opsapp

Privacy policy

opsapp, operated by WALR Brothers LLP, 12 B Utkarsh Estate, Indore, Madhya Pradesh 452016, India ("we", "the platform"). Effective: 1 August

  1. Contact: corporate@walrbrothers.com.

This policy describes how the product actually handles data. Where it gives a number — a retention window, a notification deadline — that number is enforced by the software and checked by automated tests, not merely promised. Written against the Digital Personal Data Protection Act, 2023 ("DPDP Act"), whose operative provisions commence in stages to May 2027, the Information Technology Act, 2000 and the SPDI Rules, 2011. If anything here is unclear or looks wrong to you, write to us and we will answer plainly.


1. Who this policy covers

Two different relationships:

  • Brand users — founders and operators of the D2C brands that subscribe to the platform. For your data, we are the Data Fiduciary.
  • Brands' customers — the shoppers whose orders the platform processes. For their data, the brand is the Data Fiduciary and we are a Data Processor, acting only on the brand's instructions under our contract with the brand. Shoppers' consent and notice rights are owed by the brand; requests we receive from shoppers directly are forwarded to their brand.

2. What we collect and why

From brand users (we are the Fiduciary)

DataWhy
Founder email + password (hashed)account login, security notifications
Operator names + PINs (hashed)floor login, audit trail
Activity logs (who did what, when)operational audit trail the brand relies on

Lawful basis: consent given at signup, and legitimate use for providing the contracted service (DPDP Act §7).

On behalf of brands (we are the Processor)

DataSourceWhy
Order details, line itemsbrand's Shopify storerunning the order-to-dispatch workflow
Customer name, phone, email, shipping addressbrand's Shopify storepacking, shipping, delivery support
Shipment/AWB/tracking/COD recordsbrand's Shiprocket accountshipping status, reconciliation
Packing photos (parcel contents only)brand's warehouse camerathe brand's dispute evidence

We collect no data directly from shoppers, run no trackers on shopper-facing pages (we have none), and never sell or share any of this data for advertising or any purpose other than providing the service. The one exception is the aggregated statistics described just below — which contain no personal data.

Aggregated statistics

We do compile statistics from activity across the whole platform — for example, average dispatch times or return rates — and we may publish them as industry benchmarks or use them in our own material. These are combined across many brands so that no brand, order, person or address can be identified from them; they are not personal data. We never attach your brand's name to a figure, or say that you are a customer, without asking you in writing first.

Cookies

One cookie: the sign-in session for brand users, which expires after 12 hours. It is required to keep you signed in and cannot be switched off while you use the platform. We run no analytics, advertising or third-party tracking cookies on the platform or on our public website.

3. Storage, security and isolation

  • Data is stored in a managed cloud database; access credentials (Shopify tokens, courier API credentials) are stored encrypted and never displayed back or included in exports.
  • Each brand's data is isolated at the database level (row-level security), in addition to application-level checks.
  • All access is over HTTPS. Logins are rate-limited with account-level lockouts. Sensitive account actions require re-authentication.
  • Error monitoring is configured to collect as little as possible: it is set not to gather personal fields or request contents by default, and we review what it captures. We do not claim it is impossible for a fragment of order data to appear in a crash report; we claim we have switched off everything that collects it deliberately, and we clean up anything we find.
  • Reasonable security practices per IT Act §43A / SPDI Rule 8 are maintained and reviewed; a summary is available to brands on request.

4. Sub-processors

We use the following service providers to run the platform:

ProviderPurposeData touchedStored in
Railway (hosting)application + database hostingall platform dataUnited States
Cloudflare R2 (storage)packing-photo storage, database backupsphotos, backupsAsia-Pacific, best effort (see below)
Resend (email)verification, alerts, digestsrecipient email + message contentUnited States
Sentry (error monitoring)crash reportstechnical crash logsUnited States

Where your data lives. Order records, customer names, addresses and phone numbers are held in our database in the United States. Packing photos and database backups are held with Cloudflare, which we have asked to place them in the Asia-Pacific region; Cloudflare treats that as a best effort, not a guarantee, so we say "usually Asia-Pacific" rather than promising it. Everything Cloudflare holds for us is encrypted at rest by Cloudflare. Being outside India is permitted under the DPDP Act, which restricts transfers only to countries the government specifically notifies; we tell you where the data is so you can answer your own customers if they ask.

