This Data Processing Addendum (“DPA”) forms part of, and is a Schedule to, the Storeflea Terms & Conditions between Storeflea (“Storeflea”, “we”, “us”) and the shopkeeper / business that registers an account (the “Merchant”, “you”). It governs the processing of personal data of the Merchant’s own customers (“End-Customer Data”) under the Digital Personal Data Protection Act, 2023 (“DPDP Act”).

1. Roles of the parties

For all End-Customer Data — including customer names, mobile numbers, addresses, billing and purchase history, loyalty points, and dine-in / online orders — collected or processed through the platform:

  • the Merchant is the Data Fiduciary and decides the purposes and means of processing; and
  • Storeflea is the Data Processor and processes such data only on the Merchant’s documented instructions, in line with Section 8 of the DPDP Act.

For the Merchant’s own account data (business registration, login, subscription and billing details, encrypted payment-gateway credentials), Storeflea is the Data Fiduciary and its Privacy Policy applies.

2. Purpose & scope of processing

Storeflea processes End-Customer Data solely to provide the platform services the Merchant has enabled — point-of-sale billing and e-invoicing, printing and WhatsApp/SMS delivery of bills, inventory and CRM records, loyalty programs, online-ordering and QR dine-in portals, and related messaging integrations. Storeflea will not process End-Customer Data for any independent commercial purpose, and will not sell it or use it to train public AI models on the Merchant’s private business records.

3. Merchant obligations (consent & notice)

The Merchant represents and warrants that, before entering any End-Customer Data into the platform or sending any communication (SMS, WhatsApp, email or otherwise), it has:

  • obtained valid, informed and verifiable consent from the End-Customer as required by Section 6 of the DPDP Act and applicable TRAI (TCCCPR) rules;
  • given the End-Customer an accessible privacy notice describing the collection and processing of their data via Storeflea; and
  • kept records of such consent and will promptly honour any request to withdraw consent or to access, correct or erase data, using the tools Storeflea provides in the dashboard.

4. Storeflea obligations

Storeflea will: process End-Customer Data only on the Merchant’s instructions and as required by law; keep the data confidential; make available the dashboard tools needed for the Merchant to answer End-Customer rights requests; and, on request, provide reasonable information to demonstrate compliance with this DPA.

5. Security measures

Storeflea maintains appropriate technical and organisational measures, including: AES-256 encryption at rest for sensitive credentials, TLS 1.3 for data in transit, role-based access controls for staff accounts, and regular database backups. No method of transmission or storage is fully secure, but Storeflea works to protect data using industry-standard safeguards.

6. Sub-processors

The Merchant authorises Storeflea to engage technical infrastructure sub-processors to deliver the services — for example cloud hosting (such as AWS / Google Cloud data centres in India), the WhatsApp Cloud API (Meta), and SMS/telephony providers. Storeflea remains responsible for its sub-processors’ performance of the obligations in this DPA and will maintain an up-to-date list of sub-processors on request.

7. Personal data breach

If Storeflea becomes aware of a confirmed security incident affecting End-Customer Data on its core infrastructure, it will notify the Merchant without undue delay (and in any event within 48 hours) with the information reasonably available, so the Merchant can meet its own reporting obligations to the Data Protection Board of India.

8. Assistance with data-principal rights

Storeflea provides dashboard controls that let the Merchant access, correct, export and erase End-Customer Data so the Merchant can respond to an End-Customer exercising rights under Sections 11–14 of the DPDP Act. Storeflea will direct any rights request it receives directly to the relevant Merchant.

9. Retention & deletion

Storeflea processes End-Customer Data for as long as the Merchant’s subscription is active, plus a short window (up to 30 days) for the Merchant to retrieve data, after which the data is deleted or irreversibly anonymised, except where retention is required by law (for example GST-reported invoices).

10. Liability

Each party’s liability under this DPA is subject to the limitations and indemnities set out in the Storeflea Terms & Conditions. The Merchant is responsible for its own compliance with the DPDP Act, TRAI rules and other laws in respect of its End-Customers.

This DPA is a Schedule to and forms part of the Terms & Conditions. If there is any conflict on data-processing matters, this DPA prevails.

Grievance Officer

Akshansh Gupta

Email: support@storeflea.com

Phone: 9755598800

381-382 Amrakunj colony Indore

Support

Email: support@storeflea.com

Phone: 9755598800