New: Smart ShippingSee it →
IndiSell
Legal

Privacy policy

Last updated: 15 August 2026

This Privacy Policy explains how Remold Technologies (a partnership firm registered in India, GSTIN 24ABNFR4980N1ZE), which operates the IndiSell brand ("IndiSell", "we", "us", "our"), collects, uses, discloses, retains and protects personal data. It applies to this website (indisell.io), the IndiSell merchant dashboard, and the IndiSell checkout experience that our merchants embed in their own online stores. Please read it together with our Terms of Service and Refund & Cancellation Policy.

By using the website or the service, you acknowledge that you have read and understood this policy. Capitalised terms not defined here have the meaning given in the Terms of Service.

1 · Definitions

  • Personal data / personal information — any data about an individual who is identifiable by or in relation to such data.
  • Data Principal — the individual to whom personal data relates (a merchant contact, or a shopper).
  • Data Fiduciary / controller — the person who determines the purpose and means of processing personal data.
  • Data Processor — a person who processes personal data on behalf of a Data Fiduciary.
  • Merchant — a business or person that signs up for IndiSell to run checkout on its own store.
  • Shopper — an end customer who checks out on a Merchant's store using the IndiSell checkout.
  • Sub-processor — a third party we engage to help deliver the service (e.g. cloud hosting, messaging).
  • DPDP Act — the Digital Personal Data Protection Act, 2023 of India, and the rules made under it.

2 · Our two roles (this matters)

IndiSell sits between two kinds of people, and our responsibilities differ for each:

For Merchants — we are the Data Fiduciary

When you sign up, contact us, or use the dashboard, we decide why and how your account data is handled, so we are the controller of that data and are directly answerable to you for it.

For Shoppers — we are a Data Processor

When a Shopper checks out on a Merchant's store, the Merchant is the Data Fiduciaryof that Shopper's data. We process it strictly on the Merchant's documented instructions, only to operate their checkout, risk controls and messaging — not for our own independent purposes. Shoppers should direct data requests to the Merchant they bought from; we support Merchants in fulfilling those requests.

3 · Personal data we collect from Merchants

  • Identity & account: name, business/store name, store URL, email, phone, password (stored only as a salted hash), and role assignments for your team.
  • Billing: plan, pricing terms, invoices, GSTIN, transaction/usage counts and payment status for our fees. We do not store your card details for our own billing beyond what our billing processor requires.
  • Communications: messages, demo requests, support tickets and their contents.
  • Connected credentials: API keys/tokens for the payment gateways and messaging providers you connect. These are stored encrypted and used solely to operate your checkout.
  • Usage & technical: dashboard settings, configuration, log-in events, audit-log entries, device/browser information, IP address and diagnostic logs.

4 · Personal data we process for Shoppers (on the Merchant's behalf)

To complete an order and run the Merchant's checkout, we process:

  • Contact & identity: mobile number (verified by OTP), name, and email where provided.
  • Delivery: shipping address, PIN code, landmark and delivery preferences.
  • Order: cart contents, order value, selected payment method, payment status, and order/fulfilment outcomes.
  • Fraud & COD-abuse prevention: order-history signals, prior delivery/return (RTO) outcomes, and device/network information such as IP address, used to score cash-on-delivery risk.
  • Messaging: phone/email on the channels the Merchant configured (SMS, WhatsApp, email), used to send order updates and abandoned-cart reminders that the Merchant has enabled.

Saved details (such as a Shopper's address) are recalled only after that Shopper re-verifies the same phone number by OTP — a stranger cannot pull up someone else's saved information.

5 · Purposes and legal bases

We process personal data for these purposes, on these bases under the DPDP Act:

  • To provide the service (run checkout, create the order in the Merchant's store, take payment via the Merchant's gateway) — necessary for performance of the contract / the Shopper's requested transaction.
  • Fraud & COD-risk control — our and Merchants' legitimate use to prevent losses and protect the platform.
  • Order & cart messaging — on the Merchant's configuration and the lawful basis the Merchant is responsible for maintaining (see Terms).
  • Billing, support and account administration — performance of the contract with the Merchant.
  • Security, debugging and audit — legitimate use to keep the service safe and reliable.
  • Legal compliance — where we must retain or disclose data under applicable law.

6 · What we never collect or store

We never see or store full card numbers, CVV/CVC codes, card PINs, UPI PINs or net-banking passwords. All payments are processed by the Merchant's own payment gateways(for example Razorpay, PayU, Cashfree, PhonePe); card data is handled inside the gateway's PCI-DSS environment and funds settle directly to the Merchant. We are not a payment aggregator, wallet or money-transmitter and never hold Shopper funds.

