Privacy Policy
How GoDelight Technologies collects, uses, shares and protects information across our website, ERP platforms and mobile applications.
In brief
What we collect
Account, business, transaction and usage data needed to run our website and ERP Services.
Why we use it
To deliver the Services, keep you informed and support GST-compliant business operations.
Who sees it
Trusted service providers, government systems like the GST portal, and platforms you choose to connect.
Your rights
Access, correct or erase your data, and raise concerns with our Grievance Officer.
How we protect it
Encryption, role-based access and audit trails — the same discipline built into GoDelight ERP.
What we don't do
We do not sell your personal data to third parties for their own marketing.
Introduction & scope
GoDelight Technologies ("GoDelight," "we," "us," or "our") has spent 15 years building ERP software for Retail, Restaurant and Distribution businesses, and today supports 5,000+ daily users across 200+ Indian cities. This Privacy Policy explains how we collect, use, share and protect information when you:
- visit our website;
- request a demo, contact our sales or support team, or apply for a job with us;
- use GoDelight's ERP platforms and companion apps — including WhatsNow, GoAct, GoBill, ServJoy, GoContactless, GoSales, and our Mobile POS, Business Intelligence, Delivery Management, StockTake, GRN, StockPick and StockRefill applications — as an authorized user of a business that licenses our Services; or
- interact with a GoDelight business client as an end consumer — for example, by receiving a digital receipt, joining a loyalty programme, or ordering through a QR-code menu.
This Policy is drafted with reference to the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (together, the "DPDPA"), currently being phased into force in India through 2027, as well as the Information Technology Act, 2000 and rules made under it. Under the DPDPA, an individual is a "Data Principal" and the entity that decides why and how personal data is processed is a "Data Fiduciary." Where a GoDelight business client determines how its own customers' data is used, that client acts as the Data Fiduciary for that data, and GoDelight processes it on the client's instructions.
Information we collect
2.1 Information you give us directly
- Contact details — name, email, phone number, business name, designation and company address, when you request a demo, contact us or subscribe to updates.
- Account information — login credentials, role and permissions when your organization sets you up as an authorized user of GoDelight ERP.
- Business & transaction data — entries your organization makes within GoDelight ERP, such as invoices, GSTIN details, purchase orders, inventory records, and customer or vendor records. This data belongs to your organization; GoDelight processes it as a service provider to deliver the Services.
- Application content — information submitted through job applications, support tickets or contact forms.
2.2 Information collected automatically
- Website usage data — IP address, browser and device type, pages viewed, referring pages and approximate location, collected through cookies and similar technologies (Section 06).
- App & product usage data — login times, feature usage, crash reports and diagnostic data from our web and mobile applications.
- Device information — device identifiers, operating system, app version and data about Bluetooth-paired peripherals (such as barcode scanners and receipt printers) used with our POS apps.
2.3 Location data
Field-facing apps — including GoSales and the Delivery Management App — collect GPS location from authorized field representatives and delivery personnel, for route planning, live tracking, geo-fenced beat management and proof of delivery. This is collected only on devices used for work purposes and as configured by the business client.
2.4 Information relating to end consumers of our business clients
Where a business client uses features such as digital WhatsApp/SMS receipts, loyalty programmes, online ordering or GoContactless QR ordering, we may process end-consumer information — such as name, phone number, email, purchase history and delivery address — on that business's instructions, strictly to operate the relevant feature.
2.5 Financial & payment information
Transaction amounts, GST invoice data and payment references needed for billing and GST compliance (e-Invoicing, e-Way Bills and GSTR filings). Where third-party payment gateways are used, GoDelight does not store full card numbers or payment credentials — these are handled directly by our payment partners.
How we use your information
- To provide, operate and maintain our website and the GoDelight ERP Services and apps.
- To process billing and generate GST-compliant invoices, e-Way Bills and e-Invoices, and prepare GSTR-1/3B/2A/2B filings on behalf of business clients.
- To respond to enquiries, schedule demos and provide customer support.
- To send service updates, security notices and — where you've agreed — marketing communications, which you can opt out of at any time.
- To operate features business clients configure for their own customers, such as digital receipts, loyalty messaging and order notifications.
- To improve our products, understand usage patterns and troubleshoot issues.
- To detect, prevent and investigate fraud, misuse or security incidents.
- To comply with applicable law, including tax, accounting and audit-trail requirements — the same MCA digital audit-trail discipline our ERP itself helps clients maintain.
Legal basis for processing
We process personal data on one or more grounds recognized under the DPDPA: your consent; performance of a contract with you or your organization; compliance with a legal obligation (such as GST or accounting record-keeping); and other legitimate uses recognized under the DPDPA, such as data you voluntarily provide for a specified purpose (for example, submitting a contact form). Where we rely on consent, you may withdraw it at any time as described in Section 09, without affecting processing already carried out.
