Nicsily

Privacy Policy

MERZYO POS Backup Uploader · Effective 17 September 2026

Who we are

Nicsily builds MERZYO, a business software suite. MERZYO POS is its point-of-sale module. This policy covers MERZYO POS Backup Uploader (the “uploader”), an internal backup utility that Nicsily operates for its own use. The uploader is not offered to the public. It is used only with one Google account, which is controlled by Nicsily’s owner and used for Nicsily’s business.

This policy describes the uploader only. It does not describe how MERZYO POS itself collects or uses information.

What the uploader does

Every night MERZYO POS creates a backup set: an export of its database, an archive of images uploaded to it, and a manifest listing those files with their sizes, checksums and row counts. The uploader copies the newest verified backup set to Google Drive in the Google account that authorized it, and checks that each copy arrived complete.

The uploader keeps a log of its runs on the server that runs MERZYO POS. The log does not contain Google credentials or tokens. If an upload fails, the uploader may send an alert email to Nicsily through MERZYO POS’s own outgoing email service. It does nothing else with Google Drive.

Google access we request

The uploader requests a single Google OAuth scope: https://www.googleapis.com/auth/drive.file.

Under this scope, the uploader can only access files and folders that it creates itself, or that are explicitly made available to it under that scope. It cannot see, read or change any other file in the Google Drive account.

The uploader uses this access only to:

The uploader requests no other Google permission, such as access to the account’s profile, email address or contacts, and it does not use the Google account’s name or email address.

Google user data the uploader handles

The uploader does not download backup contents from Google Drive, does not list or read any other file, and does not read the Google account profile.

What the backup files contain

The backup files are copies of MERZYO POS business records. The database export contains sales, stock, cash drawer and other business records, and it includes personal information that MERZYO POS holds:

The image archive contains images uploaded to MERZYO POS, such as product images and logos. Backups do not include login sessions, password-reset tokens, cache data, queued jobs or login-attempt records.

How your Google credentials are handled

How data is used and shared

MERZYO POS Backup Uploader’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used to develop, improve or train artificial intelligence or machine-learning models.

Retention

Revoking access

The owner of the Google account can remove the uploader’s access at any time: open the Google Account, go to Security, then Your connections to third-party apps & services (myaccount.google.com/connections), select MERZYO POS Backup Uploader and delete its access. After that, the uploader cannot start any new upload to that account, and its refresh token no longer works. Files it uploaded earlier stay in Google Drive until they are deleted.

Security

We take reasonable steps to protect the credentials and the backup files. All connections to Google use encrypted HTTPS. The Google credentials are kept in a file that only the server account can read, outside the website’s public folders, and the uploader does not share the Google Drive folders or files it creates with anyone. No method of storing or transmitting data is completely secure, so we cannot promise absolute security.

Changes to this policy

If this policy changes, we will update this page and its effective date.

Contact

Questions about this policy: admin@nicsily.com