EasyBorder

Privacy Policy

Last updated: 26 August 2026

EasyBorder (“we”, “us”) provides an HS-code classification service for Indian D2C exporters. This policy describes what data we collect, why, and your rights under India's Digital Personal Data Protection Act, 2023 (DPDP).

1. What we collect

  • Product descriptions you submit for classification — the title, description, target country, and any product-type / vendor fields you provide.
  • Account details if you sign up: your name, email address, and optionally your brand name and Shopify store URL.
  • Technical metadata: your IP address, user-agent string, and a session identifier — kept only long enough to enforce rate limits and diagnose bugs. See retention below.
  • Shopify store data if you install our Shopify app: an OAuth access token, the list of products you classify (title, description, product type, vendor), and the resulting HS codes we generate.
  • Your customers' shipping/billing details, from Shopify orders — name, street address, city, state, postal code, country, and phone number. We use this exclusively to pre-fill the consignee fields on the CSB-V (Shipping Bill) documents our Shopify app generates for you, and to compute your RoDTEP remissions eligibility. This data is not used for any other purpose.

2. What we do NOT collect

  • We do not sell or share your product descriptions, or your customers' data, with third parties.
  • We do not train any AI model on your data. Model providers (Groq, Google) may process your product description under their own no-training terms — see section 5.
  • We do not run advertising trackers on the marketing site.
  • We do not collect your customers' email addresses or payment details from Shopify orders — only the shipping/billing address fields listed above, needed for customs paperwork.

3. Purpose and lawful basis

We process the data above to provide the classification service you asked for, enforce rate limits on our free tier, and improve accuracy of the classifier. Our lawful basis under DPDP §7 is (a) your consent when you type into the classifier or install the Shopify app, and (b) legitimate interest for security and fraud prevention (rate limiting, abuse detection).

4. Retention

  • Raw IP addresses are hashed after 30 days. The hash cannot be reversed to recover the IP.
  • Classification events (product description + result) are retained for 7 years to satisfy Indian customs record-keeping obligations for export-related data, per §35 of the Customs Act.
  • Account details are retained until you exercise your right to erasure (see section 7) or the account is inactive for 3 years.
  • Shopify OAuth tokens are deleted immediately on app uninstall.
  • Customer shipping/billing details from Shopify orders are kept only as long as your merchant account exists — deleted along with everything else when you exercise your right to erasure (section 7), or on request to your customers via us.

5. Third parties (processors)

To deliver the service we route data through:

  • Supabase (database) — hosted in Mumbai, ap-south-1 region.
  • Vercel (application hosting) — receives requests to serve the site.
  • Groq and Google (Gemini) — receive your product description to produce a suggested classification. Both operate under commercial no-training terms.
  • Axiom (observability) — receives structured application logs, with secrets and email addresses redacted before send.

All processors above are contractually bound to use your data only to provide their service to us.

6. Data residency

Our primary database is hosted in Mumbai (Supabase ap-south-1). Vercel operates a global edge network; the Node.js functions that persist your data run against Mumbai. Logs shipped to Axiom are stored in Axiom's EU region.

7. Your rights under DPDP

You can, at any time:

  • Access a copy of the data we hold about you — email us.
  • Correct anything inaccurate — update it in-app or email us.
  • Erase your account and personal data — signed-in users can trigger this immediately by calling POST /api/user/delete from an authenticated session, or email us. Aggregate anonymized data (with no link to you) may be retained for accuracy benchmarking.
  • Grievance: email hello@easyborder.online. We respond within 7 working days.

8. Security

Database rows are protected by row-level security so that even if our Supabase publishable key leaked, direct database access from outside our application is blocked. All connections use TLS. We do not store payment details.

9. Changes

If we materially change this policy, we'll update the “Last updated” date at the top and, for signed-up users, notify by email before the change takes effect.

10. Contact

hello@easyborder.online

← Back to EasyBorder