Privacy Policy
How HeyMachi handles personal data of customers, merchants and their staff, delivery riders and website visitors — what we collect, why, how long we keep it, who we share it with, and how you can exercise your rights.
How HeyMachi handles personal data of customers, merchants and their staff, delivery riders and website visitors — what we collect, why, how long we keep it, who we share it with, and how you can exercise your rights.
This Privacy Policy explains how Hey Machi AI Private Limited, a private limited company incorporated under the Companies Act, 2013, CIN U62010TZ2026PTC040753, registered office at 5/185-1, Munnar Road, Pallapalayam, Udumalpet, Tiruppur, Tamil Nadu 642112, India (“HeyMachi”, “we”, “us”), handles personal data in connection with the HeyMachi platform: the HM Business merchant app (app.heymachi.ai), the HeyMachi customer app on Android, iOS and the web (app-cust.heymachi.ai), merchant storefronts and QR table ordering pages powered by HeyMachi, and our website heymachi.ai (together, the “Platform”). HeyMachi is a brand of Hey Machi AI Private Limited.
We comply with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), and we are preparing for full compliance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”). Terms such as “Data Fiduciary”, “Data Processor”, “Data Principal” and “consent” have the meanings given in the DPDP Act.
This Policy covers four groups of people:
This Policy should be read with our Merchant Terms of Service and Customer Terms of Use.
| Question | Short answer |
|---|---|
| Who is responsible? | It depends on the data. The merchant you buy from is responsible for its own customer, staff and supplier records; we process those records for the merchant. We are responsible for your HeyMachi customer-app account, the HeyMachi network identity, the loyalty network, merchant accounts, our website and platform security logs. See Section 3. |
| What do we collect? | Mobile number, name and account details; orders, bookings and payment status (not card numbers or UPI PIN); addresses and, if you allow it, your location while using the app; reviews and messages; device and security logs. See Section 4. |
| Why? | To run your account and orders, keep the Platform secure, meet legal duties, and, only if you agree, for marketing and loyalty network features. See Section 5. |
| Do we sell your data? | No. We do not sell personal data or use it for third-party advertising. |
| AI? | Merchants can use our AI assistant “Machi” and document scanning, which send limited business data to AI providers in the United States under terms that prohibit training on it. See Section 7. |
| Where is it stored? | Main servers and databases in Bengaluru, India. Some backups and service providers are outside India. See Section 9. |
| How long? | Only as long as needed or required by law. See Section 10. |
| Your rights | Access, correction, erasure, withdrawal of consent, grievance redressal and nomination. Delete your account at heymachi.ai/delete-account. See Section 12. |
| Children | No accounts for anyone under 18. See Section 6. |
| Cookies | We do not use cookies or third-party analytics. The apps use your browser’s local storage to keep you signed in. See Section 13. |
| Contact | Grievance Officer: Balachandar G, Director, sales@heymachi.ai. See Section 14. |
When we act for a merchant (Data Processor). Each merchant using HeyMachi decides what it records about its own customers, employees, patients and suppliers and why. For that data the merchant is the Data Fiduciary and we are its Data Processor. We process it only on the merchant’s instructions under our Data Processing Addendum (available to merchants in the HM Business app and on request), and we do not use it for our own purposes. If you are a customer or employee of a merchant and want to access, correct or erase what the merchant holds about you, please contact that merchant. If you contact us, we will pass your request to the merchant promptly and help the merchant respond.
