Privacy Policy
Who we are
Nicsily builds MERZYO, a business software suite. MERZYO POS is its point-of-sale module. This policy covers MERZYO POS Backup Uploader (the “uploader”), an internal backup utility that Nicsily operates for its own use. The uploader is not offered to the public. It is used only with one Google account, which is controlled by Nicsily’s owner and used for Nicsily’s business.
This policy describes the uploader only. It does not describe how MERZYO POS itself collects or uses information.
What the uploader does
Every night MERZYO POS creates a backup set: an export of its database, an archive of images uploaded to it, and a manifest listing those files with their sizes, checksums and row counts. The uploader copies the newest verified backup set to Google Drive in the Google account that authorized it, and checks that each copy arrived complete.
The uploader keeps a log of its runs on the server that runs MERZYO POS. The log does not contain Google credentials or tokens. If an upload fails, the uploader may send an alert email to Nicsily through MERZYO POS’s own outgoing email service. It does nothing else with Google Drive.
Google access we request
The uploader requests a single Google OAuth scope: https://www.googleapis.com/auth/drive.file.
Under this scope, the uploader can only access files and folders that it creates itself, or that are explicitly made available to it under that scope. It cannot see, read or change any other file in the Google Drive account.
The uploader uses this access only to:
- create folders for MERZYO POS backups;
- upload MERZYO POS backup files into those folders;
- read back the size and checksum of the files it uploaded, to confirm each copy is complete; and
- attach private labels (Google Drive app properties, visible only to the uploader) to the files and folders it creates, and use them to find backups it has already uploaded, so the same backup is not uploaded twice.
The uploader requests no other Google permission, such as access to the account’s profile, email address or contacts, and it does not use the Google account’s name or email address.
Google user data the uploader handles
- OAuth credentials and tokens: the OAuth client credentials, the refresh token issued by Google when the account owner authorized the uploader, and the short-lived access tokens obtained with it.
- Details of the files it created: for its own backup folders and files only, their Google Drive IDs, names, sizes, checksums and the private labels described above.
The uploader does not download backup contents from Google Drive, does not list or read any other file, and does not read the Google account profile.
What the backup files contain
The backup files are copies of MERZYO POS business records. The database export contains sales, stock, cash drawer and other business records, and it includes personal information that MERZYO POS holds:
- customer records, including names, phone numbers and email addresses where they were recorded;
- staff user accounts, including email addresses and password hashes (one-way scrambled forms of passwords, not the passwords themselves); and
- audit and security records of actions in the system, which can include IP addresses and browser details.
The image archive contains images uploaded to MERZYO POS, such as product images and logos. Backups do not include login sessions, password-reset tokens, cache data, queued jobs or login-attempt records.
How your Google credentials are handled
- The uploader never asks for, receives or stores the Google account password.
- Access works through OAuth credentials and a refresh token issued by Google.
- These credentials and tokens are kept private on the server that runs MERZYO POS, which is hosted by Hostinger, outside any publicly reachable folder. They are not published and are not stored in source code repositories.
How data is used and shared
- Backup data is used only to keep recoverable copies of MERZYO POS data, to check that those copies are complete and can be restored, and to restore MERZYO POS if its data is lost or damaged.
- Backup data is not sold, and it is not used for advertising.
- Backup data is not shared outside Nicsily, except with the service providers that store or carry it — Google, which stores the uploaded copies in Google Drive; Hostinger, Nicsily’s web hosting provider, which stores the original backup files on the server; and Nicsily’s email provider, which carries failure alerts — or where Nicsily is required by law to disclose it.
- Failure alerts say which backup failed and why. They never contain credentials, tokens or backup contents.
MERZYO POS Backup Uploader’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used to develop, improve or train artificial intelligence or machine-learning models.
Retention
- Backup copies stay in the Google Drive account until someone with access to that account deletes them. There is no automatic deletion schedule for these copies, and the uploader does not delete files from Google Drive or from the server. Files deleted in Google Drive stay in its Trash for up to 30 days unless the Trash is emptied.
- On the server, MERZYO POS keeps its seven most recent backup sets and removes older sets automatically.
- The OAuth credentials and refresh token are kept on the server until access is revoked or the uploader is retired.
Revoking access
The owner of the Google account can remove the uploader’s access at any time: open the Google Account, go to Security, then Your connections to third-party apps & services (myaccount.google.com/connections), select MERZYO POS Backup Uploader and delete its access. After that, the uploader cannot start any new upload to that account, and its refresh token no longer works. Files it uploaded earlier stay in Google Drive until they are deleted.
Security
We take reasonable steps to protect the credentials and the backup files. All connections to Google use encrypted HTTPS. The Google credentials are kept in a file that only the server account can read, outside the website’s public folders, and the uploader does not share the Google Drive folders or files it creates with anyone. No method of storing or transmitting data is completely secure, so we cannot promise absolute security.
Changes to this policy
If this policy changes, we will update this page and its effective date.
Contact
Questions about this policy: admin@nicsily.com