Legal
Privacy policy
Last updated
1. Who we are
The Services are operated by Yalee Network Company, a sole proprietorship of Vijay Anandh Palaniammal (registered under GST as Palaniammal V), registered as an MSME under Udyam registration number UDYAM-TN-03-0214547, GSTIN 33AXDPP5691A1ZM, with its registered office at 471, Cross Cut Road, Ponnaian Street (near State Bank of India), Coimbatore, Tamil Nadu 641012, India. Under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), Yalee is the Data Fiduciary for personal data processed through the Services. Questions about this policy: yaleeprivacy@yalee.net.
2. What we collect
Account details: name, email address, mobile number, password (stored only as a secure hash) and two-step verification settings.
Orders and payments: what you bought or subscribed to, amounts, invoices, delivery address and phone number for physical orders, and the payment reference and status we receive from Razorpay. Card numbers, CVV, UPI PIN and bank credentials are entered on Razorpay's secure pages and are never received or stored by us.
Use of the Services: pages and content viewed, watch progress, preferences, device and browser type, IP address, approximate location derived from it, and logs needed for security and troubleshooting.
What you send us: enquiries, support requests, reviews, uploaded content and job applications.
3. Why we use it
To provide the Services you ask for (your account, subscriptions, orders, delivery, invoices and customer support) and to process payments and refunds.
To keep the Services secure and prevent fraud and abuse, and to comply with law (for example GST and tax records, and lawful requests from authorities).
To personalise recommendations within Yalee and run Yalee Coin rewards, and, only with your consent (which you can withdraw at any time), to send marketing messages.
We process personal data on the basis of your consent or for the legitimate uses permitted by Section 7 of the DPDP Act (such as completing a purchase you asked for, or complying with law).
4. Who we share it with
Payment processing: Razorpay Software Private Limited, our payment partner, which handles card and bank details on its own secure, PCI-DSS compliant systems.
Order fulfilment: LeeMart sellers and courier partners receive the name, address and phone number needed to deliver your order.
Service providers acting on our instructions under contract: cloud hosting in India (Microsoft Azure, Central India region), email delivery and customer-support tools.
Authorities, where required by law or a valid legal order.
We do not sell personal data, and we do not share it with advertisers to profile you across other websites.
5. Where it is stored
Your data is stored on servers in India. If a service provider needs to process data outside India, we do so only to countries not restricted by the Government of India under the DPDP Act, with appropriate safeguards.
6. How long we keep it
Account data is kept while your account is open and deleted or anonymised within 90 days after you close it, except where the law requires us to keep it, for example invoices and payment records, which tax laws require us to keep for up to eight years. Security logs are kept for up to one year.
7. Children
The Services are not directed at children under 18 to sign up on their own. We process a child's personal data only with the verifiable consent of a parent or guardian, and we do not track, profile or target advertising at children.
8. Your rights
You can ask to access a summary of your personal data, correct or update it, erase it (where we are not required to keep it), withdraw consent, and nominate someone to exercise these rights on your behalf if you are unable to. Write to yaleeprivacy@yalee.net from the email address on your account; we respond within 30 days.
If you are not satisfied, contact Vijay Anandh Palaniammal, Proprietor (see the Grievance redressal page). You may then complain to the Data Protection Board of India.
9. Security
We use encryption in transit (HTTPS) and at rest, two-step verification for staff, access limited to people who need it, logging and regular security testing. If a personal data breach affects you, we will inform you and the Data Protection Board as the law requires.
10. Cookies
We use only cookies that are strictly necessary for sign-in, security and checkout. See the Cookie policy.
11. Changes
We will post changes to this policy here with a new date, and tell account holders about material changes before they take effect.
