LEGAL / DATA PROTECTION

Privacy policy

What we collect from vendors and their shoppers, why we hold it, who we share it with, and how to get it out or have it deleted.

VERSION
1.0
EFFECTIVE
22 August 2026
DATA STORED IN
India
In short

We collect what a store needs to run β€” your business details, your catalogue, and your customers' order details. We never sell personal data, never advertise on your storefront, and you can export or delete your data whenever you like.

01

Who is responsible

[FILL IN: Registered business/entity name] (operating as dsauq) is responsible for the data you give us as a vendor β€” your account, your plan, your invoices with us. For the shoppers who buy from your store, you are the business responsible for their data and we process it on your instructions.

Questions either way reach us at support@dsauq.com.

02

What we collect

CategoryExamplesSource
RegistrationName, business name, address, mobile, email, PAN, GSTINYou
VerificationOTP logs, documents you upload, approval decisionsYou, us
Store contentProducts, prices, HSN codes, images, theme settingsYou
CommerceOrders, invoices, refunds, payouts, bank detailsYou, partners
TechnicalIP address, device and browser, pages viewed, error logsAutomatic

We do not collect card numbers β€” payment details are captured directly by the gateway and never touch our servers.

03

Why we use it

  • To review your application and run your store, dashboard and billing.
  • To take payments, settle payouts and generate GST-compliant invoices.
  • To detect fraud, abuse and prohibited listings, and to keep the service secure.
  • To meet tax, accounting and other legal obligations.
  • To send service notices, and β€” only with your consent β€” product news you can unsubscribe from.
04

Shopper data on your store

Names, addresses, phone numbers and order histories collected through your storefront belong to your customer relationship. We hold them so orders can be fulfilled, invoiced and delivered, and so you can see them in the dashboard.

We do not use your shoppers' data to market our own products, do not share it with other vendors, and do not build cross-store profiles. You must use it only to fulfil orders and to market with consent, and you must publish your own privacy notice.

05

Who we share with

Payment partners
To collect payments and settle payouts
Courier partners
Delivery address and phone, per shipment
Cloud & messaging
Hosting, SMS and email delivery
Authorities
Where the law requires, and only that much

Every partner is bound by contract to use the data only for the task we give them. We do not sell personal data, and we do not share it for advertising.

06

Cookies and tracking

The dashboard uses strictly necessary cookies to keep you signed in and to protect the session. Storefronts use a cart cookie plus first-party analytics you can switch off in Settings. If you add your own third-party pixel or analytics tag to your theme, that tracking is yours to declare and obtain consent for.

07

How long we keep it

DataRetention
Invoices, orders and tax records8 years (statutory)
Vendor account and store contentWhile active, then 90 days
Rejected applications12 months
Security and access logs180 days
OTP and verification logs90 days
08

How we protect it

Data is encrypted in transit (TLS 1.2+) and at rest, stored in Indian data centres, and reachable only by staff who need it for support or investigation β€” with access logged. Bank details and PAN are masked in the interface.

If a breach affects your data, we will tell you and the relevant authority without undue delay, along with what happened and what to do.

09

Your rights

You can ask to see, correct, export or delete the personal data we hold about you, withdraw consent for marketing, or nominate someone to act for you. Most of it is self-service in Settings; anything else, write to us and we will respond within 30 days.

Some data survives a deletion request where tax or accounting law requires us to keep it β€” invoices, chiefly. We will say what was kept and why.
10

Children and sensitive data

dsauq is for businesses; accounts are not offered to anyone under 18. Do not upload health records, biometric data or other sensitive categories into product fields, order notes or customer records β€” the platform is not designed to hold them.

11

Changes and contact

Material changes to this policy are notified by email and in the dashboard 30 days before they take effect, and past versions stay available on request.

Grievance Officer, [FILL IN: Registered business/entity name], [FILL IN: registered city] β€” support@dsauq.com. Unresolved complaints can be escalated to the Data Protection Board of India.

Want a copy of your data?
Export products, orders and invoices any time from Settings β†’ Data.
Register your business