Privacy Policy

Last updated: 7 April 2026

Overview

Feinly ("we", "our", "us") is a SaaS order management tool for home bakers. This policy explains what personal data we collect, how we use it, and your rights under India's Digital Personal Data Protection Act, 2023 (DPDPA).

Data We Collect

Baker accounts

  • Email address and password (for authentication)
  • Shop name and phone number (for your public order form)
  • Subscription and billing information (processed by Razorpay)
  • Shop logo and UPI QR code (optional, stored in Supabase)

Customer order data

When a customer places an order through your public form, we collect on your behalf:

  • Customer name and WhatsApp phone number
  • Email address (optional)
  • Order details (flavour, size, delivery date, etc.)
  • Cake design photos (optional)
  • Delivery address (if delivery order)
  • Allergen / dietary notes (if provided)

How We Use Your Data

  • To provide and operate the Feinly service
  • To send order confirmation emails (via Resend)
  • To send push notifications for new orders (via browser push)
  • To process subscription payments (via Razorpay)
  • To send daily order summaries to bakers
  • To improve and debug the service

We do not sell your data to third parties.

Data Storage and Security

Your data is stored in Supabase (PostgreSQL database), which may be hosted in the United States or European Union. We apply Row Level Security (RLS) so bakers can only access their own data. All data is transmitted over HTTPS.

Customer data collected through your order form is stored on your behalf. As a baker using Feinly, you are the data principal for your customers' information.

Third-Party Services

  • Supabase — database, authentication, and file storage
  • Razorpay — payment processing for subscriptions
  • Resend — transactional email delivery
  • Vercel — application hosting

Each of these services has their own privacy policy governing their data practices.

Data Retention

We retain your account data for as long as your account is active. If you delete your account, all associated data — including orders, customer information, and uploaded files — is permanently deleted within 30 days.

Customer order data is retained as long as your baker account is active. Customers may contact the baker directly to request deletion of their order data.

Your Rights

Under the DPDPA 2023 and applicable law, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data
  • Withdraw consent for data processing

To exercise these rights, contact us at support@feinly.app.

Cookies

Feinly uses session cookies for authentication only. We do not use advertising or tracking cookies.

Changes to This Policy

We may update this policy from time to time. We will notify active users of material changes by email. Continued use of the service after changes constitutes acceptance of the updated policy.

Contact

For privacy-related questions or data requests, please contact us at support@feinly.app.