LEGAL
Privacy Policy
Last updated: January 1, 2026 · Effective: January 1, 2026
TABLE OF CONTENTS
- Information We Collect
- How We Use Your Data
- Data Storage & Security
- Sharing Your Information
- Cookies & Tracking
- Your Rights
- Data Retention
- Children's Privacy
- Changes to This Policy
- Contact Us
Summary: HishabX is committed to protecting your business data. We collect only what is necessary, never sell your data, and give you full control at all times.
01 Information We Collect
We collect information you provide directly when you register, use our POS or ERP services, or interact with any part of the HishabX platform.
- Account Information: Business name, owner name, email address, phone number, and billing address.
- Business Data: Transaction records, inventory data, customer lists, employee records, and financial reports.
- Device & Usage Data: IP address, browser type, operating system, pages visited, and feature usage patterns.
- Payment Information: Billing details processed securely. We never store full card numbers on our servers.
- Support Communications: Messages, emails, and chat logs when you contact our support team.
02 How We Use Your Data
Your data is used solely to deliver, maintain, and improve HishabX services. Specifically, we use your information to:
- Provide, operate, and maintain your HishabX account and all associated features.
- Process transactions and send billing notices, receipts, and renewal reminders.
- Send important service announcements, security alerts, and support messages.
- Analyze usage trends to improve software features and user experience.
- Detect, prevent, and respond to technical issues, fraud, and security incidents.
- Comply with legal obligations under Bangladesh law and applicable regulations.
We do not use your business data for advertising purposes. We do not sell, rent, or trade your personal or business information to any third party for marketing.
03 Data Storage & Security
All data stored on HishabX servers is protected using industry-standard security measures.
- Encryption: All data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256.
- Cloud Infrastructure: Stored on secure cloud servers with automated daily backups and geographic redundancy.
- Access Control: Strict role-based access controls ensure only authorised personnel can access your data.
- Security Audits: We conduct regular security audits and vulnerability assessments.
- Uptime: We maintain a 99.9% uptime guarantee backed by our monitoring systems.
04 Sharing Your Information
We do not sell or rent your personal information. We may share your data only in the following limited circumstances:
- Service Providers: Trusted third-party vendors who assist us, bound by strict confidentiality agreements.
- Legal Requirements: When required by Bangladesh law, court order, or government authority.
- Business Transfer: In the event of a merger or acquisition, with prior notice to you.
- With Your Consent: In any other case, only with your explicit written consent.
05 Cookies & Tracking
HishabX uses cookies and similar tracking technologies to enhance your experience on our platform.
- Essential Cookies: Required for the platform to function — login sessions, security tokens, and preferences.
- Analytics Cookies: Help us understand how users interact with HishabX. This data is anonymised.
- Preference Cookies: Remember your language, theme, and display settings.
You can control cookie settings through your browser. Disabling essential cookies may affect platform functionality.
06 Your Rights
As a HishabX user, you have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you at any time.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data, subject to legal retention requirements.
- Portability: Request an export of your business data in a standard format (CSV, JSON).
- Objection: Object to certain types of data processing where we rely on legitimate interests.
- Withdrawal: Withdraw consent for any data processing where consent is the legal basis.
To exercise any of these rights, please contact us at info@hishabx.com. We will respond within 30 business days.
07 Data Retention
We retain your data for as long as your account is active or as needed to provide services. Specifically:
- Account and transaction data is retained for the duration of your subscription plus 5 years to comply with financial regulations.
- Support communications are retained for 3 years.
- Upon account deletion, personal data is permanently deleted within 90 days, except where legal retention requirements apply.
- Anonymised, aggregated analytics data may be retained indefinitely as it cannot be linked to any individual.
08 Children's Privacy
HishabX is a business software platform intended for use by adults and registered businesses. Our services are not directed at individuals under the age of 18.
We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, please contact us immediately at info@hishabx.com and we will promptly delete such information.
09 Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. When we make significant changes, we will:
- Update the "Last Updated" date at the top of this page.
- Send an email notification to the primary account holder.
- Display a prominent notice within the HishabX dashboard for 30 days.
Your continued use of HishabX after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
10 Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please reach out to us:
- Email: info@hishabx.com
- Phone: +8801XXXXXXXXX
- Address: Bangladesh
- Response Time: We aim to respond to all privacy-related inquiries within 5 business days.