This Privacy Policy explains how Vefri ("Vefri", "we", "us", or "our") processes personal data when merchants use our application and when end customers interact with Vefri-powered capture links or messages.
This policy applies to our website, merchant dashboard, mobile capture experience, Shopify App Store application, and WhatsApp Business Platform integration. It describes what information we collect, why we collect it, how we use and share it, and how you can request access or deletion.
Vefri is designed for business (B2B) use by merchants. Merchants are generally responsible for providing privacy notices to their customers and obtaining required consents before collecting evidence or sending messages. This policy describes Vefri's role as a processor or service provider, depending on context, and our own practices as a controller for account and platform data.
By using the Service, you acknowledge this Privacy Policy. If you do not agree, please do not use the Service.
1. Scope & Roles
Depending on the data and context, Vefri may act as a data fiduciary/controller for merchant account information and platform operations, and as a data processor/service provider handling order, return, and evidence data on behalf of merchants.
- Merchant account data: Vefri is typically the controller
- End customer order, return, and evidence data: the merchant is typically the controller; Vefri processes on merchant instructions
- WhatsApp and SMS messaging data: processed to deliver transactional messages initiated by merchants
- Logistics data synced from courier APIs: processed to display shipment context in the merchant workspace
2. Information We Collect
2.1 Merchant account & workspace data
- Name, email address, phone number, company name, and billing details
- Billing and subscription details processed through our payment provider
- Login credentials and authentication tokens
- Team member roles, workspace settings, and audit logs
- Support communications and feedback
2.2 Order, return & operations data
- Order IDs, return IDs, SKUs, product names, values, and statuses
- Customer name, phone number, email, and address fragments as synced from merchant systems or logistics APIs
- AWB numbers, courier provider, shipment milestones, and delivery timestamps
- Risk scores, review notes, QC outcomes, and workflow events
2.3 Evidence & capture data
- Photos and videos uploaded through capture links
- File metadata such as content type, size, checksum, capture phase, and waypoint
- Upload timestamps, capture token references, and processing status
- Limited device and browser technical data needed to operate capture (user agent, IP address, approximate network information)
- Optional location or device signals only where enabled by the capture flow and permitted by applicable law and merchant disclosures
2.4 WhatsApp Business Platform & messaging data
When merchants connect WhatsApp through Vefri, we access and process data from the WhatsApp Business Platform solely to send and manage transactional messages on the merchant's behalf. We do not use WhatsApp data for advertising, profiling unrelated to the merchant's service, or resale.
- Merchant WhatsApp Business Account identifiers, phone number IDs, and display names
- End customer phone numbers used to deliver capture links, order updates, or return-related messages
- Message content such as approved template text, dynamic parameters (for example customer name or order reference), and button or link payloads
- Message delivery metadata including send status, delivery status, read receipts where available, error codes, and WhatsApp message IDs
- Inbound customer replies received through connected WhatsApp numbers, including text, button responses, and media metadata
- Template names, languages, approval status, and quality signals provided by the messaging platform
- Opt-in, opt-out, block, or complaint signals where reported by the messaging platform
2.5 Website, cookies & analytics
- Pages visited, referral URLs, and interaction events on our website and dashboard
- Cookies and similar technologies for authentication, preferences, and security
- Aggregated usage metrics to improve reliability and product design
2.6 Shopify store data
When you install the Vefri Shopify app, we access store data only through the OAuth scopes you approve. See Section 8A for full details on protected customer data, retention, compliance webhooks, and international transfers.
