Privacy Policy
Jsyxi Shipping — a shipping and fulfilment app for Shopify merchants in India.
1. Who this policy covers
Jsyxi Shipping (“the app”, “we”) is installed by a Shopify merchant on their own store. It reads that store’s orders and creates shipments with Indian courier companies.
For the personal data of buyers — the people who place orders on a merchant’s store — the merchant is the data controller (data fiduciary) and we act solely as their processor (data processor). We process buyer data only on the merchant’s instructions, for the purposes set out below, and for no purpose of our own.
For the personal data of merchant staff who hold a login to the app, we are the controller.
2. What we process
| Data | Why we need it |
|---|---|
| Recipient name, address lines, city, state, PIN code | Printing courier shipping labels and pickup manifests, and sending the booking request to the courier that will carry the parcel. |
| Recipient phone number | Required by every Indian courier for delivery contact; also used for delivery notifications and to verify a buyer on the order-tracking page. |
| Recipient email address | Delivery notifications, and to verify a buyer on the order-tracking page. |
| Order and shipment facts — order number, items, weight, COD amount, AWB, tracking events, delivery status | Creating the shipment, tracking it, handling failed deliveries, reconciling courier freight and COD remittances, and GST invoicing. |
| Merchant staff name, email and role | Signing staff in and enforcing what each person is permitted to do. |
We take only what a shipment needs. At booking we store a fixed snapshot of the delivery address and use it for the life of that shipment. We do not build buyer profiles, and we do not collect payment card details, browsing behaviour, or order history beyond the orders the merchant ships through us.
3. What we never do
- We never sell or rent personal data.
- We never use buyer data for advertising, marketing of our own, profiling, or to train machine-learning models.
- We never copy production data into development or test environments.
- We never expose a buyer’s address, contact details or order total on the public tracking page — it shows the delivery timeline and nothing more.
- Our application, worker and error logs never contain buyer names, addresses, phone numbers or email addresses. Where a value must be correlated for abuse detection we store a salted hash, never the value.
4. Who we share it with
Only these recipients, and only the fields each one needs:
| Recipient | What they receive |
|---|---|
| The courier chosen for the shipment — Delhivery, Xpressbees, Blue Dart, DTDC, Amazon Shipping, Shadowfax or Shiprocket | The delivery address and contact details needed to carry and deliver the parcel. The courier account belongs to the merchant, not to us. |
| Amazon Web Services (Mumbai region) | Hosting, database and file storage. AWS does not access the data. |
| A DLT-registered SMS gateway and a WhatsApp Business Solution Provider | The buyer’s phone number and the shipment status, to send the delivery notifications the merchant has enabled. |
We also disclose data where we are legally required to do so.
5. Where it is stored
All personal data is stored and processed in India, in the Amazon Web Services Mumbai region (ap-south-1). It is not transferred outside India except to the courier and messaging providers named above, which are themselves Indian entities.
6. How long we keep it
| Data | Retained for |
|---|---|
| Financial, tax, billing, reconciliation, shipment and audit records; invoices | 7 financial years (Indian statutory requirement) |
| Tracking events | 24 months |
| Shipping labels, manifests and temporary bundles | 90 days |
| Support ticket attachments | 180 days after the ticket closes |
| Report exports | 30 days |
| Raw webhook payloads received from Shopify and couriers | 30 days |
Deletion runs automatically on a schedule; it is not a manual process.
7. How we protect it
- In transit: TLS 1.2 or higher on every external connection — the Shopify API, courier APIs, inbound webhooks, the merchant dashboard, the public tracking page and every signed document link. Plaintext HTTP is refused, not redirected. Incoming webhooks are verified by HMAC signature.
- At rest: the database, file storage and backups are encrypted with AES-256. Courier API credentials get a second layer: each credential is sealed with its own data key, which is itself wrapped by a master key held in a key-management service and decrypted only inside the worker that makes the call.
- Credentials are write-only. No one — including the store owner and our own staff — can read a stored courier credential back through the app.
- Separation between stores. Every record, query, cache entry and file link is scoped to a single store, so one merchant’s data is not reachable from another merchant’s session.
- Least privilege. Each staff member signs in as themselves — no shared logins — and holds a role that fixes what they may see and do. Our support view of a store excludes buyer personal data.
- Audit trail. Consequential reads and every write are recorded in an append-only audit log.
8. Your rights
If you are a buyer, your relationship is with the merchant whose store you ordered from. Contact that merchant to access, correct or delete your data. When they pass the request to us — including through Shopify’s own data-request and redaction channels — we act on it and record evidence that we did.
On a deletion request we remove or irreversibly anonymise personal data across our database, search indexes, reports, file storage, caches and backups, and we revoke the tracking link for the affected shipments. We keep only the non-personal financial figures we are legally required to retain for tax and accounting.
If you are a merchant, uninstalling the app immediately ends all sessions and tracking links, stops all background processing, and destroys your stored Shopify and courier credentials. Reinstalling is a fresh connection, never a restore.
Under India’s Digital Personal Data Protection Act, 2023, and under the GDPR where it applies, you may ask for access to your data, correction of it and erasure of it, and you may complain to the relevant supervisory authority.
9. Cookies
The app sets one cookie: a session cookie that keeps a signed-in staff member signed in. It is not used for tracking or advertising, and there are no third-party analytics or advertising cookies on any page we serve.
10. Children
The app is a business tool for merchants and is not directed at children. We do not knowingly process the data of anyone under 18 other than as a delivery recipient supplied by the merchant’s store.
11. Security incidents
If we become aware of a breach affecting personal data we contain it, revoke any affected credentials, assess the scope from our audit log, and notify affected merchants, Shopify and the relevant authority without undue delay and within 72 hours of becoming aware of it.
12. Changes to this policy
If we change how we process personal data we will update this page and change the effective date above. Material changes will be notified to merchants in the app.
13. Contact
Questions, requests or complaints about privacy: privacy@jsyxi.com
Grievance Officer, as required by the Digital Personal Data Protection Act, 2023: privacy@jsyxi.com. We acknowledge grievances within 72 hours and resolve them within 30 days.