← Back to home

Privacy Policy

Last updated: 13 September 2026

Before you publish this: this is a working draft written to match what this product actually does technically. It is not legal advice. Have it reviewed by a lawyer familiar with India's Digital Personal Data Protection Act, 2023 before treating it as final — in particular to fill in the bracketed placeholders below with your actual registered business details.

1. Who this policy covers

Sūcī ("we", "us", "the platform") is operated by [Your Registered Business/Entity Name], [Business Address], India. This policy explains what personal data we process for two different groups of people who interact with the platform:

  • Shop owners — businesses on the platform, whether self-registered or onboarded by us, who log in to manage their own product catalogue.
  • Catalogue visitors — customers who browse a shop's public catalogue page, typically after scanning a QR code or clicking a WhatsApp/shared link. Visitors do not create accounts on Sūcī.

2. What we collect from shop owners

When your shop registers or is onboarded, we collect and store:

  • A login username and a securely hashed password (we never store your password in plain text).
  • Your shop's name, description, address, contact phone number, and WhatsApp business number.
  • If you self-register: your WhatsApp number is used to send a one-time verification code over WhatsApp Business Platform (operated by Meta), and we record the timestamp your number was successfully verified. The code itself is never stored — only a one-way cryptographic hash of it, discarded once used or expired.
  • A record that you accepted these Terms & this Privacy Policy at registration, including the timestamp and which version of each document you agreed to.
  • Any logo, banner, or product images you upload.
  • Billing information: your invoices, payment status, due dates, and — for payments made online — identifiers Razorpay (our payment processor) returns to us to confirm a payment (an order ID and payment ID). We do not receive or store your card, UPI, or bank account details directly; those are handled entirely by Razorpay under its own security certifications and privacy policy.
  • If you opt into UPI Autopay, a mandate/token reference from Razorpay identifying the standing authorization — again, no bank or UPI credentials pass through or are stored by us.
  • Messages we send you and, at a shop level, whether you've viewed your Messages inbox.

We use this to operate your account, verify your identity during registration, generate your public catalogue, bill you correctly, process your payments, and contact you about your shop.

3. What we collect from catalogue visitors

Browsing a shop's public catalogue does not require an account, and we do not set any tracking or advertising cookies for visitors. When you view a product or tap through to WhatsApp, our server briefly uses your IP address and browser user-agent string — for a maximum of 20 minutes — purely to avoid counting the same visit twice (for example, if a page is accidentally refreshed) and to filter out automated bot traffic. That IP address and user-agent are not saved to our database; only an anonymous count (which product, what type of event, and when) is stored. We cannot identify an individual visitor from this data.

If you use a shop's WhatsApp button, you leave our platform and begin a conversation directly with that shop on WhatsApp — that conversation is between you and the shop, governed by WhatsApp's own privacy policy, not this one.

4. Cookies

We use a small number of strictly necessary cookies for shop owners and platform administrators who log in — these keep you signed in and protect against cross-site request forgery. During self-registration, a short-lived (30-minute) cookie also holds the fact that your WhatsApp number was verified, so the next step in the registration wizard can trust it. None of these are used for advertising or cross-site tracking, and catalogue visitors browsing without logging in are not given any of these cookies.

5. Where your data is stored, and who else sees it

Shop and product data is stored in a managed PostgreSQL database and object storage provided by [Supabase — confirm hosting region here, e.g. "Singapore" or "India"]. Our application itself runs on [Render/your current host]. We share the minimum necessary data with two categories of processors on your behalf: Meta (to deliver WhatsApp OTP messages and, separately, when you use a shop's own WhatsApp click-to-chat button) and Razorpay (to process your invoice payments and, if enabled, UPI Autopay mandates). We choose infrastructure and processor providers that maintain reasonable security practices, and we do not sell shop owner or visitor data to any third party.

6. How long we keep data

We retain shop owner account and billing data for as long as your shop remains on the platform, and as needed afterward to meet our own legal and accounting obligations. Verification OTP records are deleted automatically once used or expired, whichever comes first. Deleting a shop (available to platform admins) permanently removes its products, images, and associated data. Platform announcements are automatically deleted 30 days after being sent.

7. Your rights

Under India's Digital Personal Data Protection Act, 2023, shop owners (as data principals) have the right to access the personal data we hold about them, request correction of inaccurate data, request erasure, and withdraw consent where consent is the basis for processing (including revoking WhatsApp communication consent or cancelling a UPI Autopay mandate). To exercise any of these rights, or to raise a grievance about how your data is handled, contact our Grievance Officer:

[Grievance Officer Name]
Email: [grievance@suci.app or your chosen contact]
We aim to respond within [X] business days.

8. Children's data

Sūcī is a business-to-business platform for retail shop owners and is not directed at, nor knowingly used to collect data from, children under 18.

9. Changes to this policy

We may update this policy as the platform changes. Material changes will be announced to shop owners through the in-app Messages inbox.

10. Contact us

Questions about this policy can be sent to admin@suci.app.