- Shop domain, shop ID, shop name, and OAuth access tokens
- Order IDs, line items, financial status, fulfillment status, return tags, and related order metadata
- Customer name, email address, and phone number where exposed through authorized customer read scopes
- Fulfillment and shipment events used to display delivery context in your workspace
3. How We Use Information
- Provide, operate, secure, and troubleshoot the Service
- Authenticate users and prevent fraud or abuse
- Store, organize, and display evidence for merchant review
- Send transactional WhatsApp or SMS messages that merchants configure, such as delivery proof requests, return evidence links, and status updates
- Track message delivery and troubleshoot messaging failures
- Sync and normalize logistics data from authorized courier integrations
- Generate analytics, risk indicators, and operational insights within your workspace
- Process subscription billing
- Comply with law, enforce terms, and respond to lawful requests
- Improve models, UX, and infrastructure using aggregated or de-identified data where possible
4. Legal Bases (India & International)
Where applicable under India's Digital Personal Data Protection Act, 2023 (DPDP Act) and similar laws, we rely on one or more of the following: consent, performance of a contract, compliance with legal obligations, and legitimate uses permitted by law.
Merchants are responsible for ensuring a valid legal basis exists before collecting end customer evidence, contacting customers on WhatsApp, or processing personal data through Vefri.
6. Payment Processing
When you purchase a paid Vefri plan, payment collection and related billing operations may be provided by a third-party merchant-of-record payment provider.
Vefri does not store full card numbers or complete payment credentials on our servers. We may receive limited transaction metadata such as payment status, invoice references, and subscription identifiers needed to provision and manage your workspace.
- Billing name, email address, billing address, tax identifiers, and payment method details you provide at checkout
- Transaction status, invoice numbers, subscription identifiers, and refund or chargeback records shared with Vefri for account provisioning
- Fraud-prevention, authentication, and payment-network processing performed by payment providers and their subprocessors
7. WhatsApp Business Platform Disclosures
Vefri uses the WhatsApp Business Platform to help merchants send transactional messages to their customers. Message delivery is subject to Meta's WhatsApp Business Terms of Service, WhatsApp Business Messaging Policy, and related platform policies.
Vefri is not WhatsApp. WhatsApp is a service provided by Meta. When merchants use WhatsApp through Vefri, certain personal data is processed by Meta in accordance with Meta's policies.
- Messages are sent only for merchant-initiated transactional purposes such as delivery proof requests, return evidence collection, and order or return status updates configured by the merchant
- Merchants must obtain valid opt-in from end customers before sending WhatsApp messages, in line with WhatsApp's opt-in requirements and applicable law
- Merchants must provide end customers with clear notice that WhatsApp may be used for transactional communications related to their order or return
- We process phone numbers, message content, delivery metadata, and inbound replies only as needed to operate messaging on the merchant's behalf
- We do not use WhatsApp data for unrelated marketing, advertising, or sale to third parties
- Phone numbers and message metadata may be processed or stored by Meta outside your country depending on Meta's infrastructure
- End customers may block a business number, opt out of further messages, or raise complaints through WhatsApp; merchants must honor those preferences
- Vefri may suspend messaging features if we detect policy violations, high complaint rates, or misuse
8. Logistics Partner Data
When you connect courier or shipping platforms, Vefri imports data made available through their APIs using credentials you provide. This may include personally identifiable information about your customers.
- Data is used to match evidence to orders, display shipment status, and support return workflows
- Retention follows your workspace settings and our standard retention schedule unless law requires longer storage
- You must comply with each logistics partner's developer terms, privacy policy, and data use restrictions
- Disconnecting an integration stops new syncs; previously imported data may remain until deleted under your retention settings
8A. Shopify App, Protected Customer Data & Compliance
This section applies when you install the Vefri app from the Shopify App Store or connect your Shopify store through OAuth. For Shopify-related personal data, the merchant is typically the data controller and Vefri acts as a data processor or service provider, processing data only on the merchant's instructions to operate return and evidence workflows.
Vefri does not sell Shopify store data, use it for advertising, share it with other merchants, or use it for purposes unrelated to providing the Service.
8A.1 Data collected through Shopify APIs
We request only the access scopes required for return and evidence workflows. We do not modify checkout, payments, themes, storefront content, or customer accounts through the Shopify API.
