Legal
Privacy Policy
Last updated: 14 April 2025
1. Who We Are
InstaShop (referred to as "we", "us", or "our") is an e-commerce SaaS platform that helps social media sellers (Instagram, Facebook, YouTube, and beyond) in India launch branded stores and manage orders. Our registered entity operates from India. For any privacy-related queries, contact us at: privacy@instashop.in.
2. Information We Collect
When you register and use InstaShop, we collect:
**Account Information**: Name, email address, phone number, and password (stored as a one-way bcrypt hash).
**Store Information**: Store name, logo, product images, pricing, inventory data, and order details.
**Customer Data You Provide**: When your customers place orders through your InstaShop store, their name, phone, email, and delivery address are stored in your dashboard. You control this data.
**Usage Data**: Pages visited, time on site, clicks, errors — collected anonymously for platform improvement.
**Payment Data**: We do not store credit card or UPI numbers. If you use Razorpay, payments are processed by Razorpay and governed by their Privacy Policy.
3. How We Use Your Information
We use your information to:
- Operate and maintain your InstaShop store and dashboard
- Send transactional emails (order confirmations, password resets)
- Send low-stock alerts and platform announcements you've opted into
- Improve platform features based on anonymised usage data
- Comply with legal obligations
We do not sell your data to third parties. Ever.
4. Data Storage & Security
Your data is stored in a PostgreSQL database hosted on Supabase (AWS, Singapore region). Images are stored on Cloudinary CDN. We use industry-standard encryption in transit (HTTPS/TLS) and at rest.
Access to production data is restricted to InstaShop core team members on a need-to-know basis.
5. Cookies
We use session cookies for authentication (keeping you logged in) and may use analytics cookies to understand traffic patterns. We do not use third-party advertising cookies.
6. Your Rights
Under India's Digital Personal Data Protection Act (DPDPA), you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Raise a grievance with our Data Protection Officer
To exercise any right, email: privacy@instashop.in
7. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we purge your personal data within 30 days, except where retention is required by law (e.g., financial transaction records for 7 years).
8. Children's Privacy
InstaShop is not intended for use by individuals under the age of 18. We do not knowingly collect data from minors.
9. Changes to This Policy
We may update this policy. If we make material changes, we will notify you via email or an in-app banner at least 7 days before the change takes effect.
10. Contact
For privacy concerns, contact: privacy@instashop.in
Data Protection Officer: dpo@instashop.in
InstaShop Technologies, India.