TWAICY
Home/Legal/Privacy Policy
TWAICY Legal Documentation

Privacy Policy

Learn how TWAICY collects, uses, protects and processes information while ensuring complete merchant data ownership and customer privacy.

Merchant First
Privacy by Design
No Hidden Tracking
Secure Infrastructure
GDPR Ready

Privacy Shield

Encrypted Platform • Protected

Merchant Data Ownership

1. Overview

Privacy-by-Design & Zero-Monetization Commitment

TWAICY is committed to protecting merchant business data and customer privacy. Our multi-tenant commerce platform is engineered using Privacy-by-Design principles.

We only collect and process information strictly necessary to operate your online store, process catalog data, and facilitate customer order fulfillment. We never sell, rent, or monetize merchant customer data.

Merchant Ownership

Your online store, catalog, customer records, and sales intelligence belong 100% to your business.

No Data Selling

We never sell or rent merchant or customer information to third-party ad networks or brokers.

Privacy First

Every system feature is architected with cryptographic data protection and store-level isolation.

Transparent Platform

Clear legal policies without hidden clauses or fine-print data claim loopholes.

2. Information We Collect

Categories of Operational Data Processed by TWAICY

To provide e-commerce platform services, website builder capabilities, and order routing, we process three categories of information:

Merchant Account Data
  • • Business Name & Legal Identity
  • • Email Address & Phone Number
  • • GST Number (Optional)
  • • Physical Store Address
  • • Business Preferences & Settings
Customer Data
  • • Customer Name & Contact Info
  • • Delivery & Billing Address
  • • Phone Number for Orders
  • • Order History & Invoices
  • • Product Reviews & Wishlist
Website & Catalog Data
  • • Product Descriptions & Images
  • • Categories & Collections
  • • Storefront Orders & Inventory
  • • Theme Layout & Canvas JSON
  • • Basic Storefront Visit Analytics

3. How We Use Information

Strict Operational Processing Purposes

Platform Operations

Provisioning store workspaces, theme builders, and hosting storefronts.

Order Processing

Routing orders, generating invoices, and syncing inventory ledgers.

Store Management

Allowing merchant team staff to edit products, stock levels, and settings.

Customer Support

Assisting merchants with technical troubleshooting and onboarding.

Security & Fraud Prevention

Detecting unauthorized login attempts and safeguarding API endpoints.

Performance Analytics

Measuring platform uptime, page load speeds, and database performance.

Merchant Notifications

Sending critical system updates, password resets, and order alerts.

4. Merchant Data Ownership

Intellectual Property & Data Sovereignty Guarantee

TWAICY explicitly affirms that merchants retain 100% data sovereignty and intellectual property ownership over all business assets processed within our platform. TWAICY never claims ownership over your business.

"Merchant data always remains the exclusive intellectual property of the merchant. TWAICY acts purely as a technology infrastructure provider."

Your Products belong to you

Catalog items, pricing models, SKUs, and product media gallery.

Your Customer Database belongs to you

Customer profiles, contact records, and purchasing history.

Your Orders belong to you

Sales ledger records, transaction history, and financial invoices.

Your Branding belongs to you

Logos, brand domain, theme palettes, and marketing copy.

Your Website belongs to you

Storefront layouts, section components, and canvas trees.

5. Payment Security & Direct Payouts

Zero Storage of Sensitive Financial Credentials

TWAICY is architected so that customer payments settle directly into the merchant's configured bank or payment gateway account.

Financial Data TWAICY NEVER Stores:
✕ Debit Card Numbers
✕ Credit Card CVV / Expiry
✕ Customer UPI PIN Passcodes
✕ Net Banking Credentials
Direct Payout & PCI Compliance: Merchant UPI QR transactions remain direct transfers between customer and merchant. Integrated online payment gateways (e.g. Razorpay) process card data directly on PCI-DSS Level 1 compliant servers using end-to-end tokenization.

6. Cookies & Local Storage

Session Cookies & Minimal Browser Storage Usage

We use browser cookies and local storage strictly to ensure security, maintain active login sessions, and save merchant preferences. We do not use third-party cross-site tracking cookies.

Necessary Cookies

Essential session cookies required for merchant login authentication, CSRF token security, and shopping cart persistence.

