Privacy Policy

Last updated: August 9, 2026

1. Introduction

This Privacy Policy outlines how Cladov ("we", "our", or "us") collects, utilizes, and protects the personal information of our users and their respective customers. We are committed to maintaining the highest standards of data security and transparency in accordance with applicable data protection regulations.

2. Data Collection and Usage

We collect information strictly necessary to provide and operate the Cladov platform. This includes:

  • Account Information: Name, email address, and authentication credentials for platform access.
  • Business Data: Business name, address, GSTIN, and staff details necessary for invoice generation and compliance.
  • Operational Data: Customer details, product inventory, and transaction records inputted by you into the platform.
  • Technical Data: IP addresses and browser fingerprints utilized strictly for rate limiting, security auditing, and fraud prevention.

3. Third-Party Infrastructure and Sub-processors

To ensure the reliability, security, and functionality of our platform, we share specific, limited data with vetted third-party infrastructure providers. We do not sell data to advertisers. The entities we share data with are:

  • Razorpay and Stripe: We transmit transaction amounts and configuration parameters to Razorpay and/or Stripe, whichever you or your customer selects at checkout, to facilitate secure payment processing. We do not store full card numbers, UPI IDs, or bank credentials on our servers — card details are captured directly by the gateway's own hosted checkout.
  • Zoho ZeptoMail: We utilize Zoho ZeptoMail for transactional email delivery (e.g., OTP codes, password resets). Email addresses are processed solely for the purpose of message routing.
  • Cloudflare (Turnstile): We employ Cloudflare Turnstile on public-facing forms to mitigate automated bot traffic. Cloudflare analyzes client telemetry to verify human interaction without tracking users across domains.

4. Data Security and Retention

We implement robust technical safeguards, including cryptographic hashing for passwords, rate limiting against brute-force attacks, signature-verified payment webhooks, and encrypted database connections. One-time passcodes and password reset tokens expire automatically and are purged by an automated background job within minutes of expiry. Data is otherwise retained only for the duration of an active account lifecycle, or as mandated by statutory compliance requirements.

5. User Rights and Data Backups

You maintain full ownership of the data entered into Cladov. It is strictly the user's responsibility to perform routine exports and maintain off-site backups of their business data. While we implement safeguards, we are not liable for data loss due to unexpected outages or system failures. You may request an export or complete deletion of your business data by contacting our support team at [email protected].