Legal
Privacy policy
How Gobazo handles personal data in the Gobazo platform — what we collect, why, who sees it, how long we keep it, and how to get it deleted.
Last updated: 21 July 2026
1. Who we are
Gobazo builds and operates business software for
retail chains. This policy covers the Gobazo application, the
gobazo.com website, and the email we send.
Operator (data controller): Consenko Studios Private Limited, B-30, 2nd Floor, Sector-4, Noida, Gautam Buddha Nagar, Uttar Pradesh 201301, India. Contact: support@gobazo.com.
2. Two roles: our data and our customers' data
Gobazo is sold to businesses. That gives us two different responsibilities, and it matters which one applies to you:
- We are the controller for the accounts of people who use Gobazo — their name, work email, role and sign-in activity — and for people who contact us directly. This policy governs that data.
- We are a processor for the business data a customer loads into their own Gobazo instance — sales, stock, suppliers and any customer records they choose to include. That data belongs to the retailer. We handle it only on their written instructions, under our contract with them, and we do not sell it, mine it for our own purposes, or use it to train models for anyone else. If you are a shopper asking about a retailer's records, contact that retailer; we will support them in answering you.
3. What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Account | Name, work email, mobile number, role, team, assigned stores | Entered by an administrator at the customer business, or by you |
| Authentication | Password (stored only as a one-way hash), sign-in and failed-sign-in records, session tokens | Created when you sign in |
| Usage | Actions taken in the app, audit entries, error logs, IP address | Generated as you use the product |
| Communications | Support messages and anything you send us | You |
| Customer business data | Sales, stock, purchase orders and any records the retailer loads | The customer business (we act as processor — see section 2) |
We do not use advertising cookies or third-party trackers on this website, and we do not build advertising profiles.
4. How we use it
- To give you access to the product and keep your account secure.
- To send the transactional email described in section 5.
- To provide support and answer questions you raise.
- To keep the service reliable — diagnosing faults, monitoring capacity.
- To detect and investigate abuse, fraud and security incidents.
- To meet legal and accounting obligations.
Where the GDPR or a similar law applies, our lawful bases are performance of a contract (giving you the service), legitimate interests (security, reliability, support) and legal obligation. We do not rely on consent for transactional mail, and we do not send marketing mail to users.
5. Email
We send transactional email only: invitations, password resets and
sign-in codes, operational alerts, and summaries a user or their
administrator has enabled. Production mail comes from
notifications@gobazo.com, development mail from
dev.notification@gobazo.com, and all of it is DKIM-signed.
We never send marketing email to platform users, never buy or rent mailing lists, and never email an address that an administrator of the relevant business has not entered. Alerts and summaries can be switched off per person in the app; security mail (invitations, resets) is sent only in response to a specific action. Bounces and complaints are processed automatically and the address is suppressed from future sends.
6. Who we share it with
We do not sell personal data. We share it only with:
- Infrastructure providers acting under contract — Amazon Web Services for hosting, sign-in (Amazon Cognito) and email delivery (Amazon SES).
- The customer business you work for, whose administrators can see your account, role and activity within their instance.
- Authorities, where we are legally required to — and we will tell you unless the law forbids it.
Customers running Gobazo on their own servers hold their data themselves; we see it only if they ask us to help.
6a. Google user data (Gmail integration)
Gobazo offers an optional Gmail integration: a customer administrator can
link a Gmail or Google Workspace mailbox so that incoming email is turned
into support tasks. When a mailbox is linked, Gobazo requests the
read-only Gmail scope
(https://www.googleapis.com/auth/gmail.readonly) and uses it
only to read newly arriving messages and create a task from each — the
sender, subject and message text are analysed to classify the request and
route it to the right team. We do not send, modify, label or delete any
mail, and we access only the mailboxes an administrator explicitly links.
Limited Use. Gobazo's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, Gmail data is used only to provide and improve the email-to-task feature visible to you; it is not sold or transferred to third parties, is not used for advertising, and is not used to train generalised AI/ML models. Any automated processing (for example, classifying a message's urgency and team) happens solely to deliver this feature. We do not retain the raw message body beyond the task text derived from it and the delivery log.
You can revoke access at any time by unlinking the mailbox in Gobazo (Tasks → Message Settings) or from your Google Account permissions. Deletion of the data we hold follows our account & data deletion policy.
7. How long we keep it
- Account data — for as long as the account is active.
- After deletion — removed from the live system within 30 days; residual copies in encrypted backups age out within 90 days.
- Security and audit records — up to 12 months, because they are how we investigate incidents.
- Customer business data — kept per our contract with the retailer, and returned or destroyed when it ends.
8. How we protect it
- Encryption in transit (TLS) and at rest.
- Passwords stored only as one-way hashes, never in readable form.
- Managed sign-in via Amazon Cognito, with optional one-time email codes.
- Role-based access control; each tenant's data is isolated.
- Least-privilege internal access, audited.
No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant regulator as the law requires.
9. Your rights
Depending on where you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider. You can also complain to your data protection authority.
Email support@gobazo.com. We reply within 30 days. If the data sits inside a customer's instance we will pass the request to that customer and support them in answering it. See the account and data deletion policy for how deletion works step by step.
10. Where data is stored
Cloud infrastructure runs in Amazon Web Services, primarily the Asia Pacific (Mumbai) region, with some global services such as content delivery and certificate management operating from other regions. Where data crosses borders we rely on the safeguards our providers offer, including standard contractual clauses. On-premise customers keep their data on their own infrastructure.
11. Children
Gobazo is workplace software and is not directed at children. We do not knowingly collect data from anyone under 16; if we learn that we have, we delete it.
12. Changes
If we change this policy we update the date above, and for material changes we notify account holders by email before they take effect.
13. Contact
support@gobazo.com — privacy questions, access and deletion requests, or to ask us to stop emailing an address.