Introduction
Welcome to RetailXpress, operated by Nexenstial LLP (“RetailXpress”, “we”, “our”, or “us”). Your privacy matters to us, and we are committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, distributor web portal, retailer mobile app, and customer-facing ordering app (together, the “Services”).
By accessing or using any of our Services, you agree to the practices described in this policy. If you do not agree, please discontinue use immediately and contact us to request account deletion.
Who this policy covers
This policy applies to three categories of users across our platform:
- Customers — end consumers who place orders through a retailer’s branded storefront or the RetailXpress customer app. Customers typically share delivery address, phone number, and payment method only.
- Retailers — registered shop owners and kirana store operators who use the RetailXpress retailer app to manage orders, inventory, payments, and credit from distributors. Retailers share business registration details, GST information, bank account data, and credit-assessment documents.
- Distributors — FMCG or general-trade distributors who use the RetailXpress distributor portal to manage their retailer network, catalogue, pricing, invoicing, and collections. Distributors share business entity data, GSTIN, bank details, product catalogues, and pricing configurations.
Certain sections of this policy are role-specific. Where a section applies to only one or two roles, it is labelled accordingly.
Information we collect
All users
- Name, email address, and phone number provided at registration.
- Device identifiers, IP address, OS version, and browser/app version.
- App usage data — screens visited, features used, session duration, crash logs.
- Communications you send us via chat, email, or support tickets.
Customers
- Delivery address (street, city, PIN code) and saved address book entries.
- Order history, cart contents, and reorder preferences.
- Payment method tokens (UPI VPA, card last-4, wallet ID) — full card numbers are never stored on our servers.
- Optional: profile photo and preferred language.
Retailers
- Shop name, trade licence number, and physical shop address.
- GST Identification Number (GSTIN) and GST filing category.
- Bank account number and IFSC code for settlements and credit repayments.
- KYC documents — Aadhaar/PAN of proprietor, shop photographs, and business proof submitted for credit eligibility.
- Order history with each distributor, outstanding balances, and credit utilisation.
- Inventory levels synced from the retailer app.
Distributors
- Business entity name, registered address, and CIN/partnership deed details.
- GSTIN and HSN/SAC codes for products in the catalogue.
- Bank account details for collection settlements.
- Product catalogue data — SKUs, MRP, trade price, weight, and images.
- Per-retailer pricing tiers, credit limits, and payment terms configured in the portal.
- Sales, collection, and outstanding reports generated from platform activity.
App permissions and device data
Our mobile applications may request the following device permissions. Each permission is requested only when you use the feature that requires it, and you may revoke permissions at any time from your device settings.
- Camera — used by retailers to scan barcodes during stock-taking, capture shelf images for distributor audits, and photograph KYC documents during onboarding.
- Location (approximate) — used to suggest nearby distributors during retailer onboarding and to enable delivery-route optimisation for customer orders. We do not track location continuously in the background.
- Contacts — requested optionally so retailers can invite staff members or customers via WhatsApp or SMS. We read only the contacts you explicitly select; we do not upload your full address book.
- Notifications — used to deliver order confirmations, payment receipts, dispatch alerts, credit limit warnings, and promotional offers. You can opt out in app settings.
- Storage / media — used to save invoices and delivery challans to your device and to let you attach photos during support requests.
Payments, credit and banking data
RetailXpress facilitates payments between customers, retailers, and distributors. Payment processing is handled by licensed payment aggregators (currently Razorpay and Cashfree Payments). We do not store full card numbers, CVV codes, or net-banking credentials on our servers.
- Customer payments — UPI, debit/credit card, and wallet transactions are tokenised by our payment partner. We store only the token reference, amount, and status.
- Retailer credit — when a retailer applies for buy-now-pay-later credit, we share KYC documents and repayment history with our credit-assessment partner (and, where required, a licensed NBFC or bureau). This data is subject to the credit partner’s own privacy policy.
- Distributor settlements — bank account details provided by distributors are used solely for settlement transfers. They are stored in encrypted form and accessed only by our finance operations team.
- GST-linked payment data — invoices generated on the platform carry GSTIN, HSN/SAC codes, and tax breakdowns. This data is shared with the buyer, seller, and, when e-invoicing is enabled, with the GST portal (IRP) as required by law.
GST and regulatory data
As a B2B trade platform operating in India, RetailXpress generates and processes GST-regulated documents including tax invoices, credit notes, e-way bills, and e-invoices.
- GSTIN and invoice data shared between retailers and distributors is required under the CGST Act, 2017.
- Where e-invoicing is mandated (turnover above INR 5 crore), invoices are automatically reported to the Invoice Registration Portal (IRP). The IRN and QR code returned are embedded in the PDF invoice.
- E-way bill generation for inter-state or high-value dispatches is supported through the NIC portal integration. Transporter details and vehicle numbers provided for this purpose are shared with the NIC portal only.
- We retain GST-regulated documents for a minimum of 8 years as required by law, even after account deletion is requested.
Communications and notifications
We communicate with you through the following channels, depending on the preferences you set:
- WhatsApp — order confirmations, dispatch alerts, payment reminders, and credit overdue notices. Sent via the WhatsApp Business API through a registered BSP (Business Solution Provider).
