Effective date: August 6, 2026
Last updated: August 6, 2026
Winsoft (“we”, “us”, “our”) operates the Milk Passbook mobile application (the “App”), published under the package name com.winsoftsc.passbook. This Privacy Policy explains how we collect, use, store, share, and protect information when you use the App.
By downloading, installing, or using Milk Passbook, you agree to this Privacy Policy. If you do not agree, please do not use the App.
For questions, contact us at: https://winsoftsc.com (or via email at support@winsoft.in).
1. Who This App Is For
Milk Passbook is intended for registered members of dairy societies / cooperatives who receive milk collection, billing, deduction, and ledger information from their dairy. The App displays data provided by your dairy’s backend systems. It is not intended for children under 13 (or the minimum age required in your country).
2. Information We Collect
2.1 Information You Provide at Login
When you sign in, you enter:
| Data | Purpose |
|---|---|
| Dairy code | Identifies your dairy / society |
| Phone number | Verifies your registered member account |
These are sent to the dairy’s server API (/api/passbook/meminfo) to authenticate you and retrieve your member profile.
We do not ask for a separate password in the App; authentication is handled through your dairy-registered phone number and the session token returned by the server.
2.2 Information Received From Your Dairy Server
After login, the App may fetch and display the following types of data about you as a member, as provided by your dairy’s systems:
- Member name, member code, and account number
- Society / dairy name and society code
- Milk passbook entries (dates, morning/evening sessions, cow/buffalo, liters, fat, SNF, rate, amount)
- Bill transactions and bill periods
- Deductions
- Ledger / account transactions (debit, credit, balance, particulars)
- GL account names (chart of accounts list)
- Milk sale records (if enabled for your account)
- Announcements from your society
- Session token and token expiry metadata
- Language and reporting preferences associated with your account
This data is financial and operational records related to your milk membership, not general personal browsing data.
2.3 Information Collected Automatically on Your Device
| Data | How | Purpose |
|---|---|---|
| Authentication token | Stored locally after login | Keeps you signed in between app sessions |
| Member profile (cached JSON) | Stored locally | Offline access and faster loading |
| Synced business data | Stored locally (passbook, bills, ledger, etc.) | Offline viewing and reduced network use |
| Sync timestamps / last-sync dates | Stored locally | Incremental (delta) data updates |
| Theme preference (light/dark) | Stored locally | UI preference |
| FCM device token | Generated by Firebase | Push notifications |
| Android device identifier | Collected via device_info_plus | Sent with FCM registration to your dairy server |
| Notification permission status | Android system | Whether the App may show push notifications |
The App requests these Android permissions:
- INTERNET — to communicate with your dairy server and Firebase Cloud Messaging
- POST_NOTIFICATIONS (Android 13+) — to deliver alerts and announcements
The App does not request access to your contacts, camera, microphone, location, SMS, or photo library.
2.4 Push Notifications (Firebase)
We use Google Firebase Cloud Messaging (FCM) to deliver:
- Society announcements
- Background data refresh signals (e.g. passbook, bills, ledger updates)
When notifications are enabled, the App may:
- Request notification permission on your device
- Obtain an FCM token from Google
- Send the FCM token, your society code, member code, and Android device ID to your dairy server (
/api/FCM/PostFCMToken) - Subscribe your device to Firebase topics such as
announcements_{societyCode}andannouncements_global
Firebase is operated by Google LLC. Google’s processing of data is governed by Google’s Privacy Policy and Firebase terms.
3. How We Use Your Information
We use collected information solely to:
- Authenticate you with your dairy’s membership records
- Display your passbook, bills, deductions, ledger, reports, and announcements
- Sync data between your dairy server and your device (full and incremental updates)
- Send notifications about announcements and data updates
- Improve reliability (session refresh, offline cache, error recovery)
- Remember preferences such as language and theme
We do not use your data for advertising, selling to third-party marketers, or building unrelated user profiles.
4. Where Data Is Stored and Processed
4.1 On Your Device (Local Storage)
The App stores data locally using SharedPreferences and in-memory caches, including:
- Login session token
- Member profile
- Cached API responses (passbook, bills, deductions, ledger, GL accounts, announcements, milk sales)
- Sync metadata (last verified dates)
- Theme setting
Data remains on your device until you log out, clear app data, or uninstall the App. Logging out removes the session token and user profile from local storage and clears in-memory caches.
