Legal

Privacy Policy

Effective Date: 5 May 2026 · Last Updated: 5 May 2026

This Privacy Policy describes how Nivaara Consulting (referred to as “we”, “us”, or “Nivaara”) collects, uses, stores, and shares your personal data when you use Saanchika, our warehouse management platform, accessible at saanchika.nivaaraconsulting.com (the “Service”).

This policy applies to all users of the Service and is governed by the Digital Personal Data Protection Act, 2023 of India (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025.

By using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.

1. Who We Are

Nivaara Consulting is a sole proprietorship based in Hyderabad, India, operated by Suraj Divakala, who serves as the sole proprietor and Data Fiduciary under the DPDP Act.

Registered Address

Pristine Place, Gajularamaram, Hyderabad 500055, Telangana, India

Contact

Email: privacy@nivaaraconsulting.com

Grievance Officer

Suraj Divakala — suraj@nivaaraconsulting.com

Under the DPDP Act, we act as a Data Fiduciary for personal data of account holders. We act as a Data Processor for personal data that account holders enter into Saanchika about their own customers or business contacts.

2. Personal Data We Collect

2.1 Data you provide to us

When you create an account or use the Service, you provide:

  • Full name
  • Email address
  • Phone number
  • Business name and trading name
  • GSTIN (Goods and Services Tax Identification Number)
  • Business address
  • Account password (stored only as a cryptographic hash, never in readable form)

2.2 Data collected automatically

When you use the Service, our infrastructure automatically collects:

  • IP address
  • Device type, operating system, and browser
  • Session identifiers and authentication tokens
  • Pages and features accessed within the Service
  • Timestamps of logins, actions, and errors
  • Error logs and diagnostic information when something goes wrong

This information is collected for security, fraud prevention, debugging, and service reliability. It is not used to build advertising profiles.

2.3 Data entered by you about others

Saanchika is a business tool. As part of normal use, you will enter data about your own customers, suppliers, drivers, and employees into the Service. This may include their names, business names, GSTINs, contact details, and transaction records.

For this data, you are the Data Fiduciary and we act only as a Data Processor on your behalf. You are responsible for obtaining any consents required to enter this data into the Service, and for complying with applicable laws in your handling of your own customers’ data.

2.4 Payment data

All payments are processed by Razorpay. We do not collect, store, or have access to your full card number, UPI PIN, or bank credentials. We receive only a transaction reference, the amount paid, and payment status from Razorpay, which we use to activate your subscription and generate tax invoices.

2.5 Marketing site cookies

Our marketing website (saanchika.nivaaraconsulting.com) uses a lightweight analytics tool to measure site performance and understand which pages visitors find useful. This tool may set first-party session cookies. We do not use advertising or cross-site tracking cookies.

3. Why We Collect Your Data

We process your personal data for the following purposes:

  • To provide the Service — creating and maintaining your account, delivering the features you signed up for, and supporting multi-user access within your organization.
  • To bill you — processing subscription payments, sending invoices, handling refunds, and maintaining billing records.
  • To communicate with you — sending account-related emails (sign-up confirmation, password reset, payment reminders, trial expiry notices, and service notifications). These are transactional and cannot be opted out of while you have an active account.
  • To send marketing communications — only with your explicit, separate consent. You may withdraw this consent at any time from your account settings or by clicking the unsubscribe link in any marketing email.
  • To protect the Service — detecting fraud, preventing abuse, investigating security incidents, and complying with legal obligations.
  • To improve the Service — analyzing aggregated usage patterns to make the product better. We do not sell your data or use it to build user profiles for advertising.
  • To comply with law — meeting our obligations under Indian tax law, the DPDP Act, and other applicable regulations.

4. Legal Basis for Processing

Under the DPDP Act, we process your personal data on the following bases:

  • Your consent, which you provide when you create an account and agree to this Privacy Policy.
  • Legitimate uses as defined under the DPDP Act, including for contract performance, compliance with legal obligations, and the provision of services you have requested.
  • Separate consent, which we obtain for marketing communications and any non-essential data processing.

5. Who We Share Your Data With

We share personal data only with the following categories of Data Processors, all of whom are bound by contractual confidentiality obligations:

Processor Purpose Data Location
SupabaseManaged database and authenticationMumbai, India
KoyebApplication hostingMumbai, India
VercelWeb frontend delivery (global edge network)Global; content originates from India
RazorpayPayment processingIndia
ResendTransactional email deliveryUnited States
SentryError logging and diagnosticsUnited States

We do not sell, rent, or lease your personal data to any third party. We do not share your data with advertisers.

