1. Who we are
Yukes Retail POS operates Yukes Retail, a software service for billing, customer management, inventory, reporting, and multi-shop administration. In this policy, “Yukes Retail,” “we,” “us,” and “our” refer to the operator of the Yukes Retail service.
For privacy questions or requests, contact yukesapparels@gmail.com. Our contact location is Coimbatore, Tamil Nadu, India.
2. Information we collect
- Account information: name, work email, phone number, Firebase identifier, assigned shop, role, permissions, and account status.
- Shop information: business name, owner and contact details, billing address, GST or other tax registration information, invoice settings, and message templates.
- Retail records: products, images, SKUs, barcodes, inventory, prices, taxes, customers, invoices, line items, payment status, and profit calculations.
- Customer information entered by shops: names, phone and WhatsApp numbers, email addresses, purchase history, and invoice delivery status.
- Security and usage information: sign-in and session information, actions recorded in audit logs, timestamps, delivery-provider responses, and basic technical request data needed to secure and operate the service.
3. Google and Gmail API data
Yukes Retail uses the Gmail API only to send transactional invoice emails requested by an authorized Yukes Retail user. The application calls the Gmail messages.send function through a designated Gmail account connected by the service operator.
For this feature, Yukes Retail uses Gmail send authorization, an OAuth access token, a securely stored refresh token, the connected sender email address, the recipient address, and the invoice email subject and body. We do not use the Gmail integration to read inbox messages, contacts, received-message bodies, or mailbox history.
Google OAuth credentials and refresh tokens are stored as restricted server-side secrets and are never exposed in the browser. Short-lived access tokens may be held in server memory until they expire. We store the resulting Gmail message identifier and delivery response only as needed to record whether an invoice was sent and to troubleshoot delivery.
We do not sell Google user data, use it for advertising, build advertising profiles from it, or allow people to inspect it except when required for security, support, legal compliance, or operation of the invoice-email feature. Yukes Retail’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
4. How we use information
- Authenticate users and enforce shop, role, and permission boundaries.
- Create invoices, maintain customer and product records, calculate tax and profit, and manage inventory.
- Send invoice messages through Gmail or WhatsApp when an authorized user requests delivery.
- Provide dashboards, exports, audit trails, account support, fraud prevention, and service security.
- Meet accounting, tax, contractual, and other legal obligations.
5. When we share information
We share information only as needed with infrastructure and integration providers that help operate Yukes Retail, such as Firebase for authentication, Supabase for application data and file storage, Vercel for application hosting, Google for Gmail delivery, and Meta when a shop sends an invoice through WhatsApp. These providers process data under their own terms and privacy commitments.
We may also disclose information when required by law, to protect users or the service, in connection with a business reorganization, or when the relevant user or shop has instructed or consented to the disclosure. We do not sell personal information.
6. Tenant and customer responsibilities
Each shop controls the customer and retail information its authorized users enter into Yukes Retail. Shops must have a lawful basis and provide any notices or obtain any permissions required before collecting customer details or sending messages. Customers should contact the relevant shop first about invoice or purchase records.
7. Retention and deletion
We retain account, invoice, audit, and retail records for the period configured for the service and for as long as needed to provide Yukes Retail, satisfy tax or accounting requirements, resolve disputes, and maintain security. OAuth access tokens expire automatically; the Gmail refresh token remains until the connection is revoked or the integration is removed.
You may request access, correction, export, or deletion by contacting yukesapparels@gmail.com. We will verify the request and normally respond within 30 days. Some records may be retained where law, fraud prevention, security, or legitimate accounting needs require it. Google users can also revoke Yukes Retail’s access from their Google Account permissions.
8. Security
We use encrypted HTTPS connections, server-side secret storage, authenticated sessions, role-based permissions, tenant scoping, and audit logging. No system is completely secure, so users must protect passwords, devices, and administrator access and promptly report suspected misuse.
9. International processing and children
Our service providers may process information in countries other than the user’s location. We use Yukes Retail for business operations and do not knowingly offer it directly to children or collect children’s personal information.
10. Changes to this policy
We may update this policy as Yukes Retail or legal requirements change. We will update the date above and provide additional notice where a material change affects how we use personal or Google user data.
11. Contact
Privacy requests and questions may be sent to yukesapparels@gmail.com.
