This Privacy Policy explains how Pyyor Enterprises Private Limited ("Pyyor", "we", "us", "our") collects, uses, shares, stores, and protects personal data when you use our website (https://www.pyyor.com), our mobile applications, and our related services (together, the "Services"). It is written to meet the standards of India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and, where relevant, other applicable laws.
We follow one rule above every other: only collect what we genuinely need to run the Services, and be honest about it. If anything below is unclear, please write to us at support@pyyor.com.
1. Who we are
Pyyor Enterprises Private Limited, a company incorporated in India, runs these Services. Registered office, CIN, GSTIN, and grievance contacts are on our About Us page. For privacy questions write to support@pyyor.com.
2. What this policy covers
This policy applies to every surface where you interact with Pyyor:
Our website at https://www.pyyor.com and its subdomains.
Our Pyyor mobile app on iOS and Android.
Our content delivery network at cdn.pyyor.com.
Any email, SMS, WhatsApp, or push message we send you.
Our customer support conversations, including the in-app Contact Us form.
3. Personal data we collect (itemised)
We list every category of personal data below, together with the purpose for which we collect it and how long we keep it. This is the itemised notice required by the DPDP Act and DPDP Rules 2025.
3.1 Account and profile
Full name — displayed on invoices and shared with couriers. Retained while your account is active.
Email address — for account login, order confirmations, password reset, and (if you opt in) marketing.
Phone number — for order updates, delivery coordination, and (if you opt in) marketing.
Password — stored as a one-way hash. We never see or store your plain password.
Gender, date of birth, anniversary date — optional. Used only to personalise the app if you provide them.
Google or Apple sign-in identifier — created if you sign in with those methods. Used only to sign you in.
3.2 Delivery addresses
Address label, house or flat number, street lines, landmark, area, city, state, and pin code.
Receiver name and phone (may differ from account owner).
Optional latitude and longitude only when you tap "Use current location" on the map picker.
Residence type and any building or floor details you enter.
3.3 Orders and payments
Items you buy, quantity, size, colour, and price at the time of purchase.
Payment mode you choose (prepaid or cash on delivery).
The payment session identifier returned by Cashfree, our payment gateway.
We never store your card number, CVV, UPI PIN, or netbanking credentials. Those are handled entirely by Cashfree on their own PCI-compliant systems.
Order status updates (packed, shipped, delivered) and courier tracking IDs.
Tax invoices generated in PDF form, retained for as long as tax law requires (see section 7).
3.4 Returns and exchanges
The reason you selected and any notes you wrote.
Photos you upload as evidence for damaged or wrong items.
A contact phone for pickup coordination.
For cash-on-delivery refunds only: a UPI ID or bank account details (account holder name, account number, IFSC). We use this only to push your refund and retain it while the refund is being processed and for the dispute-resolution period after that.
3.5 Customer support
Your name, email, phone (optional), the subject you chose, and the message you wrote in the Contact Us form.
The IP address and browser or app user-agent captured with the message, so we can prevent abuse of the form.
3.6 Device, usage, and diagnostics
Device platform (iOS, Android, or web), operating system version, app version.
Push notification token from Firebase Cloud Messaging so we can deliver order updates.
Approximate IP address, so we can secure our infrastructure and prevent fraud.
In-app interaction events (screens viewed, funnel steps completed), captured through our analytics and session-recording tools — see section 5.
Crash reports and performance traces captured by Sentry in production builds, so we can fix errors.
3.7 Camera, photos, location, and notifications (mobile)
The Pyyor mobile app asks your operating system for permission before it uses any of the following, and only for the stated purpose. You can revoke any of these permissions from your device settings at any time.
Camera and photo library — only to attach evidence photos to a return or exchange request.
Location — only when you tap "Use current location" while adding or editing a delivery address.
Push notifications — for order updates. Marketing pushes are opt-in and can be turned off in your account.
3.8 We do not collect
Aadhaar number, PAN, or any government identity number from customers.
Payment card numbers, CVVs, UPI PINs, or netbanking passwords.
Biometric or health data.
Data from children under 18 (knowingly).
4. How we use your data
We only process personal data where we have a lawful basis under the DPDP Act — either because you consented, or because it is necessary to perform the contract you entered by placing an order, or because it falls within "Legitimate Uses" under Section 7 (for example, to keep the platform secure or to comply with law).
