This Privacy Policy explains how Peyze (“Peyze”, “we”, “us” or “our”) collects, uses, stores, shares and protects personal data in connection with the website at peyze.com, the Peyze eCommerce platform and the related onboarding, configuration, support and custom development services (together, the “Platform”).
This Policy should be read together with the Peyze Terms and Conditions of Service. Capitalised terms not defined here have the meaning given in the Terms and Conditions.
By visiting peyze.com, submitting an enquiry, or accessing or using the Platform, you acknowledge that you have read and understood this Privacy Policy.
1. Who This Policy Applies To
Peyze processes personal data about three groups of people, and our role differs for each:
- “Website Visitors” means anyone who visits peyze.com, including those who submit the “Get a Quote” or contact form, call or email us. Peyze is the data controller (or “Data Fiduciary” under Indian law) for this data.
- “Client Users” means the owners, employees, contractors and other authorised users of a business that subscribes to the Platform (a “Client”) who log in to the admin panel, web application or mobile application to operate the Client’s store. Peyze is the data controller for account, billing and support data relating to Client Users.
- “End Customers” means the shoppers, buyers and other individuals who interact with a Client’s online store, mobile app or other sales channel built on the Platform. For End Customer data, the Client is the data controller and Peyze acts only as a data processor (or “Data Processor” under Indian law) on the Client’s instructions. Section 8 explains this in more detail.
If you are an End Customer of a store built on Peyze, the store’s own privacy policy governs how your data is used. Please contact that store directly for questions about your data; Peyze will refer any request it receives to the relevant Client.
2. Personal Data We Collect
2.1 From Website Visitors: name, email address, phone number, company name, indicative budget range, the content of your enquiry, and technical data such as IP address, browser type, device type, pages visited and referring site.
2.2 From Clients and Client Users: business name, registered address, tax identifiers (such as GSTIN), contact names, email addresses, phone numbers, job titles, login credentials, role and permission settings, billing and invoicing details, payment status, support tickets and communications with Peyze, and usage data such as login times, features used and actions performed within the admin panel.
2.3 From End Customers (processed on behalf of Clients): name, email address, phone number, delivery and billing addresses, order history, cart contents, payment status and transaction identifiers (Peyze does not receive full card numbers; these are handled by Stripe or the Client’s chosen payment gateway), shipment tracking data, account preferences, reviews, support messages, and technical data such as IP address, device identifiers and browsing behaviour within the store.
2.4 Third-party account data: where the Client connects Stripe, DHL, marketplaces or other Additional Integrations, Peyze processes the API credentials, transaction records, shipment records and related data exchanged with those services to the extent needed to operate the integration.
2.5 Peyze does not intentionally collect sensitive personal data (such as health, religious, biometric or financial account data beyond what is described above). Clients must not configure the Platform to collect sensitive personal data from End Customers without Peyze’s prior written agreement and without the appropriate legal basis.
3. How We Collect Personal Data
- Directly from you, when you fill in a form, create an account, contact support, or communicate with us by email, phone or messaging apps.
- Automatically, through cookies, server logs, analytics tools and the normal operation of the Platform (see Section 7).
- From Clients, who supply Client User details during onboarding and End Customer data through the operation of their store.
- From third-party services that the Client has connected to the Platform, such as Stripe, DHL, marketplaces, analytics or marketing tools.
- From publicly available sources or business contacts, for example when a prospective Client is referred to us.
4. Why We Use Personal Data and Our Legal Basis
We use personal data only for the purposes below. Where the law requires a specific legal basis (for example under the GDPR / UK GDPR or India’s Digital Personal Data Protection Act, 2023), the basis is indicated in brackets.
- Responding to enquiries and quote requests, and following up on them [consent; legitimate interests in running our business].
- Onboarding Clients, configuring the Platform, providing access, and delivering the services described in the Terms and Conditions [performance of a contract].
- Billing, invoicing, collecting payment, and maintaining accounting and tax records [performance of a contract; legal obligation].
- Providing technical support, resolving issues and communicating service notices, maintenance windows and changes to the Platform or these policies [performance of a contract; legitimate interests].
- Operating, securing, monitoring, maintaining and improving the Platform, including detecting fraud, abuse and security incidents [legitimate interests; legal obligation].
- Producing aggregated, anonymised statistics about Platform usage to improve our products [legitimate interests]. Anonymised data that cannot identify any individual is not personal data.
- Sending Clients information about new features, plans or services that are relevant to their subscription [legitimate interests; you may opt out at any time].
- Complying with legal obligations, court orders, regulatory requests, and enforcing our Terms and Conditions [legal obligation; legitimate interests].
For End Customer data, Peyze processes it solely to operate the Client’s store on the Client’s documented instructions and does not use it for Peyze’s own purposes, other than in anonymised, aggregated form for Platform improvement and security.
