Privacy Policy
Last Updated: August 18, 2026 • Dokan Software Technologies Ltd.
Service Provider: Dokan Software Technologies Ltd. (Incorporated under the laws of Bangladesh)
Registered Address: Level 7, Software Technology Park, Kawran Bazar, Dhaka-1215, Bangladesh
Contact Email for Privacy & Security: support@dokan.app
1. Overview & Commitment to Merchant Privacy
At Dokan (“we”, “our”, or “us”), we recognize that your retail sales, supplier costs, customer credit records, and inventory data represent the lifeblood of your business. We are committed to maintaining the highest standards of data isolation, confidentiality, and operational security.
This Privacy Policy explains how information is collected, processed, and safeguarded when you access our cloud application, subdomains ({shop-slug}.dokan.app), offline Progressive Web App (PWA), or marketing website.
2. Information We Collect
We collect information across the following categories:
- Account & Membership Information: Name, business email, mobile phone number, login credentials (passwords are stored as salted Argon2/bcrypt hashes), tenant name, subdomain slug, and assigned user roles.
- Store & Operational Data: Product catalog, SKU identifiers, categories, supplier contact info, purchase orders, stock ledger movements, customer profiles, credit dues, and expense entries.
- Point of Sale (POS) Transactions: Invoice items, discounts, tax configurations, split payment records (Cash, bKash, Nagad, Card), register float sessions, and printed receipt metadata.
- Local Device Storage (IndexedDB): For offline POS operation, encrypted local queues temporarily store offline sales and cache product catalogs directly in your browser until connectivity is restored.
- Technical & Audit Telemetry: Append-only audit logs capturing mutating actions (user ID, tenant ID, action type, IP address, user-agent, and before/after diffs) for security auditing.
3. Multi-Tenant Data Isolation (PostgreSQL RLS)
Dokan is architected with strict 3-layer data isolation:
- Database Kernel Row-Level Security: Every tenant-owned database table is enforced by PostgreSQL RLS policies (
SET LOCAL app.current_tenant). Cross-tenant queries are rejected at the database engine level. - Fail-Closed Repositories: Backend database drivers refuse to run queries without verified tenant context.
- No Cross-Tenant Data Sharing: Your store's financial data, cost prices, and customer records are never aggregated, sold, or shared with other merchants or third parties.
4. Data Ownership & Exportability
You retain 100% ownership of all business data uploaded or generated in Dokan. You have the right at any time during an active or trial subscription to export your complete database (products, customers, suppliers, stock ledger, invoices, and expenses) in standardized CSV format packaged in a ZIP archive.
5. Third-Party Sub-Processors
We use vetted infrastructure providers strictly necessary to deliver the Dokan service:
- Cloudflare R2 / S3-compatible storage (for encrypted receipt and product photo attachments)
- Telecommunications SMS Gateways (e.g. BulkSMSBD for SMS receipts and OTP verification)
- Single-tenant VPS cloud hosting (managed infrastructure in compliance with data residency standards)
6. Account Deletion & Cooling Period
Tenant owners may request complete shop deletion from their account settings. To protect against accidental deletions or malicious staff takeovers, deletion requests trigger a mandatory 24-hour cooling period and require super-admin review before data is permanently purged from active databases and backups.
7. Contact Our Data Protection Officer
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us at:
Email: support@dokan.app
Hotline: +880 1800-DOKAN (36526)
Postal Address: Level 7, Software Technology Park, Kawran Bazar, Dhaka-1215, Bangladesh