Privacy Policy

Effective April 25, 2026

This Privacy Policy explains how Label House Technologies LLP (“Vakaru”, “we”, “us”, or “our”) collects, uses, shares, and protects personal information when you use the Vakaru cart-recovery service, our website, dashboard, and Shopify app (collectively, the “Service”).

We've written this policy to be readable. It is also designed to comply with the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by CPRA (CCPA), and India's Digital Personal Data Protection Act, 2023 (DPDP Act).

1. Who We Are

The data controller responsible for personal information processed under this policy is:

Label House Technologies LLP
PURI 81 HIGH STREET, SECTOR 81
Faridabad, Haryana 121004
India
Contact: dev@getvakaru.com

When a Shopify merchant installs Vakaru and connects their store, the merchant is the data controllerfor their shoppers' personal information, and Vakaru acts as their data processor. We process shopper data only under the merchant's instructions and as described in this policy.

2. Scope

This policy applies to two groups of people:

  • Merchants — store owners and team members who sign up for Vakaru and use the dashboard.
  • Shoppers — end customers of Vakaru merchants whose interactions on the merchant's storefront are processed by Vakaru on the merchant's behalf.

It does not cover websites, services, or apps operated by third parties (including merchants' storefronts), even when linked from Vakaru. Those have their own privacy policies.

3. Personal Information We Collect

3.1 Information from merchants

  • Email address and name, provided during sign-up via one-time passcode (OTP).
  • Business name, Shopify shop domain, and storefront brand details (colors, fonts, voice) used to personalise emails.
  • API credentials you choose to connect (e.g. Klaviyo API key) — stored encrypted.
  • Billing details, when you upgrade to a paid plan (processed via Shopify Billing or another payment processor — we don't store full card numbers).
  • Communications you send us (support emails, feedback).

3.2 Information about shoppers (processed for merchants)

  • An anonymous identifier — a SHA-256 hash of the shopper's IP address and browser user agent. This is not directly identifying on its own.
  • Storefront events received via the Shopify Web Pixel: page views, product views, cart actions, checkout steps, exit signals.
  • Cart contents and checkout state (line items, prices, shipping costs, applied discounts).
  • Customer name and email address — only when the shopper provides them during checkout, or when the merchant's scopes permit reading them via the Shopify Admin API.
  • Order history relevant to recovery (recent orders, abandoned-checkout records) — only with merchant authorisation via OAuth scopes.

We do notrequest payment card details, government IDs, precise geolocation, biometrics, or any “special category” data under GDPR.

3.3 Technical data we collect automatically

  • IP address, browser type, device type, operating system, referring URL, and timestamps for requests to our dashboard or API.
  • Application logs and error reports, used for debugging and reliability.
  • Cookies and local storage entries described in Section 11.

4. How We Use Personal Information

We use personal information for the following purposes, with the GDPR Article 6 lawful basis noted in brackets:

  • Provide and operate the Service — account creation, store connection, sending recovery emails, dashboard analytics. (Performance of contract)
  • Analyse cart abandonment — apply AI to event sequences to predict abandonment reasons and generate personalised email content. (Performance of contract / merchant's legitimate interest)
  • Service improvement — measure feature usage, evaluate model quality, fix bugs. We use aggregated and de-identified data wherever possible. (Legitimate interest)
  • Security, fraud prevention, abuse handling — detect bots, rate-limiting, incident response. (Legitimate interest)
  • Compliance — respond to legal requests, enforce our Terms, comply with tax and accounting obligations. (Legal obligation)
  • Communications with merchants — service announcements, security notices, and (with consent) product news. (Consent / legitimate interest)

We do not use personal information for automated decision-making that produces legal or similarly significant effects on shoppers. The AI we use generates email content; merchants always control whether and when emails are sent.

5. Sharing & Sub-Processors

We share personal information with vetted service providers (“sub-processors”) who help us deliver the Service. They process data only on our instructions and under written agreements with confidentiality and security obligations.

Sub-processorPurposePrimary location
Shopify Inc.Source platform; storefront events, Admin API accessCanada / Global
OpenAI, L.L.C.Large-language-model analysis and email content generationUSA
Twilio SendGridTransactional email deliveryUSA
Vercel Inc.Web dashboard hosting and edge deliveryUSA / Global edge
Railway Corp.Backend service hostingUSA
Supabase Inc.Managed PostgreSQL databaseEU / USA (region-selectable)
Langfuse GmbHLLM observability and tracingEU (Germany)
Functional Software, Inc. (Sentry)Error monitoringUSA
Zep AI Inc.Memory layer for AI-driven personalisationUSA
Klaviyo Inc.Email channel delivery, only when merchant connects their Klaviyo accountUSA

We will update this list as our suppliers change. An up-to-date version is always published at this URL. Material changes are notified to merchants under Section 13.

We do not sell personal information. We may disclose personal information if required by law, court order, or valid governmental request, or to enforce our Terms or protect our rights.

6. International Data Transfers

Vakaru is operated from India and uses sub-processors located in the United States, European Union, and other countries listed in Section 5. When personal information is transferred outside the country of origin, we rely on appropriate safeguards:

  • For transfers from the EU/UK to countries without an adequacy decision, we use the European Commission's Standard Contractual Clauses (2021) and the UK International Data Transfer Addendum.
  • For transfers under India's DPDP Act, we transfer to permitted jurisdictions and apply contractual safeguards equivalent to those required under the Act.
  • For transfers under CCPA, we contractually restrict secondary use of personal information in line with the “service provider” framework.

