Privacy policy
Last updated 24 September 2026Plain-language summary first
This policy explains how [Registered company name] (“Resandhi”, “we”, “us”) handles personal data when you visit resandhi.com, when you use Resandhi as a merchant, and when you chat on WhatsApp with a shop that uses Resandhi. If you are a shop’s customer, our DPDP notice is written for you and is a shorter read.
Who is responsible for what
Resandhi is used by businesses — we call them merchants. A merchant connects its WhatsApp number and its product list, and Resandhi’s agent replies to the merchant’s customers on its behalf. That creates two different relationships with data:
- Merchant account data. Your name, phone number, email address, business details, team members, billing records and how you use the product. For this data Resandhi is the data fiduciary: we decide why and how it is used, and this policy is our commitment to you.
- Conversation data. Messages between a merchant and its customers, and what comes with them: customer names and WhatsApp numbers, carts, orders, delivery addresses, return requests. For this data the merchant is the data fiduciary and Resandhi is its data processor. We use it only to provide the service to that merchant, on the merchant’s instructions, and for nothing of our own.
What we collect
If you are a merchant
- Sign-up and profile details: name, phone number (for the one-time sign-in code), email address, and your Google account’s name and email if you sign in with Google.
- Business details you give us: store name, what you sell, your policies on delivery, payment and returns, and the tone and languages you want the agent to use.
- Your catalogue: the Google Sheet, Excel file or Shopify store you connect, and the products, prices and stock levels in it.
- Credentials for the services you connect (for example a payment gateway key). These are kept only in an encrypted secrets vault; our database stores a reference to them, never the secret itself.
- Billing records: plan, invoices, payment status and your GST details if you give them. Card and bank details are entered on our billing provider’s page and never reach us.
- Usage and technical data: sign-in times, the pages and features you use, device and browser type, IP address, and error reports, so we can keep the service working and secure.
- Anything you send our support team.
If you chat with a shop that uses Resandhi
- Your WhatsApp number and the profile name WhatsApp shares with the business.
- Your messages, including voice notes (turned into text so the agent can read them) and images you send.
- What you do with the shop: products you asked about, carts, orders, delivery addresses, payment status (paid or not — never card details) and return requests.
- Preferences that make the next conversation easier, such as your language or size, and whether you have asked not to be messaged.
If you visit resandhi.com
Standard web server logs (IP address, browser, pages requested) and a small amount of analytics that tells us how many people move from a page to signing up. We do not use advertising cookies or sell visitor data.
How we use it
- To run the service: sign you in, read your catalogue, reply to your customers, create orders and payment links, and show you your inbox and reports.
- To bill you for your plan and keep the records tax law requires.
- To keep the service safe and reliable: detect abuse, investigate errors and protect accounts.
- To check the agent’s quality. Staff with a specific need can look at a conversation trace to fix a problem a merchant reported or an error our systems flagged. This access is restricted and logged.
- To tell merchants about changes to the service, their account or their bill.
We do not sell personal data, rent it, or use a shop’s customer conversations for our own marketing or to benefit any other merchant.
AI models
The agent’s replies are written by large language models from Anthropic and OpenAI. When a customer sends a message, the text needed to answer it — the conversation so far, the relevant products and the shop’s policies — is sent to one of these providers for that request.
- We use these providers only under zero-data-retention terms: they do not store the content after answering.
- Conversations are not used to train their models or ours.
- Customer messages and catalogue text are treated as data, not instructions, so a message cannot tell the agent to ignore the shop’s rules.
Who else processes data
We use a small number of service providers to run Resandhi. Each gets only what it needs for its part of the job:
- Amazon Web Services, Mumbai region: hosting, database, file storage and the encrypted secrets vault.
- Meta (WhatsApp): carries messages between the shop and its customers. Meta is an independent provider and handles WhatsApp messages under its own terms and privacy policy.
- Anthropic and OpenAI: generate the agent’s replies, under zero-data-retention terms.
- Services the merchant chooses to connect, such as a payment gateway (for example Razorpay), Shopify, Google Sheets, or an email or SMS provider. These act on the merchant’s instructions under their own terms.
- Razorpay and Stripe: collect our own subscription fees from merchants (Razorpay in India, Stripe outside India).
We may also disclose data when the law requires it, for example in response to a valid order from a court or government authority, and we will tell the affected merchant unless we are not allowed to.
Where data is stored
Resandhi’s data is stored in India, in the AWS Asia Pacific (Mumbai) region. Some service providers above work from their own infrastructure, which may be outside India — for example, the AI providers while they write a reply, Meta while a WhatsApp message is in transit, and Stripe for merchants billed outside India. We share only what each of them needs, and only under terms that protect it.
How we protect it
- Data is encrypted in transit and at rest.
- Passwords, API keys and tokens for connected services are kept in AWS Secrets Manager, encrypted with AWS KMS, and never written into our database or logs.
- Every merchant’s data is kept separate at the database level (row-level security), and our tests check that one merchant can never read another’s.
- Full message bodies are not written to our general application logs. They appear only in conversation traces, which a small number of staff can open, and every access is recorded.
- Messages from payment gateways, Meta and Shopify are checked for a valid signature before we act on them.
- Actions by our staff and by merchants’ team members are recorded in an audit log.
No system is perfectly secure. If a breach affects personal data, we will inform affected merchants and, where the law requires, the Data Protection Board of India and the people affected.
How long we keep it
- Merchant account data is kept while the account is open. After it is closed we delete it, except records we must keep by law, such as invoices for tax purposes, which we keep for the period the law sets.
- Conversation data is kept for as long as the merchant uses Resandhi and needs it, and deleted when the merchant asks or closes its account.
- When a shop’s customer asks for their data to be deleted, it is deleted within 24 hours of the request being confirmed, including the search data derived from it.
Your choices and rights
Merchants can see and correct their account details in the app, export their data, and close their account. You can also write to us to ask what we hold about you, to correct it or to delete it, or to raise a grievance.
A shop’s customers can stop messages at any time by replying STOP, and can ask for a copy of their data, a correction, or deletion. The shop is responsible for your data, so it is usually quickest to ask the shop — but you may also write to us and we will make sure it is done. The DPDP notice explains these rights in full.
Children
Resandhi is a service for businesses and is not meant for anyone under 18 to sign up to. Merchants must not use it to knowingly collect children’s data without the consent of a parent or guardian, as the law requires.
Changes to this policy
When we change this policy we update the date at the top. If a change is significant, we tell merchants by email or in the app before it takes effect.
Contact and grievances
[Registered company name]
[Registered office address, India]
Privacy questions: [email protected]
Grievance Officer: [Grievance Officer name], [email protected]
If you are not satisfied with our response, you may complain to the Data Protection Board of India.