Privacy Policy — Karoobar

Last updated: September 3, 2026

This Privacy Policy explains how BuildUnic (“we,” “us,” “our”) collects, uses, stores, and protects information through the Karoobar mobile application (“App”), the Karoobar web ordering pages, and related services (together, the “Service”).

By using Karoobar, you agree to the practices described in this policy. If you do not agree, please do not use the Service.

1. Who This Policy Covers

Karoobar is a business tool used by shop owners (“Shop Owners,” “you,” “your account”) to manage billing, inventory, staff, customers, orders, and expenses for their retail business. It also includes web pages where a Shop Owner’s own customers can browse that shop’s catalogue and place an order.

Roles

  • You (the Shop Owner) are the data controller for information about your own customers, staff, and suppliers that you enter into the Service (for example a customer’s name, phone number, and credit/khata balance). You are responsible for having the appropriate consent from those people to store their information in a business record-keeping tool like Karoobar.
  • We (BuildUnic) act as the data processor / service provider that stores and processes this data on your behalf, using the safeguards described below.
  • Customers who place a web order submit their details directly to the Shop Owner through our Service; we process those details on the Shop Owner’s behalf.

This policy describes all three: (a) what we collect directly from you as our app user, (b) how we handle data you input about your business, customers, and staff, and (c) what a customer submits when placing a web order.

2. Information We Collect

2.1 Account & business information

  • Shop Owner name, phone number, email address (optional), and shop/business details — business name, address, shop category, GSTIN and UPI ID if provided — entered at signup or in settings.
  • We verify your phone number by sending a one-time password (OTP) over SMS. Login for Shop Owners is phone + OTP based.
  • Staff accounts you create (name, username, assigned role and module permissions). Staff sign in with a username and password; passwords are stored only as a salted hash and are never visible to us in plain text.
  • A device identifier / device details and a push-notification token for each signed-in device, so we can deliver notifications and keep your session secure.

2.2 Customer data you enter

  • Customer names, phone numbers, purchase history, and credit/khata balances and repayments that you record while using the billing and credit-tracking features.

2.3 Customer data from web orders

  • When a customer places an order through a shop’s Karoobar ordering link or QR code, we collect the name, mobile number, and an optional delivery note they enter, along with the items and amount of that order. This is shared with the Shop Owner so they can fulfil the order.

2.4 Product & inventory data

  • Product names, prices, cost prices, stock quantities, units, barcodes, images, and category-specific details (including IMEI / serial numbers for electronics products) that you or your staff enter, scan, or import.

2.5 Billing, order & transaction data

  • Bills and invoices generated, order records, payment records, refunds, expense entries, and payroll/salary records (staff advances, bonuses, leave, salary payments) you create within the Service.

2.6 Subscription & payment data

  • If you subscribe to a paid (Pro) plan, payment is processed by our payment partner Cashfree. We share your name, phone number, and email (if provided) with Cashfree to set up the subscription. We do not store your full card, UPI, or bank account credentials — Cashfree collects those directly and shares only the transaction status and reference with us.

2.7 Device permissions & media

  • Camera: used for barcode / product scanning, IMEI / serial-number scanning, and photographing purchase bills for AI-assisted inventory entry. Product images and other photos you choose to attach are uploaded to our secure cloud storage (Cloudflare R2). A purchase-bill photo is sent for AI extraction and is not stored (see Section 3).
  • Microphone: used only when you actively start a voice entry (for example, speaking an order). Audio is recorded only while you are using that feature and is processed as described in Section 3 — it is not recorded in the background.
  • Photos & files: used so you can attach images (product photos, bill photos) or import a product list (for example a CSV/Excel file) from your device.
  • Notifications: used to send you app notifications (such as low-stock alerts, staff payment reminders, subscription and order updates). Delivery uses your device’s push token via Firebase Cloud Messaging (Google).

2.8 Technical & usage data

  • Device type, operating system and app version, preferred language, and server-side request logs (including the API endpoint, timing, and — for troubleshooting — parts of a request or response) that we keep to operate, secure, and debug the Service.
  • We do not use a third-party analytics or crash-reporting SDK (such as Firebase Analytics, Crashlytics, or similar) in the App. Firebase is used only for push notifications.

3. AI Features and How Your Data Is Processed

Karoobar uses artificial intelligence to reduce manual data entry. Specifically:

  • Purchase-bill photo → inventory extraction: when you photograph a purchase bill, the image is sent to OpenAI (a vision model) to extract product names, quantities, and prices, which help you quickly add items to your inventory. The image is processed in memory only — it is not saved to our cloud storage, our servers’ disks, or our database.
  • Voice entry → text: when you use a voice feature, the recorded audio is uploaded to our server and sent to OpenAI and/or Groq for speech-to-text transcription. The audio itself is discarded after transcription; the resulting text transcript and the matched items are kept in a voice-order log so the feature can be improved and usage limits enforced.
  • Business insights & reports: to generate periodic sales insights and reports, a summary of your shop’s sales and inventory data is sent to Groq. Depending on the report, this summary can include customer names and their outstanding credit/khata balances (for example, to flag a customer nearing their credit limit).
  • Product-page understanding: when the barcode lookup falls back to a web search (see Section 4), text from candidate product pages is sent to Groq to fill in missing product fields.