When we act for ourselves (Data Fiduciary). We decide the purposes and means, and are responsible, for:
| Data | Merchant | HeyMachi |
|---|---|---|
| Order, bill, booking and invoice records kept by the merchant | Data Fiduciary | Data Processor |
| Merchant’s own customer record (name, birthday, anniversary, notes, tier) | Data Fiduciary | Data Processor |
| Merchant’s employee, payroll, attendance and HR records | Data Fiduciary | Data Processor |
| Clinic appointments and consultation notes | Data Fiduciary | Data Processor |
| Merchant–customer chat and WhatsApp inbox | Data Fiduciary | Data Processor |
| Rider live location during a delivery | Data Fiduciary | Data Processor |
| Customer-app account and network identity | — | Data Fiduciary |
| Loyalty network membership, points ledger, fraud signals | Joint, as set out in the Loyalty Network Programme Terms | Data Fiduciary |
| Published reviews and moderation | Receives and replies | Data Fiduciary |
| Merchant account, users, KYC, billing | — | Data Fiduciary |
| Platform security and audit logs; website enquiries | — | Data Fiduciary |
| Category | Examples | Source | Our role |
|---|---|---|---|
| Account and identity | Mobile number, name or display name, email (optional), profile photo (optional), verification status, hashed OTP, consent choices | You | Fiduciary |
| Addresses and location | Saved delivery addresses with map pin (latitude and longitude); your device location while you use the app, if you allow it, to show nearby merchants and set a delivery pin | You, your device | Fiduciary (account); Processor (on an order) |
| Orders and bookings | Items, amounts, taxes, fees, merchant, time, order type, table number, delivery address, delivery notes, cancellation reason, booking time and service | You, merchant | Processor |
| Payments | Payment status, amount, method type, payment and refund reference IDs. We do not receive card numbers, CVV or UPI PIN | Payment provider | Processor (merchant payment); Fiduciary (platform fee) |
| Delivery | Rider position during your delivery, encrypted delivery PIN, handover photo of the package | Rider, merchant | Processor |
| Reviews | Rating, title, text, photos, display name, merchant reply, review-invite records (mobile number, WhatsApp message ID) | You, merchant | Fiduciary |
| Messages | Chats with merchants in the app or on WhatsApp, “call waiter” requests, appointment reminders | You, merchant | Processor |
| Loyalty network (if joined) | Membership, tier, points earned and redeemed, merchants visited, device ID, risk score, fraud flags, disputes | You, merchants, our systems | Fiduciary |
| Device and security | Session and device information (model, OS, app version), IP address, login times, security events | Your device | Fiduciary |
| QR table diners | Display name, table number, order, optional mobile number | You | Processor |
A merchant may also record information about you at its own counter, such as your birthday, anniversary, gender, preferences, notes, or business name and GSTIN for a B2B invoice. That is the merchant’s record, handled by us as its processor.
| Category | Examples |
|---|---|
| Business and KYC | Business and branch names and addresses, GSTIN, FSSAI licence number, PAN, bank account and IFSC (stored as a hash for verification where possible), UPI ID, founder’s phone number, registered address and location, logo |
| User account | Username, name, email, phone, photo, role and permissions |
| Security | Password (bcrypt hash), POS PIN (hash), two-factor authentication secret and backup codes (encrypted), sessions with IP address, user agent and device, audit log of actions |
| Payment gateway | The merchant’s own payment gateway API keys, encrypted |
| Support and billing | Support tickets and messages, subscription plan and billing records |
| AI assistant | Prompts and responses in conversations with Machi |
Our platform administrators can, for support purposes and only with a time-limited (30-minute) authorisation, access a merchant account as if they were a merchant user. Every such access is logged and is subject to the controls in our Merchant Terms of Service.
| Category | Examples |
|---|---|
| Account | Name, mobile number, merchant you ride for, hashed OTP, sessions |
| Location | GPS position sent about every 10 seconds only while you have an active delivery assigned and the rider screen is open; stops when the delivery is completed or cancelled |
| Delivery records | Assigned orders, pickup and handover times, handover photos, delivery PIN verification result |
The merchant that engages you is the Data Fiduciary for your delivery data and must give you a notice about location tracking. Rider location is shown to the customer only during that customer’s active delivery.
| Category | Examples |
|---|---|
| Contact and demo requests | Name, business name, phone, email, city and message. The form is delivered to us through Web3Forms, a form-processing service |
| Technical | IP address and request logs kept by our hosting provider (Vercel) for security and operation |
| “Powered by HeyMachi” link | When you click that link on a merchant page, we count the click with coarse device type, operating system and browser only; no identifier is stored |
We use personal data for which we are the Data Fiduciary only for the purposes below. Where we rely on consent, you can withdraw it at any time (Section 12); withdrawal does not affect processing already done.