5. Who We Share Personal Data With
Peyze does not sell personal data. We share it only with:
- Infrastructure and hosting providers, including cloud servers, content delivery networks, DNS and edge security services, database hosting, backup storage, and email delivery services, that host and run the Platform.
- Payment gateways (Stripe by default, or an Additional Integration chosen by the Client) to process payments. These providers act as independent controllers for the payment data they receive and have their own privacy policies.
- Delivery and logistics partners (DHL by default, or an Additional Integration chosen by the Client) to arrange shipment and tracking of orders.
- Other third-party services the Client chooses to connect to the Platform, such as marketplaces, accounting or ERP systems, marketing and analytics tools, and messaging providers. Peyze shares data with these services only as configured by the Client.
- Monitoring, error-tracking, analytics and customer-support tools used by Peyze to keep the Platform running and to assist Clients.
- Professional advisers, including accountants, auditors, lawyers and insurers, where necessary.
- Government authorities, regulators, courts or law enforcement where required by law or to protect Peyze’s rights, property or safety, or those of Clients or others.
- A buyer or successor in the event of a merger, acquisition, restructuring or sale of all or part of Peyze’s business, subject to that party honouring this Policy.
A current list of the sub-processors Peyze uses to process Client and End Customer data is available on request at [email protected]. Peyze will notify Clients of material changes to its sub-processors.
6. Where Data Is Stored and International Transfers
6.1 Peyze is based in Kerala, India, and serves Clients in many countries, including the United Kingdom, the European Union, the United Arab Emirates and other Gulf states, Australia, Africa and elsewhere. The Platform is hosted on cloud infrastructure contracted by Peyze under its own accounts, in data-centre regions that Peyze selects on a per-Client basis.
6.2 Hosting region selection. When configuring the Platform for a Client, Peyze selects the hosting region based on the Client’s requirements and the data protection, data localisation and data residency laws that apply to the Client’s business and its End Customers. For example, a Client subject to the GDPR or UK GDPR will typically be hosted in an EU or UK region; a Client in the UAE will be hosted in a region that satisfies UAE data protection and any applicable localisation rules; a Client in Australia will be hosted in an Australian region where required by the Privacy Act; and Clients in Africa will be hosted in a region compliant with the laws of their country. Each Client’s data is stored in its selected region and is not moved to another region without the Client’s agreement, except for transient processing, support access or backups as described below.
6.2A Regardless of the hosting region, Peyze’s engineering and support personnel in India may access Client and End Customer data remotely for the purposes of configuration, support, maintenance, security and incident response. Such access is limited to authorised personnel, is logged, and is subject to confidentiality obligations and appropriate transfer safeguards. Backups may be replicated within the same region or a legally compatible region for resilience.
6.2B Website Visitor data (enquiries submitted through peyze.com) and Peyze’s own Client account, billing and support records are processed primarily in India and may be stored with cloud, email and business-tool providers located in India, the European Union, the United States or other regions.
6.2C Because of the above, personal data may be transferred to and processed in countries other than the one in which it was collected, and some of those countries may not provide the same level of data protection as your home country. Peyze applies the safeguards described in this Section to any such transfer.
6.3 Where personal data protected by the GDPR or UK GDPR is transferred outside the EEA or UK, Peyze relies on appropriate safeguards such as Standard Contractual Clauses, the UK International Data Transfer Addendum, or adequacy decisions, and will enter into a Data Processing Agreement with the Client on request (see Section 8).
6.4 Where the laws of a Client’s jurisdiction impose specific requirements (for example, data localisation rules in certain Gulf states or Africa, cross-border transfer restrictions in Australia, or sector-specific rules in India), Peyze will configure hosting in a compliant region and provide the supporting documentation the Client reasonably requires. Region-specific hosting may affect Configuration and Subscription Fees, as described in the Terms and Conditions. The Client is responsible for telling Peyze about such requirements before Configuration begins and for its own compliance as controller.
7. Cookies and Similar Technologies
7.1 peyze.com and the Platform use cookies and similar technologies (such as local storage and pixels) for the following purposes: (a) strictly necessary cookies that enable login, session management, security and core functionality; (b) preference cookies that remember settings such as language and currency; (c) analytics cookies that help us understand how the website and Platform are used; and (d) where enabled by a Client on its store, marketing cookies and third-party pixels.
7.2 Strictly necessary cookies do not require consent. For other cookies, we will ask for consent where the law requires it. You can control cookies through your browser settings, but disabling necessary cookies will prevent the Platform from working correctly.
7.3 Clients are responsible for configuring and disclosing any cookies, pixels or tracking technologies they enable on their own stores and for obtaining any consents required from End Customers.
8. Peyze as a Data Processor for Clients
8.1 For End Customer data and other personal data that a Client uploads to or generates within the Platform, the Client is the controller and determines the purposes and means of processing. Peyze processes such data only on the Client’s documented instructions, which are given by the Client through its use and configuration of the Platform and through the Terms and Conditions.