To create and manage your account, and to sign you in securely.
To process orders end-to-end: charge you, ship the item, notify you of status, handle returns, and issue refunds.
To respond to your support messages.
To improve the app and website — measuring which flows work, fixing crashes, running A/B tests.
To prevent fraud, misuse of coupons, and unauthorised access.
To send you order-related transactional messages, which are not marketing and cannot be turned off while the order is live.
To send you marketing on channels you have opted in to. You can turn each channel off at any time in your account settings.
To comply with legal obligations — chiefly tax, accounting, and consumer law.
We do not sell your personal data. We do not rent lists to advertisers.
5. Cookies, session recording, and analytics
We use a small set of first-party cookies to run the site and a handful of third-party cookies that only load when you use a specific feature (for example, Cashfree at checkout).
5.1 First-party cookies
pyyor_at — Pyyor (first-party, httpOnly, Secure). Keeps you signed in to your Pyyor account. Duration: 7 days rolling. Essential.
pyyor_rt — Pyyor (first-party, httpOnly, Secure). Refreshes your session so you do not have to sign in again. Duration: 30 days. Essential.
lang — Pyyor (first-party). Remembers your preferred language. Duration: 1 year. Not essential.
5.2 Third-party cookies and trackers
UXCam cookies / storage — UXCam (uxcam.com). Records anonymised session replays and interaction analytics so we can improve the site. Duration: Up to 12 months.
Statsig cookies / storage — Statsig (statsig.com). Powers feature flags, product analytics, and A/B tests. May include a session-replay component. Duration: Up to 12 months.
Sentry cookies / storage — Sentry (sentry.io) — production only. Captures errors and performance data to keep the site reliable. Duration: Up to 90 days.
Google Sign-In cookies — Google (accounts.google.com). Used only when you choose Sign in with Google. Duration: Set by Google.
Apple Sign-In cookies — Apple (appleid.apple.com). Used only when you choose Sign in with Apple. Duration: Set by Apple.
Cashfree cookies — Cashfree (cashfree.com) — checkout only. Handles prepaid payment processing. Set only when you enter the checkout flow. Duration: Set by Cashfree.
5.3 Session recording and product analytics
We use session recording and product-analytics tools to understand how the site and app are used and to fix confusing flows. Sensitive screens and fields — passwords, OTPs, addresses, payment forms — are masked before they leave our systems, and we do not send card, UPI, or bank details to these tools. The processors we use for this are named in section 6.
Essential cookies that keep you signed in cannot be disabled without signing out. To withdraw consent for marketing or analytics, or to request a copy of your data, write to support@pyyor.com. We will confirm and act on the request after verifying the account.
We do not show a first-visit cookie banner. Essential cookies fall within Section 7 (Legitimate Uses) of the DPDP Act. We will move to a granular consent banner before the DPDP Rules 2025 come into force on 13 May 2027.
6. Who we share your data with
We only share personal data with service providers that help us run the Services, and only the fields those providers actually need. Each provider is bound by a contract that limits their use of the data to the purpose we specify.
Supabase — Database and file storage host. All account, order, address, and support data at rest.
Cloudflare R2 — Media and invoice storage, over-the-air app bundles. Product images, order invoices, generated design assets, app update bundles.
Resend — Transactional email. Email address, OTPs, order status updates, contact form receipts.
Firebase Cloud Messaging (Google) — Push notifications. Push tokens, notification payloads for order updates and (if opted in) marketing.
Cashfree — Payment processing (prepaid). Name, email, phone, order amount. Card, UPI, netbanking credentials are entered on Cashfree and never sent to us.
Google Places — Address autocomplete on delivery flows. The search term you type and approximate location bias.
OpenStreetMap Nominatim — Reverse geocoding fallback for address search. The search term you type and, if used, your latitude / longitude.
Google Sign-In — Optional sign-in method. Google account identifier and email.
Apple Sign In — Optional sign-in method. Apple identity token, optional name and relay email.
UXCam — Session replay and interaction analytics. Screen recordings and interaction events with sensitive screens (address, payment, OTP, password) masked.
Statsig — Product analytics, feature flags, experiments. User identifier, email, phone, name (when logged in), interaction events.
Sentry — Crash and performance monitoring (production only). Errors, stack traces, coarse device information. Personally identifying user metadata is not sent by default.