| Purpose | Data used | Basis under the DPDP Act |
|---|---|---|
| Create and secure your account; sign you in by OTP | Mobile number, OTP, device and session data | Consent at sign-up (s.6); security is also a use for which you voluntarily provide the data (s.7(a)) |
| Let you order, book, pay and track with any merchant; pass your order details to the merchant | Account, address, order data | Consent at sign-up; s.7(a) for each order you place |
| Show merchants near you | Device location (while using the app, if allowed) or a location you enter | Consent via device permission |
| Send service messages (OTPs, confirmations, status updates, bills) | Mobile number, order data | Consent at sign-up; s.7(a) |
| Publish and moderate reviews | Review, display name, order verification | Consent at review submission |
| Run the loyalty network | Membership, ledger, merchants visited, device and fraud signals | Separate consent when you join |
| Run the network identity: recognise you at businesses you visit, show your name to a business that enters your number, and pre-fill your profile | Mobile number, name, and details recorded by businesses you have visited | Consent when you give your number to a business or sign up, with notice shown at that time |
| Marketing messages from HeyMachi or merchants | Mobile number, email, preferences | Separate, optional consent |
| Prevent fraud and abuse; secure the Platform; keep logs | Device, IP, session, ledger and security data | Consent at sign-up; legal obligations (CERT-In Directions, DPDP Rules log retention) under s.7(c) |
| Merchant account, KYC, billing and support | Merchant user and business data | Contract with the merchant; consent of individual users; legal obligations (KYC, tax) |
| Comply with law, court orders and lawful requests; establish or defend legal claims | As relevant | s.7(c) to (e) and s.17 exemptions as applicable |
| Respond to website enquiries | Contact form data | s.7(a): you voluntarily provided it for this purpose |
We do not use personal data for automated decisions that produce legal or similarly significant effects on you. The loyalty network uses automated risk scores to detect points fraud; a flagged transaction is held for review by a person, and you can dispute it.
Machi, the merchant AI assistant. Merchants can ask Machi questions about their business, and Machi can read and, where the merchant allows, update records such as sales, products, customers, employees, attendance, leave and salaries. To answer, Machi sends the merchant’s question and the relevant records to a third-party AI model provider, currently OpenAI or Anthropic, as chosen for the merchant. This may include customer names, phone numbers, purchase history and employee details.
Document scanning. Merchants can photograph supplier bills, invoices and menus. These images are sent to OpenAI’s vision model to extract text, or processed on our own servers with open-source OCR software.
Our commitments. We use AI providers only under business terms that:
We send only the records needed to answer the request, and, where technically feasible, we mask sensitive identifiers such as Aadhaar, PAN, bank account numbers and health information before sending. AI output may be inaccurate; merchants must check it before relying on it.
Stored conversations. Machi conversations are stored in the merchant’s account so the merchant can review them. Voice input is converted to text on the merchant’s device.
Model improvement. We may use samples of Machi requests to improve Machi only after removing all personal data and merchant-identifying information so that they are no longer personal data. We do not use customers’ data from merchant records to train any AI model.
We do not use AI to detect emotion or sentiment, to profile customers, or to make decisions about individuals.
We share personal data only as follows:
| Category | Provider | Location |
|---|---|---|
| Cloud hosting, database, file storage, backups | DigitalOcean | India (Bengaluru); backups in India or Singapore |
| SMS and WhatsApp messaging, OTP delivery | MSG91 (via DLT-registered operators); Meta (WhatsApp Business Platform) | India; WhatsApp global |
| Payments | Razorpay (RBI-authorised payment aggregator) | India |
| AI model providers | OpenAI; Anthropic | United States |
| Error monitoring | Sentry | United States or EU |
| Website hosting | Vercel | Global edge network |
| Website contact form | Web3Forms | Outside India |
| Uptime monitoring and internal alerts | UptimeRobot; Slack | United States |
| Maps | OpenStreetMap tile servers (your IP address and requested area); Google or Apple device geocoding services | Various |
| Code hosting and build (no production personal data) | GitHub; Firebase App Distribution (test builds for testers only) | United States |
Payments you make to a merchant for an order are processed by an RBI-authorised payment aggregator and settled to the merchant’s bank account. HeyMachi does not receive or hold customer payments for orders.
