Privacy Policy
Effective date: 31 August 2026
This policy explains what information the Petrol Pump Management System ("the Service") collects, how it is used, and the choices you have. The Service is operated by Bitworld Solution ("we", "us"). By using the Service you agree to the practices described here.
1. Who this policy covers
The Service is business software used by petrol pump owners and their authorised staff to manage fuel stock, sales, customers and reporting. Accounts are created by an administrator — the Service is not offered for direct public sign-up, and it is not intended for use by children.
2. Information we collect
We collect only what the Service needs to function:
- Account information — name, email address, role and account status of each user created by an administrator.
- Business records you enter — fuel purchases and sales, meter and dip readings, inventory, customer and vendor details, payments, expenses and uploaded documents.
- Device and session information — when device approval is enabled, we record the browser family, operating system and IP address of devices used to sign in, so an administrator can approve or block them.
- Activity logs — records of significant actions such as sign-ins and changes to financial data, used for audit and troubleshooting.
We do not collect payment card numbers, and we do not use advertising trackers or third-party analytics that profile individuals.
3. How we use information
- To provide the Service and display your business records back to you.
- To authenticate users and enforce role-based and device-based access controls.
- To generate the reports, ledgers and exports you request.
- To create database backups when you enable that feature.
- To investigate errors, misuse or security incidents.
We do not sell your information, and we do not use it to build advertising profiles.
4. Google Drive access and Limited Use
The Service offers an optional database backup feature. If an administrator chooses to enable it, they connect a Google account and grant access using Google OAuth. We request only these scopes:
drive.file— permission to create and manage only the files this application creates. It does not grant access to any other file in your Google Drive.userinfo.email— to display which Google account is connected, so you can confirm backups are going to the right place.
When enabled, the Service creates a folder named “Petrol Pump Backups” in that account and uploads compressed database backup files to it on the schedule you configure. Older backups beyond your chosen retention limit are deleted automatically. We never read, modify, list or delete any other content in your Drive.
Your Google authorisation credentials are stored encrypted on our server and are used solely to upload, list, download and delete the backup files this application created. You can revoke access at any time by clicking Disconnect in the application, or from your Google account permissions page.
Limited Use disclosure. Our use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, we do not transfer it to others except as necessary to provide the backup feature or to comply with applicable law, and we do not allow humans to read it except with your explicit consent, for security purposes, or where required by law.
5. Data sharing
We share information only in these limited circumstances:
- Google Drive — backup files, only when you enable the backup feature and only into the folder this application creates.
- WhatsApp Business API (Meta) — if you enable messaging, the phone number and message content you choose to send are transmitted to Meta for delivery, subject to Meta’s own privacy terms.
- Hosting infrastructure — our server and database providers, who process data on our instructions.
- Legal requirements — where we are required by law to disclose information.
6. Data isolation between businesses
Each petrol pump’s records are scoped to that pump. Owners can access only the pumps assigned to their account, and this restriction is enforced on the server for every request — not only in the interface. One business cannot see another business’s data.
7. Security
- Passwords are stored using one-way hashing and are never readable by us.
- Third-party credentials, including Google refresh tokens, are stored encrypted.
- Access requires authentication, and administrators can additionally require device approval before a sign-in is allowed.
- Sensitive changes are recorded in an audit log.
- Rate limiting is applied to authentication and other sensitive endpoints.
No system can be guaranteed completely secure. If we become aware of a breach affecting your data, we will notify you without undue delay.
8. Data retention
Business records are retained for as long as your account is active, because financial history must remain available for reporting and audit. Deleted records are typically soft-deleted so history is preserved. Backup files are retained according to the retention limit you configure — older copies are deleted automatically. Audit logs are pruned periodically.
On written request to the address below, we will delete your account and associated records, subject to any legal obligation to retain them.
9. Your rights
You may, at any time:
- Request a copy of the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your account and data, subject to legal retention requirements.
- Disconnect Google Drive, which immediately stops all future backups.
- Export your business records using the built-in PDF and spreadsheet exports.
10. Cookies and local storage
The Service stores an authentication token, your language preference and, where device approval is enabled, a device identifier in your browser’s local storage. These are required for the Service to work. We do not use advertising or tracking cookies.
11. Changes to this policy
We may update this policy as the Service changes. The effective date at the top of this page will be updated when we do. Continued use of the Service after a change constitutes acceptance of the revised policy.
12. Contact
For any question about this policy or your data, contact Bitworld Solution at kaleemullahdev@gmail.com.