4.2 On Your Dairy Server
Login credentials (dairy code + phone), API requests, and FCM registration data are transmitted to your dairy cooperative’s backend server (currently configured at http://103.102.144.180:2002 in the App). That server is operated by or on behalf of your dairy / Winsoft as the software provider.
Important: The App currently communicates with the dairy API over HTTP. Data in transit may not be encrypted at the transport layer unless your server infrastructure uses additional security (VPN, private network, etc.). We recommend operators deploy HTTPS (TLS) for production.
4.3 Google Firebase
FCM tokens and notification delivery are processed by Google’s infrastructure. No milk transaction data is intentionally stored in Firebase by this App for its core features; Firebase is used primarily for message delivery.
5. Data Sharing and Disclosure
We do not sell your personal information.
We share data only in these situations:
| Recipient | What | Why |
|---|---|---|
| Your dairy / society backend | Login details, member ID, API requests, FCM token, device ID | To provide App functionality |
| Google (Firebase) | FCM token, notification payloads | Push notification delivery |
| Legal authorities | As required by law | Compliance with valid legal process |
Employees and contractors of Winsoft who maintain the App may access technical logs on servers only as needed to support the service, subject to confidentiality obligations.
6. Data Retention
| Location | Retention |
|---|---|
| On device | Until logout, app data clear, or uninstall |
| Dairy server | Governed by your dairy society’s own policies and record-keeping rules |
| FCM / Firebase | Per Google’s retention practices for messaging services |
You may clear locally cached data at any time via Logout in the App or through Android Settings → Apps → Milk Passbook → Clear storage.
7. Security
We take reasonable measures to protect your information, including:
- Bearer token authentication for API requests after login
- Automatic session refresh and re-login on expired tokens
- Local storage limited to what is needed for offline functionality
However, no method of electronic storage or transmission is 100% secure. You are responsible for keeping your device secure (screen lock, not sharing your phone, etc.).
8. Your Choices and Rights
Depending on your location, you may have rights to access, correct, or delete personal data. In the App, you can:
- Log out — removes local session and cached credentials
- Deny notification permission — you will not receive push alerts (you may still use the App)
- Clear app data / uninstall — removes all locally stored information
- Reload data — refresh information from the server on demand
For changes to your member account, phone number, or financial records, contact your dairy society / cooperative administrator. Winsoft provides the software; membership records are controlled by your dairy.
If you are in India, you may have rights under applicable law including the Digital Personal Data Protection Act, 2023, such as the right to access, correction, erasure, and grievance redressal. Contact us using the details below to exercise applicable rights.
9. Third-Party Services
The App uses the following third-party components:
| Service | Provider | Purpose |
|---|---|---|
| Firebase Core & Cloud Messaging | Google LLC | Push notifications |
| Flutter Local Notifications | Open-source plugin | Display notifications on device |
| device_info_plus | Open-source plugin | Device identifier for FCM registration |
Links to third-party policies:
- Google Privacy Policy: https://policies.google.com/privacy
- Firebase: https://firebase.google.com/support/privacy
10. International Transfers
Firebase services may process data on servers located outside India (including the United States). By using notifications, you acknowledge that FCM tokens may be processed by Google globally in accordance with Google’s policies.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised policy with a new “Last updated” date. Continued use of the App after changes constitutes acceptance. For material changes, we may notify you through the App or your dairy society.
12. Contact Us
Winsoft Software Consultancy
Website: https://winsoftsc.com
Email: support@winsoft.in
For data held by your dairy cooperative (milk records, payments, bills), please contact your society office directly.
13. Google Play Data Safety Summary (Reference)
For your Play Console Data safety form, the App generally collects:
- Personal info: Phone number, name (from server), user IDs (member/society codes)
- Financial info: Milk payment and ledger records (from server, not entered manually for payment processing in-app)
- Device or other IDs: FCM token, Android device ID (for notifications)
Data is not sold, used for app functionality and notifications, and may be encrypted in transit once the server uses HTTPS (currently HTTP — upgrade recommended).