We may also disclose personal data when required by law, to enforce our Terms, to protect the safety of our users or the public, or in the context of a merger, acquisition, or asset sale (in which case the acquiring entity assumes the obligations of this policy).
7. How long we keep your data
Account data — for as long as your account is active. If you delete your account, we anonymise your profile immediately (see section 10).
Order records and tax invoices — retained for 8 years, as required by the Income Tax Act, 1961 and the Goods and Services Tax framework.
Return refund UPI or bank details — retained while the refund is being processed and for up to 3 years after (Limitation Act, 1963), then anonymised.
Contact Us messages — retained for up to 3 years for dispute resolution and quality review.
Session recordings and analytics events — up to 12 months at the vendor, then deleted.
Crash reports — up to 90 days.
Marketing preferences — retained as part of your account so we honour your choices even if you re-enable an account.
8. Security
All traffic is encrypted with TLS in transit.
Passwords are hashed with a modern one-way algorithm and never stored in plain text.
Session tokens are set as httpOnly, Secure, SameSite cookies on the web, and stored in the platform Keychain on mobile.
Access to production systems is restricted to a small team, audited, and requires multi-factor authentication.
We rate-limit sensitive endpoints (login, OTP, password reset, data export) to defend against brute force and abuse.
Payments are handled by Cashfree on PCI-DSS certified infrastructure, so card data never touches our systems.
No system is perfectly secure. If you believe your account has been compromised, please write to us at support@pyyor.com right away.
9. Your rights under the DPDP Act
As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the following rights over the data we hold about you.
Right to access — request a copy of your personal data by writing to support@pyyor.com. We aim to respond promptly and always within legal timelines.
Right to correction — edit your name, email, phone, gender, and dates directly from Account → Edit Profile.
Right to erasure — delete your account from Account → Delete Account. See section 10 for what happens and what we are required to keep.
Right to withdraw consent — write to support@pyyor.com to stop marketing or analytics processing. We will confirm after verifying the account.
Right to nominate — you can nominate another person to exercise your rights in the event of your death or incapacity, by writing to support@pyyor.com.
Right to grievance redressal — write to our Grievance Officer (section 14) if you are dissatisfied with how we handle your data or your order.
Right to complain to the Data Protection Board of India — if your grievance is not resolved to your satisfaction, you can escalate to the Data Protection Board at https://www.dpb.gov.in.
To exercise any of these rights we may need to verify your identity, typically through the email or phone number linked to your account.
10. What happens when you delete your account
You can delete your Pyyor account from within the app or by writing to support@pyyor.com. When you do, we take the following steps immediately:
Your profile row is soft-deleted and your name, email, phone, gender, dates of birth and anniversary, saved passwords, and OAuth linkages are anonymised.
Your push notification tokens are removed so you stop receiving notifications.
If you used Sign in with Apple, we revoke our Apple refresh token so Apple stops sharing data with us.
Your marketing preferences are set to opted-out.
We are, however, required to keep certain records even after deletion:
Order history, tax invoices, and payment records — retained for 8 years under the Income Tax Act and GST law.
Delivery addresses attached to past orders — retained as part of the order record for the same 8 years, because the shipping address is part of the tax invoice.
Return records and refund payout details — retained for up to 3 years to defend against chargebacks and disputes, then anonymised.
Contact Us conversations — retained for up to 3 years for dispute resolution.
These records are held under legal obligation, not for marketing or profiling. They are not used to identify you as an active customer after deletion.
11. Children
Pyyor is not directed at children under 18. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, please write to support@pyyor.com and we will delete it.
12. Cross-border transfers
Our primary database is hosted with Supabase in a region approved for use in India. Some of our processors (for example Sentry and UXCam) may store limited technical data outside India. We only use processors that offer contractual safeguards for personal data. The Central Government may restrict transfers to specific countries under the DPDP Act; we will comply with any such notification and update this policy accordingly.
13. Changes to this policy
We may update this policy from time to time. When we do, we will bump the effective date shown at the top and, for material changes, notify you by email or an in-app message. Continued use of Pyyor after the effective date means you accept the revised policy.
14. Contact us
Privacy Officer: Vishwjeet Gupta (Privacy Officer), support@pyyor.com. For the registered office, CIN, GSTIN, and Grievance Officer, see About Us.