8.2 Peyze will: (a) process Client data only as instructed and as necessary to provide the Platform; (b) ensure that personnel with access to Client data are bound by confidentiality obligations; (c) implement appropriate technical and organisational security measures; (d) engage sub-processors only under written terms that impose equivalent obligations; (e) assist the Client, at the Client’s reasonable cost, in responding to End Customer rights requests and in meeting its security, breach-notification and impact-assessment obligations; (f) notify the Client without undue delay on becoming aware of a personal data breach affecting Client data; and (g) on termination, return or delete Client data in accordance with the Terms and Conditions, except where retention is required by law.
8.3 Where a Client is subject to the GDPR, the UK GDPR or another law that requires a written data processing agreement, Peyze will enter into a Data Processing Agreement on its standard form, which is incorporated into the Terms and Conditions once signed.
8.4 The Client is responsible for: (a) having a lawful basis for collecting End Customer data; (b) publishing its own privacy policy and cookie notice on its store; (c) obtaining any consents required; (d) responding to End Customer rights requests; (e) ensuring that its instructions to Peyze comply with applicable law; and (f) not uploading data to the Platform that it has no right to process.
9. Security
9.1 Peyze uses reasonable technical and organisational measures appropriate to the risk to protect personal data, including encryption of data in transit (TLS), encrypted storage of credentials, role-based access controls, network segmentation, firewall and edge protection, regular backups, logging and monitoring, and restricted access to production systems by authorised personnel only.
9.2 Payment card data is handled by Stripe or the Client’s chosen payment gateway, which are responsible for PCI DSS compliance. Peyze does not store full card numbers or security codes.
9.3 No system is completely secure. Client Users are responsible for keeping their credentials confidential, using strong passwords, enabling any available multi-factor authentication, and promptly notifying Peyze of any suspected unauthorised access.
9.4 If Peyze becomes aware of a personal data breach affecting data for which it is a controller, it will notify affected individuals and the relevant regulator where required by law, and in any event without undue delay.
10. How Long We Keep Personal Data
- Website enquiry data: for up to twenty-four (24) months after the last contact, unless the enquiry leads to a subscription.
- Client and Client User account data: for the duration of the subscription and for up to seven (7) years afterwards to the extent required for accounting, tax, audit and legal purposes.
- Billing and invoicing records: for the period required by applicable tax and company law (generally eight (8) years in India).
- Support tickets and communications: for up to three (3) years after closure.
- End Customer data and other Client data: for the duration of the subscription and for thirty (30) days after termination, during which the Client may request an export, after which it is deleted from live systems. Backup copies are overwritten on a rolling basis within a further ninety (90) days.
- Server and security logs: for up to twelve (12) months, or longer where needed to investigate an incident.
Anonymised and aggregated data may be retained indefinitely.
11. Your Rights
Depending on where you are located and which law applies, you may have the right to:
- Access the personal data we hold about you and receive a copy.
- Correct inaccurate or incomplete data.
- Request deletion of your data, subject to legal retention requirements.
- Restrict or object to certain processing, including direct marketing.
- Receive your data in a portable, machine-readable format.
- Withdraw consent at any time, where processing is based on consent, without affecting processing already carried out.
- Nominate another person to exercise your rights on your behalf in the event of death or incapacity (Indian law).
- Lodge a complaint with a supervisory authority, such as the Data Protection Board of India, the UK Information Commissioner’s Office, or the data protection authority in your country.
To exercise any of these rights, contact us at [email protected]. We may need to verify your identity before acting on a request. We will respond within the timeframe required by applicable law and in any event within thirty (30) days. If you are an End Customer, please contact the store you dealt with; we will forward any request we receive to the relevant Client.
12. Marketing Communications
Peyze may send Clients and prospective Clients information about the Platform, new features and related services. You can opt out at any time by using the unsubscribe link in any marketing email or by contacting us. Opting out does not affect service, billing or security notices, which we will continue to send as needed to operate your subscription.
13. Children
The Platform and peyze.com are intended for businesses and are not directed at individuals under eighteen (18) years of age. Peyze does not knowingly collect personal data from children for its own purposes. Clients whose stores may be used by children are responsible for complying with the applicable laws on children’s data, including obtaining verifiable parental consent where required, and for configuring their stores accordingly.
14. Third-Party Websites and Services
peyze.com and the Platform may contain links to, or integrate with, third-party websites and services, including Stripe, DHL and other Additional Integrations. Peyze is not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies before providing them with personal data.
15. Changes to This Policy
Peyze may update this Privacy Policy from time to time. The current version will always be published at peyze.com with the “Last updated” date shown above. Where changes are material, we will notify Clients by email or through the Platform at least thirty (30) days before they take effect. Continued use of the Platform after that date constitutes acceptance of the updated Policy.
16. Contact Us
For questions, requests or complaints about this Privacy Policy or how we handle personal data, contact:
- Peyze
- Email: [email protected]
- Phone: +91 98092 34516
- Website: https://peyze.com