Privacy Policy

Effective Date: April 20, 2026 · Last Updated: April 20, 2026

OrdScale Technologies · 89, Faiq Enclave, Pilibhit Bypass Road, Bareilly, UP, 243006 · hello@ordscale.com

OrdScale Technologies ("OrdScale", "we", "us") operates the OrdScale SaaS platform. This Privacy Policy explains how we collect, use, and protect information when you use the Service. Our primary users are businesses and merchants. Data we process on behalf of merchants regarding their end-customers is governed by our Data Processing Agreement (DPA), not this policy.

1. Information We Collect

1.1 Account Information

When you sign up, we collect your name, email address (provided directly or via Google OAuth through Clerk), organisation name, store name, plan type, and billing history (processed via Razorpay).

1.2 Integration Credentials

When you connect your platforms, we store OAuth access tokens and API keys — encrypted at rest using AES-256-GCM. We never store plaintext secrets. Credentials are used solely to sync your data.

1.3 Store Data (Synced via Integrations)

Once connected, we periodically sync: Shopify orders, products, and fulfilment status; Razorpay payment records and settlements; Meta Ads campaign spend and ROAS; shipping carrier tracking events. This data belongs to you — we process it solely to power your dashboard.

1.4 Usage Data

We collect data about how you interact with the Service via PostHog (pages visited, features used, session duration) and error events via Sentry. We use this to improve the product. We do not use it for advertising.

2. How We Use Your Information

  • Providing the Service (dashboards, syncs, alerts) — Contract performance
  • Billing and subscription management — Contract performance
  • Security and fraud prevention — Legitimate interest
  • Product improvement and analytics — Legitimate interest
  • Legal and regulatory compliance — Legal obligation

We do not sell, rent, or barter your data. We do not use your store data to train AI models or enrich profiles of third parties.

3. Sub-Processors

We engage the following vendors to operate the Service:

VendorPurposeLocation
Clerk IncAuthenticationUSA
Supabase IncDatabase (AWS ap-south-1)USA/India
Vercel IncApp hosting and CDNUSA
n8n GmbHWorkflow automation and data syncsGermany
Upstash IncRedis caching and rate limitingUSA
Sentry (Functional Software)Error monitoringUSA
PostHog IncProduct analyticsUSA/EU
Razorpay Software Pvt LtdSubscription billingIndia

4. Data Retention

  • Account and billing records: 7 years (Indian accounting law)
  • Store integration data: duration of active account + 30 days
  • Usage analytics: 12 months rolling
  • Error logs: 90 days

5. Your Rights (DPDP Act 2023)

Under India's Digital Personal Data Protection Act 2023, you have the right to:

  • Access — Request a summary of personal data we hold about you
  • Correction — Request that inaccurate data be updated
  • Erasure — Request deletion of your personal data (subject to legal retention obligations)
  • Grievance redressal — Lodge a complaint with our Grievance Officer
  • Nomination — Nominate another person to exercise rights on your behalf

To exercise any right, email hello@ordscale.com. We will respond within 30 days.

6. Security

We implement AES-256-GCM encryption for stored credentials, TLS 1.2+ for data in transit, role-based access controls within organisations, and audit logs for integration access events. If you discover a vulnerability, please disclose responsibly to hello@ordscale.com.

7. Changes to This Policy

We will notify you of material changes by email or via an in-app notice at least 14 days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the revised policy.

Questions? Email us at hello@ordscale.com or write to us at 89, Faiq Enclave, Pilibhit Bypass Road, Bareilly, UP, 243006.