Back to Duitho

Duitho

Privacy Policy

Last updated: 6 September 2026

1. Scope and roles

This policy applies to Duitho websites, public shop pages, demos, dashboards, order and appointment flows, support, and related services. Duitho operates the platform. A shop owner decides what customer information the shop collects and is responsible for its shop-specific privacy notices and lawful use. For that shop information, Duitho generally acts as the owner’s service provider or processor.

2. Information you provide

We may collect account name, email, phone number, one-time-login details, shop name, category, address, city, state, pincode, hours, products, services, prices, GST information, UPI ID, delivery notes, customer names, contact details, order lines, booking details, payment status, cancellations, support messages, and other information you choose to enter.

3. Information collected automatically

We may record IP address, browser and device type, operating system, language, approximate location derived from technical data, pages visited, timestamps, referring page, error logs, security events, and product interaction events. We use these records for authentication, fraud prevention, reliability, diagnostics, and aggregate improvement; they are not used to create a public shop profile.

4. Purposes and legal basis

We process information to provide requested services, authenticate users, create and display shops, process orders and bookings, send status messages, generate invoices, support WhatsApp or UPI hand-offs, provide support, secure the platform, prevent abuse, improve features, comply with legal obligations, and protect rights. Where consent is required, we will request it and allow withdrawal where applicable.

5. Public and private information

Owners choose which shop name, category, address, contact details, hours, catalog, services, prices, and link appear publicly. A privacy-safe link can use a unique store ID instead of a phone number. Dashboard data, customer contact details, internal notes, UPI settings, and order details are not intended to be public unless a user deliberately shares them or disclosure is required by law.

6. Shop-owner obligations

Owners must collect only necessary customer information, provide appropriate notices, use it for legitimate shop purposes, keep access secure, honour applicable access or deletion requests, and avoid exporting or sharing it unnecessarily. Duitho may assist with owner instructions but does not take responsibility for a shop’s independent privacy practices.

7. Orders, bookings, payments and WhatsApp

We share relevant information with the shop and customer to complete an order or booking and may open WhatsApp, email, UPI, or another payment app when a user chooses that action. External providers process information under their own terms. Duitho does not request or store UPI PINs, card PINs, banking passwords, or payment credentials.

8. Cookies and local storage

Essential cookies, session storage, and local storage may support login sessions, language, theme, security, and core product operation. Limited diagnostics or analytics may be used where enabled. Disabling essential storage can prevent login or parts of the service from working.

9. Service providers and disclosures

We may use hosting, database, authentication, email, messaging, monitoring, analytics, security, and support providers under confidentiality and security obligations. We may disclose information to the relevant shop or customer, professional advisers, an acquirer or successor, or authorities where needed for law, court process, safety, fraud prevention, or a valid request. We do not sell personal information or share it for unrelated advertising.

10. Security and incident response

We use access controls, scoped shop permissions, authenticated sessions, encrypted connections, logging, least-privilege service access, backups, and operational safeguards appropriate to the risk. No service is risk-free. We investigate suspected incidents, contain access where practical, preserve evidence, and provide notices when required by applicable law. Report suspected compromise through the in-product support channel.

11. Retention and deletion

We retain information for service delivery, order and accounting records, dispute resolution, abuse prevention, security, legal compliance, and enforcement. When no longer needed, information is deleted, anonymised, or securely isolated. Backups and legally required records may remain for a limited period. Account closure does not automatically erase records that a shop must retain or information needed for another person’s transaction.

12. Rights and requests

Subject to applicable law, you may request access, correction, export, deletion, restriction, objection, or withdrawal of consent. We may verify identity and may refer shop-customer requests to the relevant shop owner. Requests should use the support channel in Duitho; the operator should add its legal entity name, privacy email, registered address, and grievance contact before launch.

13. Children and sensitive data

Duitho is not directed to children and should not knowingly collect children’s data without appropriate authorisation. Do not enter health, biometric, financial-account credentials, government ID, or other sensitive information unless the feature and legal basis clearly require it. Shop owners must apply extra safeguards where their sector requires them.

14. International processing

Service providers may process information in countries different from where a user lives. Where cross-border safeguards or notices are required, the operator will implement them. The operator should complete this section with the hosting regions and transfer mechanism before launch.

15. Changes and contact

We may update this policy when the product, processing, or law changes. The latest version and effective date appear on this page. For privacy questions, requests, or security concerns, use the support channel available inside Duitho.