Your own Shopify and Shiprocket accounts are not in this list on purpose: they are your contracts with those providers, not ours. We connect to them with the credentials you give us. See section 7 of the Terms of Service.

We have a data processing agreement in place with each of the four providers above. They are contractually bound in how they may handle your data, not merely told about it.

5. Retention

WhatHow longHow it ends
Order and operational recordswhile the brand's workspace is activedeleted with the workspace
Activity log (who did what, when)while the workspace is activedeleted with the workspace
Packing photos180 daysdeleted automatically, every day, by a scheduled job
Job queue records (including failed jobs)30 daysdeleted automatically
Support exports (a zip we generate for you)not retained by usthe download is the only copy; we keep none
Offsite database backups30 dayspruned past 30 days; nothing older is kept

Packing photos age out on their own clock because a photo of a parcel can catch the shipping label, and a label carries a shopper's name and address. When a photo is deleted the packing event stays — who packed the order and when is the brand's operational record; only the image goes.

On workspace deletion (self-serve, in Settings) all workspace data is permanently deleted and encrypted credentials are destroyed immediately. Deletion removes the stored files before anything else, and stops with an error rather than reporting success if any file cannot be removed. Backups made before the deletion age out within the backup window above.

6. Your rights

Brand users may access, correct, and delete their data. Most of this is self-serve in Settings: a workspace data export (a zip of CSVs covering orders, line items, confirmations, packing events, inventory, stock movements, SKU mappings, returns, RTO receipts, courier delivery-attempt (NDR) records, delivery history, COD records, extra-payment records, B2B orders, operators and the activity log — with credential and password columns stripped) and permanent workspace deletion. Two things the export does not contain: your workspace settings, and the packing photo image files. Ask us and we will supply both. You may also complain to us at corporate@walrbrothers.com or to the Data Protection Board of India per the DPDP Act.

Brands' customers should contact the brand they purchased from — the brand, not us, decides on the request. What we provide the brand is: search and correction of any order's customer details in-app, the export above, and deletion on request. Deletion of a single shopper's data is not yet a self-serve button: the brand asks us and we carry it out, within 7 days and in any case within the time the law allows. We will say when it is done.

7. Grievance officer (IT Act, 2000)

Rohan Paliwal, Grievance Officer — rohan@walrbrothers.com, F23-24 Radhika Kunj, LIG Link Road, Indore, Madhya Pradesh 452011. We acknowledge complaints within 24 hours and resolve within 7 days or as law requires.

8. Breach notification

If we become aware of a personal-data breach, we will tell every affected brand within 24 hours: what happened, what data was involved, which of their customers appear to be affected, and what we are doing about it. We keep telling you as we learn more.

Telling the Data Protection Board of India and the affected shoppers is the brand's call and the brand's duty, not ours. The law puts that on the Data Fiduciary, and for shopper data the Data Fiduciary is you. Our job is to get you what you need fast enough to meet your own deadlines under the DPDP Act and the DPDP Rules, 2025 as their provisions come into force — and to help with the filing if you want it.

Separately, where a law requires us to report an incident directly to an authority — for example CERT-In's cyber-incident reporting rules — we will make that report ourselves and tell you we have done so, unless the law forbids us from telling you.

Your own account data is different. For founder and operator accounts we are the Data Fiduciary ourselves (see section 1), so if a breach affects those, the notifications to the Board and to the people affected are ours to make.

9. Changes

Material changes are notified to brand founders by email at least 14 days before taking effect.