Privacy
What TOSS ERP collects, where it is kept, and who can reach it. The technical statements here describe how the product actually behaves.
Version 2026-08-18 · we record which one you accepted when you create a workspace
Who we are
TOSS ERP is operated by The OneSoft Solutions (SMC-Private) Limited, a single-member company limited by shares, incorporated in Pakistan under the Companies Act, 2017 and registered with the Securities and Exchange Commission of Pakistan.
- Corporate Unique Identification Number 0336707 — you can check that against the public register rather than take our word for it.
- Incorporated 11 May 2026. Registered office in the province of Sindh, Pakistan.
For anything on this page — a question, a copy of your data, a correction, or a deletion — write to privacy@toss-erp.com. A person reads that address; it is not an automated queue.
We have not appointed a data protection officer. One is required of organisations whose core activity is large-scale monitoring of people or handling of sensitive categories of data, and neither describes us: we run business software, and the personal data in it belongs to our customers rather than being the product.
We do not print a street address here, because the registered one is a home. The identification number above is the better answer anyway: it is checkable against the public register, which a line of text on our own website is not. If you need the registered address in writing, ask and we will send it.
What we collect
When you browse this site
Every page view on the public site is recorded. Each record holds:
- The page you opened and anything after the ? in the address
- Your IP address, browser user agent, and the page that linked you here
- The identifier of your browser session
- The country, region, and city your IP resolves to
We use this to see which pages people read and where they come from. The location is worked out on our own servers — either from a header our proxy adds, or from an offline country database — so your address is not sent to a third party to be looked up. These records are kept for 90 days and then deleted by a scheduled job.
When you create a workspace
The signup form asks for, and we store:
- Organization name and the subdomain you choose
- Administrator email address and password (stored only as a salted hash, never in readable form)
- The country you select and the modules you enable
- That you agreed to the terms and privacy policy — the time of agreement, which version of the terms was current, and the IP address of the request (when the network makes it available). We record this when you submit the form, not later when you verify your email.
When you contact sales
The enquiry form on the home page records what you type, and in addition:
- Your IP address, browser user agent, and the country it resolves to
We collect those three to stop automated spam — the form blocks repeated submissions from one address. They are kept on the enquiry record and are visible to our staff.
Inside your workspace
Whatever your team enters — customers, employees, invoices, stock, and so on — is your data. We do not use it to train anything, we do not sell it, and we do not share it with other customers. Our staff can reach it only through the routes described under Who can see your data below.
How your workspace is used
Separately from the business data above, we record page views inside your workspace on our own systems, not yours. Each record holds the page opened, the time, the IP address and browser, and the email address of the signed-in user. Our staff can see these.
This tells us which parts of the product are used and helps us investigate a problem you report. It records that a page was opened, not the contents of the records on it. These are kept for 90 days on the same schedule as above.
When something goes wrong
If the software raises an error — a failed page, a background job that could not finish, a notification that did not send — we keep a record on our control systems so our staff can fix it. Each record can hold the exception type and message, a truncated traceback, the request path and method, the workspace slug, and the signed-in user's email when one is known. Records that share the same underlying fault are grouped together rather than stored once per visit.
These records stay on our own servers (the same Hetzner machines as everything else). Resolved errors older than 90 days are deleted by the same weekly job that clears page-view records; unresolved ones are kept until someone marks them fixed, because an open fault does not stop mattering with age. We do not send this data to a third-party error service.
Where it is stored
- Each company gets its own PostgreSQL database (
portal_tenant_<slug>) — not a shared table with a customer column. - Uploaded files are stored per tenant and served only to signed-in users of that workspace.
- In production the site is served over HTTPS with HSTS, and session cookies are marked secure.
Which country
Our servers are in Germany, and your data stays in the European Union. If we move to another hosting provider it will be one in the EU; we will not move your data outside it without telling you first.
Who else touches it
To run the service we rely on one company, and it is worth naming plainly rather than burying:
- Hetzner Online GmbH (Germany) — the servers themselves. Everything sits on them: the databases, the files you upload, the backups, and the mail server that sends notifications.
That is the whole list, and a few absences are deliberate. Visitor locations are worked out from a database file on our own disk, so no lookup service sees an address. Payments are recorded by hand by our staff, so no card processor is involved. There is no analytics provider, and no part of the site is loaded from another company's network.
How long we keep it
- Page-view records — 90 days, then deleted by a scheduled job.
- Resolved application-error records — 90 days after they were last seen; unresolved ones stay until fixed.
- Your workspace, after it ends — 90 days, whether you closed it or it lapsed unpaid. During that window you can still ask us to restore it or send you an export. After it, the database and files are destroyed and we cannot get them back.
- Backups — no backup outlives that 90-day window, so a deletion is not quietly undone by a copy sitting somewhere.
- Sales enquiries and support tickets — kept while we are talking, and for two years afterwards, so we can pick up a conversation you started. Ask and we will delete yours sooner.
Who can see your data
- Your own users, according to the roles you give them.
- Our staff, when they take a support action. Staff actions on a tenant are written to an audit log, and signing in as a customer requires a single-use, short-lived token — while it is in use the workspace shows a banner saying so.
Taking your data with you
Any workspace administrator can download a full backup — the database and the uploaded files — from the administration page, at any time, without asking us.
Cookies
The site sets a session cookie when you sign in, and a CSRF cookie that protects forms from being submitted by another site. Neither is used for advertising. The session identifier is stored on the page-view records described above, which is how repeated visits are counted as one person rather than many.
There are no third-party analytics or advertising scripts. The site serves its own fonts, icons, stylesheets, and scripts rather than loading them from someone else's network, so visiting a page does not tell another company that you were here.
Because none of those cookies track you across other sites, there is no consent banner to click through. If we ever add an analytics or advertising script this paragraph stops being true, and a banner will appear before the script does.
Your rights
Which law applies to you depends on where you are, and we would rather not make you work that out. So we offer the same rights to everyone, wherever you live:
- See it — ask what we hold about you and get a copy.
- Correct it — tell us what is wrong and we will fix it.
- Delete it — ask us to erase it, unless we are required to keep it (an issued invoice, for example, has to survive for tax reasons).
- Take it elsewhere — get it in a form another system can read. Your workspace backup already does this without asking us.
- Object — tell us to stop a particular use, such as the page-view records described above.
- Complain — to us first, and to your local data protection authority if we have not put it right.
Write to privacy@toss-erp.com and we will answer within 30 days. We will not charge you for it.
One thing to be clear about: if your employer put your details into their workspace, that data is theirs and not ours to change. Ask them, and if you cannot reach them, ask us and we will pass it on.
Changes
When something on this page changes materially — a new sub-processor, a new kind of data, a shorter retention period — we will email every workspace administrator at least 30 days before it takes effect. Smaller edits, such as clearer wording, are made in place and the date at the top changes.
Contact
Anything on this page, including a request to see, correct, or delete your data: privacy@toss-erp.com. For anything else, support@toss-erp.com.