Legal

Privacy Policy

Effective date: 25 June 2026, Last updated: 25 June 2026

This Privacy Policy explains how SaathiX URL ("SaathiX", "we", "us", "our") collects, uses, stores, shares and protects information about you ("you", "user") when you access our website www.saathixurl.online, our dashboard, the public profile pages we host on your behalf (e.g. saathixurl.online/yourname), our QR codes, NFC cards and related services (together, the "Service"). By using the Service you confirm that you have read, understood and accepted this policy.

1. Who we are

SaathiX URL is a business software product operated from India that lets shops, restaurants, gyms, salons, doctors and other small businesses publish a single profile page, NFC card and QR code. The data controller for personal data publish a single profile page, NFC card and branded QR code. The data controller for personal data processed through the Service is SaathiX URL. For all privacy enquiries you can reach the team at privacy@saathixurl.online.

2. Information we collect

We only collect the data we genuinely need to run the Service. The categories are:

  • Account data, your name, mobile number, email address and password hash created during sign-up.
  • Profile content, anything you publish on your public profile: business name, tagline, photos, logo, social links, gallery items, UPI handle, WhatsApp number and similar fields.
  • Authentication data, one-time codes we email to you, browser session tokens and OAuth identifiers (e.g. Google sign-in).
  • Usage & analytics, page views on your profile, link clicks, QR scans, approximate location (country/city level), device type, browser and referrer.
  • Communications, messages you send to support, abuse or sales teams.
  • Payment metadata, plan, status and invoice IDs. Card numbers and bank details are handled directly by our payment processors; we never store them.

3. How we use information

  • Create and secure your account, send OTPs and prevent fraud.
  • Render your public profile to visitors and generate QR codes.
  • Provide analytics so you can see scans, clicks and visitor trends.
  • Send essential service emails (security alerts, billing, policy updates) and, only with consent, product announcements.
  • Improve the Service, debug issues and develop new features.
  • Comply with legal obligations and enforce our Terms.

We do not sell your personal data. We do not use your profile content to train third-party AI models.

4. Legal bases for processing

Where the GDPR, UK GDPR or India's DPDP Act applies, we rely on the following legal bases:

  • Contract, to provide the Service you signed up for.
  • Legitimate interests, to keep the Service secure, prevent abuse and improve features.
  • Consent, for optional cookies, marketing emails and analytics where required.
  • Legal obligation, to comply with tax, accounting and lawful requests from authorities.

5. Sharing & sub-processors

We share personal data only with vetted providers acting on our instructions:

  • Hosting & database, Lovable Cloud (Supabase) for authentication, database and storage.
  • Email delivery, Resend for transactional email from notification@saathixurl.online.
  • CDN & edge, Cloudflare for caching, security and DDoS protection.
  • Payments, Razorpay / Stripe / Paddle (whichever you use at checkout).
  • Analytics, privacy-friendly, aggregated analytics on our own infrastructure.

We may also disclose data if required by law, a binding court order, or to protect the safety of users and the public.

6. Cookies & tracking

We use a small number of strictly necessary cookies for authentication and security, plus optional analytics cookies. See our Cookies Policy for the full list and how to manage them.

7. Data retention

  • Account data, kept while your account is active and for up to 90 days after deletion for backup and abuse-prevention.
  • Profile content, deleted within 30 days of you removing it or closing your account.
  • Scan / click analytics, stored in raw form for 12 months, then anonymised and kept for aggregate trends.
  • Invoices and tax records, retained for 8 years to satisfy Indian accounting law.

8. Security

We use TLS 1.3 in transit, AES-256 at rest, hashed passwords (bcrypt/argon2 via Supabase Auth), row-level security on every tenant table and least-privilege access for staff. See the Security page for details.

9. Your rights

Subject to applicable law you have the right to access, correct, export, restrict or delete your personal data, and to object to certain processing. You can exercise most of these directly from your dashboard, or by emailing privacy@saathixurl.online. We respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

10. International transfers

Our primary infrastructure is hosted in India and the EU. Where data is transferred outside your region we rely on Standard Contractual Clauses or equivalent safeguards.

11. Children's privacy

The Service is not intended for children under 13 (or 16 in the EU). We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

12. Changes & contact

We may update this policy from time to time. Material changes will be announced by email and posted here with a new "Last updated" date. Questions? Email privacy@saathixurl.online or write to SaathiX URL, India.