Privacy Policy

This Privacy Policy explains how CustomVendz and the applicable machine owner, tenant, merchant or operator may collect, use, disclose, retain and protect information connected with the CustomVendz platform, websites, applications, APIs, vending machines, payment activity, support channels and operational services.

1. Categories of information

CustomVendz support personnel will not request a UPI PIN, banking password, card PIN or one-time password intended solely for bank or payment authentication. Users must not disclose such secrets.

2. Purposes and lawful processing

Information may be processed where reasonably necessary to:

Where processing depends on consent, the person may withdraw that consent through the published contact channel, subject to lawful retention and processing that remains necessary for contractual, security, accounting, fraud-prevention or statutory purposes.

3. Payment providers

Banks, UPI participants, payment gateways and other authorised payment-system providers may independently process transaction data under their own legal obligations and privacy policies.

CustomVendz may retain payment references, amount, timestamps, status responses, reconciliation results and refund records. CustomVendz does not require storage of a customer’s UPI PIN, card PIN, banking password or bank-authentication OTP.

4. Sharing and processors

Information may be disclosed only where reasonably necessary to:

Personal information is not sold to advertisers. Service providers must use information only for authorised purposes and subject to applicable contractual and legal safeguards.

5. Retention

Information is retained for periods reasonably necessary for the relevant service, transaction reconciliation, refunds, fraud prevention, machine investigation, security, accounting, tax, audit, dispute resolution and applicable legal obligations.

Retention differs by record type. Temporary machine and diagnostic records may be held for a shorter period, while transaction, accounting, security and dispute records may be retained longer. Data may also be preserved while a complaint, investigation, chargeback, legal hold or regulatory matter remains unresolved.

6. Security and incidents

Reasonable administrative, organisational and technical safeguards may include role-based access, authentication, encryption, tenant separation, audit logging, backups, monitoring and restricted support access.

No internet-connected, payment, mobile, cloud or vending-machine system can be guaranteed to be completely secure or continuously available. Users must protect credentials, use authorised devices and report suspected unauthorised access promptly.

Security incidents will be assessed and handled according to their nature, impact and applicable notification obligations.

7. Rights and requests

Subject to applicable law, a person may request access to information about processing, correction of inaccurate data, updating of incomplete data, erasure where lawful, withdrawal of consent where applicable and grievance redressal.

Identity and authority may be verified before fulfilling a request. A request may be limited or refused where disclosure would affect another person’s rights, compromise security, prejudice a fraud or legal investigation, or conflict with a lawful retention duty.

8. Cookies, sessions and device storage

Cookies, sessions or local storage may be used for authentication, security, preferences and essential platform operation. Disabling essential storage may prevent login or other functionality.

9. Children and capacity

The administrative platform is intended for authorised business users. Persons lacking legal capacity should not create or operate an account without legally valid authorisation, consent and supervision.

10. Cross-border and third-party infrastructure

Hosting, communications, payment or technical providers may process information in locations permitted by applicable law. Appropriate safeguards will be applied where legally required.

11. Policy changes and acknowledgement

This policy may be updated for service, operational, security, legal or regulatory changes. The current version and effective date will be displayed. Material changes may require renewed acknowledgement where appropriate.

12. Contact and grievance redressal

Privacy and grievance requests must be submitted through the contact information displayed on the current published policy. The requester should provide sufficient information to identify the relevant account, machine or transaction without sharing any PIN, password or OTP.