How your data is protected
A database of your own
Every company's records are kept in a separate database. One company's data never shares a table with another's.
Encrypted on the way
The website and the app talk to our servers only over HTTPS (TLS). The released app refuses unencrypted connections.
Passwords never stored
Only a one-way PBKDF2-HMAC-SHA256 hash is kept, with a random salt and 210,000 rounds. Nobody at Keycode can read your password. A forgotten one is replaced by a temporary password that must be changed at the next sign-in.
Rights by role and branch
Each person sees only the screens their role allows, in their own branch. The server checks those rights again on every request, from the website and from the app.
Every change recorded
An audit trail records who changed what and when. Invoices and receipts are voided with a reason, never erased.
Secrets sealed
Passwords for company databases and keys for connected services such as Razorpay and WhatsApp are encrypted at rest, with keys held only on our servers.
Files kept private
Photos and documents are stored outside the website's public folders. They are served only to signed-in people with the right to see them, or to a customer through their own private link.
Safe sign-in on the phone
The app keeps its sign-in tokens in Android's encrypted storage. Each access token lasts 30 minutes, and signing out removes the tokens from the phone. The app's sign-in accepts at most 10 attempts a minute from one address.
Links that cannot be guessed
The quotation and system links a company sends its customers carry long random keys, and are limited in how often they can be opened.
What the SolarXErp app collects
The same as declared in the app's data safety section on Google Play. Nothing in this table is sold or used for advertising.
| Data | What exactly | Why | Optional? |
|---|---|---|---|
| Personal info | Name, email address, phone number, address; for payroll, PAN, UAN and bank details | App functionality, account management | Name and login are required. The rest is what your company records. |
| Financial info | Quotations, invoices, payments, salary and bank details | App functionality | Recorded by your company |
| Location | Precise location, only when you check in or out, survey a site or attach a site photo. Never in the background. | App functionality | Yes |
| Photos | Site photos you take or choose, attached to surveys, projects and service tickets | App functionality | Yes |
| App info and performance | Crash logs and diagnostics: the error, app version, phone model, Android version, screen, your name | Fixing faults | Sent automatically when the app fails |
| Device or other IDs | A push notification token | Sending you notifications | Yes, allow or deny notifications |
- Encrypted in transit: yes, all of it.
- Shared with third parties: no. The providers who run SolarXErp for us (hosting, and push notifications through Expo and Google Firebase Cloud Messaging) process it only on our behalf. Services your company connects receive only what they need. See the Privacy policy, section 4.
- You can ask for it to be deleted: yes, at Delete account.
- Not collected: contacts, call logs, SMS, microphone audio, the advertising ID, background location.
Report a security problem
If you think you have found a weakness in SolarXErp, please tell us before telling anyone else, and we will look into it straight away.
- Online
- Ask for your account or data to be deleted, with no sign-in needed