Privacy Policy
Last updated: September 6, 2026
This Privacy Policy explains what information LupinSync (“LupinSync”, “we”, “us”) processes when you use the LupinSync PDF Invoices WooCommerce plugin and the LupinSync.tech service (the “Service”), and how that information is used and protected. The data operator for the Service is Bhoi Enterprises, a proprietorship, operating under the LupinSync.tech technology brand — see the business identification details near the end of this page. This policy describes our actual architecture rather than generic boilerplate.
1. Categories of information we process
Website/installation information
- Your store's domain/website address, used to identify and authenticate your installation.
- A stable site instance identifier and installation telemetry: the LupinSync plugin version, and your WordPress, WooCommerce, and PHP versions, sent periodically so we can support you and keep the plugin compatible with your environment.
Account information (where applicable)
Where LupinSync offers a customer account (sign-up, login, and a customer dashboard), we process the account information needed to operate it, such as a name and email address, and — for future Google Sign-In — the identifiers Google provides to authenticate you.
Invoice and order information
To generate a tax invoice for a WooCommerce order, we process:
- Customer/business name, email, and phone number (as recorded on the order).
- Billing and shipping address.
- GSTIN, for B2B invoices.
- WooCommerce order details needed to build the invoice: line items, quantities, prices, taxes, shipping, discounts/coupons, and payment method.
- The generated invoice itself (its data and the resulting PDF file), which we store so it can be downloaded, re-downloaded, and regenerated.
Subscription and payment information
For Premium plans, once subscription billing is live, we process subscription and payment identifiers — such as a subscription ID, plan, billing status, and payment/transaction references from our payment processor (Razorpay) — so we can maintain your Premium license and billing history.
Support queries
If you contact us for support, we process the information you provide in that query and our replies to it, to resolve your request.
2. What we do NOT need to receive or store
LupinSync does not receive, process, or store your customers' or your own:
- complete card numbers,
- card CVV/security codes,
- UPI PIN, or
- internet-banking credentials.
Payment instrument handling (card, UPI, net-banking, and similar) is performed entirely by our payment provider/bank/payment network — Razorpay — once billing is introduced, not by LupinSync — we only ever receive a payment/subscription reference and status, never the underlying instrument details.
3. Why we process this information
- To generate, store, and make available the GST tax invoices you request.
- To authenticate your WooCommerce installation and, where applicable, your customer account.
- To provide support when you contact us.
- To operate Premium licensing and billing.
- To maintain and improve the reliability and compatibility of the Service.
4. Data retention
Issued invoices and their underlying data are retained for as long as your store account exists with us, consistent with normal recordkeeping expectations for tax invoices. We have not yet finalized specific retention periods for every other category above (for example, installation telemetry or resolved support queries); we will not claim a specific retention period until it has actually been defined and implemented, and will update this section when it is.
5. Sharing
We share information with the sub-processors needed to run the Service — for example, our hosting infrastructure, and, for Premium billing, our payment processor (Razorpay) — strictly to the extent needed to provide the Service. We do not sell your information.
6. Security
Requests between the WooCommerce plugin and LupinSync are authenticated using signed requests. Credentials stored by the plugin in WordPress are encrypted at rest. Invoice PDFs are stored server-side and made available only through authenticated download, never a public URL. We do not make a formal compliance certification (e.g. a specific security or privacy standard) beyond what has actually been independently assessed.
7. Your choices
You can disconnect the LupinSync plugin from your store at any time. Where a customer account exists, you will be able to manage and, where applicable, request deletion of your account information through that account or by contacting us.
8. Changes to this policy
We will update this Privacy Policy as the Service evolves (for example, when customer accounts, Google Sign-In, or subscription billing go live) and will update the “Last updated” date above when we do.
9. Contact
Questions about this Privacy Policy can be sent through our Contact page.
10. Data operator
The data operator for LupinSync.tech and LupinSync Invoices is Bhoi Enterprises, a proprietorship — not a private limited company, so no CIN or company registration number applies, and no dedicated Data Protection Officer has been appointed at this stage.
Business identification
- Operated by
- Bhoi Enterprises
- Business type
- Proprietorship
- Technology brand
- LupinSync.tech
- Product
- LupinSync Invoices
- GSTIN
- 27FRMPB2160L1ZM
- Udyam registration
- UDYAM-MH-26-0457900
