01 Who this policy covers
Zaisus Commerce is operated by ZAISUS TECHNOLOGIES (OPC) PRIVATE LIMITED, registered at A4, Chandrasekhar Avenue, Thoraipakkam, Greater Chennai, Tamil Nadu 600097 (“Zaisus Commerce”, “we”, “us”). This policy explains how we handle personal information across our marketing site, the store builder, the merchant app and the stores we host.
Two different relationships run through this product, and the difference decides who is answerable for what:
- You, the merchant
- When you sign up, we are the controller of your information. We decide what to collect about you and why, and this policy is the answer.
- Your shoppers
- When someone buys from a store you built on Zaisus Commerce, you are the controller of that shopper's information and we are your processor. We hold and move that data on your instructions. Your own privacy policy governs it — not this one. See section 10.
If you are a shopper trying to reach a store owner, contact the store directly. We will pass on a request if we can identify the store, but we cannot act on it ourselves.
02 Information we collect
- Information you give us. Your name, business name, email address, phone number, city, chosen currency, store URL and branding. If you book a demo or contact support, whatever you write in that message.
- Store content. Everything you publish or upload — products, prices, descriptions, images, policies, categories, discount rules and templates.
- Order and customer records. Orders placed in your store, along with the buyer details you need to fulfil them: name, delivery address, contact details, order contents and status. We hold this for you.
- Payment information. Amounts, currency, status, timestamps and the reference issued by your payment provider. We do not receive, store or process full card numbers, CVVs or bank credentials — those go straight from the shopper's browser to the provider.
- Billing information for your Zaisus Commerce subscription. Plan, billing period, invoices, tax identifiers, and the payment token our billing provider returns. Again, not the card itself.
- Usage and device information. Pages viewed, features used, referring page, approximate location derived from IP address, browser and operating system, device type, screen size, and timestamps. Collected as server logs and product analytics.
- Communications. Support conversations, bug reports, feedback, and whether you opened or clicked a message we sent you.
- Information from integrations you enable. If you connect a payment provider, a messaging channel, an analytics tool or an advertising platform, that service returns account identifiers, status and delivery or performance metrics to us so we can show them to you.
We do not ask for special-category information — health, biometrics, political or religious views, and so on. Please do not put it into free-text fields.
03 How we use information
Each use has a stated purpose and a lawful basis. Where the basis is consent, you can withdraw it at any time without affecting what happened before.
| Purpose | What it involves | Lawful basis |
|---|---|---|
| Providing the service | Creating and hosting your store, processing orders, sending notifications | Performance of a contract |
| Billing | Charging your plan, issuing invoices, chasing failed payments | Performance of a contract |
| Support | Answering questions, reproducing bugs, restoring data | Performance of a contract |
| Security and abuse prevention | Rate limiting, fraud checks, audit logs, investigating misuse | Legitimate interests |
| Improving the product | Aggregated usage analysis, performance measurement | Legitimate interests |
| Service messages | Outages, security notices, changes to terms | Legitimate interests |
| Marketing to you | Product news and offers by email | Consent, or soft opt-in where permitted |
| Non-essential cookies | Analytics and advertising measurement | Consent |
| Legal and tax obligations | Keeping invoices, responding to lawful requests | Legal obligation |
We do not sell personal information, and we do not use your store's order data to train general-purpose models or to build advertising profiles about your shoppers.
04 Cookies and similar technologies
Cookies, local storage and pixels are all covered here. Only the strictly necessary ones are set before you choose.
| Category | What it does | Set by default | Typical life |
|---|---|---|---|
| Strictly necessary | Sign-in session, CSRF protection, cart contents, load balancing | Yes — the service will not work without them | Session to 30 days |
| Preferences | Language, currency, reduced-motion and theme choices | Yes | 12 months |
| Analytics | Which features are used and where people get stuck | No — consent first | 13 months |
| Advertising measurement | Attributing a signup to the campaign that produced it | No — consent first | 90 days |
You can change your choice at any time by adjusting , or clearing cookies in your browser. Blocking strictly necessary cookies will sign you out and break the checkout.
Stores built on Zaisus Commerce may set their own cookies where the merchant has enabled an integration. That is the merchant's decision and their policy applies.
We honour the Global Privacy Control signal where the law gives it effect, and we treat Do Not Track as a request to skip non-essential analytics.
05 Who we share information with
We share only what a recipient needs, under a written contract that limits them to acting on our instructions. A current list of named sub-processors is available upon request at contact@zaisustechnologies.com, and we will give 30 days notice there before adding a new one.
| Category | Why | What they receive |
|---|---|---|
| Hosting and infrastructure | Running the platform | Everything, encrypted at rest |
| Payment providers | Taking payments and paying you out | Order amounts, references, and the shopper details the provider requires |
| Messaging providers | Sending order and delivery notifications | Recipient contact details and message content |
| Email and SMS delivery | Transactional and marketing messages | Address or number, message content, delivery events |
| Analytics and error monitoring | Understanding usage, diagnosing crashes | Pseudonymous usage and device data |
| Advertising platforms | Only where you connect one — see the note below | Campaign identifiers and conversion events |
| Professional advisers | Accounting, audit, legal | Whatever the engagement requires |
We may also disclose information where we are legally compelled to, where it is needed to establish or defend a legal claim, or to prevent imminent harm. If a business transfer such as a merger or acquisition happens, information moves with the business and we will tell you before it does.