- SMS — OTPs, transaction alerts, and critical account notifications.
- Push notifications — in-app alerts for new orders, stock updates, and promotions. You can manage these in device settings.
- Email — account statements, GST invoice copies, and policy updates.
You may opt out of marketing communications at any time. Transactional messages (e.g., OTPs, payment receipts, legal notices) cannot be opted out of while your account remains active.
How we use your information
- Provide, operate, and improve the RetailXpress platform and all its applications.
- Process orders, generate GST-compliant invoices, and facilitate delivery and fulfilment.
- Enable buy-now-pay-later credit for eligible retailers and manage repayment schedules.
- Help distributors manage their retailer network, pricing, credit exposure, and collections.
- Deliver transactional notifications via WhatsApp, SMS, push, and email.
- Verify identity and conduct KYC checks as required by our financial partners and regulation.
- Detect, prevent, and respond to fraud, chargebacks, and platform abuse.
- Analyse aggregate usage patterns to improve reliability, features, and user experience.
- Comply with applicable laws, court orders, and regulatory requirements.
Sharing your information
We share your information only in the following circumstances:
- Between platform participants — retailers receive order and pricing information from distributors; distributors receive order, KYC, and payment data from retailers. Customer name and delivery address are shared with the fulfilling retailer and delivery partner only.
- Payment processors — Razorpay, Cashfree, and banking partners receive the minimum data required to process a payment or settlement.
- Credit and NBFC partners — retailer KYC, transaction history, and repayment data are shared with our credit partners when a retailer opts in to the credit programme.
- Government and tax portals — GSTIN, invoice data, and e-way bill details are shared with IRP and NIC as mandated by Indian tax law.
- Infrastructure and SaaS providers — cloud hosting (AWS/GCP), analytics, logging, and monitoring vendors operating under data-processing agreements.
- Legal authorities — when required by a valid court order, statutory authority request, or to protect the rights, property, or safety of our users and the public.
We never sell, rent, or auction personal information to any third party.
Your privacy rights
You have the following rights regarding your personal data:
- Access — request a copy of the personal information we hold about you.
- Correction — request correction of inaccurate or outdated information.
- Deletion — request deletion of your account and personal data. Note that GST-regulated financial records cannot be deleted before the statutory retention period expires.
- Portability — request your order history, invoice records, and profile data in a machine-readable format (CSV or JSON).
- Opt-out of marketing — unsubscribe from promotional communications at any time via the link in any email or by contacting support.
- Withdraw consent — where processing is based on consent (e.g., credit assessment), you may withdraw consent by contacting us, subject to any contractual obligations.
To exercise any of these rights, email hello@retailxpress.ai with your registered phone number or email. We will respond within 30 days.
Data retention
We retain your information for as long as your account is active and for the following minimum periods after account closure:
- GST invoices and financial records — 8 years (as mandated by CGST Act, 2017).
- KYC documents — 5 years after the last credit transaction (PMLA, 2002).
- Order and transaction data — 3 years for dispute resolution.
- App usage and device logs — 90 days rolling, then anonymised.
- Support chat transcripts — 2 years.
Data subject to a legal hold or ongoing dispute will be retained until the matter is resolved.
Security
We apply industry-standard and regulatory-grade controls to protect your data:
- TLS 1.3 for all data in transit between apps, APIs, and our servers.
- AES-256 encryption for data at rest, including database backups.
- Role-based access control (RBAC) — staff access only the data required for their role.
- Multi-factor authentication enforced for all internal admin consoles.
- Regular third-party penetration testing and automated vulnerability scanning.
- Separate data environments for production, staging, and development — no real user data in staging.
- 24×7 anomaly detection and alerting on our cloud infrastructure.
In the event of a data breach that is likely to result in high risk to your rights and freedoms, we will notify affected users within 72 hours of becoming aware of the breach, in accordance with applicable law.
Third-party links and integrations
Our Services may link to or integrate with third-party websites, payment gateways, logistics partners, and government portals. These include the GSTN/IRP portal, NIC e-way bill portal, WhatsApp Business API, and logistics aggregators. This policy does not cover the data practices of those third parties.
We recommend reviewing the privacy policy of each third-party service you interact with through our platform.
Children’s privacy
RetailXpress is a business-to-business and business-to-consumer trade platform intended for users aged 18 and above. We do not knowingly collect personal information from anyone under the age of 18. If you believe a minor has created an account, please contact us at hello@retailxpress.ai and we will promptly delete the account.
Updates to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated via email or in-app notification at least 14 days before they take effect. The updated effective date at the top of this page always reflects the latest version. Continued use of the Services after the effective date constitutes acceptance of the updated policy.
Contact us
For privacy-related queries, data requests, or to report a concern:
- Email: hello@retailxpress.ai
- Phone: +91 95913 92656
- Address: Nexenstial LLP, Hubli, Karnataka — 580029, India
We aim to respond to all privacy requests within 30 days. For urgent matters involving potential misuse of your account, call us directly during business hours (Mon–Sat, 9 AM–8 PM IST).