1. Introduction
Maruti Software Solutions ("we," "us," "our," or "Company"), the owner and operator of OptoSoft Optical Retail Software, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the OptoSoft Optical Retail Software web/cloud platform and POS Mobile Application (the "Application") and related services.
Our role: OptoSoft Optical Retail Software is a business-to-business (B2B) platform used by optical retailers. With respect to the account and business information of the optical retailer who subscribes to the Application, we act as a Data Fiduciary under the Digital Personal Data Protection Act, 2023. With respect to the personal data of the retailer's own end-customers that the retailer enters into the Application (such as customer contact details and optical prescription records), the subscribing retailer is the Data Fiduciary and we act as a Data Processor, processing that data solely on the retailer's instructions and on their behalf. Retailers are responsible for obtaining any consent required from their end-customers and for the lawful use of such data.
Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use the Application.
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: Name, email address, phone number, business details, and login credentials
- Payment Information: Bank account and billing details used for subscription payments (we do not collect payment card details)
- Business Data: Sales records, inventory information, customer data, and transaction history
- Sensitive / Prescription Data: Where the retailer uses the relevant features, optical prescription records and related eye-care details (for example, lens power, sphere, cylinder, and axis values) that the retailer enters for its end-customers. We treat such data as sensitive personal data, restrict access to it, and process it only on the retailer's instructions as a Data Processor.
- Communication Data: Messages, feedback, and support requests
2.2 Information Collected Automatically
- Device Information: Device type, operating system version, unique device identifiers, mobile network information
- Usage Data: Features used, actions performed, dates and times of activities, crash reports
- Location Data: Approximate location based on IP address (if location permissions are enabled)
- Analytics Data: App performance metrics, user interactions, and session information
2.3 Third-Party Information
We may receive information from third-party services, including banks and service providers, to enhance and improve our services.
3. How We Use Your Information
We use the information we collect for various purposes, including:
- Providing, maintaining, and improving the Application and related services
- Processing transactions and sending related information
- Sending transactional and promotional communications
- Responding to your inquiries and providing customer support
- Monitoring and analyzing trends, usage, and activities for security and performance
- Detecting, preventing, and addressing fraud, abuse, and security issues
- Complying with legal obligations and enforcing our agreements
- Personalizing and improving user experience
4. How We Share Your Information
4.1 Service Providers
We share your information with third-party service providers who perform services on our behalf, including:
- Banks and financial institutions (for subscription payments)
- Cloud storage and hosting providers
- Analytics and monitoring services
- Customer support platforms
4.2 Legal Requirements
We may disclose your information when required by law, legal process, or government request, or when we believe in good faith that such disclosure is necessary to:
- Comply with applicable laws, regulations, or court orders
- Protect the rights, privacy, safety, or property of our company, users, or the public
- Enforce our Terms and Conditions
4.3 Business Transfers
Your information may be transferred as part of a merger, acquisition, bankruptcy, or sale of assets. We will provide notice before your information becomes subject to a different privacy policy.
4.4 Your Consent
We may share your information with your explicit consent for purposes not covered by this Privacy Policy.
5. Data Security
We implement comprehensive security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using industry-standard protocols (and, where applicable, encryption at rest)
- Secure authentication mechanisms
- Periodic security reviews and vulnerability assessments
- Role-based access controls and user authentication
- We do not collect or store payment card details; subscription payments are made via bank transfer and similar methods
Note: While we strive to protect your information, no security system is impenetrable. We cannot guarantee absolute security of your data. Any transmission of information is at your own risk.
6. Your Privacy Rights
6.1 Access and Control
You have the right to access, correct, or delete your personal information. You can manage your account settings within the Application or contact us for assistance.
6.2 Data Portability
You can export your data using the standard data-export features available within the Application, in a structured, commonly used format. Additional data backups or exports in custom formats are an optional, chargeable service as described in our Terms and Conditions.
6.3 Opt-Out
We send promotional communications only on the basis of the consent you provide (for example, at the time of sign-up). You can withdraw this consent and opt out at any time by clicking the "unsubscribe" link in our emails or adjusting your notification settings in the Application. Transactional and service-related messages are not promotional and may still be sent.
