Legal and service information
Privacy Policy
This Privacy Policy explains how CustomVendz and the applicable machine owner, tenant, merchant or operator may collect, use, disclose, retain and protect information connected with the CustomVendz platform, websites, applications, APIs, vending machines, payment activity, support channels and operational services.
1. Categories of information
- Account and identity information, including name, email, mobile number, user ID, organisation, assigned role and authentication records.
- Tenant, machine and operational information, including tenant identifier, machine ID, location, stock, cabin, door, motor, sensor, temperature, vend, fault and maintenance records.
- Transaction information, including product selection, amount, order reference, bank or gateway reference, payment status, vending result, reversal and refund records.
- Technical and security information, including IP address, browser, device, application version, session information, timestamps, access logs, security events and error records.
- Support and dispute information, including correspondence, complaint details, photographs, videos, screenshots and evidence voluntarily submitted by a user.
- CCTV or site-security records where separately operated, lawfully installed and relevant to security, vending disputes or machine protection.
CustomVendz support personnel will not request a UPI PIN, banking password, card PIN or one-time password intended solely for bank or payment authentication. Users must not disclose such secrets.
2. Purposes and lawful processing
Information may be processed where reasonably necessary to:
- provide and administer the requested service;
- authenticate users and enforce permissions;
- operate machines, stock, orders, vending and service systems;
- process, reconcile and investigate payments and refunds;
- investigate failed vends, product disputes, fraud, misuse, tampering, security events and unauthorised access;
- provide support and grievance redressal;
- maintain accounting, tax, audit and legal records;
- protect users, machines, tenants and platform infrastructure;
- comply with lawful directions and regulatory obligations;
- improve reliability, safety and service performance.
Where processing depends on consent, the person may withdraw that consent through the published contact channel, subject to lawful retention and processing that remains necessary for contractual, security, accounting, fraud-prevention or statutory purposes.
3. Payment providers
Banks, UPI participants, payment gateways and other authorised payment-system providers may independently process transaction data under their own legal obligations and privacy policies.
CustomVendz may retain payment references, amount, timestamps, status responses, reconciliation results and refund records. CustomVendz does not require storage of a customer’s UPI PIN, card PIN, banking password or bank-authentication OTP.
4. Sharing and processors
Information may be disclosed only where reasonably necessary to:
- the relevant tenant, merchant, seller or machine operator;
- banks, UPI participants and payment gateways;
- hosting, cloud, communications and technical providers;
- authorised support, maintenance, audit and security personnel;
- professional advisers and insurers under confidentiality duties;
- courts, regulators, law-enforcement or government authorities when disclosure is legally required or reasonably necessary to establish, exercise or defend legal rights.
Personal information is not sold to advertisers. Service providers must use information only for authorised purposes and subject to applicable contractual and legal safeguards.
5. Retention
Information is retained for periods reasonably necessary for the relevant service, transaction reconciliation, refunds, fraud prevention, machine investigation, security, accounting, tax, audit, dispute resolution and applicable legal obligations.
Retention differs by record type. Temporary machine and diagnostic records may be held for a shorter period, while transaction, accounting, security and dispute records may be retained longer. Data may also be preserved while a complaint, investigation, chargeback, legal hold or regulatory matter remains unresolved.
6. Security and incidents
Reasonable administrative, organisational and technical safeguards may include role-based access, authentication, encryption, tenant separation, audit logging, backups, monitoring and restricted support access.
No internet-connected, payment, mobile, cloud or vending-machine system can be guaranteed to be completely secure or continuously available. Users must protect credentials, use authorised devices and report suspected unauthorised access promptly.
Security incidents will be assessed and handled according to their nature, impact and applicable notification obligations.
7. Rights and requests
Subject to applicable law, a person may request access to information about processing, correction of inaccurate data, updating of incomplete data, erasure where lawful, withdrawal of consent where applicable and grievance redressal.
Identity and authority may be verified before fulfilling a request. A request may be limited or refused where disclosure would affect another person’s rights, compromise security, prejudice a fraud or legal investigation, or conflict with a lawful retention duty.
8. Cookies, sessions and device storage
Cookies, sessions or local storage may be used for authentication, security, preferences and essential platform operation. Disabling essential storage may prevent login or other functionality.
9. Children and capacity
The administrative platform is intended for authorised business users. Persons lacking legal capacity should not create or operate an account without legally valid authorisation, consent and supervision.
10. Cross-border and third-party infrastructure
Hosting, communications, payment or technical providers may process information in locations permitted by applicable law. Appropriate safeguards will be applied where legally required.
11. Policy changes and acknowledgement
This policy may be updated for service, operational, security, legal or regulatory changes. The current version and effective date will be displayed. Material changes may require renewed acknowledgement where appropriate.
12. Contact and grievance redressal
Privacy and grievance requests must be submitted through the contact information displayed on the current published policy. The requester should provide sufficient information to identify the relevant account, machine or transaction without sharing any PIN, password or OTP.