Privacy Policy
v1.0 · Effective 1 August 2026 · Last updated 29 July 2026
This document is published in English only. The English version is the one that applies.
In plain English
This policy is about you — the shop owner and your staff. It says what we know about you and why.
Your own customers' details are a separate thing. There you are in charge and we only follow your instructions. That is covered by the Data Processing Agreement.
We do not sell anything about you, and we do not train artificial intelligence on your data.
If a plan ends, your workspace stays readable for 90 days and is then deleted. Our own tax records naming your business are kept eight years, because the law says we must.
You can ask us what we hold, ask us to fix it, and ask us to delete it. Write to [email protected].
A summary to help you read this. It is not the agreement — the sections below are.
1. Who we are, and what this policy covers
Vaadify is operated by Anbu Gnana Durai, a sole proprietor trading as Rani Software Labs, at 26/1 Ellaya Mudali Street, Korukkupet, Chennai, Tamil Nadu 600021, India.
This policy explains how we handle personal data about you: the person who signs up, the people in your workspace, and the business details you give us so we can bill you. For that data, under the Digital Personal Data Protection Act, 2023, we are the Data Fiduciary — we decide why and how it is processed.
It does not cover your own customers' data. When you record a renter's name, phone number, address or identity document in Vaadify, you are the Data Fiduciary for that person and we are your Data Processor. We process it only on your instructions. Section 10 explains that split, and the full terms are in our Data Processing Agreement at https://vaadify.com/legal/data-processing-agreement.
2. What we collect, and why
Your account. Your name, email address, and the password or sign-in method you choose. Collected so we can create your account, sign you in, and tell your workspace apart from everyone else's. Sign-in is handled for us by Clerk; we never see your password.
Your business details. Your shop name, address, GSTIN, phone number and billing email. Collected so we can raise a valid tax invoice to you and work out the right GST. Some of it is required by tax law, not chosen by us.
Your billing records. What plan you are on, what you paid, when, and the invoices we issued you. Payments themselves go through Razorpay. We never see or store your card number, UPI PIN or bank details — Razorpay holds those, and we only receive confirmation that a payment succeeded or failed, along with a reference number.
Your staff. For each person you add to the workspace: their name, email and role. You give us this, so please tell them.
Your agreement to our terms. When you accept our terms we record which documents, which version, the date and time, and the IP address and browser your device reported. This is the evidence that an agreement exists. Without it, publishing terms would prove nothing.
How you use the product. Pages visited, actions taken, features used, error reports, and technical details your browser sends — IP address, browser and device type, and rough location from the IP. Collected to keep the service working, find and fix faults, prevent abuse, and decide what to build next. Error reports go to Sentry and can occasionally contain personal data that appeared on the screen where the error happened.
Messages between us. Emails you send to support, and the replies. Kept so we can follow up and so the next person who reads it has the history.
Website visitors. Our public website uses Cloudflare Web Analytics, which is cookieless and does not follow you across sites.
What we do not collect. We do not buy data about you from anyone, we do not run advertising or profiling cookies, and we do not track you across other websites.
3. Why we are allowed to hold it
- Because you asked for the service. Most of it is data you gave us so we could give you an account and run it. You consented when you created the account and accepted our terms, and you can withdraw that consent by closing the account — though we cannot run the service without it.
- Because the law requires it. Your business name, GSTIN, address and our invoices to you are kept because tax and accounting law requires us to keep our books.
- Because we must keep the service safe and working. Logs, error reports and security records. We keep these to the minimum that is useful.
We do not use your data for any purpose other than the one it was collected for. If we ever want to, we will ask you first.
4. How long we keep it
| What | How long |
|---|---|
| Your workspace data while you are a customer | For as long as your account is open |
| Your workspace data after a plan ends or is cancelled | Readable and exportable for 90 days, then permanently deleted |
| Our own billing records about you — invoices, payments, your name, GSTIN and address | Eight years, because tax and company law require it |
| Your acceptance of our terms | Eight years, as evidence that the agreement existed |
| Support emails | Three years |
| Server and security logs | Up to 12 months |
| Error reports | 90 days |
We would rather say this plainly than bury it. "Deleted after 90 days" is true of your shop's operational data — orders, customers, inventory, documents and files. It is not true of our own accounting records that happen to name your business, because we are required to keep those for eight years. They are our books, they are not used for anything else, and nobody else sees them except our accountant and the authorities if they ask.
5. Who we share it with
We share your data only with the companies we need to run Vaadify, and only as much as each one needs. Every one of them, what it does, and the country its data sits in is listed at https://vaadify.com/legal/sub-processors. That page is dated, and we update it before a new company is added.
