Legal

Privacy Policy

How DiamondOar collects, uses, protects, and manages business and customer data.

Last updated: 24 September 2026

1. Who We Are

DiamondOar is jewellery shop software operated by Pepulux (Private) Limited(company registration PV 00331930), No. 15, Murukesar Lane, Nallur, Jaffna, Sri Lanka. You can reach us at [email protected].

This policy explains what we hold, who else can see it, where it is kept, and how long we keep it. It covers the DiamondOar website and the software your shop signs in to.


2. Who Is Responsible for What

Your shop decides what customer information to collect and why. Your shop is responsible for that information, for telling your customers about it, and for having the right to hold it. We hold and process it on your shop's behalf, and we act on your instructions.

We are responsible for the accounts of the people who sign in, for our billing records, and for this website.


3. What We Hold

Your shop's staff enter this information, and it is stored on our systems:

  • Customers: name, phone number, email address, home address and date of birth
  • Identity records: when your shop buys gold from a member of the public, the type and number of the ID shown (such as an NIC) and a scan or photograph of it
  • Photographs: pictures of items, including pledged and repaired jewellery, and of design requests, where your staff upload them
  • Sales and money: bills, payments, credit, pawning, savings schemes, and the ledger behind them
  • Messages: the phone number a message was sent to and the text of the message
  • Notes: free-text notes your staff type against a customer, a bill, a repair or a pledge
  • Staff: name, email, phone, role, and — where your shop uses attendance — the internet address (IP) the check-in and check-out came from
  • Sign-in records: the internet address and browser of the person signing in, kept for security

We do not buy personal information from anyone else, and we do not sell or rent what we hold. We do not use your shop's customer records to advertise to those customers.


4. How We Use It

We use it to run the software your shop pays for:

  • Producing bills, receipts, tags and reports
  • Keeping stock, pawning, repairs and the accounts up to date
  • Sending the messages your shop chooses to send
  • Signing people in, and keeping a record of who did what
  • Keeping backups, and fixing problems when you ask us for help

5. Who Else Sees It

We use these companies to run the service. Each one is named here with what reaches it.

  • Supabase — holds the database and the uploaded files. Everything in this policy is stored there.
  • Vercel — runs the website and the software. Vercel sees the requests your browser makes. We also use Vercel Analytics and Speed Insights, which measure page loads and speed without cookies and without identifying a person.
  • SMSLenz — sends SMS. The recipient's phone number and the full text of the message reach them.
  • Google (Gemini) — powers the AI assistant, and only when someone uses it. What is typed into the assistant, along with the shop records needed to answer it, is sent to Google. Do not type anything into the assistant you would not want to leave our systems.
  • Meta (WhatsApp Business Platform) — used only if your shop connects its own WhatsApp Business account. Then the recipient's number and the message reach Meta. If your shop disconnects it, we stop sending.
  • Tawk.to — the chat window on our public pages only. It is not loaded once you sign in, so it never sees your shop's records.

We also give information to the police, a court or a regulator where the law requires it.


6. Where It Is Stored

Your data is stored outside Sri Lanka. The database and uploaded files are held by Supabase in Singapore. The software runs on Vercel, whose servers are in several countries. The companies named above are based outside Sri Lanka, so information sent to them is handled under the laws of those countries.


7. Security

  • Traffic between your device and our servers is encrypted (HTTPS).
  • Our database provider stores data encrypted on disk and takes regular backups.
  • Each shop's records are separated from every other shop's, and staff see only what their role allows.
  • ID documents and purchase bills are kept in private storage and opened through a link that expires.
  • Sensitive actions are recorded, with the person and the time.

No system is perfect. If something happens to your data that puts people at risk, we will tell you and tell you what we know.


8. Cookies

We use cookies to keep you signed in and to remember settings such as your theme. Without them you cannot stay signed in. The chat window on our public pages sets its own cookies. Our page and speed measurements do not use cookies and do not identify a person. We do not use advertising cookies and we do not run advertising pixels.

Our Cookie Policy lists them.


9. Billing

We keep your subscription, invoices and payment records for your shop. We do not hold card numbers. Invoices and payment records are kept for as long as Sri Lankan tax and company law requires, even after an account closes.


10. Keeping and Deleting Data

While your account is open, we keep your data so the software works.

When your shop closes its account:

  • We offer you an export first, including the ID records your shop must keep by law.
  • The account is closed but restorable for 30 days, in case it was a mistake.
  • Within 60 days of closing, we permanently remove customer personal information — names, phone numbers, emails, addresses, dates of birth, ID numbers and scans, photographs and message text. Sales, stock and ledger records stay, with the customer shown as [removed], because those records have to balance and may be required by tax law.
  • Backups roll off within 90 days after that.

If one of your staff deletes their own login, the shop's records stay with the shop. Sign-in and attendance records that contain internet addresses are kept with the attendance record today; we have not yet set an automatic limit on them.


11. Your Rights

If you are a customer of a shop that uses DiamondOar, ask the shop. They decide what is held about you and they can correct or remove it. If they ask us for help, we help them.

If you are a shop using DiamondOar, you can ask us to:

  • Export your data in a readable format
  • Correct something that is wrong
  • Delete your account, as described above

Write to [email protected]. We answer within 30 days.


12. Contact

For questions about this policy, an export, or a deletion request:

Pepulux (Private) Limited · PV 00331930
+94 77 208 2227

Need help with privacy questions?

Ask us anything about what we hold, where it is kept, or how to get it out.

Contact Support