Privacy Policy
- Legal name of the operator
- Full address of your place of business
- Customer care email
- Customer care phone
- Name of the grievance officer
- Grievance email
Who we are
These details are not configured on this deployment yet. The site is not ready to be published until they are.
What this covers
This notice explains what One Tap Manager does with personal data. It is published because the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 require it, and because Rule 3(1)(a) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 requires an intermediary to publish a privacy policy.
If you are a shopper who bought something from a shop built with One Tap Manager, this is not the notice you want. That shop is responsible for your data and publishes its own notice, linked in its footer. What we do in that situation is described under "Shops built on this platform" below.
What we collect from you, and why
When you create an account: your email address, a password which is stored only as a one-way hash and never in a readable form, and your shop name. We need these to give you an account and to let you back into it.
When you use the app: the sales and review files you upload, the products you enter, the photographs you upload, and the content the app generates for you. This is the substance of the service. Without it there is nothing to analyse.
Automatically: your IP address, browser type, and the pages you opened, written to server logs. We keep these for 180 days because the CERT-In Directions of 28 April 2022 require us to, and we use them to find faults and to investigate abuse.
If you pay us: the payment is handled by our payment gateway. We receive a confirmation and the last four digits of the instrument. We never see or store your full card number.
What we do not do
We do not sell your data. We do not share it with advertisers. We do not use your customer lists to market anything to your customers on our own behalf.
We do not train artificial intelligence models on your data. When the app generates a caption or a picture for you, your brief is sent to the model provider named below to produce that one result, and we do not add your content to any training set. If that ever changes we will ask you first, separately, and it will be something you switch on rather than something you fail to switch off.
Who else sees it
The app runs on Render, which hosts the servers. Data is stored with Supabase. Email is sent through our configured mail provider. Payments are processed by Razorpay. When you ask the app to generate text, an image or a video, the brief for that request goes to the provider you picked at the time, which may be OpenAI, Google, Cloudflare or Hugging Face.
Some of these providers process data outside India. Indian law currently permits this. We name them here so you know who is involved rather than discovering it later.
How long we keep it
Your account data and your uploads stay while your account is open. If you cancel, you have 30 days to download everything, and we delete it 90 days after cancellation.
Server logs are kept for 180 days as described above. Records we are required by law to retain, such as invoices, are kept for as long as that law requires.
Your choices
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. You can withdraw any consent you gave, and withdrawing it is as easy as giving it was. Write to the grievance officer named below and we will acknowledge within 24 hours and answer within 7 days.
Deleting your account data will end the service, because the service is the analysis of that data. We will tell you plainly what will stop working before we do it.
Security
Passwords are hashed, not stored. Data is encrypted in transit. Uploaded datasets are encrypted before they are stored. Access to the production systems is limited and logged.
No system is perfectly safe, and we will not pretend otherwise. If there is a breach that affects you we will tell you, and we will report it to CERT-In within six hours of becoming aware of it as the 2022 Directions require.
Shops built on this platform
Sellers use this app to run their own shops. When a seller uploads their customer list, or a shopper places an order on a seller's shop, the seller decides why that data is collected and what it is used for. In the language the law uses, the seller is the data fiduciary and we handle the data on their instructions.
We hold each seller to a written agreement that requires them to have a lawful basis for the data they upload, and we keep our own obligations for the security of it. If you are a shopper with a question about your order, the shop is the right first contact, and we will help if they do not.
Children
This app is for people running a business and is not intended for anyone under 18. We do not knowingly collect data from children.
Changes
This notice was last reviewed on 15 September 2026. If we change it we will say so in the app, and we review it at least every three months because Rule 3(1)(f) of the IT Rules 2021 requires us to tell users about changes that often.
Grievance officer
Not configured, Proprietor and Grievance Officer. Email not configured.
We acknowledge every complaint within 24 hours and aim to resolve it within 7 days, which is the timeline Rule 3(2) of the IT Rules 2021 sets.
This is written to cover the obligations we know apply to us, and it names the rule behind each one so it can be checked. It is not legal advice, and it is not a substitute for having a lawyer read it.