Privacy Policy
Effective date: 20 June 2025 · Last updated: 20 June 2025
SoftVibe Services (“we”, “us”, or “our”) operates IceSaathi (“the Service”). This Privacy Policy explains what personal and business data we collect, how we use it, who we share it with, and your rights regarding your data. By using the Service, you consent to the practices described in this policy.
1. What Data We Collect
1.1 Information you provide directly
- Account registration data: Name, email address, phone number, shop/business name, password (hashed, never stored in plain text).
- Business profile data: GSTIN, business logo, digital signature image, QR code image, bank details (account holder name, account number, IFSC code, UPI ID, bank name).
- Product data: Product names, categories, prices, stock levels.
- Customer data: Customer shop names, contact numbers, address, area, GPS location coordinates.
- Order and billing data: Order details, invoice numbers, amounts, payment modes, settlement status.
- Delivery partner data: Name, email, contact number of delivery staff you register.
1.2 Data collected automatically
- Device fingerprint: A hashed identifier generated from your browser characteristics (screen resolution, CPU cores, timezone, canvas rendering) to detect new device logins. This is stored in your browser's localStorage and never transmitted to third parties.
- Usage logs: Activity logs of key actions performed in the dashboard (e.g. “Product added”, “Order created”) for audit purposes.
- IP address: Collected at login for security and fraud prevention.
- Browser and device information: User agent string, operating system, for device session management.
1.3 GPS location data
- Delivery partners voluntarily share their GPS location during active deliveries. Location data is stored temporarily and is visible only to the Account Owner who manages that delivery partner.
- Customer GPS coordinates (if you record them) are stored as part of the customer record and visible only to users of your account.
1.4 Payment data
Payment processing is handled by Razorpay. We do not store your credit card, debit card or UPI credentials. We store only Razorpay's order and payment IDs for our records.
2. How We Use Your Data
- To provide the Service: Storing and displaying your products, customers, orders and invoices.
- Account management: Creating and maintaining your account, verifying your email, managing sessions.
- Security: Detecting suspicious logins using device fingerprinting, IP logging and session management.
- Billing: Processing subscription payments and verifying payment status through Razorpay.
- Communication: Sending OTPs for email verification and password reset, subscription alerts, and important service notices to your registered email.
- Analytics (internal): Aggregated, anonymised usage data to improve the Service. We do not sell individual user data for advertising.
- Legal compliance: Maintaining records required by law.
3. Legal Basis for Processing
We process your data on the following legal bases:
- Contractual necessity: Processing required to provide the Service you subscribed to.
- Legitimate interests: Security monitoring, fraud prevention, and improving the Service.
- Consent: Where you have explicitly opted in, such as GPS location sharing by delivery partners.
- Legal obligation: Where we are required to retain records by applicable Indian law.
4. Data Sharing
We do not sell your personal or business data to any third party. We share your data only with the following categories of sub-processors, and only to the extent necessary to provide the Service:
| Sub-processor | Purpose | Data shared |
|---|---|---|
| Razorpay | Payment processing | Email, amount, order ID |
| Cloudinary | Image storage | Business logo, signature, QR code images |
| MongoDB Atlas | Database | All account and business data |
| Firebase (Google) | Push notifications | FCM device tokens |
| Nodemailer / SMTP | Transactional emails | Email address, OTP |
We may also disclose your data if required to do so by law or in response to a lawful request by public authorities (e.g. a court order).
5. Data Storage & Security
- Data is stored on MongoDB Atlas servers, which use encryption at rest and in transit.
- Passwords are hashed using bcrypt before storage. We never store plain-text passwords.
- Authentication uses JWT tokens with expiry limits, stored in HTTP-only cookies.
- Device fingerprinting adds an additional layer of session security.
- All communication with the Service is over HTTPS.
Despite our measures, no internet transmission or electronic storage is 100% secure. We cannot guarantee absolute security of your data.
6. Data Retention
- Active accounts: Data is retained for as long as your account is active.
- After account deletion or termination: Your data is retained for 30 days to allow for recovery requests, then permanently deleted.
- Payment records: Transaction records are retained for 7 years as required by Indian financial regulations.
- Activity logs: Retained for 90 days, then automatically purged.
You may request deletion of your data at any time by emailing softvibeservices@gmail.com. We will respond within 30 days.
8. Your Rights
You have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate data. You can update most data directly from your dashboard profile.
- Deletion: Request deletion of your account and all associated data.
- Portability: Request your business data (products, customers, orders) in a structured, machine-readable format.
- Withdraw consent: Where processing is based on consent (e.g. GPS location for delivery partners), you may withdraw consent at any time.
- Objection: Object to processing of your data for any purpose that is not strictly necessary to provide the Service.
To exercise any of these rights, email us at softvibeservices@gmail.com. We will respond within 30 days.
9. Children's Privacy
The Service is not directed at children under 18 years of age. We do not knowingly collect personal data from anyone under 18. If you believe a minor has registered, please contact us at softvibeservices@gmail.com and we will promptly delete the account.
10. International Data Transfers
Your data is primarily stored on servers located in or near India (MongoDB Atlas Asia-Pacific region). Some sub-processors (e.g. Cloudinary, Firebase) may process data in other regions. These providers maintain adequate security standards and comply with applicable data protection laws.
11. Changes to This Policy
We may update this Privacy Policy periodically. When we make significant changes, we will notify you by email or an in-app notice and update the “Last updated” date. Continued use of the Service after the update constitutes your acceptance of the revised policy.
12. Contact Us
For privacy-related enquiries or to exercise your rights, contact us:
Company: SoftVibe Services
Product: IceSaathi
Email: softvibeservices@gmail.com
Website: https://softvibe-service.vercel.app/