Winsoft Logo

Privacy Policy — Milk Passbook

Milk Passbook Mobile Application (com.winsoftsc.passbook)

Effective date: August 6, 2026
Last updated: August 6, 2026

Winsoft (“we”, “us”, “our”) operates the Milk Passbook mobile application (the “App”), published under the package name com.winsoftsc.passbook. This Privacy Policy explains how we collect, use, store, share, and protect information when you use the App.

By downloading, installing, or using Milk Passbook, you agree to this Privacy Policy. If you do not agree, please do not use the App.

For questions, contact us at: https://winsoftsc.com (or via email at support@winsoft.in).


1. Who This App Is For

Milk Passbook is intended for registered members of dairy societies / cooperatives who receive milk collection, billing, deduction, and ledger information from their dairy. The App displays data provided by your dairy’s backend systems. It is not intended for children under 13 (or the minimum age required in your country).

2. Information We Collect

2.1 Information You Provide at Login

When you sign in, you enter:

DataPurpose
Dairy codeIdentifies your dairy / society
Phone numberVerifies your registered member account

These are sent to the dairy’s server API (/api/passbook/meminfo) to authenticate you and retrieve your member profile.

We do not ask for a separate password in the App; authentication is handled through your dairy-registered phone number and the session token returned by the server.

2.2 Information Received From Your Dairy Server

After login, the App may fetch and display the following types of data about you as a member, as provided by your dairy’s systems:

  • Member name, member code, and account number
  • Society / dairy name and society code
  • Milk passbook entries (dates, morning/evening sessions, cow/buffalo, liters, fat, SNF, rate, amount)
  • Bill transactions and bill periods
  • Deductions
  • Ledger / account transactions (debit, credit, balance, particulars)
  • GL account names (chart of accounts list)
  • Milk sale records (if enabled for your account)
  • Announcements from your society
  • Session token and token expiry metadata
  • Language and reporting preferences associated with your account

This data is financial and operational records related to your milk membership, not general personal browsing data.

2.3 Information Collected Automatically on Your Device

DataHowPurpose
Authentication tokenStored locally after loginKeeps you signed in between app sessions
Member profile (cached JSON)Stored locallyOffline access and faster loading
Synced business dataStored locally (passbook, bills, ledger, etc.)Offline viewing and reduced network use
Sync timestamps / last-sync datesStored locallyIncremental (delta) data updates
Theme preference (light/dark)Stored locallyUI preference
FCM device tokenGenerated by FirebasePush notifications
Android device identifierCollected via device_info_plusSent with FCM registration to your dairy server
Notification permission statusAndroid systemWhether the App may show push notifications

The App requests these Android permissions:

  • INTERNET — to communicate with your dairy server and Firebase Cloud Messaging
  • POST_NOTIFICATIONS (Android 13+) — to deliver alerts and announcements

The App does not request access to your contacts, camera, microphone, location, SMS, or photo library.

2.4 Push Notifications (Firebase)

We use Google Firebase Cloud Messaging (FCM) to deliver:

  • Society announcements
  • Background data refresh signals (e.g. passbook, bills, ledger updates)

When notifications are enabled, the App may:

  1. Request notification permission on your device
  2. Obtain an FCM token from Google
  3. Send the FCM token, your society code, member code, and Android device ID to your dairy server (/api/FCM/PostFCMToken)
  4. Subscribe your device to Firebase topics such as announcements_{societyCode} and announcements_global

Firebase is operated by Google LLC. Google’s processing of data is governed by Google’s Privacy Policy and Firebase terms.

3. How We Use Your Information

We use collected information solely to:

  1. Authenticate you with your dairy’s membership records
  2. Display your passbook, bills, deductions, ledger, reports, and announcements
  3. Sync data between your dairy server and your device (full and incremental updates)
  4. Send notifications about announcements and data updates
  5. Improve reliability (session refresh, offline cache, error recovery)
  6. Remember preferences such as language and theme

We do not use your data for advertising, selling to third-party marketers, or building unrelated user profiles.