7 · Cookies, storage and tracking

  • This website uses only essential cookies/local storage needed to serve pages and remember basic preferences. It does not run third-party advertising cookies to build ad profiles of you.
  • The checkout uses browser storage strictly to keep a Shopper's session working — for example remembering that a phone number was OTP-verified so the Shopper isn't asked to verify again on every visit. This is functional, not advertising.
  • Merchant-enabled conversion tracking: if a Merchant turns on ad-conversion tracking, the Merchant's own Google/Meta/GA4 tags may run on their store under the Merchant's control and their own cookie notice.

You can block or delete cookies in your browser; essential cookies are required for checkout to function.

8 · How and with whom we share data

We share personal data only as needed to run the service, and never sell it:

  • Payment gateways chosen by the Merchant — to authorise and capture payment.
  • Messaging providers (SMS/DLT aggregators, WhatsApp Business, email senders) — to deliver order and cart messages the Merchant enabled.
  • Shopify — orders are created in the Merchant's own Shopify store; Shopify processes that order data as the Merchant's provider.
  • Cloud hosting & infrastructure — to run and secure the service.
  • Ad platforms (Google, Meta, GA4)only when the Merchant enables conversion tracking, and limited to order values, click identifiers and hashed (irreversible) email/phone for match purposes.
  • Professional advisers (auditors, lawyers, accountants) under confidentiality, where necessary.
  • Authorities — where disclosure is required by law, court order, or to protect rights, safety or the integrity of the platform.
  • Business transfers — if the business is merged, acquired or reorganised, data may transfer to the successor under this same policy; we will notify affected Merchants.

We do not sell personal data, and we do not share it for third parties' own advertising.

9 · Sub-processors

We engage the categories of sub-processors listed above to deliver the service. We require them, by contract, to protect personal data, use it only to provide their service to us, and apply appropriate security. On written request, a Merchant may ask for the current list of sub-processors relevant to its account.

10 · Cross-border transfers

We primarily host and process data on infrastructure located in or serving India. Where a sub-processor (for example a messaging or analytics provider) processes data outside India, we do so only as permitted by applicable law and subject to appropriate safeguards. Payment data stays within the relevant gateway's compliant environment.

11 · Data retention

  • Merchant account & order records are kept while the Merchant's account is active, because they form the Merchant's own business records, and for a reasonable period afterwards to meet legal, tax and audit obligations.
  • Demo/contact-form details are kept only as long as needed to follow up, then deleted or anonymised.
  • Security & audit logs are kept for a limited period appropriate to their purpose.
  • On the closure of an account, a Merchant may request export and deletion of its store's data; we will comply subject to records we must retain by law.

12 · How we protect data (security)

  • Encryption in transit (TLS) across the website, dashboard and checkout.
  • Encryption at rest for sensitive credentials (gateway/messaging keys).
  • Role-based access control with an audit log of team actions.
  • OTP rate-limiting and abuse controls; server-side re-verification of prices and discounts so amounts can't be tampered with client-side.
  • Principle of least privilege and regular review of access.

No method of transmission or storage is perfectly secure, but we work to protect data using reasonable, industry-standard safeguards. See our security page for more.

13 · Your rights

Merchants

You may access, correct, update or request deletion of your account data, request a copy/export, withdraw consent where processing is based on consent, and nominate another person to exercise your rights in the event of death or incapacity, as provided under the DPDP Act. Write to us using the contact details below.

Shoppers

Because the Merchant is the Data Fiduciary of your checkout data, please raise access, correction, erasure or grievance requests with the Merchant you purchased from. If you reach us directly, we will route your request to the relevant Merchant and assist them in responding. Where the DPDP Act grants you rights against us for data we control, we honour them.

14 · Children

The service is intended for businesses and adult shoppers. We do not knowingly collect personal data of children (individuals under 18) for our own purposes. Merchants are responsible for their own compliance where their audience includes minors, and for obtaining verifiable parental consent where the DPDP Act requires it.

15 · Breach notification

If a personal-data breach affecting the service occurs, we will act to contain and remediate it, notify the relevant Merchant(s) without undue delay, and comply with any notification obligations to the Data Protection Board of India and affected individuals under the DPDP Act.

16 · Grievance Officer & contact

In line with the DPDP Act and the Information Technology rules, you can raise privacy questions, requests or grievances with our Grievance Officer:

Grievance Officer, Remold Technologies
B-6002, Ascon Plaza, Anand Mahal Road, Adajan, Surat, Gujarat 395009, India
GSTIN: 24ABNFR4980N1ZE

We aim to acknowledge grievances promptly and resolve them within the timelines applicable under law. General queries can go to hello@indisell.io.

17 · Changes to this policy

We may update this policy as the service, our practices or the law evolve. We will change the "Last updated" date above and, for material changes affecting Merchants, provide reasonable notice. Continued use after an update means you accept the revised policy.

This document is provided for transparency and does not constitute legal advice. Remold Technologies recommends having independent counsel review it against your specific circumstances.

See it on your store
20-min walkthrough · no commitment
Book a demo