Privacy Policy
Last updated: May 1, 2026 · Effective: May 1, 2026
This Privacy Policy describes how Veyra Technologies Pvt. Ltd. ("Veyra", "we", "our", or "us") collects, uses, shares, and protects your personal information when you use our AI-powered commerce platform at veyraweb.com and related services.
1. Information We Collect
Section 1We collect information you provide directly and information generated through your use of our platform:
Account Information: When you create a Veyra account, we collect your name, email address, and password (stored as a secure hash). You may optionally provide a profile picture and phone number.
Transaction Data: When you make a purchase, we collect order details including product name, amount, payment gateway reference (Razorpay order ID and payment ID), and order status. We do NOT store full card numbers or sensitive payment credentials — all payment processing is handled by Razorpay, a PCI DSS-compliant payment gateway.
AI Conversation Data: Messages exchanged with the Veyra AI agent are processed to fulfill your commerce requests. Conversation history is stored to provide continuity of service and is associated with your account.
Usage Data: We automatically collect information about how you interact with our platform, including pages visited, features used, session duration, device type, browser, and IP address.
Seller Data: If you register as a seller, we collect additional business information including business name, category, API endpoint configurations, and product data you provide.
2. How We Use Your Information
Section 2We use your personal information for the following purposes:
Service Delivery: To process orders, facilitate payments, and deliver purchased digital goods or services through our seller network.
AI Agent Operation: To power the Veyra AI agent's ability to understand your requests, search for products, and execute commerce transactions on your behalf.
Account Management: To authenticate your identity, manage your account settings, and maintain your transaction history.
Communications: To send transactional emails (order confirmations, payment receipts, account alerts) and, with your consent, marketing communications about new features.
Platform Improvement: To analyze usage patterns, debug issues, improve our AI models' recommendations, and develop new features.
Legal Compliance: To comply with applicable laws, respond to legal requests, and enforce our Terms of Service.
Fraud Prevention: To detect and prevent fraudulent transactions, unauthorized access, and other harmful activities.
3. Data Sharing & Disclosure
Section 3We do not sell your personal data. We share data only in the following limited circumstances:
Sellers: When you place an order, we share necessary fulfillment information (your name, contact details, and order specifics) with the relevant seller to enable product delivery.
Payment Processors: We share transaction data with Razorpay to process payments. Razorpay operates under its own privacy policy and is PCI DSS Level 1 certified.
AI Service Providers: We use Google Gemini API to power our AI agent. Conversation content is processed by Google's infrastructure subject to Google's data processing terms.
Infrastructure Providers: We use cloud infrastructure providers (including database hosting and vector storage) under appropriate data processing agreements.
Legal Requirements: We may disclose information when required by law, court order, or government authority, or when necessary to protect the rights, property, or safety of Veyra, our users, or the public.
Business Transfers: In the event of a merger, acquisition, or sale of assets, user data may be transferred as part of the transaction, with prior notice provided.
4. Data Security
Section 4We implement industry-standard security measures to protect your personal information:
Encryption: All data transmitted between your browser and our servers is encrypted using TLS 1.3. Sensitive data at rest is encrypted using AES-256-GCM.
Credential Security: Passwords are hashed using bcrypt with appropriate cost factors. We never store plaintext passwords.
Access Controls: Access to production systems and user data is restricted to authorized personnel on a need-to-know basis, with multi-factor authentication enforced.
Vault Architecture: Our credential vault uses AES-256-GCM encryption with per-user keys for storing any sensitive configuration data.
Regular Audits: We conduct regular security reviews and maintain logging of all data access events for audit purposes.
Despite these measures, no method of transmission over the internet is 100% secure. If you believe your account has been compromised, please contact us immediately at [email protected].
5. Your Rights
Section 5Depending on your location, you may have the following rights regarding your personal data:
Access: Request a copy of the personal data we hold about you.
Correction: Request correction of inaccurate or incomplete personal data.
Deletion: Request deletion of your personal data, subject to legal retention requirements and ongoing service obligations.
Portability: Request your data in a structured, machine-readable format.
Objection: Object to processing of your personal data for marketing purposes.
Withdrawal of Consent: Where processing is based on consent, you may withdraw consent at any time.
To exercise these rights, contact us at [email protected]. We will respond within 30 days. For India-based users, these rights are exercised in accordance with India's Digital Personal Data Protection Act, 2023 (DPDP Act).
7. Data Retention
Section 7We retain your personal data for as long as necessary to provide our services and comply with legal obligations:
8. Children's Privacy
Section 8Veyra is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have inadvertently collected personal information from a child under 18, we will take steps to delete such information. If you believe a child has provided us with personal information, please contact us at [email protected].
9. Changes to This Policy
Section 9We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business. We will notify you of material changes by email or by posting a prominent notice on our platform at least 30 days before the changes take effect. Your continued use of Veyra after the effective date constitutes acceptance of the updated policy.
10. Contact Us
Section 10If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: [email protected] Support Portal: veyraweb.com/contact Mailing Address: Veyra Technologies Pvt. Ltd., India
We are committed to resolving complaints about our data practices. If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection authority.