Analytics Cookies

Aggregated, anonymized performance metrics measuring website page load speeds, response times, and platform errors.

Preference Cookies

Remembers merchant admin settings such as language selection, dark/light theme choices, and dashboard view filters.

Security Cookies

Used by NestJS security guards to detect suspicious login patterns and prevent unauthorized API session hijacking.

7. Third Party Services & Integration Subprocessors

Strict Infrastructure Data Transfer Controls

We integrate with trusted third-party infrastructure subprocessors to provide delivery routing, payment collection, and email dispatch. Only minimum data necessary to execute the request is transmitted. Data is never sold.

Subprocessor

Cloudflare

CDN & Edge Security

Provides DDoS protection, SSL termination, and static asset caching.

Subprocessor

Shiprocket

Courier API Integration

Receives order delivery addresses when merchant initiates AWB generation.

Subprocessor

Razorpay

Payment Gateway

Processes online card/netbanking payments via PCI-compliant API.

Subprocessor

Email Service Providers

System Email Dispatch

Delivers merchant password resets, invoices, and store notifications.

Subprocessor

SMS Gateway Providers

OTP & Order Alerts

Sends login verification OTPs and order status SMS updates.

8. Data Security Safeguards

Multi-Layered Technical Safeguards Protecting Store Infrastructure

HTTPS & TLS Encryption

Transport Layer Security encrypting all browser-to-server data in transit.

JWT Authentication

Cryptographically signed JSON Web Tokens for stateless, secure session validation.

Role Based Access (RBAC)

Granular permissions restricting store data to authorized staff & merchant owners.

Password Hashing

Credentials are salt-hashed prior to storage; plaintext passwords are never saved.

System Audit Logs

Event tracking logging administrative updates, store settings, and role changes.

Secure Guard APIs

NestJS authorization guards, DTO input sanitization, and rate limiting.

Automated Database Backups

Regular database snapshots safeguarding store records against hardware faults.

Website Version Rollbacks

Immutable layout state snapshots enabling instant 1-click version rollbacks.

9. Data Retention Policy

Lifecycle & Archival Duration for Platform Records

We retain merchant data for as long as your store workspace account remains active. Retention timelines for specific system ledgers are defined below:

Active Merchant Data

Retained throughout active subscription duration. Upon store closure request, account data is purged following a 30-day grace period.

Active Account Life

Customer Orders & Invoices

Order ledger records and GST tax invoices are retained as required by applicable commercial accounting and tax laws.

Statutory Tax Compliance

Audit Logs & Backups

System access logs, audit trails, and encrypted database snapshots are rotated on an automated 90-day rolling cycle.

90-Day Rotation Cycle

10. Your Rights & Merchant Control

Merchant Rights Over Store Workspace & Personal Identifiers

As a merchant operating on TWAICY, you exercise complete authority over your store workspace and business data:

Download & Export Data

Download complete CSV/JSON exports of your products, customer records, and orders anytime.

Request Data Inspection

Request a detailed audit breakdown of data logged for your merchant account.

Correct Business Information

Update your business name, store address, GST identity, and staff access roles.

Withdraw Marketing Consent

Opt-out of non-essential platform announcements or promotional communications.

Store Closure & Purge

Request complete termination and soft/hard deletion of your store workspace.

11. Policy Updates & Revision Notifications

Transparent Notification Procedure for Policy Revisions

We may update this Privacy Policy periodically to reflect enhancements in platform security, feature capabilities, or regulatory requirements.

Merchant Revision Notification Guarantee

If material revisions are made to how merchant data or customer privacy is handled, TWAICY will notify store owners via email and dashboard banner alerts at least 14 days prior to the effective date.

12. Contact Privacy & Legal Team

Dedicated Privacy Assistance & Compliance Enquiries

If you have questions regarding data rights, privacy safeguards, or system compliance, contact our privacy desk directly:

Privacy Officer
privacy@twaicy.com

For merchant data requests & privacy inquiries.

General Platform Support
support@twaicy.com

For merchant onboarding, store assistance & billing help.

Still Have Privacy Questions?

Our Privacy & Compliance team is ready to assist you with data sovereignty verifications and store governance questions.

HomeSearchProfile