Security & Compliance
Your data is protected by bank-grade security.
We treat your financial data with the same rigor as banks treat yours. Strong encryption at every layer, and data protection practices built around Indian and global standards.
Security by the numbers
Encryption at rest
Encryption in transit
Audit
Data storage region
Security architecture
Six layers of protection for every byte.
From the wire to the disk, from the browser to the database — your data never exists in a vulnerable state.
Encryption at Rest
AES-256 encryption for every sign-in token we store. Industry-standard encryption with a unique key per record.
Encryption in Transit
TLS 1.3 for every connection between your browser, our servers, and the platform. No data crosses the wire unencrypted.
OAuth 2.0 Only
We never store your platform passwords. Sign-in tokens are limited in scope and you can disconnect anytime.
Multi-Tenant Isolation
Every table and every query is scoped to your company. One seller's data is never mixed with another's.
Access Control
JWT-based authentication on every request. Passwords are hashed with BCrypt, never stored in plain text.
Compliance
Certifications and regulations we follow.
Data protection principles we build around today, and formal certifications we're working toward.
Data Residency
All data is stored in Microsoft Azure's Central India region (Pune). No cross-border data transfer without your consent.
DPDP Act 2023
Built with the principles of India's Digital Personal Data Protection Act in mind — you can request access to or deletion of your data anytime.
GDPR-Aligned Principles
Right to access, rectification, erasure, and data portability guide how we handle your data.
SOC 2 Type II
A formal, independently audited report on our security controls.
ISO 27001
Information security management system aligned with ISO 27001 standards.
Data sovereignty
Your data never leaves India.
All databases, backups, and processing run in Microsoft Azure's Central India region (Pune). No cross-border data transfer without your explicit consent. Your financial data stays under Indian jurisdiction, governed by Indian law.
Start free — data stays in IndiaOperations & transparency
Straightforward security, transparent data handling.
We'd rather tell you exactly what's true today than promise more than we've built.
Security Practices
What we do today to keep your data safe.
What we collect
Marketplace order data (orders, fees, returns, ad campaigns) · Product information (SKUs, titles, prices, categories) · Your business details (company name, GSTIN, email) · Aggregate usage analytics (page views, feature usage)
What we never store
Platform passwords (we use sign-in tokens only) · Payment card details (processed by Razorpay) · Your customers' personal information beyond what's needed for order data · Data after you delete your account (30-day grace period, then permanent deletion)
Your rights
Access all your data anytime via dashboard or API · Export your data in CSV, JSON, or PDF formats · Request complete deletion of your account and data · Opt out of analytics and marketing communications
Found a vulnerability?
Email security@sellerbooks.in — we take every report seriously and will respond as quickly as we can.
Security questions?
Reach out at security@sellerbooks.in — happy to walk through how your data is handled.