Our main servers and databases are in India. Some sub-processors in Section 8 process data outside India, in particular AI providers in the United States and backup storage, which may be in Singapore. Under Section 16 of the DPDP Act, transfers are permitted except to countries the Central Government restricts by notification. We transfer only what is needed, under contracts with appropriate protections, and we will stop transfers to any restricted country.
| Data | Retention (HeyMachi as Data Fiduciary) |
|---|---|
| Customer-app account, profile, saved addresses, favourites | Until you delete your account; then deleted or anonymised within 30 days (backups roll off within a further 30 days) |
| Inactive customer accounts | Deleted after 3 years of inactivity, with at least 48 hours’ notice before deletion |
| OTPs (hashed) | Until verified or expired (10 minutes); attempt logs are kept as security logs |
| Reviews | While published; after you delete a review or your account, anonymised text is kept only if you choose, otherwise deleted |
| Loyalty network ledger | While you are a member, then 8 years for financial and tax records |
| Platform fee and HeyMachi invoices | 8 years (Companies Act s.128 and CGST Act s.36 record-keeping) |
| Consent records | For as long as the consent is relied on, plus 7 years to prove it |
| Security and audit logs | At least 180 days in India (CERT-In Directions) and at least one year (DPDP Rules); then deleted |
| Merchant account and KYC | For the life of the account plus 8 years, or longer if required by law or an open dispute |
| Website enquiries | 12 months after the last contact, unless you become a merchant |
| Database backups | Rolling 30 days, encrypted |
Data we process for a merchant is kept according to the merchant’s instructions and settings. When a merchant leaves HeyMachi we return or delete its data within 90 days, except where law requires us to keep it.
We use reasonable security practices modelled on ISO/IEC 27001, including: encryption in transit (TLS); encryption of backups (AES-256) and of secrets such as payment gateway keys and delivery PINs; database row-level security separating each merchant’s data; hashed passwords, PINs and OTPs; optional two-factor authentication for merchant users; role-based access; logged and time-limited administrator access; and monitoring.
No system is perfectly secure. If a personal data breach affects you, we will inform you and the Data Protection Board of India as the DPDP Act and DPDP Rules require, and we report cyber security incidents to CERT-In within six hours. Where the breach concerns data we process for a merchant, we will inform the merchant without undue delay so that it can notify you.
For data for which we are the Data Fiduciary, you have the right to:
How. Email sales@heymachi.ai, or write to the Grievance Officer. To delete your account, follow the steps at heymachi.ai/delete-account. We will verify your identity by OTP to your registered mobile number.
Timeline. We will acknowledge your request within 48 hours and respond within 30 days, and in any case within the period prescribed under the DPDP Rules.
Merchant data. For records a merchant holds about you, contact the merchant. You can also send the request through the app; we will forward it to every merchant you have transacted with and tell you which merchants we forwarded it to.
Complaints to the Data Protection Board. If you are not satisfied with our response, you may complain to the Data Protection Board of India, in the manner the Board prescribes, after first using our grievance process.
We do not use cookies for advertising or analytics on heymachi.ai or in our apps, and we do not use third-party analytics or advertising SDKs. The customer and merchant web apps use your browser’s local storage to keep you signed in and to remember your cart, language and settings. This is strictly necessary for the service. Signing out clears your sign-in data; you can clear the rest in your browser settings.
The mobile apps may ask for these device permissions, each only when you use the related feature:
You can change permissions in your device settings.
| Details | |
|---|---|
| Grievance Officer | Balachandar G, Director |
| Address | Hey Machi AI Private Limited, 5/185-1, Munnar Road, Pallapalayam, Udumalpet, Tiruppur, Tamil Nadu 642112, India |
| sales@heymachi.ai (privacy requests: sales@heymachi.ai) | |
| Phone | +91 70100 43040 |
| Response | Acknowledgement within 24 hours; resolution within 15 days for Platform and content grievances, and within one month for consumer complaints |
More ways to reach us are on our Contact and Grievance Officer page.
We will post any change on this page with a new effective date and, for material changes, notify you in the app or by message before the change takes effect. Where a change requires fresh consent, we will ask for it.