- read_orders: order identifiers, order status, line items, product titles, SKUs, quantities, prices, financial status, tags, and return-related metadata
- read_customers: customer identifiers and contact fields needed for return communication, including name, email address, and phone number where exposed by Shopify
- read_fulfillments: fulfillment status, shipment events, tracking references, and delivery timestamps
- Shop and installation metadata: shop domain, shop ID, shop name, OAuth access tokens, granted scopes, and webhook payloads
8A.2 Data collected directly from merchants
- Merchant account registration details such as name, email address, phone number, and company name
- Workspace settings, billing details, team access, and audit activity within the Vefri dashboard
- Support messages and voluntary information you provide when contacting us
- Automated technical logs relating to app usage, authentication, errors, and security events
8A.3 Data collected from merchants' customers
Vefri does not install tracking pixels or cookies on a merchant's Shopify storefront. Customer data is collected when merchants initiate evidence or return workflows.
- Photos and videos submitted through secure capture links sent by the merchant
- Limited device and browser technical data on the capture page, such as user agent and IP address, needed to operate and secure uploads
- Customer name, phone number, or email when synced from Shopify or logistics integrations to match orders and send capture links
- WhatsApp or SMS delivery metadata when the merchant enables messaging for transactional capture requests
8A.4 How Shopify-related data is used
- Sync orders, customers, and fulfillment data into the merchant workspace
- Match evidence to the correct order and return request
- Send transactional capture links and status updates configured by the merchant
- Display shipment and return context for merchant review
- Generate risk indicators and workflow suggestions to assist human review
- Operate, secure, troubleshoot, and improve the Service using aggregated or de-identified data where possible
- We do not use Shopify data for unrelated marketing, advertising, profiling, or resale
8A.5 Retention of Shopify-related data
- Synced Shopify order and customer data is retained while the app remains installed and as needed to provide the Service
- Evidence media is retained according to workspace settings, plan limits, and legal requirements
- When a merchant uninstalls the app or Shopify sends a shop redact request, we revoke access tokens, stop new syncs, and delete or anonymize shop-linked personal data according to our retention schedule, typically within 48 hours of a valid shop redact signal unless a longer period is required by law
- When Shopify sends a customer redact request, we delete or anonymize personal data associated with the identified customer and orders, subject to legitimate legal or security retention needs
- Backups may retain deleted data for a limited period before being overwritten
8A.6 International transfers and establishment
Vefri is established in India. Shopify-related data may be processed and stored in India and in other countries where we or our subprocessors operate, including cloud hosting and object storage regions outside your country.
Where required by applicable law, we implement appropriate safeguards for cross-border transfers, such as contractual clauses and technical security controls.
8A.7 Mandatory Shopify compliance webhooks
As required by Shopify for apps distributed through the Shopify App Store, Vefri implements and responds to mandatory compliance webhooks.
- customers/data_request: when a store customer requests access to personal data, we review records linked to the customer identifiers Shopify provides and assist the merchant in fulfilling the request
- customers/redact: when a store customer requests erasure, we delete or anonymize personal data associated with the identified customer and orders in our systems
- shop/redact: after app uninstall, we delete or anonymize shop-linked personal data and revoke stored access tokens
- Invalid webhook signatures are rejected. Valid requests are processed in line with Shopify's requirements and applicable law
8A.8 Customer rights and merchant contact
End customers who purchased from a Shopify store should contact the merchant first to exercise privacy rights relating to their order or evidence. Merchants may contact us at support@vefri.io for assistance fulfilling customer requests received through Shopify compliance webhooks or direct merchant requests.
Merchants may disconnect Shopify at any time from the Vefri dashboard. New data sync stops after token revocation or uninstall.
9. Evidence Storage & Access Controls
- Evidence files are stored in encrypted object storage with access restricted to authorized systems and personnel
- Merchant workspace users can access evidence according to their role permissions
- Vefri personnel access production data only on a need-to-know basis for support, security, or legal compliance
- Download and export actions may be logged for audit purposes
10. International Data Transfers
Vefri may process and store data in India and other countries where we or our subprocessors operate. Where required, we implement appropriate safeguards such as contractual clauses and security controls for cross-border transfers.
