Legal

Privacy Policy

Last updated: February 2026

This Privacy Policy explains how Vendorly ("we", "our", grahakly.app) collects, uses, stores, and protects personal information from two groups: vendors (business owners who register accounts) and end customers (people who scan a vendor's QR code and share their contact details).

1. Information we collect

From vendors: name, email address, phone number, business name, business type, hashed password, IP address, subscription and payment status.

From end customers: name, mobile number, and optionally email address and preferences — only the details a customer voluntarily enters into a vendor's QR form.

2. How we use it

  • To operate vendor accounts, dashboards, QR codes, and WhatsApp campaigns.
  • To send transactional emails (verification, password reset, payment receipts) via Resend.
  • To deliver WhatsApp messages to end customers via Twilio's Meta-approved infrastructure.
  • To process subscription payments via Razorpay.
  • To prevent fraud, abuse, and spam through IP and phone-based rate limits.

3. Legal basis (India DPDP Act, 2023)

We process personal data on the following lawful bases: (a) consent — customers voluntarily submit their number to a vendor's QR form; (b) contract — to deliver the paid service to vendors; (c) legitimate interest — to secure the platform against abuse; (d) legal obligation — to retain payment records for statutory audits.

4. Data sharing

We share personal data only with the following data processors, strictly for the purposes listed:

  • Twilio (USA) — to deliver WhatsApp messages using Meta-approved templates.
  • Razorpay (India) — to process subscription payments.
  • Resend (USA) — to send transactional emails.
  • MongoDB Atlas (Mumbai region preferred) — to store account and campaign data.

We never sell, rent, or exchange customer phone numbers with any third party. Each vendor's customer list is isolated at the database level and cannot be accessed by other vendors.

5. Customer opt-out (STOP)

Every WhatsApp message we send contains a "Reply STOP to opt out" line. When a customer replies STOP, we mark that phone number as opted-out for that vendor within 24 hours and no further messages are sent.

6. Data retention

  • Active vendor and customer records: retained while the vendor's account is active.
  • Deleted accounts: all personal data is purged within 30 days of deletion request.
  • Payment records: retained for 7 years to meet Indian tax and audit obligations.
  • Server logs: 90 days rolling window.

7. Security

  • All traffic is encrypted in transit with HTTPS/TLS 1.2+.
  • Passwords are hashed with bcrypt (12 rounds) — we never store plain-text passwords.
  • JSON Web Tokens are transmitted as HttpOnly cookies to defend against XSS.
  • API responses expose customer phone numbers only in masked form (********1234).
  • Cross-vendor data access is blocked at every database query.

8. Your rights

You have the right to access, correct, export, or delete your personal data. To exercise any of these rights, email vendorlyadmin@gmail.com from the email address linked to your account. We will respond within 30 days.

9. Cookies

We use only two cookies: an access cookie (30 minutes) and a refresh cookie (7 days), both strictly necessary to keep vendors signed in. We do not use advertising or third-party tracking cookies. We do use PostHog for anonymous product analytics with cross-origin session replay — this can be disabled by using a privacy-focused browser or extension.

10. Children

Vendorly is not directed at children under 18. If we learn we have collected personal data from a minor, we delete it promptly.

11. Grievance officer

Under India's DPDP Act, 2023, our grievance officer is:

  • Name: Dikshant Agarwal
  • Email: vendorlyadmin@gmail.com
  • Response time: within 15 days

12. Changes to this policy

We may update this policy over time. Material changes will be announced via email to registered vendors at least 7 days before taking effect.