provisioning artifacts are purged within 30–90 days following subscription expiration or non-renewal.
  • Technical Access Logs: Retained for rolling periods of 90 to 180 days for automated threat detection and audit compliance.

We implement industry-standard physical, organizational, and electronic safeguards, including HTTPS TLS 1.3 encryption in transit, strict role-based access control, firewall isolation, and scheduled vulnerability assessments.

07 Your Rights & Choices

Under applicable data protection legislation (including the Digital Personal Data Protection Act, 2023), you possess the following rights regarding your personal information:

Right to Access & Review

Request a summary of the personal data we hold about you and copies of your invoices.

Right to Rectification

Update inaccurate, incomplete, or outdated profile information in your dashboard or via support.

Right to Erasure

Request permanent deletion of your account, subject to mandatory tax retention mandates.

Right to Withdraw Consent

Opt out of promotional communications at any time by contacting our support team.

To exercise any of these rights, email us directly at support@onestopERP.com. We respond to verified requests within thirty (30) days.

08 Third-Party Services & Infrastructure

To deliver high-availability cloud instances and smooth web operations, we work with trusted enterprise vendors bound by strict confidentiality obligations:

  • Razorpay Software Private Limited: Secure Indian payment gateway handling UPI, credit/debit cards, and netbanking transactions.
  • Cloudflare, Inc.: Global Content Delivery Network (CDN), Web Application Firewall (WAF), and DDoS protection provider.
  • Cloud Hosting & Data Center Facilities: Enterprise-grade hosting partners providing underlying bare-metal compute and hypervisor infrastructure.
  • Transactional Email Gateways: Dispatching order confirmations, invoice attachments, and reset links securely.

We do not sell, rent, trade, or monetize your personal or business data to third-party advertisers or data brokers under any circumstances.

09 Changes to This Policy

We may update this Privacy Policy periodically to reflect enhancements in our cloud infrastructure, service portfolio, or changes in legal regulations. When material revisions are posted, the "Last updated" date at the top of this document will be revised accordingly.

We encourage users to periodically review this page to stay informed of our latest privacy and security practices. Continued usage of our website or instances after any modifications constitutes acceptance of the updated terms.

10 Contact Us & Grievance Redressal

For inquiries, clarification, or grievances concerning this Privacy Policy or our data handling practices, please contact our designated support and grievance desk:

support_agent

onestopERP Privacy & Grievance Desk

Direct Customer Care & Compliance Office

Direct Phone / WhatsApp

+91 93154 04424

Support Timings

Mon to Sat, 9:00 AM to 9:00 PM IST

Official Domain

onestoperp.com