06 Where information is processed
Primary hosting is in India and the United States. Support, monitoring and some sub-processors operate from other countries, so your information may be transferred outside the country where it was collected.
Where it is, we rely on one of: an adequacy decision covering the destination; standard contractual clauses with the recipient; or your explicit consent. A copy of the safeguards in place is available on request at contact@zaisustechnologies.com.
07 How long we keep it
We keep information for as long as it serves the purpose it was collected for, then delete or anonymise it.
- Account and store data — for as long as your account is open, then 30 days in a recoverable state so an accidental closure can be undone, then deletion.
- Order and invoice records — 8 years, or whatever your local tax law requires, whichever is longer.
- Support conversations — 24 months.
- Security and audit logs — 12 months.
- Marketing consent records — for as long as needed to prove the consent was validly obtained.
- Backups — deleted data persists in encrypted backups for up to 35 days before those backups age out.
08 How we protect it
Transport is encrypted with TLS and stored data is encrypted at rest. Access to production is role-based, granted on a need-to-know basis, requires multi-factor authentication, and is logged. Backups are encrypted and restores are tested. Staff receive data-protection training and are under confidentiality obligations.
No system is perfectly secure. If a breach happens that is likely to put you at risk, we will notify you and the relevant supervisory authority within the period the law requires — 72 hours of becoming aware, under most regimes — and tell you what happened and what to do about it.
Report a suspected vulnerability to contact@zaisustechnologies.com. We will not pursue researchers who act in good faith and give us reasonable time to fix an issue.
09 Your rights and choices
Depending on where you live, some or all of the following apply. We do not charge for exercising them and we will not treat you worse for doing so.
- Access — a copy of the information we hold about you.
- Correction — fix anything inaccurate or incomplete.
- Deletion — erase it, where we have no overriding obligation to keep it.
- Portability — receive it in a structured, machine-readable format, or have it sent elsewhere.
- Restriction and objection — pause a use, or object to processing based on legitimate interests.
- Withdraw consent — for anything we do on the basis of consent, including marketing.
- Opt out of marketing — unsubscribe in any message, or change it in your account settings. Service messages about outages, security and billing continue regardless.
- Nominate — where local law provides it, appoint someone to exercise these rights if you die or become incapacitated.
- Complain — to us first, and to your data protection authority whenever you like.
Write to contact@zaisustechnologies.com from the address on your account, or use the export and delete tools in your account settings. We respond within 30 days, and will tell you if we need longer. We may ask for proof of identity before acting on a request — that check protects you, not us.
If your request concerns data held on a merchant's behalf, we will forward it to that merchant and tell you we have done so. See section 10.
10 If you are a shopper on a merchant's store
The merchant you bought from decides what happens to your information. They chose what to collect, they set the retention, and their privacy policy is the one that governs. We provide the software and hold the data for them.
So: send access, correction and deletion requests to the store you dealt with. If you cannot reach them, write to us at contact@zaisustechnologies.com with the store address and we will route it, but we cannot delete a merchant's records on your say-so — that instruction has to come from them.
Merchants agree in our terms to publish their own privacy notice and to handle these requests properly.
11 Children
Zaisus Commerce is a business tool and is not directed at children. We do not knowingly collect information from anyone under 18. If we learn that we have, we delete it. If you believe a child's information has reached us, write to contact@zaisustechnologies.com.
12 Automated decisions and profiling
We use automated checks for fraud, spam and abuse — for example, flagging an unusual burst of signups from one address. These can delay or block an action.
We do not make decisions with a legal or similarly significant effect on you purely by automated means without a human able to review them. If an automated check affects your account, you can ask a person to look at it by writing to contact@zaisustechnologies.com, and you can contest the outcome.
13 Changes to this policy
When this policy changes we update the version number and effective date at the top. For a change that materially affects your rights we will tell you by email or in the product at least 30 days before it takes effect, so you can object or close your account first.
Previous versions are available upon request at contact@zaisustechnologies.com.
14 Contact and complaints
- Privacy questions and rights requests
- contact@zaisustechnologies.com
- Data Protection Officer
- Privacy Desk, contact@zaisustechnologies.com
- Grievance Officer
- Grievance Redressal Officer, contact@zaisustechnologies.com — Acknowledgement within 48 hours, resolution within 30 days.
- Postal address
- ZAISUS TECHNOLOGIES (OPC) PRIVATE LIMITED, A4, Chandrasekhar Avenue, Thoraipakkam, Greater Chennai, Tamil Nadu 600097
- Supervisory authority
- You may complain to Data Protection Board of India (DPBI) at any time, without going through us first.
Read alongside our Terms & Conditions.