6.4 Indian Data Protection Rights (DPDP Act, 2023)
As the Company is based in India, we process your personal data as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act). You have the right to access, correct, update, and erase your personal data, to withdraw consent at any time, to nominate another individual to exercise your rights on your behalf, and to grievance redressal. If your concern is not resolved, you may lodge a complaint with the Data Protection Board of India. To exercise these rights or raise a grievance, contact our Grievance Officer using the details in Section 13.
6.5 GDPR and Other Regional Rights
If you are located in the European Union or other jurisdictions with data protection laws, you have additional rights, including the right to withdraw consent and the right to lodge a complaint with a supervisory authority.
7. Data Retention
We retain your personal information for as long as necessary to provide our services and fulfill the purposes outlined in this Privacy Policy. You may request deletion of your data, subject to legal retention requirements. Upon termination of your account, you may export your data using the in-application export features within 30 days, after which it may be deleted in line with our retention policy (as set out in our Terms and Conditions). Some data may be retained for legal, tax, or regulatory purposes.
8. Children's Privacy
The Application is a business tool and is not intended to be used directly by children under the age of 18. We do not knowingly create user accounts for children. However, optical retailers using the Application may process the data of their own end-customers who are minors (for example, when fitting children's eyewear). In accordance with the Digital Personal Data Protection Act, 2023, processing the personal data of a child (any individual under 18 years of age) requires verifiable consent from a parent or lawful guardian. Where a retailer enters a minor's personal or prescription data into the Application, the retailer (as Data Fiduciary) is responsible for obtaining such verifiable parental or guardian consent. If we become aware that data has been collected in violation of this requirement, we will take appropriate steps to delete it.
9. Third-Party Links and Services
The Application may contain links to third-party websites and services that are not operated by us. This Privacy Policy does not apply to third-party services, and we are not responsible for their privacy practices. We encourage you to review their privacy policies before providing any information.
10. Cookies and Tracking Technologies
We use cookies, local storage, and similar tracking technologies to:
- Maintain your session and remember your preferences
- Analyze usage patterns and improve the Application
- Deliver and personalize relevant in-app content
- Detect and prevent fraud
When you first visit our website, a cookie consent banner lets you accept or reject non-essential (analytics) cookies. Analytics cookies, including Google Analytics, are set only after you give consent. You can change or withdraw your choice at any time using the "Cookie Preferences" link in the website footer, or by adjusting cookie settings in your device and browser. Disabling essential cookies may affect the Application's functionality.
11. International Data Transfers
Your data is primarily stored and processed on servers located in India. Where information is transferred to, stored in, or processed in other countries, such transfers are made in compliance with the Digital Personal Data Protection Act, 2023 — including any restrictions notified by the Government of India on transfers to specific countries — and applicable data protection laws. We take reasonable steps to ensure your data receives an adequate level of protection wherever it is processed.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The "Last Updated" date at the bottom of this page indicates when the policy was last modified. Your continued use of the Application following notification of changes constitutes your acceptance of the updated Privacy Policy.
13. Contact Us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about our privacy practices, please contact us:
Maruti Software Solutions
Product: OptoSoft Optical Retail Software
Grievance Officer: Hitarth Pandya — hitarth@optosoft.in (please use the subject "DPDP Grievance")
Email: info@optosoft.in
Phone (India): +91-820-072-7974
Website: www.optosoft.in
Address: Ahmedabad, Gujarat, India
14. Compliance Commitments
Maruti Software Solutions is committed to complying with applicable privacy laws and regulations, including:
- Digital Personal Data Protection Act, 2023 (DPDP Act) – India
- Indian Information Technology Act, 2000 (IT Act)
- General Data Protection Regulation (GDPR) – where applicable to users in the European Union
- California Consumer Privacy Act (CCPA) – where applicable to users in California
- Health Insurance Portability and Accountability Act (HIPAA) – where applicable to protected health information of customers in the United States
- Other applicable regional and international privacy laws
Last Updated: June 2026
This Privacy Policy is effective for all users of the OptoSoft Web & POS Mobile Application