How we share your information
We do not sell personal data to third parties for their own independent marketing. We may share information with:
- Group entities and personnel, on a need-to-know basis, to operate our business.
- Service providers who support us — cloud hosting, SMS/WhatsApp Business API providers, email delivery, analytics and payment gateway partners — bound by contractual confidentiality and data-protection obligations.
- Government & regulatory systems, where necessary to deliver Services — for example, the GST Invoice Registration Portal (IRP) for e-Invoicing, the e-Way Bill system, and GSTN for GSTR filings, acting on the instructions of the relevant business client.
- Online aggregator & delivery platforms (such as Swiggy, Zomato and ONDC), only where a restaurant client enables such an integration, to sync menu and order data.
- Principal ERP systems (such as SAP, Oracle or Tally) via EDI, only where a distribution client configures such an integration.
- Professional advisors and authorities, where required to comply with law, respond to a valid legal request, or protect the rights, property or safety of GoDelight, our clients or others.
- A successor entity, in the event of a merger, acquisition or sale of assets, with notice to you where required by law.
Cookies & similar technologies
Our website uses cookies and similar technologies to keep the site working correctly, remember your preferences and understand how visitors use our site. You can control or disable cookies through your browser settings; disabling some cookies may affect site functionality.
We use the following broad categories of cookies:
- Strictly necessary — required for core site functionality such as page navigation, secure login and session management. These cannot be switched off in our systems.
- Functional — remember choices you make (such as language, region or preferred layout) so we can offer a more personalised experience.
- Analytics — help us understand how visitors move through the site so we can improve performance, content and navigation. Data is aggregated and does not identify you personally.
- Marketing — used with your consent to measure the reach of our campaigns and, where enabled, deliver relevant content across other platforms.
On your first visit you will see a consent banner where you can accept, reject or customise non-essential cookie categories. You can revisit and change these choices at any time from the "Cookie settings" link in our website footer.
Data security
We apply administrative, technical and physical safeguards designed to protect personal data, including encryption of data in transit, role-based access controls and audit trails — the same principles of access control and accountability we build into GoDelight ERP for our clients. No system can be guaranteed 100% secure. We investigate and respond to security incidents in accordance with applicable law, including notifying the Data Protection Board of India and affected individuals of qualifying breaches without undue delay, where required under the DPDPA.
Data retention
We retain personal data only as long as necessary for the purposes described in this Policy, or as required by applicable law — for example, financial, tax and audit-trail records are retained for the periods mandated under Indian tax and corporate law. When data is no longer needed, we securely delete or anonymize it.
Your rights as a Data Principal
Subject to applicable law and its phased implementation, you may have the right to:
- be informed about what personal data we process and why;
- access a summary of your personal data and the processing activities we carry out;
- request correction or updating of inaccurate or incomplete data;
- request erasure of personal data no longer needed for the purpose it was collected;
- withdraw consent at any time, where processing is based on consent;
- nominate another individual to exercise your rights in the event of death or incapacity; and
- register a grievance with us and, if unresolved, escalate it to the Data Protection Board of India.
To exercise these rights, contact us using the details in Section 14. We may need to verify your identity before acting on a request.
Children's privacy
Our website and Services are intended for business use and are not directed at children. Under the DPDPA, anyone under 18 is treated as a child, and processing a child's personal data requires verifiable parental or guardian consent; we do not knowingly track, profile or serve targeted advertising to children. If you believe we have inadvertently collected a child's personal data without appropriate consent, please contact us so we can address it.
Cross-border data transfers
We may store or process personal data on servers located outside India through our hosting and service providers. The DPDPA permits such transfers except to countries or territories specifically restricted by the Central Government by notification. Where data is transferred internationally, we require our service providers to apply protections consistent with this Policy and applicable law.
Third-party links & integrations
Our website and Services may link to, or integrate with, third-party platforms — such as payment gateways, online-ordering aggregators or social media pages — that we don't control. This Policy doesn't cover those third parties; we encourage you to review their own privacy policies.
Changes to this policy
We may update this Policy from time to time to reflect changes in our practices or in applicable law. We will post the revised Policy on this page with an updated "Last reviewed" date, and where changes are material, we will provide additional notice as required by law.
Grievance officer & contact
For questions, requests, or grievances about this Policy or our handling of personal data, please contact our Grievance Officer, appointed in accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023:
Governing law & jurisdiction
This Policy is governed by the laws of India. Any disputes arising out of or in connection with this Policy will be subject to the exclusive jurisdiction of the courts at Mumbai, India.
Note: This Privacy Policy is drafted with reference to the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025 and the Information Technology Act, 2000. DPDPA obligations are being phased in through 2027; we will update this Policy as those requirements come into force.
© 2026 GoDelight Technologies Pvt. Ltd. All rights reserved.
