Privacy Policy
This policy explains what NayiHaat collects and why, in plain language. There are two kinds of people on NayiHaat: merchants, who create a store, and buyers, who visit a merchant's storefront or receive an invoice from one. This policy covers both, and is written for India.
Merchants and buyers are different
If you run a store on NayiHaat, this policy tells you what we collect from you and why. If you are a buyer — you visited a merchant's storefront, placed an order, or received an invoice — the merchant decides what to collect from you and why, and NayiHaat processes that information on the merchant's behalf under the Digital Personal Data Protection Act, 2023. Merchants remain responsible to their own customers, and every storefront publishes its own privacy, refund and shipping policies — please check the store's own page for those.
What we collect from merchants
When you create and run a store, we collect: your name, email and phone number; business details such as your GSTIN and address; your password, which we store hashed and never in plain text; your two-factor authentication secret, stored encrypted, if you turn it on; details of any team members you add; and the products, images, invoices and customers you enter into your store.
If you choose to connect them, we also collect: your Razorpay account connection, so you can accept payments (access tokens are stored encrypted); and your Google account connection — Sign in with Google uses only your name, email and profile picture, Google Analytics uses read-only access to your own GA4 property, and Google Merchant Center uses the Content API to publish your products, all only if and while you connect them.
For security, we keep a record of login activity — the IP address and browser identifier used to sign in — and an audit log of actions taken on your account.
What we collect from buyers
When you check out on a storefront or view an invoice, we collect what you type in: your name, phone number, delivery address and email address, along with your order details and payment status.
Payments are processed by Razorpay, directly into the merchant's own Razorpay account. NayiHaat never sees or stores your card, UPI or bank details, and never holds your money.
If you choose to send a WhatsApp message to a merchant from their store, that message goes straight to the merchant through WhatsApp (Meta) — NayiHaat does not see it.
Storefront visit analytics
So a merchant can see how many people visited their store each day, we count visits without cookies or trackers, using a one-day salted hash of the visitor's IP address and browser identifier. That hash is deleted within a day, so there is no tracking across days or across sites, no advertising profiles are built, and a merchant's own visits to their own store are excluded from the count. A merchant may choose to add their own Google Analytics or Meta Pixel to their store separately — if they do, that is covered by that store's own policy, not this one.
NayiHaat's own website
NayiHaat's own marketing site and app pages at nayihaat.com (not merchant storefronts) use Google Analytics to understand how visitors use them.
Cookies
We use a session cookie to keep you signed in and remember your cart, a security (CSRF) token to protect your forms, and an optional "remember me" cookie if you choose to stay signed in. We do not use advertising cookies.
Who we share information with
We use a small number of service providers to run NayiHaat: Razorpay for payments; Google for sign-in, Analytics and Merchant Center, only when you connect them; Meta for the product catalogue feeds you enable and for WhatsApp; Hostinger for hosting, with your data stored in India; and an email delivery provider to send transactional email such as receipts and password resets.
How long we keep information
We keep your information while your account is active, and for as long as tax law requires for invoices and other GST records. Security logs are kept for a limited period. Storefront analytics are kept only as daily totals, for 13 months. We delete information on request, except where the law requires us to keep it.
Your rights under the DPDP Act, 2023
Under the Digital Personal Data Protection Act, 2023, you can ask to access, correct or erase your personal data, raise a grievance, and nominate someone to exercise these rights on your behalf if you are unable to. To exercise any of these, write to us at the address below — we respond within 30 days.
Security
We use HTTPS everywhere, encrypt connected-account tokens at rest, offer optional two-factor authentication, and audit admin access to accounts.
Children
NayiHaat is for adults running a business. It is not directed at, and should not be used by, anyone under 18.
Changes to this policy
If we change this policy, we will post the new version on this page with an updated date.
Questions, or want to exercise your rights? Write to us at info@websyi.com.
Last updated 12 September 2026