Apart from those, we share your data:
- when the law requires it — a court order, a lawful demand from an authority, or to establish or defend a legal claim;
- to protect people — where there is a serious risk to someone's safety or to the security of the service;
- if the business changes hands — if Vaadify is transferred to a company or registered firm that takes it over, your data moves with it, on the same terms, and we will tell you before it happens.
We do not sell your personal data. We do not share it with advertisers. We do not use it to train artificial-intelligence models.
6. Where your data is kept
Vaadify's database, application servers and file storage are operated by other companies, and some of them hold data outside India. The exact country for each is named at https://vaadify.com/legal/sub-processors.
Indian law permits personal data to be transferred outside India except to countries the government has restricted. We tell you where it goes because you are entitled to know, not because there is anything to hide.
7. How we protect it
The measures we actually have in place:
- Separation between shops is enforced by the database itself. Every tenant-owned table carries a Postgres row-level security policy, so one shop cannot read another's rows even if application code has a bug. The application connects with a restricted database role that cannot bypass those policies.
- Government identity numbers are encrypted at rest with AES-256-GCM at the application layer, so they are unreadable in the database and in a backup.
- Everything travels over TLS, between your browser and us and between us and the services we depend on.
- Sign-in is handled by Clerk, a specialist provider. We never store your password.
- Access is limited to the people who need it, which today is a very short list.
We do not hold SOC 2, ISO 27001 or any other security certification, and we have not commissioned an independent penetration test. We would rather tell you that than let a page of security words imply otherwise. No system is perfectly secure.
8. Your rights
Under the Digital Personal Data Protection Act, 2023, you can:
- Ask what we hold about you and how we have used it and shared it.
- Ask us to correct it if it is wrong, incomplete or out of date, or to complete it if something is missing.
- Ask us to erase it, unless the law requires us to keep it — our billing records being the main case where it does.
- Complain to us and have your complaint dealt with, which is what the Grievance Officer in section 12 is for.
- Nominate someone to exercise these rights on your behalf if you die or become unable to act.
- Withdraw your consent, as easily as you gave it. Closing your account withdraws it for everything the service does not legally have to keep.
How to use them. Write to [email protected] from the email address on your account, and say what you want. We will acknowledge within two working days and resolve within fifteen working days. If we need to check who you are before acting, we will ask.
There is no charge. If a request is repetitive or clearly excessive we may say so and explain why, rather than quietly ignore it.
9. Cookies and similar things
We keep this short because there is not much of it.
- Sign-in cookies, set by Clerk. Strictly necessary — without them you cannot stay signed in. They are not used for tracking.
- A language cookie, remembering which of the nine languages you chose.
- Cloudflare Web Analytics on the public website. Cookieless. It counts page views without identifying you or following you elsewhere.
- On-device storage. If you install Vaadify as an app, it keeps some data on your own device so it works when the connection drops. That data is yours and is cleared when you sign out or remove the app.
There are no advertising cookies, no profiling and no cross-site tracking, which is why you do not see a consent banner. A banner offering a choice that does not exist would be theatre.
10. Your own customers' data
This is the part shop owners most often get wrong, so it is worth being clear.
When you enter a renter's name, phone number, address, photograph or identity document into Vaadify:
- You decide to collect it, why, and for how long. Under the Act that makes you the Data Fiduciary for that person.
- We hold and process it only on your instructions, to run the service for you. That makes us your Data Processor.
- The duty to tell that person what you are collecting and why, and to have a lawful basis for it, is yours. It is not ours and we cannot do it for you.
- If that person asks us directly to see or delete their data, we will point them to you and tell you they asked.
The terms on which we process it — security, confidentiality, sub-processors, breach notice, deletion — are in the Data Processing Agreement at https://vaadify.com/legal/data-processing-agreement, which forms part of your agreement with us.
11. Children
Vaadify is business software and is not meant for anyone under 18. Do not create an account if you are under 18, and do not enter a child's personal data into a workspace without the verifiable consent of their parent or guardian that the law requires.
If we learn that we hold a child's data that should not be there, we will remove it.
12. Complaints, and our Grievance Officer
If anything about your personal data concerns you, tell us first — most of it is fixed the same week.
Grievance Officer: Anbu Gnana Durai Email: [email protected] Address: Rani Software Labs, 26/1 Ellaya Mudali Street, Korukkupet, Chennai, Tamil Nadu 600021, India
We acknowledge within two working days and resolve within fifteen working days. Full details are at https://vaadify.com/legal/contact-and-grievance.
If we do not resolve it to your satisfaction, you have the right to complain to the Data Protection Board of India.
13. Changes to this policy
If we change this policy we will publish the new version here with a new version number and date. For a change that materially affects your rights we will give at least 30 days' notice by email and in the app, and say plainly what changed.
Older versions are kept, and we record which version was in force when.