TechAge Systems (“TechAge”, “we”, “us”, “our”) operates the TechTrade ERP platform and an integrated WhatsApp Business messaging service (together, the “Service”). This Privacy Policy explains how we collect, use, store and share information. By using the Service, you agree to the practices described here.
1. Introduction
TechAge Systems is an ERP and billing software provider for retail, wholesale and distribution businesses in India — for example tile and sanitaryware showrooms, hardware stores, supermarkets and distributors. We have served Indian SMBs for over 20 years.
This policy covers both parts of our Service: (a) our ERP / billing software, and (b) our WhatsApp Business Platform integration, which lets our merchant customers send transactional messages to their own customers directly from the ERP.
2. Scope & our role
It is important to understand the two distinct roles involved, because they determine who is responsible for personal data.
- TechAge as a Technology Provider (data processor). We provide the technology that enables our merchant customers — businesses such as retail, tile, hardware and wholesale shops — to send transactional messages (invoices, order confirmations, shipment/delivery updates and similar service notifications) to their own customers, via the merchant's own connected WhatsApp Business number. When we process end-customer data for this purpose, we act on the merchant's documented instructions.
- The merchant as the data controller. The merchant decides why and how their customers' data is used and is the data controller for that data. TechAge processes it on the merchant's behalf as a processor. The merchant is responsible for having a lawful basis and for obtaining any required consent or opt-in from their customers before messaging them.
For our direct relationship with the merchant (their account, billing and login information), TechAge is the controller.
3. Information we collect
3.1 From merchants (our business customers)
- Business name, GST number, address and contact details
- Names, email addresses and phone numbers of authorised users
- Login credentials (passwords are stored only as salted hashes)
- WhatsApp Business Account (WABA) ID and Phone Number ID, obtained via Meta's Embedded Signup
- Access tokens issued by Meta for sending messages on behalf of the merchant's business
- Billing and payment information
3.2 From merchants' end-customers (processed on the merchant's behalf)
- Customer phone number and name (provided by the merchant)
- The message, order and invoice content necessary to deliver the WhatsApp message (for example the invoice amount, order number or shipment details)
- Delivery status and inbound replies returned via the WhatsApp Business Platform
- Media files (such as invoice PDFs) uploaded by the merchant for delivery
3.3 Technical data
- Log data and API request logs (endpoint, timestamp, API key identifier)
- Message delivery and read receipts and their timestamps
- IP address and basic device/browser information
- Error and diagnostic logs used for troubleshooting
4. How we use information
We use the information collected only to operate and support the Service:
- To deliver WhatsApp messages (invoices, order confirmations, shipment updates) on the merchant's behalf
- To provide, maintain and secure the ERP and billing service
- To maintain message delivery logs so merchants can confirm what was sent and delivered
- To authenticate users, prevent fraud and abuse, and provide customer support
- To comply with legal and regulatory obligations
We do not sell personal data, and we do not use WhatsApp data for advertising, ad targeting, or building profiles for marketing.
5. Use of the Meta / WhatsApp Business Platform
Our WhatsApp integration is built on the WhatsApp Business Platform (Cloud API) provided by Meta Platforms, Inc.
- Our use and transfer of information received from Meta APIs to any other app adheres to the Meta Platform Terms and Developer Policies, including the Limited Use requirements.
- We use the WhatsApp Business Platform (Cloud API) solely to send the messages that merchants initiate, and to receive the related delivery status and replies.
- Message delivery is also subject to WhatsApp's own terms and privacy policy. See the WhatsApp Business Policy and the Meta Privacy Policy.
- Access tokens issued by Meta are stored securely and used only to send messages from the merchant's connected WhatsApp Business number.
6. How we share information
We do not sell or rent personal information, and we do not share it with unrelated third parties for their own marketing. We share information only in these limited cases:
- With Meta / WhatsApp — as the messaging platform, we transmit the recipient phone number, message content and metadata required to deliver each WhatsApp message.
- With hosting and infrastructure sub-processors — our servers and databases are hosted with our infrastructure providers strictly to run the Service.
- Where required by law — to comply with applicable law, a valid court order or a lawful government request.
- Business transfers — in a merger, acquisition or sale, data may transfer to the successor entity under this same policy.
7. Data retention
We keep personal data only as long as needed for the purposes above:
- Message and delivery logs: retained for 90 days for delivery troubleshooting and audit, then deleted or anonymised.
- Uploaded media (PDFs, images): retained for 30 days after sending, then automatically deleted.
- Merchant account data: retained for the duration of the contract plus up to one year for legal and audit purposes.
- Access tokens: retained until revoked by the merchant or expired by Meta.
Data is deleted when it is no longer needed, or earlier on request (see Your rights & data deletion).
8. Data security
- Encryption in transit using HTTPS/TLS for all web, API and webhook traffic
- Access controls and role-based permissions; database access restricted to authorised personnel
- Secure, encrypted storage of access tokens and credentials at rest
- Verification of webhook payloads received from Meta, and regular security patching
No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work continuously to protect your data.
9. Your rights & data deletion
Merchants and end-customers can request access to, correction of, or deletion of their personal data, and can object to or restrict certain processing.
Data deletion requests. To request deletion of your data, email techageindia@gmail.com with the subject “Data Deletion Request” and the phone number or account the request relates to. We will verify and action verified requests within 30 days, subject to any legal retention obligations. End-customers may also ask the relevant merchant, who can trigger deletion through us.
End-customers receiving WhatsApp messages can opt out at any time by replying STOP; the merchant is responsible for honouring opt-outs under WhatsApp Business Platform policies.
If you are in India, you have rights under the Digital Personal Data Protection Act, 2023 (DPDP Act), including the right to access, correction, erasure and grievance redressal. You may exercise these rights, or escalate a complaint, using the Grievance Officer details below.
10. International data transfers
Our servers are primarily located in India. However, because messaging runs on the WhatsApp Business Platform, some data may be processed on Meta's infrastructure and on servers located outside India. Where data is transferred internationally, we rely on appropriate safeguards and require that it remains protected consistent with this policy.
11. Cookies
Our website uses a small number of cookies and similar technologies: strictly necessary cookies to keep you signed in and secure, and basic analytics to understand aggregate site usage and improve the site. You can control cookies through your browser settings; disabling non-essential cookies will not block access to this policy or other public pages. We do not use cookies to build advertising profiles.
12. Children's privacy
The Service is intended for businesses and is not directed to children under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes we will revise the “Last updated” date at the top of this page and, where appropriate, notify merchants by email. The “Last updated” date always reflects the most recent changes. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
14. Grievance Officer & contact
In line with India's DPDP Act and applicable IT rules, you can contact our Grievance Officer for any privacy question, request or complaint. We aim to acknowledge grievances promptly and resolve them within the timelines required by law.