We may disclose your personal data to government authorities, law enforcement, or courts where legally required to do so under valid process, and only to the extent required.

6. Cross-Border Data Transfers

Your business data and user content are stored in Supabase and Koyeb infrastructure located in Mumbai, India.

However, some metadata is processed outside India:

  • Email delivery metadata (recipient email, delivery status, timestamps) passes through Resend in the United States when we send you transactional or marketing emails.
  • Error logs and diagnostic data are sent to Sentry in the United States when technical errors occur.
  • Web traffic metadata (IP addresses, request headers) may pass through Vercel’s global edge network, including servers outside India, before reaching our India-hosted backend.

These transfers comply with Rule 12 of the DPDP Rules, 2025, which permits cross-border data transfer subject to government notifications. No country is currently restricted by the Government of India. We monitor updates and will adjust our processors if required.

7. How Long We Keep Your Data

Data Category Retention Period
Active account dataFor the duration of your account
Account data after cancellation90 days in read-only mode, then deleted
Billing and tax invoices8 years, as required by Indian tax law
Database backupsUp to 30 days after the original deletion
Error logs (Sentry)90 days
Transactional email metadata (Resend)Up to 30 days
Audit logs (Enterprise customers only)For the duration of the subscription plus 12 months
Marketing consent recordsUntil you withdraw consent, plus 3 years for proof of consent

After the retention period, personal data is permanently deleted or irreversibly anonymized. Where deletion is technically infeasible (for example, within backup snapshots), data is rendered inaccessible until the backup naturally expires.

If you request deletion of your account, your data will enter the 90-day read-only window described above. Billing records required by tax law cannot be deleted until their statutory retention period ends.

8. Your Rights Under the DPDP Act

As a Data Principal, you have the following rights:

  • Right to Access: You may request a copy of the personal data we hold about you.
  • Right to Correction: You may request corrections to inaccurate or incomplete personal data.
  • Right to Erasure: You may request deletion of your personal data, subject to statutory retention obligations (for example, tax-related records).
  • Right to Nominate: You may nominate another person to exercise your rights in the event of your death or incapacity.
  • Right to Withdraw Consent: You may withdraw consent for any processing based on consent. Withdrawal does not affect the lawfulness of past processing.
  • Right to Grievance Redressal: You may raise any complaint regarding our handling of your personal data with our Grievance Officer.

To exercise any of these rights, email privacy@nivaaraconsulting.com. We will respond within 30 days of receiving a verified request.

If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India.

9. Security

We use industry-standard safeguards to protect your data, including:

  • Encryption of data in transit (TLS 1.2 or higher on all connections)
  • Encryption of data at rest (provided by Supabase and our hosting infrastructure)
  • Password hashing using bcrypt or equivalent cryptographic functions
  • Authentication via JSON Web Tokens with short expiration windows
  • Role-based access controls within the Service
  • Principle of least privilege for our team’s access to customer data
  • Regular security patches and dependency updates
  • Logging and monitoring of authentication events
  • Hosting within secure data centers in Mumbai, India

No system is completely secure. While we follow industry best practices, we cannot guarantee absolute security of your data.

10. Data Breaches

If a personal data breach occurs that affects your data, we will:

  • Notify you without undue delay through the email address on your account
  • Notify the Data Protection Board of India as required under the DPDP Act and Rules
  • Provide information about what happened, what data was affected, what we are doing about it, and what steps you can take

11. Children

Saanchika is a business tool intended for users aged 18 and above. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected data from a minor, we will delete it promptly. If you believe a minor has provided us with personal data, please contact us at privacy@nivaaraconsulting.com.

12. Third-Party Links

The Service and our marketing site may contain links to third-party websites (for example, Razorpay’s payment page or an external knowledge base article). This Privacy Policy does not apply to those sites. Please review their respective privacy policies.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do:

  • We will revise the “Last Updated” date at the top of this page.
  • For material changes, we will notify you by email at least 14 days before the changes take effect.
  • Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

14. Contact Us

For privacy-related questions, requests, or complaints:

Data Fiduciary: Nivaara Consulting

Email: privacy@nivaaraconsulting.com

Grievance Officer: Suraj Divakala — suraj@nivaaraconsulting.com

Address: Pristine Place, Gajularamaram, Hyderabad 500055, Telangana, India