Data sent to these providers is used to generate the requested output for your use within the Service. We do not knowingly permit these providers to use your data to train their general models beyond what is described in their own standard API terms. These third parties are independently responsible for their own data handling once information is transmitted to them; we encourage you to review OpenAI’s and Groq’s own API data-usage policies.

International data transfer notice: OpenAI and Groq operate infrastructure outside India (including in the United States). Using these AI features means the relevant data may be processed on servers located outside India.

4. Barcode and Product Lookup

When you scan a product barcode, the barcode number (not any personal data) is sent to a chain of third-party product databases so we can fetch the product’s name, image, and specifications: Open Food Facts, Open Beauty Facts, Open Products Facts, UPCitemdb, eBay, UPCDatabase.org, go-upc, and Barcode Lookup.

If none of those return a match and your Shop Owner account has the feature enabled, we may additionally search the public web for that barcode (via Brave Search and/or DuckDuckGo) and fetch a few candidate product pages to extract structured product details. Again, only the barcode is transmitted — no customer or account data.

5. Third-Party Service Providers

We share limited data with the following service providers, solely to operate the features described:

ProviderPurposeData involved
Cloudflare R2Cloud file storageProduct images, bill photos, generated PDF invoices and payslips
CashfreePayment processing for Pro subscriptionsName, phone, email, and transaction status (not full card / UPI / bank data)
Message CentralSending login OTP codes over SMSMobile number and the OTP
Firebase Cloud Messaging (Google)Delivering push notificationsDevice push token and notification content
Sandbox (sandbox.co.in)Verifying a GSTIN you enter during onboardingThe GSTIN; returns the registered legal name, status, and state
OpenAIBill-photo extraction and voice transcriptionPurchase-bill images, voice audio (not retained by us)
GroqVoice transcription, item extraction, business insightsVoice/text transcripts, sales summaries (which may include customer names and credit balances)
Product barcode databasesLooking up a scanned barcodeThe barcode number only (see Section 4)
Google AdMobBanner ads on the Free tierAdvertising identifiers, as governed by Google’s AdMob privacy practices

PDF invoices and payslips are generated on our own servers — no third-party PDF service is used.

We do not sell your personal data or your customers’ data to third parties for advertising or any other purpose.

6. How We Use Information

We use collected information to:

  • Provide, operate, and maintain the Service’s billing, inventory, staff, orders, expense, and reporting features.
  • Verify your identity at login and keep your account secure.
  • Process your subscription payments.
  • Send you service-related notifications (stock alerts, payment reminders, subscription and order updates).
  • Improve app performance, understand feature usage, and fix issues.
  • Comply with legal obligations, including tax / GST record-keeping requirements applicable to invoicing software.

7. Data Retention

We retain your account, business, and transaction data for as long as your account remains active, and for a reasonable period afterward as required for legitimate business, tax, or legal record-keeping purposes. Financial records such as bills and invoices may be retained for up to 7 years to meet accounting and GST requirements.

You may request deletion of your account and associated data as described in our Data Deletion Policy and Section 9 below, subject to any statutory retention requirements.

8. Data Security

We use industry-standard measures — including encrypted data transmission, hashed storage of staff passwords, secrets kept in secure device storage, access controls tied to staff role permissions, rate limiting, and secure cloud storage — to protect the data you store with us. However, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.

9. Your Rights

Depending on applicable law (including India’s Digital Personal Data Protection Act, 2023), you may have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and associated data.
  • Withdraw consent for optional features (for example AI photo extraction or voice input) at any time by not using those features.

To exercise these rights, contact us at tarunlohar@buildunic.com. You can also delete your account from within the App (Profile / Settings → Delete Account).

If you are a Shop Owner and wish to delete a customer’s data at their request, you can do so directly within the App’s customer management screen, or contact us for assistance.

10. Children's Privacy

Karoobar is a business tool intended for shop owners and staff who are adults. We do not knowingly collect personal information from individuals under 18 years of age.

11. Advertising

Free-tier users may see banner advertisements served through Google AdMob. AdMob may use advertising identifiers to serve ads; you can manage ad personalization through your device settings (on Android: Settings → Privacy → Ads). Pro subscribers do not see ads.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date, and material changes will be notified within the App where appropriate.

13. Grievance Officer / Contact Us

In accordance with applicable Indian regulations, you may direct privacy-related questions, concerns, or grievances to:

BuildUnic

Email: tarunlohar@buildunic.com

Address: Triveni nagar railway station road kankroli rajsamand

14. Governing Law

This Privacy Policy is governed by the laws of India.

Questions about this policy? Email tarunlohar@buildunic.com.