Legal and service information
Privacy Policy
This Privacy Policy explains how CustomVendz and, where applicable, the relevant machine owner, tenant, merchant, seller or operator collect, use, store, disclose and protect information connected with the CustomVendz platform, websites, applications, APIs, vending machines, payment activity, support channels, service operations and related business services.
1. Categories of information
- Account and identity information, including name, email, mobile number, user ID, organisation, assigned role, authentication information and account status.
- Tenant, machine and operational information, including tenant identifier, machine ID, machine mapping, location, stock, product, cabin, tray, slot, spiral, door, motor, sensor, temperature, vend, configuration, fault, maintenance and service records.
- Transaction information, including product selection, amount, order reference, bank or gateway reference, payment status, vending result, reversal, cancellation and refund records.
- Machine-performance and diagnostic information, including vending attempts, successful and unsuccessful vending events, event/status codes, configuration information, device communications, machine availability and diagnostic logs.
- Technical and security information, including IP address, browser, device, operating-system/application version, session details, timestamps, access logs, login history, authentication events, security events and error records.
- Policy and contractual acknowledgement records, including policy version, effective date, acknowledgement or acceptance timestamp, associated user/account information and relevant audit records.
- Support, warranty and dispute information, including correspondence, service requests, complaint details, technician findings, photographs, videos, screenshots, replacement/repair information and evidence submitted or generated in connection with support or a dispute.
- CCTV or site-security information where separately and lawfully operated and relevant to security, vending disputes, fraud investigation or protection of machines, users or property.
CustomVendz personnel will not request a UPI PIN, card PIN, banking password or one-time password intended solely for bank or payment authentication. Users must not disclose such credentials.
2. Purposes of processing
Information may be processed where permitted by applicable law and reasonably necessary to:
- provide, administer and secure the requested service;
- authenticate users and enforce roles and permissions;
- operate machines, inventory, products, trays, slots, configurations, orders, vending and service systems;
- operate and troubleshoot software, machine and payment integrations;
- process, reconcile and investigate payments, vending results, cancellations, reversals and refunds;
- determine the circumstances surrounding failed or interrupted vending transactions;
- distinguish technical faults from configuration, loading, operational, environmental, payment or other event-specific causes where reasonably possible;
- diagnose machines and determine warranty, maintenance or service requirements;
- verify machine usage, transaction activity and service history;
- investigate fraud, misuse, tampering, unauthorised access, security incidents and machine interference;
- provide technical support, training, maintenance and grievance redressal;
- maintain accounting, tax, audit, contractual, warranty and legal records;
- establish, exercise or defend contractual or legal rights and respond to complaints, chargebacks, notices, investigations or legal proceedings;
- protect users, merchants, machines, tenants, sellers and the CustomVendz platform;
- comply with applicable legal and regulatory obligations;
- analyse reliability, safety and service performance and improve the platform.
Machine or transaction information may be used together with service records, configuration information, physical inspection and other relevant evidence when investigating an operational, warranty, refund or legal dispute.
Machine logs and automated records provide technical information concerning recorded system events but do not necessarily determine by themselves the legal or technical cause of every incident.
3. Consent, notice and account acknowledgement
Where processing is based on consent, the applicable notice will identify the relevant personal data and the purposes for which it is proposed to be processed in accordance with applicable law.
Where required, users may be asked to provide an affirmative acknowledgement or consent through the website, application, login interface or another appropriate mechanism.
CustomVendz may maintain records of the notice or policy displayed, policy version, effective date, acknowledgement timestamp, account/user identifier and relevant technical audit information for the purpose of demonstrating the terms and notice applicable to a particular period of use.
Withdrawal of consent, where consent is the applicable basis for processing, may be requested using the published contact channel. Withdrawal does not require deletion or cessation of processing where continued processing or retention is otherwise required or permitted by applicable law.
4. Payment providers
Banks, UPI participants, payment gateways, merchant-acquiring providers and other authorised payment-system providers may independently process transaction information under their own terms, privacy notices and legal obligations.
CustomVendz may retain transaction references, amount, timestamps, payment status, gateway responses, reconciliation information, vending result and refund/reversal records.
CustomVendz does not require storage of a customer's UPI PIN, card PIN, banking password or bank-authentication OTP.
5. Machine, transaction and diagnostic records
CustomVendz may automatically generate and retain operational records when a connected vending machine or account is used. These may include machine activity, vending attempts, successful or unsuccessful transactions, payment responses, product or slot configuration, machine events, sensor information, faults, service events and other diagnostic information.
Such records may be used for operational support, reconciliation, technical diagnosis, warranty assessment, refund investigation, fraud prevention, service verification, dispute resolution and establishment, exercise or defence of legal rights.
