Privacy Policy
Learn how TWAICY collects, uses, protects and processes information while ensuring complete merchant data ownership and customer privacy.
Privacy Shield
Encrypted Platform • Protected
1. Overview
Privacy-by-Design & Zero-Monetization Commitment
TWAICY is committed to protecting merchant business data and customer privacy. Our multi-tenant commerce platform is engineered using Privacy-by-Design principles.
We only collect and process information strictly necessary to operate your online store, process catalog data, and facilitate customer order fulfillment. We never sell, rent, or monetize merchant customer data.
Your online store, catalog, customer records, and sales intelligence belong 100% to your business.
We never sell or rent merchant or customer information to third-party ad networks or brokers.
Every system feature is architected with cryptographic data protection and store-level isolation.
Clear legal policies without hidden clauses or fine-print data claim loopholes.
2. Information We Collect
Categories of Operational Data Processed by TWAICY
To provide e-commerce platform services, website builder capabilities, and order routing, we process three categories of information:
- • Business Name & Legal Identity
- • Email Address & Phone Number
- • GST Number (Optional)
- • Physical Store Address
- • Business Preferences & Settings
- • Customer Name & Contact Info
- • Delivery & Billing Address
- • Phone Number for Orders
- • Order History & Invoices
- • Product Reviews & Wishlist
- • Product Descriptions & Images
- • Categories & Collections
- • Storefront Orders & Inventory
- • Theme Layout & Canvas JSON
- • Basic Storefront Visit Analytics
3. How We Use Information
Strict Operational Processing Purposes
Platform Operations
Provisioning store workspaces, theme builders, and hosting storefronts.
Order Processing
Routing orders, generating invoices, and syncing inventory ledgers.
Store Management
Allowing merchant team staff to edit products, stock levels, and settings.
Customer Support
Assisting merchants with technical troubleshooting and onboarding.
Security & Fraud Prevention
Detecting unauthorized login attempts and safeguarding API endpoints.
Performance Analytics
Measuring platform uptime, page load speeds, and database performance.
Merchant Notifications
Sending critical system updates, password resets, and order alerts.
4. Merchant Data Ownership
Intellectual Property & Data Sovereignty Guarantee
TWAICY explicitly affirms that merchants retain 100% data sovereignty and intellectual property ownership over all business assets processed within our platform. TWAICY never claims ownership over your business.
Your Products belong to you
Catalog items, pricing models, SKUs, and product media gallery.
Your Customer Database belongs to you
Customer profiles, contact records, and purchasing history.
Your Orders belong to you
Sales ledger records, transaction history, and financial invoices.
Your Branding belongs to you
Logos, brand domain, theme palettes, and marketing copy.
Your Website belongs to you
Storefront layouts, section components, and canvas trees.
5. Payment Security & Direct Payouts
Zero Storage of Sensitive Financial Credentials
TWAICY is architected so that customer payments settle directly into the merchant's configured bank or payment gateway account.
6. Cookies & Local Storage
Session Cookies & Minimal Browser Storage Usage
We use browser cookies and local storage strictly to ensure security, maintain active login sessions, and save merchant preferences. We do not use third-party cross-site tracking cookies.
Necessary Cookies
Essential session cookies required for merchant login authentication, CSRF token security, and shopping cart persistence.
Analytics Cookies
Aggregated, anonymized performance metrics measuring website page load speeds, response times, and platform errors.
Preference Cookies
Remembers merchant admin settings such as language selection, dark/light theme choices, and dashboard view filters.
Security Cookies
Used by NestJS security guards to detect suspicious login patterns and prevent unauthorized API session hijacking.
7. Third Party Services & Integration Subprocessors
Strict Infrastructure Data Transfer Controls
We integrate with trusted third-party infrastructure subprocessors to provide delivery routing, payment collection, and email dispatch. Only minimum data necessary to execute the request is transmitted. Data is never sold.
Cloudflare
Provides DDoS protection, SSL termination, and static asset caching.
Shiprocket
Receives order delivery addresses when merchant initiates AWB generation.
Razorpay
Processes online card/netbanking payments via PCI-compliant API.
Email Service Providers
Delivers merchant password resets, invoices, and store notifications.
SMS Gateway Providers
Sends login verification OTPs and order status SMS updates.
8. Data Security Safeguards
Multi-Layered Technical Safeguards Protecting Store Infrastructure
HTTPS & TLS Encryption
Transport Layer Security encrypting all browser-to-server data in transit.
JWT Authentication
Cryptographically signed JSON Web Tokens for stateless, secure session validation.
Role Based Access (RBAC)
Granular permissions restricting store data to authorized staff & merchant owners.
Password Hashing
Credentials are salt-hashed prior to storage; plaintext passwords are never saved.
System Audit Logs
Event tracking logging administrative updates, store settings, and role changes.
Secure Guard APIs
NestJS authorization guards, DTO input sanitization, and rate limiting.
Automated Database Backups
Regular database snapshots safeguarding store records against hardware faults.
Website Version Rollbacks
Immutable layout state snapshots enabling instant 1-click version rollbacks.
9. Data Retention Policy
Lifecycle & Archival Duration for Platform Records
We retain merchant data for as long as your store workspace account remains active. Retention timelines for specific system ledgers are defined below:
Active Merchant Data
Retained throughout active subscription duration. Upon store closure request, account data is purged following a 30-day grace period.
Active Account LifeCustomer Orders & Invoices
Order ledger records and GST tax invoices are retained as required by applicable commercial accounting and tax laws.
Statutory Tax ComplianceAudit Logs & Backups
System access logs, audit trails, and encrypted database snapshots are rotated on an automated 90-day rolling cycle.
90-Day Rotation Cycle10. Your Rights & Merchant Control
Merchant Rights Over Store Workspace & Personal Identifiers
As a merchant operating on TWAICY, you exercise complete authority over your store workspace and business data:
Download & Export Data
Download complete CSV/JSON exports of your products, customer records, and orders anytime.
Request Data Inspection
Request a detailed audit breakdown of data logged for your merchant account.
Correct Business Information
Update your business name, store address, GST identity, and staff access roles.
Withdraw Marketing Consent
Opt-out of non-essential platform announcements or promotional communications.
Store Closure & Purge
Request complete termination and soft/hard deletion of your store workspace.
11. Policy Updates & Revision Notifications
Transparent Notification Procedure for Policy Revisions
We may update this Privacy Policy periodically to reflect enhancements in platform security, feature capabilities, or regulatory requirements.
If material revisions are made to how merchant data or customer privacy is handled, TWAICY will notify store owners via email and dashboard banner alerts at least 14 days prior to the effective date.
12. Contact Privacy & Legal Team
Dedicated Privacy Assistance & Compliance Enquiries
If you have questions regarding data rights, privacy safeguards, or system compliance, contact our privacy desk directly:
