Privacy Policy

Last updated: April 10, 2026

1. Who We Are

YRG Commerce ("we", "our", "us") operates the yrgtechsolutions.in platform, a software-as-a-service solution that allows merchants ("Tenants") to create and manage their own online stores. This Privacy Policy explains how we collect, use, and protect personal data when you use our platform — both as a merchant and as an end customer of a merchant store.

2. Data We Collect

2.1 Merchant Account Data

  • Name, email address, and password (hashed with bcrypt)
  • Store name, slug, and configuration settings
  • Billing information (payment processed by Razorpay — we do not store card numbers)
  • Usage data: products created, orders processed, storage used

2.2 End Customer Data (collected on behalf of merchants)

  • Name, email, phone number, and shipping address
  • Order history and payment status
  • Product reviews and wishlist items
  • Newsletter subscription preferences

2.3 Automatically Collected Data

  • IP addresses and browser user agent (server logs)
  • Pages visited and time on site (via Google Analytics if configured)
  • Cookies for session management and cart persistence

3. How We Use Your Data

  • To provide and operate the YRG Commerce platform
  • To process orders and send transactional emails (order confirmation, shipping updates)
  • To send platform announcements, billing reminders, and service notices
  • To detect and prevent fraud and abuse
  • To improve platform performance and features
  • To comply with legal obligations

We do not sell your personal data to third parties.

4. Data Sharing

We share data only with:

  • Razorpay — payment processing (subject to Razorpay's privacy policy)
  • Neon / PostgreSQL — database hosting (data stored in secure cloud infrastructure)
  • Cloudflare R2 / AWS S3 — file and image storage
  • Resend / SMTP provider — transactional email delivery
  • Law enforcement when required by applicable law

5. Cookies

We use strictly necessary cookies for authentication sessions and shopping cart state. If Google Analytics is enabled on a tenant store, analytics cookies may also be set. You can disable cookies in your browser settings, though this may affect platform functionality.

6. Data Retention

  • Merchant accounts: retained while the account is active; deleted 30 days after cancellation
  • Order records: retained for 7 years for financial/legal compliance
  • Uploaded files: deleted when the merchant account is hard-deleted or files are removed
  • Server logs: retained for 90 days

7. Security

We implement industry-standard security measures including: bcrypt password hashing (cost 12), HTTPS everywhere, input validation and sanitization (DOMPurify + Zod), fail-closed webhook verification, and rate limiting on sensitive endpoints. However, no system is 100% secure and we cannot guarantee absolute security.

8. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data (right to be forgotten)
  • Export your data in a portable format
  • Withdraw consent for optional processing

Merchant accounts can self-delete their store from Admin → Settings → Danger Zone. To exercise other rights, contact us at yrgtechsolutions@gmail.com.

9. Children's Privacy

Our platform is not directed to children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us immediately.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify merchants via email and platform announcements when significant changes are made. Continued use of the platform after changes constitutes acceptance of the updated policy.

11. Contact Us

For privacy-related questions or requests, contact us at: yrgtechsolutions@gmail.com