This Privacy Policy explains how Vefri ("Vefri", "we", "us", or "our") processes personal data when merchants use our platform and when end customers interact with Vefri-powered capture links or messages.

Vefri is designed for business (B2B) use by merchants. Merchants are generally responsible for providing privacy notices to their customers and obtaining required consents before collecting evidence. This policy describes Vefri's role as a processor or service provider, depending on context, and our own practices as a controller for account and website data.

By using the Service, you acknowledge this Privacy Policy. If you do not agree, please do not use the Service.

1. Scope & Roles

Depending on the data and context, Vefri may act as a data fiduciary/controller for merchant account information and platform operations, and as a data processor/service provider handling order, return, and evidence data on behalf of merchants.

  • Merchant account data: Vefri is typically the controller
  • End customer order, return, and evidence data: the merchant is typically the controller; Vefri processes on merchant instructions
  • Messaging metadata (WhatsApp/SMS): processed to deliver capture links at merchant direction
  • Logistics data synced from courier APIs: processed to display shipment context in the merchant workspace

2. Information We Collect

2.1 Merchant account & workspace data

  • Name, email address, phone number, company name, and billing details
  • Login credentials and authentication tokens
  • Team member roles, workspace settings, and audit logs
  • Support communications and feedback

2.2 Order, return & operations data

  • Order IDs, return IDs, SKUs, product names, values, and statuses
  • Customer name, phone number, email, and address fragments as synced from merchant systems or logistics APIs
  • AWB numbers, courier provider, shipment milestones, and delivery timestamps
  • Risk scores, review notes, QC outcomes, and workflow events

2.3 Evidence & capture data

  • Photos and videos uploaded through capture links
  • File metadata such as content type, size, checksum, capture phase, and waypoint
  • Upload timestamps, capture token references, and processing status
  • Limited device and browser technical data needed to operate capture (user agent, IP address, approximate network information)
  • Optional location or device signals only where enabled by the capture flow and permitted by applicable law and merchant disclosures

2.4 WhatsApp and messaging data

  • Business phone numbers and WhatsApp Business account identifiers you connect
  • Message delivery metadata, template IDs, session status, and error codes
  • End customer phone numbers and message content necessary to send capture links or status updates you configure
  • Opt-in/opt-out signals where provided by the messaging platform

2.5 Website, cookies & analytics

  • Pages visited, referral URLs, and interaction events on vefri.io and the dashboard
  • Cookies and similar technologies for authentication, preferences, and security
  • Aggregated usage metrics to improve reliability and product design

3. How We Use Information

  • Provide, operate, secure, and troubleshoot the Service
  • Authenticate users and prevent fraud or abuse
  • Store, organize, and display evidence for merchant review
  • Send capture links and transactional messages you configure through connected channels
  • Sync and normalize logistics data from authorized courier integrations
  • Generate analytics, risk indicators, and operational insights within your workspace
  • Comply with law, enforce terms, and respond to lawful requests
  • Improve models, UX, and infrastructure using aggregated or de-identified data where possible

5. How We Share Information

We do not sell personal data. We share information only as described below:

  • Service providers & subprocessors who help us run the Service, such as:
    • Cloud hosting and object storage providers (e.g., AWS)
    • Email and notification delivery vendors
    • Authentication, monitoring, and security tools
    • Payment processors for subscriptions, if applicable
  • Messaging platforms including Meta/WhatsApp when you enable WhatsApp messaging
  • Logistics platforms you connect, solely to sync data you authorize
  • Professional advisers, auditors, or authorities when required by law or to protect rights and safety
  • Business transfers in connection with a merger, acquisition, or asset sale, subject to confidentiality

6. WhatsApp-Specific Disclosures

When you use WhatsApp through Vefri, message delivery is subject to Meta's terms and policies. Vefri receives and stores only the data necessary to send messages you initiate, track delivery, and support capture workflows.

  • You must provide end customers with clear notice that WhatsApp may be used for transactional capture requests
  • Phone numbers and message metadata may be processed by Meta outside India depending on infrastructure configuration
  • You must honor end customer preferences, blocks, and complaints under WhatsApp rules
  • Vefri may suspend messaging features if we detect policy violations or excessive complaint rates

7. Logistics Partner Data

When you connect courier or shipping platforms, Vefri imports data made available through their APIs using credentials you provide. This may include personally identifiable information about your customers.

  • Data is used to match evidence to orders, display shipment status, and support return workflows
  • Retention follows your workspace settings and our standard retention schedule unless law requires longer storage
  • You must comply with each Logistics Partner's developer terms, privacy policy, and data use restrictions
  • Disconnecting an integration stops new syncs; previously imported data may remain until deleted under your retention settings

8. Evidence Storage & Access Controls

  • Evidence files are stored in encrypted object storage with access restricted to authorized systems and personnel
  • Merchant workspace users can access evidence according to their role permissions
  • Vefri personnel access production data only on a need-to-know basis for support, security, or legal compliance
  • Download and export actions may be logged for audit purposes

9. International Data Transfers

Vefri may process and store data in India and other countries where we or our subprocessors operate. Where required, we implement appropriate safeguards such as contractual clauses and security controls for cross-border transfers.

10. Security Measures

We use administrative, technical, and organizational measures designed to protect personal data, including encryption in transit, access controls, monitoring, and secure development practices. No method of transmission or storage is completely secure; you use the Service at your own risk.

  • Report suspected security issues to security@vefri.io
  • Merchants must protect dashboard credentials and restrict team access appropriately

11. Data Retention

We retain personal data for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Evidence retention may be configurable within your workspace subject to plan limits.

  • Account data: retained while the workspace is active and for a limited period after closure
  • Evidence media: retained per workspace settings, plan, and legal requirements
  • Messaging logs: retained for troubleshooting, compliance, and dispute resolution periods
  • Backups: may persist for a limited time after deletion from active systems

12. Your Rights & Choices

Depending on applicable law, merchants and individuals may have rights to access, correct, delete, withdraw consent, nominate a representative, or lodge grievances regarding personal data.

  • Merchants can update account information in dashboard settings
  • Merchants may request export or deletion of workspace data by contacting privacy@vefri.io
  • End customers should generally contact the merchant they purchased from for evidence-related requests; Vefri will assist merchants where required by law
  • You may opt out of non-essential marketing emails using unsubscribe links

13. Merchant Obligations to End Customers

If you are a merchant, you are responsible for providing a clear privacy notice to end customers explaining evidence collection, retention, sharing with Vefri, use of WhatsApp or SMS, and customer rights. Your notice should identify Vefri as a service provider where appropriate.

  • Inform customers before requesting camera, microphone, or location access
  • Only request evidence necessary for delivery proof, returns, or QC
  • Respond to customer data requests within timelines required by law

14. Children's Privacy

The Service is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided data through Vefri, contact privacy@vefri.io.

15. Automated Decision-Making

Vefri may provide risk indicators, mismatch flags, or workflow suggestions based on rules and signals you configure. These features assist human review and do not, by themselves, make legally binding decisions unless you configure them to do so.

16. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the dashboard, email, or website. The "Last updated" date at the top indicates the latest revision.

17. Grievance Officer & Contact

For privacy questions, data requests, or complaints under applicable Indian law, contact:

Grievance Officer, Vefri

Email: privacy@vefri.io

Response timeline: we aim to acknowledge requests within 7 business days and resolve eligible requests within timelines required by applicable law.

Questions about this document?

Contact us at legal@vefri.io or privacy@vefri.io.