Privacy Policy

What personal data LetBuyy handles, why, and what rights you have.

Applies to
Everyone
Clauses
11
Reading time
5 min
Revised
3 August 2026

These policies are published for review and are not yet in force. LetBuyy has not opened to merchants, so no agreement has been formed with anyone. They take effect on the day the platform launches, and the effective date will be stated here. Last revised 3 August 2026.

In short

  • For merchant accounts, LetBuyy decides what data is collected and why — so we answer to you directly for it.
  • For shopper data inside a store, the merchant decides and we process on their instruction. Ask the store first; we will help them answer.
  • We do not sell personal data. We do not use a merchant's customer list for our own marketing.

This summary is written to be understood. The clauses below are what actually applies — where the two differ, the clauses govern.

  1. Two different relationships

    LetBuyy handles personal data in two distinct roles, and your rights differ depending on which one applies.

    When you hold a LetBuyy merchant account, we are the Data Fiduciary — we decide what is collected and why, and you exercise your rights against us.

    When you shop at a store built on LetBuyy, that merchant is the Data Fiduciary. We are their Data Processor: we hold the data and act on their instruction. Your rights are exercised against the store, and we support them in answering you.

    NoteIf you are not sure which applies: did you sign up at letbuyy.com, or buy something from a store? The first is us; the second is the store.

  2. What we collect from merchants

    To create and operate your account we collect your name, email address, phone number, and password credentials. Passwords are stored hashed and are never recoverable in readable form.

    To operate your store we hold your business details, GSTIN where you provide one, store configuration, catalogue, and the orders your store receives.

    To keep the platform working and secure we log requests, errors, and device and network information such as IP address and browser type.

    Payment credentials are collected by your payment provider, not by us. We hold references and status, not card numbers.

  3. What stores collect from shoppers

    A store typically holds the shopper's name, email, phone, delivery address, order history, and any account credentials created on that storefront.

    Card details are never held by the store or by us — the payment provider collects them directly and returns only a reference.

    Each store's data is isolated from every other store at the database level. One merchant cannot read another merchant's customers, and a shopper account on one storefront is not an account on another.

  4. Why we process it

    To provide the service you asked for: running your store, processing orders, computing tax, sending order emails.

    To keep it secure: detecting fraud, rate-limiting abuse, distinguishing humans from bots at sign-up and login, and investigating incidents.

    To meet legal obligations: tax records, invoices, and responses to lawful requests.

    To improve the product, using aggregated and de-identified usage patterns rather than individual records.

  5. Who else sees it

    Service providers that run parts of the platform — hosting, database, payments, email, shipping, error monitoring. Each is listed in the Sub-processor Register with what it does and where it runs.

    A merchant's courier and payment provider, to the extent an order requires it.

    Authorities, where we are legally compelled. We check that a request is valid before responding, and tell the affected person unless the law forbids it.

    An acquirer, if the business is sold. Notice would be given, and the successor would be bound by this policy until it is properly replaced.

    NoteWe do not sell personal data, and we do not share it with advertisers or data brokers.

  6. How long we keep it

    Account and store data is kept while the account is open, and for a limited wind-down period after closure so an accidental closure can be reversed.

    Orders, invoices, and payment ledger entries are kept for the longer period Indian tax and company law requires, and survive account closure for that reason.

    Operational telemetry is retained for 90 days. Webhook delivery records are retained for 90 days after reaching a terminal state.

    When a retention period ends, data is deleted or irreversibly de-identified.

  7. Your rights

    You have the right to know what personal data is held about you and how it is processed; to have inaccurate data corrected; to have data erased where no legal duty requires us to keep it; to withdraw consent for optional processing; and to nominate someone to exercise these rights if you die or become incapacitated.

    Merchants: exercise these against us at the contact route below, or from your account settings where the action is self-service.

    Shoppers: exercise these against the store you bought from. If a store will not respond, escalate through our grievance process and we will act.

    We respond within the time the DPDP Rules require, and will tell you if a legal obligation prevents us from acting on part of a request.

  8. How it is protected

    Data is encrypted in transit and at rest. Tenant isolation is enforced in the database itself, so an application-layer mistake does not expose another store.

    Actions that move money or change payout destinations require verification beyond a password.

    The Security Practices page describes the controls in more detail.

  9. Children

    LetBuyy is not intended for children. Merchant accounts require you to be old enough to enter a contract.

    The DPDP Act requires verifiable parental consent before processing a child's data and prohibits behavioural advertising directed at children. Merchants selling to children are responsible for meeting that standard in their own store.

  10. Changes

    Material changes are notified to account holders by email before they take effect. The revision date at the top of this page always reflects the current text.

Questions about this document

Write to support@letbuyy.com and quote the clause number. For a complaint rather than a question, use the grievance process.