A copy of the safeguards in place can be requested at dev@getvakaru.com.

7. Data Retention

We retain personal information only as long as necessary for the purposes set out in this policy:

  • Merchant account data — for the lifetime of the account, and for 30 days after account closure to allow recovery, then deleted or anonymised.
  • Shopper event data and abandonment analyses — rolling 12-month window, after which records are deleted or aggregated.
  • Email campaign logs — 24 months for performance reporting and deliverability disputes.
  • Backups — encrypted backups are retained for up to 30 days and then permanently deleted.
  • Aggregated or anonymised data — may be retained indefinitely as it no longer identifies anyone.
  • Legal holds — longer where required by applicable law (tax, accounting, dispute records).

When a merchant uninstalls Vakaru, we mark the store inactive immediately and process Shopify's shop/redactwebhook (delivered 48 hours after uninstall) by deleting the merchant's shop-scoped data.

8. Your Rights

8.1 Under GDPR / UK GDPR

If you are in the EU, EEA, UK, or Switzerland, you have the right to:

  • Request access to your personal information.
  • Have inaccurate information corrected.
  • Have your information erased (the “right to be forgotten”), subject to limitations.
  • Restrict or object to certain processing.
  • Receive a portable copy of information you provided to us.
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with your local supervisory authority.

8.2 Under CCPA / CPRA (California)

If you are a California resident, you have the right to:

  • Know the categories and specific pieces of personal information we collect, use, disclose, and (if applicable) sell or share.
  • Delete personal information we hold about you.
  • Correct inaccurate personal information.
  • Opt out of the “sale” or “sharing” of personal information for cross-context behavioural advertising — Vakaru does neither.
  • Limit the use of sensitive personal information — Vakaru does not collect sensitive personal information as defined by CPRA.
  • Not be discriminated against for exercising your rights.

8.3 Under DPDP Act, 2023 (India)

If you are an Indian resident (a “Data Principal”), you have the right to:

  • Access information about the personal data we process.
  • Have inaccurate or incomplete information corrected.
  • Have personal data erased when no longer required, subject to legal exceptions.
  • Nominate another individual to exercise rights in case of death or incapacity.
  • Grievance redressal — see Section 14.

8.4 How to exercise your rights

Email dev@getvakaru.com with your request. We will verify your identity (to prevent unauthorised disclosure) and respond within 30 days. There is no fee for the first request in any 12-month period; we may charge a reasonable fee for excessive or repeated requests.

If you are a shopper of a Vakaru merchant, please contact the merchant directly — they are the data controller and we will route your request to them.

9. Shopify Compliance Webhooks

Vakaru implements the three mandatory Shopify GDPR compliance webhooks:

  • customers/data_request — when a merchant asks us for a shopper's data, we provide it within 30 days.
  • customers/redact — we delete a shopper's personal information within 30 days of receiving the request.
  • shop/redact — when a merchant uninstalls Vakaru, we delete shop-scoped data within 30 days of receiving the redaction request (Shopify delivers it 48 hours after uninstall).

Each webhook request is verified using HMAC-SHA256 signed with our app's secret to ensure authenticity.

10. Security

We apply industry-standard administrative, technical, and physical safeguards, including:

  • TLS 1.2+ encryption for all data in transit.
  • Encryption at rest for sensitive fields (e.g. third-party API keys, access tokens).
  • Role-based access controls and the principle of least privilege for engineering access.
  • Centralised secret management; no credentials in source code.
  • Regular dependency updates and security reviews.
  • Logging and alerting for suspicious activity.

No system is perfectly secure. If we discover a personal-data breach that is likely to result in a risk to your rights, we will notify affected merchants and regulators within 72 hours of becoming aware, as required by GDPR and equivalent laws.

11. Cookies and Similar Technologies

The Vakaru dashboard uses a small number of first-party cookies and storage entries:

  • Strictly necessary — authentication, session, and CSRF protection. These are always on.
  • Functional — UI preferences (theme, layout), remembered for your convenience.

The Vakaru dashboard does not use third-party advertising or cross-site tracking cookies.

The Vakaru pixel is installed by merchants on their own storefront via Shopify's Web Pixels framework. It is governed by the merchant's cookie banner and consent settings; merchants are responsible for obtaining the necessary shopper consent before the pixel fires.

12. Children's Privacy

Vakaru is a business-to-business service intended for adults. We do not knowingly collect personal information from children under 16 (or under 18, where applicable under the DPDP Act for “child” processing without verifiable parental consent). If you believe a child has provided us with personal information, please contact dev@getvakaru.com and we will delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified to merchants by email at least 30 days before they take effect. Non-material changes (clarifications, formatting, sub-processor list updates) will be reflected on this page with an updated “Effective” date.

14. Contact & Grievance Redressal

For privacy questions, requests to exercise your rights, or grievances under the DPDP Act, please contact our Grievance Officer:

Grievance Officer
Label House Technologies LLP
PURI 81 HIGH STREET, SECTOR 81
Faridabad, Haryana 121004
India
Email: dev@getvakaru.com

We will acknowledge requests within 7 days and respond substantively within 30 days where possible. If you are not satisfied with our response, you may lodge a complaint with your local data protection authority.