Where a dispute concerns whether a machine was operational, whether a vending event occurred, the reason recorded for an event, or the period during which a machine/account remained in use, CustomVendz may preserve the relevant records subject to applicable law.
6. Support, service and warranty records
CustomVendz may maintain records of support requests, telephone or electronic correspondence, technician attendance, configuration assistance, training, inspection findings, photographs, videos, component conditions, service action and warranty decisions.
These records may be used to understand reported problems, distinguish operational or environmental conditions from technical failures, provide support and establish the history of service provided.
Warranty coverage itself is governed by the applicable invoice, warranty and service terms and not by this Privacy Policy.
7. Sharing and processors
Information may be disclosed where reasonably necessary and legally permitted to:
- the relevant tenant, merchant, seller, machine owner or authorised operator;
- banks, UPI participants, gateways and payment-service providers;
- hosting, cloud, communications, analytics and technical service providers;
- authorised support, maintenance, audit and security personnel;
- professional advisers, auditors and insurers subject to appropriate duties of confidentiality;
- courts, tribunals, regulators, law-enforcement or governmental authorities where disclosure is required or permitted by law;
- persons to whom disclosure is reasonably necessary to establish, exercise or defend legal or contractual rights.
Personal data is not sold to advertisers. Data processors and service providers must process information only for authorised purposes and in accordance with applicable contractual and legal safeguards.
8. Retention and legal holds
Information is retained only for periods reasonably necessary for the applicable purpose and subject to applicable legal requirements.
Retention periods may differ according to the type of record. Temporary diagnostic information may be retained for a shorter period, while transaction, accounting, security, warranty, service and audit records may require longer retention.
Where a complaint, warranty claim, payment dispute, chargeback, investigation, legal notice, litigation, regulatory matter or reasonably anticipated dispute exists, relevant information may be preserved while reasonably necessary for that matter and as permitted or required by law.
A request for deletion does not require CustomVendz to erase information that must or may lawfully be retained for an ongoing transaction, contractual obligation, security investigation, legal claim, statutory record-keeping duty or other permitted purpose.
9. Security and integrity of records
Reasonable technical and organisational safeguards may include role-based access control, authentication, encryption where appropriate, tenant separation, audit logging, backups, monitoring and restricted administrative or support access.
CustomVendz may maintain audit trails and integrity controls for significant operational, transaction, policy-acknowledgement and service records so that relevant historical events can be investigated.
No internet-connected, payment, mobile, cloud or vending-machine system can be guaranteed to be completely secure or continuously available. Users must protect their account credentials and report suspected unauthorised access promptly.
Personal-data breaches will be assessed and notified or otherwise handled in accordance with applicable legal requirements.
10. Rights and grievance requests
Subject to applicable law, a Data Principal may exercise rights concerning access to information about processing, correction, completion, updating, erasure, withdrawal of consent where applicable and grievance redressal.
Identity and authority may be verified before acting upon a request.
A request may be subject to lawful limitations where, for example, retention is required for an ongoing transaction, security investigation, another person's rights, fraud prevention, contractual/legal claims or a statutory obligation.
11. Cookies, sessions and device storage
Cookies, sessions, device identifiers or local storage may be used where necessary for authentication, fraud prevention, security, preferences and essential platform operation.
12. Children and authorised business users
The CustomVendz administrative and merchant platform is intended for authorised business users and is not intended to be operated independently by children.
Where personal data of a child is processed, applicable legal requirements concerning parental or lawful guardian consent and children's data will apply.
13. Cross-border and third-party infrastructure
Hosting, communications, payment or technical providers may process information in locations permitted under applicable law. Applicable restrictions and safeguards will be observed where required.
14. Policy versions and changes
This Privacy Policy may be updated for operational, technical, security, legal or regulatory reasons.
Each published version should display an effective date and, where practicable, a version identifier.
CustomVendz may preserve prior versions for contractual, compliance, audit and dispute-resolution purposes.
Material changes requiring a fresh notice, acknowledgement or consent will be handled in accordance with applicable law.
15. Relationship with other CustomVendz terms
This Privacy Policy governs the handling of personal data and related records. It does not replace the applicable:
- Terms & Conditions / Terms of Use;
- Warranty & Service Policy;
- Vending & Refund Policy;
- invoice and purchase terms;
- machine operating instructions; or
- other contractual documents applicable to a transaction.
Warranty eligibility, machine operation, operator responsibilities, repairs, replacement, paid service and refund rights are governed by those applicable contractual documents and applicable law.
16. Contact and grievance redressal
Privacy and data-related grievance requests may be submitted through the contact information published with this policy.
Requests should contain sufficient information to identify the relevant account, machine or transaction. Users must never provide a UPI PIN, banking password, card PIN or bank-authentication OTP.