11. Security Measures
We use administrative, technical, and organizational measures designed to protect personal data, including encryption in transit, access controls, monitoring, and secure development practices. No method of transmission or storage is completely secure; you use the Service at your own risk.
- Report suspected security issues to support@vefri.io
- Merchants must protect dashboard credentials and restrict team access appropriately
12. Data Retention
We retain personal data for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Evidence retention may be configurable within your workspace subject to plan limits.
- Account data: retained while the workspace is active and for a limited period after closure
- Evidence media: retained per workspace settings, plan, and legal requirements
- WhatsApp and messaging logs: retained for troubleshooting, compliance, and dispute resolution periods, then deleted or anonymized according to our retention schedule
- Backups: may persist for a limited time after deletion from active systems
13. Data Deletion Requests
You have the right to request access to, correction of, or deletion of personal data we process, subject to applicable law and legitimate retention needs.
If you connected Vefri through a third-party platform such as Meta or Shopify and remove the app or revoke permissions, you may also submit a data deletion request through that platform. We will process verified deletion requests in line with our obligations under applicable law and platform terms.
- Merchants: email support@vefri.io from your registered account email with the subject line "Data Deletion Request". Include your company name and workspace email. We will verify your identity and confirm deletion or explain any data we must retain by law
- Shopify merchants: uninstalling the Vefri app triggers Shopify's shop redact process. Customer-specific erasure requests are handled through Shopify's customers/redact compliance webhook and merchant support requests
- Merchant team members: ask your workspace administrator to remove your account, or email support@vefri.io with your account email
- End customers who purchased from a merchant: contact the merchant you purchased from first. Merchants can request deletion of customer-linked evidence and order data through support@vefri.io on behalf of their customers where required by law
- WhatsApp messaging data: deletion requests for message-related data may require verification of the phone number or merchant relationship. We will delete or anonymize eligible records unless retention is required for legal, security, or dispute-resolution purposes
- We aim to acknowledge deletion requests within 7 business days and complete eligible deletions within timelines required by applicable law
14. Your Rights & Choices
Depending on applicable law, merchants and individuals may have rights to access, correct, delete, withdraw consent, nominate a representative, or lodge grievances regarding personal data.
- Merchants can update account information in dashboard settings
- Merchants may request export or deletion of workspace data by contacting support@vefri.io
- End customers should generally contact the merchant they purchased from for evidence-related requests; Vefri will assist merchants where required by law
- You may opt out of non-essential marketing emails using unsubscribe links
15. Merchant Obligations to End Customers
If you are a merchant, you are responsible for providing a clear privacy notice to end customers explaining evidence collection, retention, sharing with Vefri, use of WhatsApp or SMS, and customer rights. Your notice should identify Vefri as a service provider where appropriate.
- Obtain valid WhatsApp opt-in before sending business-initiated messages
- Inform customers before requesting camera, microphone, or location access
- Only request evidence necessary for delivery proof, returns, or QC
- Respond to customer data requests within timelines required by law
16. Children's Privacy
The Service is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided data through Vefri, contact support@vefri.io.
17. Automated Decision-Making
Vefri may provide risk indicators, mismatch flags, or workflow suggestions based on rules and signals you configure. These features assist human review and do not, by themselves, make legally binding decisions unless you configure them to do so.
18. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the dashboard, email, or website. The "Last updated" date at the top indicates the latest revision.
19. Grievance Officer & Contact
For privacy questions, data requests, or complaints under applicable Indian law, contact:
Grievance Officer, Vefri
Email: support@vefri.io
Place of business: Jaipur, India
Response timeline: we aim to acknowledge requests within 7 business days and resolve eligible requests within timelines required by applicable law.
Questions about this document?
Contact us at support@vefri.io.