Back to Home

Privacy Policy

Last updated: August 19, 2026 · Effective: August 19, 2026

1. Introduction

MYSIQRA ("Company", "we", "us", or "our") operates the MYSIQRA Vendor Management Platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By accessing or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.

We are committed to protecting your personal data in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and other relevant regulations.

2. Information We Collect

2.1 Personal Data

When you register for an account, we collect the following personal information:

  • Full name (first name and last name)
  • Email address
  • Phone number (optional)
  • Business name and category
  • Business address (address line 1, address line 2, city, state, country, pincode)
  • Tax identification numbers (GST Number, PAN Number) where applicable
  • Website URL (optional)

2.2 Financial Data

Payment processing is handled by third-party payment processors. We do not store your credit card numbers, bank account details, or other financial information on our servers. Payment data is processed in accordance with PCI-DSS standards by our payment processor.

2.3 Usage Data

We automatically collect certain information when you use the Service:

  • IP address and browser type
  • Device information and operating system
  • Pages visited, features used, and time spent on the Service
  • Referring URLs and exit pages
  • Date and time of your visits

2.4 Content Data

Any content you upload to the Service, including event details, documents, images, invoices, and communications, is stored and processed solely to provide the Service to you.

3. How We Use Your Information

We use your personal data for the following purposes:

  • Service delivery: To create and manage your account, process transactions, and provide vendor management features
  • Communication: To send you service-related notifications, transactional emails, and marketing communications (with your consent where required)
  • Security: To detect, prevent, and address fraud, unauthorized access, and other illegal activities
  • Improvement: To analyze usage patterns and improve the Service, features, and user experience
  • Legal compliance: To comply with applicable laws, regulations, and legal processes
  • Support: To respond to your inquiries and provide customer support

4. Legal Basis for Processing (GDPR)

If you are in the European Economic Area (EEA) or United Kingdom, we process your personal data based on the following legal grounds:

  • Contract performance: Processing necessary to perform our contract with you (providing the Service)
  • Legitimate interests: Processing for our legitimate business interests (security, improvement, analytics) that do not override your fundamental rights
  • Consent: Processing based on your explicit consent (e.g., marketing emails, non-essential cookies)
  • Legal obligation: Processing required to comply with applicable laws

5. Data Sharing and Subprocessors

We do not sell your personal data. We share your information only with the following categories of third parties:

  • Hosting providers: Cloud infrastructure providers that host our Service and data
  • Payment processors: Third-party payment processors that handle transactions
  • Email service providers: Services that deliver transactional and marketing emails
  • Analytics providers: Tools that help us understand Service usage (anonymized where possible)
  • Legal authorities: When required by law, subpoena, or other legal process

All subprocessors are contractually bound to protect your data to standards no less protective than those in this Privacy Policy.

6. International Data Transfers

Your data may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) where required by applicable data protection laws, to protect your personal data during international transfers.

7. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy:

  • Account data: Retained for the lifetime of your account plus 30 days after deletion
  • Transaction records: Retained for 7 years as required by tax and financial regulations
  • Usage logs: Retained for 90 days for security and performance analysis
  • Marketing data: Retained until you withdraw consent or unsubscribe

After the retention period, your data is securely deleted or anonymized.

8. Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data ("right to be forgotten")
  • Portability: Request your data in a structured, machine-readable format
  • Restriction: Request restriction of processing in certain circumstances
  • Objection: Object to processing based on legitimate interests or direct marketing
  • Withdraw consent: Withdraw consent at any time where processing is based on consent
  • Opt-out of sale: Under CCPA/CPRA, opt out of the sale or sharing of personal data (we do not sell personal data)

To exercise any of these rights, contact us at privacy@mysiqra.com. We will respond to verified requests within 30 days.

9. Data Security

We implement industry-standard security measures to protect your personal data, including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Secure authentication with bcrypt password hashing
  • Role-based access controls and session management
  • Regular security audits and vulnerability assessments
  • Automated rate limiting and intrusion detection

While we strive to use commercially acceptable means to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

10. Cookies and Tracking

We use cookies and similar tracking technologies to maintain your session, remember your preferences, and analyze Service usage:

  • Essential cookies: Required for authentication and core functionality (session cookies)
  • Functional cookies: Remember your preferences and settings (persistent cookies)
  • Analytics cookies: Help us understand how the Service is used (with consent where required)

You can control cookies through your browser settings. Disabling essential cookies may affect Service functionality.

11. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children under 18. If we become aware that we have collected personal data from a child under 18, we will take steps to delete such information promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes, we will provide additional notice (e.g., email notification) at least 30 days before the changes take effect.

13. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us: