Legal & Data

Privacy Policy

This policy explains how Design Corporation handles information in connection with DCORP services, including DCORP Invoice & Stock and its optional Google Drive integration.

Effective: 19 September 2026 · Last updated: 19 September 2026

1. Who we are

Design Corporation ("DCORP", "we", "us" or "our") develops and operates business software and related services. This Privacy Policy applies to the DCORP website and to DCORP Invoice & Stock where the application or service references this policy.

2. Information we may process

Depending on the features used, DCORP may process business identity information, user profiles and permissions, device identifiers used for licence/device approval, branch information, transaction and receipt metadata, stock and barcode records, configuration data, technical logs, and support communications.

Some operational application data may be stored locally on the user's device. Cloud-connected features process only the data required for those features.

3. Why we use information

  • To provide invoicing, sales, stock, receipt and branch-management functions.
  • To authenticate approved devices and enforce licence or workspace access.
  • To maintain business and branch identity associated with records.
  • To provide requested integrations such as Google Drive.
  • To troubleshoot, secure and improve reliability of DCORP services.
  • To respond to support, privacy and data requests.

4. Google user data and Google Drive

Google Drive integration is optional. When a user chooses to connect Google Drive, DCORP requests the following OAuth scope:

https://www.googleapis.com/auth/drive.file

DCORP uses this per-file permission to create or manage Google Drive files associated with DCORP Invoice & Stock. We do not request broad permission to access all unrelated files in a user's Google Drive.

Google data accessed

  • The connected Google account email address.
  • OAuth access and refresh credentials required for the authorized connection.
  • Files and related metadata created by or explicitly associated with DCORP through the authorized scope.

How Google data is used

  • To identify the account the business chose to connect.
  • To save and manage supported DCORP-generated receipts and documents in that user's Drive.
  • To maintain the authorized connection for permitted operations.

Google data sharing

DCORP does not sell Google user data, use it for targeted advertising, provide it to data brokers, or use it for purposes unrelated to the functionality disclosed to the user. Service providers may process limited data where technically necessary to operate infrastructure, subject to appropriate access controls and the purpose of providing the service.

Google API data policy

Our use and transfer of information received from Google APIs is limited to the disclosed product functions and is intended to follow Google's applicable user-data and limited-use requirements.

5. Storage and security

DCORP uses reasonable technical and organizational safeguards appropriate to the type of data processed. Sensitive service credentials are intended to be held server-side rather than exposed in the customer application. No system can guarantee absolute security.

6. Retention

We retain information for as long as reasonably necessary to provide the relevant service, maintain business records, protect system integrity, satisfy legitimate operational requirements, or comply with applicable legal obligations. Retention periods may differ by data type and business requirement.

7. Deletion and disconnection

Users can revoke Google authorization through their Google account permissions. Revocation prevents future Google Drive API access using that authorization. Users may also request deletion of eligible DCORP-held Google connection information or other eligible personal data using our Data Request page.

Deletion requests may not require removal of records that must be retained for legal, accounting, fraud-prevention, security or legitimate business-record purposes. Locally stored application data may also require action on the user's device.

8. Data sharing

We do not sell personal information. We may use infrastructure and service providers where necessary to deliver hosting, storage, authentication, email/support or other technical functions. Information may also be disclosed where required by law or to protect legitimate rights and system security.

9. Children

DCORP Invoice & Stock is a business operations product and is not designed as a consumer service directed to children.

10. Changes to this policy

We may update this policy when product functionality, integrations, legal requirements or data practices change. The latest version will be published at this URL with an updated effective date.

11. Contact

Privacy questions and data requests can be sent to . General product support can be sent to .