Privacy Policy

Last updated

This explains what EzyBook collects, why, who can see it and where it is kept. There are two distinct things at play: the small amount of information we hold about you as our customer, and the business records you keep inside your own workspace. They are treated very differently, and clause 3 explains why.

1.Who is responsible

EzyBook, India, is responsible for the personal data described here. Indian data-protection law calls that role the data fiduciary — it means the decisions about what is collected and why are ours to answer for, not our suppliers’.

For anything in this policy, to raise a grievance, or to exercise any right in clause 9, email info@procraft.ae. That address is our grievance contact and reaches a person.

2.What we collect

When you visit this website. Your browser sends an IP address and basic device information. If you accept analytics cookies we also record which pages you viewed, to understand what people read. Decline, and no analytics cookie is set.

When you contact us. Whatever you put in the form or email — typically your name, business, email address and your question.

When you create a workspace. Your business name, your name, email address, phone number and country. If you later subscribe, the billing details needed to invoice you: legal entity name, address and, if you have one, your tax registration number. We do not see or store card numbers — those go directly to our payment provider.

While you use the service. Sign-in times and IP addresses, and an audit record of changes made in your workspace, showing which user made each change and when. This is a security feature, visible to you inside the product.

We do not buy personal data from anyone, and we do not build advertising profiles.

3.Your business records are different

The data you put into the product — your customers, suppliers, employees, invoices and ledger — belongs to you. Where it contains personal data about other people, you decide what is collected and why. We only hold and process it so the software works for you.

In data-protection language: for our own customer records we are the controller; for the contents of your workspace we act on your instructions. We do not use your business records for our own purposes, do not sell or share them, and do not use them to train machine-learning models.

If you record personal data about your own customers or staff, telling those people how you use it is your responsibility, not ours.

4.Why we hold it

To provide the service you asked for, and to keep your account working.

To take payment, issue invoices and keep the accounting records the law requires.

To reach you about your own account — a trial ending, a failed payment, a change to these documents, a security issue. You cannot opt out of these while you hold an account, because they concern the service you are paying for. Marketing email is separate and only sent if you ask for it.

To keep the service secure, investigate misuse and fix faults.

5.Who can see it

You and the people you invite. What each of them can see is controlled by the permissions you set.

Us, in two specific ways. A small number of our staff can reach the servers to operate and support the service.

And a vendor administrator account exists on every workspace, including yours. It is created automatically when a workspace is built and is how we provide support, apply fixes and recover accounts. You can see it in your own user list. We use it to operate the service and to help you — not to read your business for any other purpose — and anything it does is written to the same audit log you can read. If your business cannot accept a vendor account, tell us before you subscribe so we can discuss whether we can serve you.

6.Companies we rely on

Running the service needs a few others, each with a defined role:

  • Hostinger — the servers your workspace and database run on.
  • Razorpay — takes card, UPI, netbanking and wallet payments from customers in India, and holds the payment details we never see.
  • Stripe — takes card payments from customers in the UAE, and holds the payment details we never see.
  • Google Analytics — website usage statistics, only if you accept analytics cookies.
  • Shopify — only if you switch on the Shopify module, in which case your product, price and stock data is sent to your own Shopify store, and paid orders come back. That is the feature; turning it off stops the exchange.

We do not give your data to anyone else, unless the law requires it. If we are ever compelled to, we will tell you unless we are legally prevented from doing so.

7.Where your data is stored

Our servers are operated by Hostinger and are physically located in Kuala Lumpur, Malaysia. We are an Indian company, you may be trading in the UAE, and your records sit in neither — so your data leaves the country you are in. Indian law permits that transfer; we state it because you should not have to guess.

Payment data for Indian customers is processed by Razorpay in India, and for UAE customers by Stripe. If you enable Shopify, data also reaches Shopify’s infrastructure.

If your business requires data to remain in a particular country, contact us before subscribing — do not assume it.

8.How long we keep it

Your workspace data is kept while your subscription is live. After non-payment or cancellation it survives the read-only and suspension periods described in our Terms of Service — at least fourteen days, during which you can still export — and is then permanently deleted along with its database.

Invoices and payment records are kept for as long as tax and company law requires — under Indian company law that is eight years, longer than the five a UAE business would keep — even after your account closes. Website analytics are kept for fourteen months. Enquiries you send us are kept for two years unless you ask us to delete them sooner.

9.Your rights

You can ask us for a copy of the personal data we hold about you, to correct it if it is wrong, to delete it, or to object to a particular use. You can export your workspace data yourself at any time, without asking.

Email info@procraft.ae. We reply within 30 days. If you are unhappy with our answer you can complain to the Data Protection Board of India, or to the data-protection authority where you live.

Where a request concerns personal data inside a customer’s workspace, we will pass it to that customer, because it is theirs to answer.

10.Cookies

This site sets only what it needs to work, plus analytics if you accept them. You choose when the banner first appears and can change your mind at any time by clearing this site’s cookies. Declining changes nothing about how the site behaves.

Inside the product, cookies keep you signed in. Those are essential — the app cannot work without them — and are not used for tracking.

11.Security

Every workspace has its own separate database, so one customer’s records are never in the same table as another’s. Traffic is encrypted in transit, passwords are stored hashed, and access is controlled by the permissions you set. Changes are audit-logged with user, time and IP address.

No system is perfectly secure. If a breach affects your data, we will tell you promptly and explain what happened and what we are doing about it.

12.Changes to this policy

We will update this page as the service changes, and the date at the top is always the current version. For a change that materially affects how we handle your personal data, we will email you before it takes effect.

Back to home