Privacy Policy

Last updated 3 September 2026.

Nexsim is sales software sold to businesses. An organisation subscribes, its staff sign in, and the records they create — customers, quotations, invoices, payments, visits — belong to that organisation. This policy describes what the Nexsim web app and the Nexsim Android app collect, why, and who can see it.

Who is responsible

The service is operated by IT Simple System Solutions Sdn. Bhd.. For anything in this policy, write to sales@itsimple.com.my.

For the business records inside an organisation’s account, that organisation decides what is collected and why; Nexsim processes it on their instructions. For the account itself — who may sign in, and the security around it — Nexsim is responsible.

What is collected

Accounts and access:

  • Your name and email address, so an account can exist and be addressed.
  • A hashed password, and session tokens for the browser and for each mobile device you sign in on. Sessions can be revoked.
  • An audit trail of significant actions — who approved, voided or edited a document, and when. This is a deliberate feature of an accounting product, not analytics.

Business records you enter:

  • Customers and leads, including the contact names, phone numbers, email addresses and postal addresses your staff record against them.
  • Quotations, sales orders, delivery orders, invoices, cash sales and payments.
  • Products, price books and stock figures.

From the mobile app specifically:

  • Location, only at a visit check-in or check-out. When a salesperson checks in or out of a customer visit, the app asks Android for a single coordinate and stores it against that visit so the organisation can evidence the call. It is requested at that moment, never in the background, and the app keeps working if you refuse — the visit is simply recorded without a coordinate.
  • Photos, when you attach one to a product or a visit, taken with the camera or chosen from your library. Only the image you pick is read.
  • Your device session token, held in Android’s own encrypted keystore so it is not readable by other apps. It is what keeps you signed in; signing out or revoking the device deletes it.

What is not collected

  • No advertising identifiers, and no data is shared with advertisers or data brokers.
  • No background or continuous location tracking.
  • No contacts, call logs, SMS, or files outside what you explicitly attach.
  • No fingerprint, face or other biometric data — the app never asks Android for any.
  • No third-party analytics or behavioural tracking SDKs in the mobile app.

Why it is used

To run the service you have subscribed to: authenticate you, show your organisation its own records, produce its documents and reports, and keep an audit trail. Aggregate figures such as outstanding balances are computed from your own records and shown only to your own organisation.

Your records are never used to train models, and are never sold.

Who can see it

Members of your organisation, according to the permissions your administrator grants them. Nexsim staff access production data only where necessary to operate or support the service.

Customers of your organisation may be sent a portal or shop link, which shows only the documents that link was issued for.

If your organisation connects the AutoCount integration, documents and master data are exchanged with the AutoCount installation it points at, under your organisation’s control.

How long it is kept

Business records are kept for as long as the organisation’s account is open, because they are its accounting history. When you choose to remove data, it is removed immediately — there is no delayed purge and no archived copy kept behind the scenes.

Mobile sessions expire after 30 days. Revoking a session or signing out ends it immediately.

Your choices

  • Location can be refused, or withdrawn later in Android Settings. Check-in continues to work without it.
  • Camera and photo access are asked for by Android when you first attach an image.
  • To see, correct or delete records held about you, contact the organisation whose account they sit in. If that is not possible, write to sales@itsimple.com.my.
  • Account and data deletion sets out how to delete an account or an entire organisation, what is removed, and what is kept.

Changes

Material changes will be reflected here with a new date at the top of the page. The current version is always at /privacy.