Privacy Policy

Effective date: 27 September 2026

This Privacy Policy explains how Onelyn (“we”, “us”), operated by Goutham Raj S, Chennai, India, collects, uses and protects personal data. It is written to comply with the Digital Personal Data Protection Act, 2023 (“DPDPA”) and the Information Technology Act, 2000.

1. Our role

  • For merchants, and for shoppers who create an account on the Onelyn customer app, Onelyn is responsible for how that account data is used.
  • For a store’s customer records (bills, purchase history, rewards), the store decides how the data is used. Onelyn handles it only on the store’s behalf and instructions.

2. Data we collect

Merchants: name, business name, phone, email, business address, registration details, account settings, and payment status. Payments are handled by Razorpay; we never receive your full card or bank details.

Shoppers (via stores): name, phone number, bill details, reward points, coupons, and message delivery status.

Customer app users: phone number for login, saved offers, and app activity.

Automatically: device and browser type, IP address and basic usage logs for security. We use only essential cookies needed to keep you logged in.

3. How we use data

  • To provide the Service: bills, rewards, offers, messages approved by the store, and dashboards.
  • To give each store insights about its own customers.
  • To verify logins by one-time password.
  • To bill merchants, provide support, keep the Service secure, and meet legal obligations.

We do not sell personal data. We do not share one store’s customer data with any other store.

4. Who we share data with

Only with trusted service providers that help us run the Service — such as cloud hosting, messaging and SMS delivery, payment processing, email, and analytics providers — under contracts that require them to protect the data and use it only for our Service. We may also disclose data where required by law.

5. Storage and security

Data is stored on servers in India and protected with encryption in transit, access controls and restricted internal access. We will notify affected users and the Data Protection Board of India of any personal data breach as required by law.

6. Retention

  • Merchant account data is kept while the account is active and for up to [30] days after closure to allow data export, unless law requires longer (for example, tax records).
  • Shopper data is kept while the store uses Onelyn, or until deletion is requested.
  • Deletion requests are completed within [30] days.

7. Your rights

Under the DPDPA you can: access a summary of your data; correct or update it; ask for it to be erased; withdraw consent; nominate someone to act for you; and raise a grievance.

Shoppers: to stop messages from a store, reply STOP or use the opt-out option in the message, or contact the store.

To make a request, email [email protected] mentioning your registered phone number.

8. Children

Merchant accounts are for adults (18+). We do not knowingly create customer app accounts for children under 18 without verifiable parental consent.

9. Grievance Officer

Name: Goutham Raj S Email: [email protected] Phone: +91 7418601026 Address: Chennai, Tamil Nadu.

We acknowledge grievances within 48 hours and aim to resolve them within 15 days.

10. Changes

We may update this policy and will post the new version here with a new effective date.