Data Governance & Security

Privacy Policy (DPDP Act Compliant)

Compliance Standard: India Digital Personal Data Protection (DPDP) Act 2023 & IT Rules · Last Updated: September 2026

1. Our Commitment to Data Privacy

Shiperon (operated by Naveenkumar M K, registered in Tamil Nadu, India; "Shiperon", "we", "our") is deeply committed to protecting the privacy of our registered business merchants and their end-consumers. This Privacy Policy details our data collection, encryption, processing, and retention practices under India's Digital Personal Data Protection (DPDP) Act 2023.

2. Data Fiduciary vs. Data Processor Role

When merchants sign up on Shiperon, we act as a Data Fiduciary regarding the merchant’s account profile, business KYC records, and wallet ledger. When merchants upload their customer order lists (recipient name, address, phone number, and pincode) for shipping label generation or catalog checkout, Shiperon acts strictly as a Data Processor on behalf of the merchant.

3. Enterprise Encryption & Storage Architecture

We employ defense-in-depth architectural controls to guarantee data isolation and integrity:

  • Encryption at Rest: Bank account numbers, IFSC codes, courier API secrets, and webhook tokens are encrypted using AES-256 GCM authenticated ciphers.
  • Encryption in Transit: 100% of platform traffic and third-party carrier API communications operate exclusively over TLS 1.3 encryption.
  • Multi-Tenant Data Isolation: Every seller’s orders, customers, and financial ledger rows are partitioned with strict tenant foreign-key scoping.

4. Permitted Use of End-Consumer Delivery Details

End-consumer data (name, delivery address, phone number) uploaded by merchants is processed solely for the following legitimate purposes:

  • Dispatching the waybill request to the selected carrier (BlueDart, Delhivery, Shadowfax, DTDC, Xpressbees, etc.).
  • Generating physical thermal 4x6 barcode shipping labels and dispatch manifests.
  • Transmitting live tracking updates and Non-Delivery Report (NDR) re-attempt OTPs via WhatsApp/SMS.

We strictly enforce a zero data selling policy. We never sell, monetize, or rent merchant customer lists to third-party advertisers or competing businesses.

5. Merchant Rights & Retention Timelines

Merchants may request access, correction, or permanent erasure of their account data by emailing our Data Protection Officer at . Financial transaction records and invoice passbook entries are retained for a minimum statutory period of 8 years in compliance with Indian Goods and Services Tax (GST) laws and the Companies Act.