1. Introduction & Scope
Storli.in ("Storli", "We", "Our", or "Us") operates the Storli SaaS E-Commerce Platform accessible via https://storli.in and merchant subdomains (e.g., tenant.storli.in). We are committed to protecting the privacy and personal data of our SaaS subscribers ("Merchants"), their storefront customers ("End Consumers"), and visitors to our platform.
This Privacy Policy complies with India's Digital Personal Data Protection (DPDP) Act 2023 and international data protection standards.
2. Information We Collect
- Merchant Account Data: Full Name, Business Email Address, Phone/WhatsApp Number, Business Name, Password hash, and Payment Information (processed securely via Razorpay).
- Customer Store Order Data: When customers place orders on merchant storefronts, we collect shipping addresses, customer names, phone numbers, and Cash on Delivery / payment confirmation tokens to facilitate order fulfillment.
- Technical & Usage Analytics: IP Address, browser type, device identifiers, session cookies, and visual editor draft states to ensure high performance and prevent unauthorized access.
3. Purpose of Data Processing
We process personal data strictly for legitimate business purposes:
- To provision, maintain, and secure e-commerce storefronts on tenant subdomains and custom domains.
- To process subscription payments and recurring SaaS billing via Razorpay.
- To enable dropshipping fulfillment (CJ Dropshipping API) and WhatsApp automated order notifications.
- To prevent fraud, cyber threats, and unauthorized platform abuse.
4. Data Isolation & Security Architecture
Storli implements enterprise-grade multi-tenancy database schema isolation. Every merchant's storefront data is strictly separated using PostgreSQL tenant search paths (`SET search_path TO "tenant"`), preventing cross-tenant data leakage.
All communications are encrypted using 256-bit SSL encryption. We do not store raw credit card or banking credentials on our servers; all payment transactions are handled by PCI-DSS compliant payment gateways (Razorpay).
5. Data Principal Rights (DPDP Act 2023)
Under India's DPDP Act 2023, merchants and consumers have the following rights:
- Right to Access & Correction: You can review and update your account data anytime via the Merchant Dashboard.
- Right to Erasure: Upon account cancellation or written request, we will purge tenant data within 30 business days.
- Grievance Redressal: You may contact our designated Grievance Officer for data inquiries.
6. Grievance Officer & Contact Us
If you have any questions or grievances regarding this Privacy Policy, please contact our Grievance Redressal Desk:
Entity Name: Storli.in SaaS Technologies
Email Desk: support@storli.in
WhatsApp Desk: +91 98765 43210
Response Time SLA: Within 48 Hours