Overview
Outshade Digital Media Pvt. Ltd. (“Velodine”, “we”, “us”, or “our”) operates the Velodine platform at velodine.in — a Software-as-a-Service (SaaS) product that enables Indian businesses to create and publish professional digital product catalogs.
This Privacy Policy governs the collection and processing of personal data from two distinct groups: Merchants (businesses that sign up for a Velodine account) and Catalog Visitors (customers who browse a merchant’s published catalog). This policy is compliant with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (DPDPA).
By using Velodine, you consent to the data practices described in this policy. If you do not agree, please discontinue use of our services.
Information We Collect
From Merchants (Account Holders)
When you create and manage a Velodine account, we collect:
- Account information: Full name, business name, email address, and password (stored as a salted hash via Supabase Auth).
- Business profile: Company tagline, logo, contact phone number, contact email, business address, and custom domain settings.
- Catalog content: Product names, descriptions, prices, images, categories, SKUs, and availability status that you upload.
- Billing information: Subscription plan details and transaction records. Full payment card data is handled exclusively by Razorpay — we never store raw card numbers or CVVs.
- Team member data: Names and email addresses of colleagues you invite to manage your catalog.
- Usage & audit logs: Actions taken within the admin panel (e.g., product additions, setting changes), along with timestamps and IP addresses, for security auditing purposes.
- Support communications: Emails or messages you send to our support team.
From Catalog Visitors
When end-customers visit a merchant’s published catalog, we may collect:
- Inquiry data: Name, phone number, email address, and message submitted via quote request or inquiry forms.
- Technical data: IP address, browser type, device type, referring URL, and pages visited — collected anonymously for performance analytics and fraud prevention.
- Spam-prevention tokens: Cloudflare Turnstile generates a challenge token on inquiry forms to distinguish humans from bots. This involves limited browser environment data processed by Cloudflare.
Automatically Collected Data
Whether you are a merchant or a catalog visitor, our servers automatically record standard web server logs including IP addresses, HTTP request details, response codes, and timestamps. This data is retained for up to 90 days for security and debugging purposes.
How We Use Your Information
We use the information we collect to:
- Provide the service: Create and maintain your account, render your catalog, deliver inquiries to you, and process payments.
- Communicate with you: Send transactional emails (account confirmations, inquiry notifications, payment receipts) via the Resend email platform. We do not send marketing emails without your explicit consent.
- Improve the platform: Analyse anonymised usage patterns to identify bugs and plan new features.
- Security & compliance: Detect fraud, enforce our Terms of Service, and maintain audit logs as required by applicable law.
- Legal obligations: Comply with court orders, government requests, or other legal processes to the extent required under Indian law.
- Billing & payments: Process subscription payments and maintain records for GST compliance.
We do not sell, rent, or trade your personal data to any third party for marketing purposes, ever.
Data Sharing & Disclosure
We share personal data only in the following circumstances:
- With sub-processors: Supabase (cloud database and authentication), Razorpay (payment processing), Resend (transactional email), and Cloudflare (DDoS protection and Turnstile). Each of these providers has their own privacy policies and data processing agreements in place.
- Within a merchant’s team: If you invite team members to your Velodine account, they will have access to catalog data, leads, and settings as permitted by their assigned role.
- Inquiry routing: When a catalog visitor submits an inquiry, their name, contact details, and message are shared with the merchant who owns that catalog. Velodine acts as a data processor in this flow; the merchant is the data controller for that customer data.
- Legal requirements: We may disclose personal data when required by Indian law, a court order, or a directive from a competent government authority.
- Business transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, user data may be transferred as part of that transaction. We will provide notice before your data is transferred and becomes subject to a different privacy policy.
Data Storage & Security
All data is stored on Supabase-managed PostgreSQL instances hosted in data centers within or accessible from India. Product images are stored in Supabase Storage backed by an S3-compatible object store.
We implement the following security measures:
- Encryption in transit: All traffic between your browser and Velodine is encrypted using TLS 1.2 or higher.
- Encryption at rest: Databases and object stores are encrypted at rest by the underlying cloud provider.
- Row-Level Security (RLS):Supabase RLS policies enforce strict tenant isolation — no merchant can access another merchant’s data at the database level.
