Privacy Policy
Last updated: 27 July 2026
1. Who we are
Drapeinn (operated by Akshanth V, “we”, “us”) provides the Drapeinn e-commerce Platform to clothing businesses. Contact: drapeinn@gmail.com.
2. Data we collect and why
| Category | Data | Purpose |
|---|---|---|
| Merchant account | Name, email, store details | Platform access and billing |
| End-customer orders | Name, email, phone, address, items purchased | Order fulfilment on behalf of the Merchant (Data Processor role) |
| Payment references | Razorpay order/payment IDs | Refund and dispute resolution — we never store card/bank numbers |
| Shipping | Delivery address, Shiprocket order IDs | Courier booking on behalf of the Merchant |
| Analytics | Order counts, revenue (aggregated, per store) | Admin dashboard shown only to that store’s members |
3. Our role under the DPDP Act 2023
With respect to end-customer data:
- The Merchant is the Data Fiduciary — they decide why and how personal data is collected from their customers.
- Drapeinn is the Data Processor — we process personal data only on the Merchant’s instructions to operate the Platform.
Drapeinn is not currently classified as a Significant Data Fiduciary and does not operate a children’s service. We retain end-customer order data for up to 3 years or as required by law.
4. Who we share data with
- Razorpay — payment processing (Merchant’s own account; we pass order details, never raw card data).
- Shiprocket — courier booking (name, address, phone, order details).
- Supabase — database hosting (data stored in the Mumbai, India region).
- Resend — transactional email delivery (order confirmations, shipping updates).
- Vercel — application hosting (US-based CDN; no personal data stored there, only served).
We do not sell personal data and do not share it with advertisers.
5. Security
We use Row-Level Security (RLS) in Supabase, HTTPS everywhere, AES-256-GCM encryption for stored payment credentials, HMAC-verified webhooks, and per-store access controls. Despite these measures, no system is perfectly secure.
6. Your rights (DPDP Act 2023)
End-customers of a Drapeinn-powered store should contact that store’s Grievance Officer for data requests. Merchants may request access to, correction of, or deletion of their account data by emailing drapeinn@gmail.com. We will respond within 30 days.
7. Cookies
We use session cookies (Supabase Auth) to keep Merchants signed in to their admin panel. Store storefronts use localStorage for cart and wishlist — no tracking cookies are set on shoppers.
8. Changes
We will notify Merchants by email at least 14 days before material changes. The current version is always at drapeinn.com/platform/privacy.
Contact / Grievance
For any privacy concerns: drapeinn@gmail.com. We will acknowledge within 48 hours and resolve within 30 days (Consumer Protection (E-Commerce) Rules 2020).
⚠ Template — not legal advice. Have a qualified lawyer review before publishing to boutique customers.