Privacy Policy

Effective date: 20 June 2025  · Last updated: 20 June 2025

SoftVibe Services (“we”, “us”, or “our”) operates IceSaathi (“the Service”). This Privacy Policy explains what personal and business data we collect, how we use it, who we share it with, and your rights regarding your data. By using the Service, you consent to the practices described in this policy.

1. What Data We Collect

1.1 Information you provide directly

  • Account registration data: Name, email address, phone number, shop/business name, password (hashed, never stored in plain text).
  • Business profile data: GSTIN, business logo, digital signature image, QR code image, bank details (account holder name, account number, IFSC code, UPI ID, bank name).
  • Product data: Product names, categories, prices, stock levels.
  • Customer data: Customer shop names, contact numbers, address, area, GPS location coordinates.
  • Order and billing data: Order details, invoice numbers, amounts, payment modes, settlement status.
  • Delivery partner data: Name, email, contact number of delivery staff you register.

1.2 Data collected automatically

  • Device fingerprint: A hashed identifier generated from your browser characteristics (screen resolution, CPU cores, timezone, canvas rendering) to detect new device logins. This is stored in your browser's localStorage and never transmitted to third parties.
  • Usage logs: Activity logs of key actions performed in the dashboard (e.g. “Product added”, “Order created”) for audit purposes.
  • IP address: Collected at login for security and fraud prevention.
  • Browser and device information: User agent string, operating system, for device session management.

1.3 GPS location data

  • Delivery partners voluntarily share their GPS location during active deliveries. Location data is stored temporarily and is visible only to the Account Owner who manages that delivery partner.
  • Customer GPS coordinates (if you record them) are stored as part of the customer record and visible only to users of your account.

1.4 Payment data

Payment processing is handled by Razorpay. We do not store your credit card, debit card or UPI credentials. We store only Razorpay's order and payment IDs for our records.

2. How We Use Your Data

  • To provide the Service: Storing and displaying your products, customers, orders and invoices.
  • Account management: Creating and maintaining your account, verifying your email, managing sessions.
  • Security: Detecting suspicious logins using device fingerprinting, IP logging and session management.
  • Billing: Processing subscription payments and verifying payment status through Razorpay.
  • Communication: Sending OTPs for email verification and password reset, subscription alerts, and important service notices to your registered email.
  • Analytics (internal): Aggregated, anonymised usage data to improve the Service. We do not sell individual user data for advertising.
  • Legal compliance: Maintaining records required by law.

4. Data Sharing

We do not sell your personal or business data to any third party. We share your data only with the following categories of sub-processors, and only to the extent necessary to provide the Service:

Sub-processorPurposeData shared
RazorpayPayment processingEmail, amount, order ID
CloudinaryImage storageBusiness logo, signature, QR code images
MongoDB AtlasDatabaseAll account and business data
Firebase (Google)Push notificationsFCM device tokens
Nodemailer / SMTPTransactional emailsEmail address, OTP

We may also disclose your data if required to do so by law or in response to a lawful request by public authorities (e.g. a court order).

5. Data Storage & Security

  • Data is stored on MongoDB Atlas servers, which use encryption at rest and in transit.
  • Passwords are hashed using bcrypt before storage. We never store plain-text passwords.
  • Authentication uses JWT tokens with expiry limits, stored in HTTP-only cookies.
  • Device fingerprinting adds an additional layer of session security.
  • All communication with the Service is over HTTPS.

Despite our measures, no internet transmission or electronic storage is 100% secure. We cannot guarantee absolute security of your data.

6. Data Retention

  • Active accounts: Data is retained for as long as your account is active.
  • After account deletion or termination: Your data is retained for 30 days to allow for recovery requests, then permanently deleted.
  • Payment records: Transaction records are retained for 7 years as required by Indian financial regulations.
  • Activity logs: Retained for 90 days, then automatically purged.

You may request deletion of your data at any time by emailing softvibeservices@gmail.com. We will respond within 30 days.

7. Cookies & Local Storage

We use the following:

  • Authentication cookies (HTTP-only): Secure, HTTP-only cookies to maintain your login session. These are essential for the Service to function.
  • localStorage — device fingerprint: A hashed device identifier stored under the key dv_fp to detect login from new devices. Contains no personally identifiable information.
  • localStorage — user session: Your name, shop name and role are cached in localStorage for faster dashboard loading. This data is cleared on logout.

We do not use third-party advertising cookies or analytics cookies (e.g. Google Analytics) at this time.

8. Your Rights

You have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate data. You can update most data directly from your dashboard profile.
  • Deletion: Request deletion of your account and all associated data.
  • Portability: Request your business data (products, customers, orders) in a structured, machine-readable format.
  • Withdraw consent: Where processing is based on consent (e.g. GPS location for delivery partners), you may withdraw consent at any time.
  • Objection: Object to processing of your data for any purpose that is not strictly necessary to provide the Service.

To exercise any of these rights, email us at softvibeservices@gmail.com. We will respond within 30 days.

9. Children's Privacy

The Service is not directed at children under 18 years of age. We do not knowingly collect personal data from anyone under 18. If you believe a minor has registered, please contact us at softvibeservices@gmail.com and we will promptly delete the account.

10. International Data Transfers

Your data is primarily stored on servers located in or near India (MongoDB Atlas Asia-Pacific region). Some sub-processors (e.g. Cloudinary, Firebase) may process data in other regions. These providers maintain adequate security standards and comply with applicable data protection laws.

11. Changes to This Policy

We may update this Privacy Policy periodically. When we make significant changes, we will notify you by email or an in-app notice and update the “Last updated” date. Continued use of the Service after the update constitutes your acceptance of the revised policy.

12. Contact Us

For privacy-related enquiries or to exercise your rights, contact us:

Company: SoftVibe Services

Product: IceSaathi

Email: softvibeservices@gmail.com

Website: https://softvibe-service.vercel.app/