Privacy Policy

A comprehensive privacy policy for our website, mobile apps, API products, and SaaS marketplace integrations.

Last updated: 25 February 2026

1. Scope and Coverage

This Privacy Policy applies to digital products and services operated by Streak Technologies LTD, including websites, web applications, mobile applications, APIs, integration services, and marketplace-published apps or extensions.

It is intended to support privacy disclosure requirements commonly used by app stores, web app stores, and SaaS marketplaces, including Apple App Store, Google Play, QuickBooks App Store, Zoho Marketplace, Odoo Apps, Xero App Store, and similar B2B extension platforms.

This same policy URL is designed to be reusable across our store listings, extension submissions, and integration marketplace profiles.

2. Who We Are

Streak Technologies LTD is the provider of ebsmauritius.com services and related product offerings. For specific customer implementations, we may act either as a data controller or as a data processor depending on the data type and contract context.

3. Privacy Principles

  • Lawful, fair, and transparent processing
  • Purpose limitation and data minimization
  • Accuracy and retention controls
  • Security, confidentiality, and accountability
  • Data sovereignty and jurisdiction-aware handling

4. Data We Collect

4.1 Account and identity data

Name, company, role, email address, phone number, account credentials, and basic verification details required to operate user accounts and provide support.

4.2 Business and transaction data

Invoice content, tax details, fiscalisation payloads, QR references, submission status data, audit trail entries, and related compliance records required for service operations.

4.3 Integration and platform data

Data exchanged via authorized integrations with accounting platforms, ERPs, and third-party APIs (for example, QuickBooks, Zoho Books, Odoo, Xero, and similar systems), including tokens, metadata, and callback events.

4.4 Technical and usage data

IP address, browser type, device identifiers, operating system details, network logs, timestamp records, and diagnostic events for security and service reliability.

4.5 Support and communication data

Data shared through support requests, onboarding sessions, email, messaging, or call logs used for issue resolution and service improvement.

4.6 Mobile and app permissions

Depending on enabled features, mobile or extension products may request permissions such as camera access (QR scanning), file or storage access (document handling), notifications, and connectivity permissions.

5. How We Use Data

  • Provide core platform functionality and account access
  • Generate, process, validate, and transmit fiscal or compliance documents
  • Operate authorized integrations and extension workflows
  • Detect and prevent fraud, abuse, and security incidents
  • Deliver customer support, onboarding, and technical assistance
  • Maintain auditability, legal compliance, and operational records
  • Perform service quality monitoring and reliability optimization

Where required by applicable law, we process personal data under one or more legal bases:

  • Performance of a contract
  • Compliance with legal or regulatory obligations
  • Legitimate interests (such as security, fraud prevention, and service reliability)
  • Consent (where specifically requested)

7. Controller and Processor Roles

For customer business data submitted through the platform, customers generally act as controllers and we act as a processor. For account, billing, security, and direct relationship data, we may act as controller.

8. Data Sharing and Disclosure

We do not sell personal data. Data may be shared only where needed for legitimate service delivery or legal obligations, including:

  • Tax and regulatory authorities when submission is legally required
  • Authorized integration endpoints selected by the customer
  • Infrastructure, security, and support subprocessors under confidentiality and security obligations
  • Professional advisors, auditors, or legal representatives where required
  • Law enforcement or regulators where disclosure is legally required

9. International Processing, Data Sovereignty, and Cross-Border Transfers

We support data sovereignty requirements and apply jurisdiction-aware controls where legally required or contractually agreed. Where data is transferred across borders, we apply appropriate safeguards such as contractual protections and security controls consistent with applicable data protection obligations.

We aim to process and store data in alignment with the jurisdictional requirements of the markets we serve, while maintaining secure and resilient service operations.

10. Compliance with Data Protection Laws

We comply with applicable data protection legislation and equivalent frameworks in the jurisdictions where we operate, including GDPR and UK GDPR principles where applicable, Mauritius Data Protection requirements, and comparable legal obligations in relevant operating markets.

11. Security Controls

  • Encryption in transit and controlled encryption at rest where applicable
  • Role-based access controls and account security measures
  • Authentication, session controls, and administrative access governance
  • Logging, monitoring, and audit trails
  • Regular security hardening, testing, and vulnerability management
  • Operational controls for backup, resilience, and incident response

12. Data Retention

We retain data only for as long as required for contractual delivery, legal and tax obligations, dispute handling, security operations, and legitimate business continuity purposes. Retention periods vary by data type and jurisdictional requirements.

When data is no longer required, we delete it, anonymize it, or securely archive it according to legal obligations and internal controls.

13. Data Subject and User Rights

Subject to applicable law, users may request to:

  • Access and obtain a copy of relevant personal data
  • Correct inaccurate data
  • Request deletion or restriction of processing
  • Object to certain processing activities
  • Request data portability where applicable
  • Withdraw consent where processing is consent-based

We may need to verify identity before actioning requests and may retain limited records where required by law.

14. Account Deletion and Marketplace Privacy Requests

For website users, mobile app users, and marketplace-installed integrations, account and data deletion requests can be submitted through our support channels listed below. We process valid requests within applicable legal timeframes, subject to mandatory retention obligations.

15. Children's Privacy

Our services are intended for business and professional use and are not directed to children. If we become aware that data was provided in breach of applicable child privacy laws, we will take appropriate corrective steps.

Our products may connect to third-party services and marketplaces. Those services maintain their own privacy notices and practices. We recommend reviewing their privacy documentation before enabling integrations.

17. Incident Handling and Notifications

We maintain incident response procedures for security events. Where legally required, affected parties and competent authorities are notified in line with applicable breach notification obligations.

18. Contact Information

Email: [email protected]

Phone: +230 215 2998

WhatsApp: +230 5813 7398

Address: Royal Road, Pointe Aux Cannonier, Mauritius

Due to the Oct 1 & 31 e-Invoicing deadlines, our lines could be busy. Please message us on WhatsApp, email us, or fill in our contact form and we’ll get back to you ASAP.

For privacy and data rights requests, include your account identifier, organization name (if applicable), and request details so our team can process your request efficiently.

19. Policy Updates

We may update this policy to reflect legal, product, marketplace, or operational changes. The latest version is always published at this URL and becomes effective on publication unless otherwise stated.