4. Where Data Is Stored and Processed

4.1 On Your Device (Local Storage)

The App stores data locally using SharedPreferences and in-memory caches, including:

  • Login session token
  • Member profile
  • Cached API responses (passbook, bills, deductions, ledger, GL accounts, announcements, milk sales)
  • Sync metadata (last verified dates)
  • Theme setting

Data remains on your device until you log out, clear app data, or uninstall the App. Logging out removes the session token and user profile from local storage and clears in-memory caches.

4.2 On Your Dairy Server

Login credentials (dairy code + phone), API requests, and FCM registration data are transmitted to your dairy cooperative’s backend server (currently configured at http://103.102.144.180:2002 in the App). That server is operated by or on behalf of your dairy / Winsoft as the software provider.

Important: The App currently communicates with the dairy API over HTTP. Data in transit may not be encrypted at the transport layer unless your server infrastructure uses additional security (VPN, private network, etc.). We recommend operators deploy HTTPS (TLS) for production.

4.3 Google Firebase

FCM tokens and notification delivery are processed by Google’s infrastructure. No milk transaction data is intentionally stored in Firebase by this App for its core features; Firebase is used primarily for message delivery.

5. Data Sharing and Disclosure

We do not sell your personal information.

We share data only in these situations:

RecipientWhatWhy
Your dairy / society backendLogin details, member ID, API requests, FCM token, device IDTo provide App functionality
Google (Firebase)FCM token, notification payloadsPush notification delivery
Legal authoritiesAs required by lawCompliance with valid legal process

Employees and contractors of Winsoft who maintain the App may access technical logs on servers only as needed to support the service, subject to confidentiality obligations.

6. Data Retention

LocationRetention
On deviceUntil logout, app data clear, or uninstall
Dairy serverGoverned by your dairy society’s own policies and record-keeping rules
FCM / FirebasePer Google’s retention practices for messaging services

You may clear locally cached data at any time via Logout in the App or through Android Settings → Apps → Milk Passbook → Clear storage.

7. Security

We take reasonable measures to protect your information, including:

  • Bearer token authentication for API requests after login
  • Automatic session refresh and re-login on expired tokens
  • Local storage limited to what is needed for offline functionality

However, no method of electronic storage or transmission is 100% secure. You are responsible for keeping your device secure (screen lock, not sharing your phone, etc.).

8. Your Choices and Rights

Depending on your location, you may have rights to access, correct, or delete personal data. In the App, you can:

  • Log out — removes local session and cached credentials
  • Deny notification permission — you will not receive push alerts (you may still use the App)
  • Clear app data / uninstall — removes all locally stored information
  • Reload data — refresh information from the server on demand

For changes to your member account, phone number, or financial records, contact your dairy society / cooperative administrator. Winsoft provides the software; membership records are controlled by your dairy.

If you are in India, you may have rights under applicable law including the Digital Personal Data Protection Act, 2023, such as the right to access, correction, erasure, and grievance redressal. Contact us using the details below to exercise applicable rights.

9. Third-Party Services

The App uses the following third-party components:

ServiceProviderPurpose
Firebase Core & Cloud MessagingGoogle LLCPush notifications
Flutter Local NotificationsOpen-source pluginDisplay notifications on device
device_info_plusOpen-source pluginDevice identifier for FCM registration

Links to third-party policies:

10. International Transfers

Firebase services may process data on servers located outside India (including the United States). By using notifications, you acknowledge that FCM tokens may be processed by Google globally in accordance with Google’s policies.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised policy with a new “Last updated” date. Continued use of the App after changes constitutes acceptance. For material changes, we may notify you through the App or your dairy society.

12. Contact Us

Winsoft Software Consultancy

Website: https://winsoftsc.com

Email: support@winsoft.in

For data held by your dairy cooperative (milk records, payments, bills), please contact your society office directly.

13. Google Play Data Safety Summary (Reference)

For your Play Console Data safety form, the App generally collects:

  • Personal info: Phone number, name (from server), user IDs (member/society codes)
  • Financial info: Milk payment and ledger records (from server, not entered manually for payment processing in-app)
  • Device or other IDs: FCM token, Android device ID (for notifications)

Data is not sold, used for app functionality and notifications, and may be encrypted in transit once the server uses HTTPS (currently HTTP — upgrade recommended).