- Service role key isolation: The Supabase service role key (which bypasses RLS) is never sent to or accessible from a browser. It is used exclusively in server-side code.
- Password hashing: Passwords are hashed using bcrypt via Supabase Auth and are never stored in plaintext.
- Audit logs: All sensitive admin operations are recorded with before/after diffs, timestamps, and actor identities.
Despite these measures, no system is 100% secure. If you discover a security vulnerability, please report it to security@velodine.in immediately.
Data Retention
- Active accounts: Data is retained for the lifetime of the account.
- Deleted accounts: Upon account deletion, personal data is purged within 30 days, except where retention is required for legal or billing compliance (e.g., GST records, which are retained for 8 years as required under the GST Act).
- Inquiry/lead data: Retained until the merchant deletes it or closes their account.
- Server logs: Retained for 90 days.
Cookies & Tracking
Velodine uses minimal cookies necessary for the platform to function:
- Authentication cookies: Set by Supabase Auth to maintain your admin session. These are essential and cannot be disabled without logging out.
- CSRF protection tokens: Short-lived tokens to protect form submissions.
- Cart state (localStorage):On public catalog pages, the cart contents are saved to the browser’s localStorage (not cookies) under the key
velo-cart-[slug]. This data never leaves your device unless you submit an inquiry.
We do not use third-party advertising cookies, Google Analytics, Facebook Pixel, or any cross-site tracking technologies on the Velodine admin panel or marketing site.
Your Rights
Under the Digital Personal Data Protection Act, 2023, and applicable Indian privacy law, you have the following rights:
- Right to access: Request a copy of the personal data we hold about you.
- Right to correction: Request correction of inaccurate or incomplete personal data.
- Right to erasure: Request deletion of your personal data, subject to legal retention obligations.
- Right to portability: Receive your catalog and account data in a machine-readable format (CSV/JSON).
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to nominate: Nominate a person to exercise your rights in the event of your death or incapacity, as provided by the DPDPA.
To exercise any of these rights, email privacy@velodine.in from your registered email address. We will respond within 30 days.
Catalog Visitor Data
Velodine acts as a data processor(not controller) for personal data submitted by customers through a merchant’s catalog. The merchant is the data controller for all inquiry and lead data generated through their catalog.
If you are a customer who submitted an inquiry through a Velodine-powered catalog and want to exercise data rights, you should contact the merchant directly. If you are unable to do so, you may write to us at privacy@velodine.in and we will assist in routing your request.
Merchants are responsible for handling catalog visitor data in compliance with applicable privacy laws and for maintaining their own privacy notices on their published catalogs.
Third-Party Services
Velodine integrates with the following third-party services. Each has its own privacy policy:
- Supabase — Database, authentication, and file storage. Privacy policy at supabase.com/privacy.
- Razorpay — Payment processing. Privacy policy at razorpay.com/privacy.
- Resend — Transactional email delivery. Privacy policy at resend.com/privacy.
- Cloudflare — CDN, DDoS protection, and Turnstile bot-prevention. Privacy policy at cloudflare.com/privacypolicy.
We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before using our service.
Children’s Privacy
Velodine is a B2B platform intended for use by businesses and individuals who are at least 18 years of age. We do not knowingly collect personal data from anyone under 18. If we become aware that we have inadvertently collected data from a minor, we will delete it promptly. Contact us at privacy@velodine.in if you believe this has occurred.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will:
- Update the “Last updated” date at the top of this page.
- Send an email notification to all registered merchant accounts at least 7 days before the changes take effect.
- Display a prominent notice in the admin dashboard for 30 days after the change.
Your continued use of Velodine after the effective date of a revised policy constitutes your acceptance of the changes.
Grievance Officer
As required under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we have appointed a Grievance Officer:
- Name: Grievance Officer, Outshade Digital Media Pvt. Ltd.
- Email: grievance@velodine.in
- Address: Hyderabad, Telangana, India — 500094
- Response time: We will acknowledge your complaint within 24 hours and resolve it within 15 days.
Contact Us
For any privacy-related questions, requests, or concerns, reach out to us:
- Email: privacy@velodine.in
- General support: support@velodine.in
- Registered address: Outshade Digital Media Pvt. Ltd., Hyderabad, Telangana, India — 500094