Privacy Policy
Last updated: March 3, 2026
HOX ERP ("we," "our," or "us") operates the HOX ERP platform accessible at hoxnow.com and app.hoxnow.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Please read this policy carefully. By using the Service, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
a) Personal Information
When you register for an account or use our Service, we may collect the following personal information:
- Full name (first and last name)
- Email address
- Phone number
- Company/Organisation name
- Industry and company size
- Billing and subscription information
b) Business Data
As part of using our ERP, CRM, and HRMS modules, you may store business data including but not limited to:
- Employee records and attendance data
- Customer and vendor information
- Purchase orders, sales orders, and invoices
- Inventory and product data
- Financial and GST reports
- Lead, contact, and deal information
c) Automatically Collected Information
- IP address and browser type
- Device information and operating system
- Usage patterns and feature interactions
- Cookies and similar tracking technologies
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Create and manage your account
- Process transactions and send related information
- Send administrative communications, including security alerts and support messages
- Respond to your comments, questions, and customer service requests
- Monitor and analyse usage trends to improve user experience
- Detect, prevent, and address technical issues
- Comply with legal obligations and enforce our terms of service
3. Data Storage & Security
We implement industry-standard security measures to protect your data:
- All data is encrypted in transit using TLS/SSL (HTTPS)
- Passwords are hashed using Argon2id algorithm (never stored in plain text)
- Database backups are performed hourly with encrypted storage
- File uploads are stored securely on Cloudflare R2 with private-only access
- Access to production systems is restricted and monitored
- JWT-based authentication with short-lived access tokens
4. Multi-Tenant Data Isolation
HOX ERP uses a multi-tenant architecture where each organisation ("tenant") has logically isolated data. Your business data is never shared with or accessible to other tenants. Each tenant's data is scoped at the database level to ensure complete isolation.
5. Third-Party Services
We use the following third-party services to operate our platform:
- Cloudflare R2 — Secure file storage (privacy policy at cloudflare.com)
- Resend — Transactional email delivery (privacy policy at resend.com)
- Twilio — SMS/WhatsApp OTP verification (privacy policy at twilio.com)
These third-party providers have their own privacy policies. We only share the minimum information required for these services to function (e.g., email addresses for sending transactional emails).
6. Cookies
We use essential cookies and local storage to maintain your login session and remember your preferences. We do not use third-party tracking cookies or advertising cookies. You can disable cookies in your browser settings, but this may affect the functionality of the Service.
7. Data Retention
We retain your personal information and business data for as long as your account is active or as needed to provide the Service. If you wish to delete your account and all associated data, you may contact us at support@hoxnow.com. Upon account deletion, all your data will be permanently removed within 30 days, except as required by law.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data
- Export: Request a machine-readable export of your data
- Restriction: Request restriction of processing
- Objection: Object to processing of your data
To exercise any of these rights, contact us at support@hoxnow.com.
9. Children's Privacy
Our Service is not intended for use by children under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child, we will take steps to delete that information.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.
11. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us: