All policies
Legal

Privacy Policy

How HeyMachi handles personal data of customers, merchants and their staff, delivery riders and website visitors — what we collect, why, how long we keep it, who we share it with, and how you can exercise your rights.

1. About this Policy

This Privacy Policy explains how Hey Machi AI Private Limited, a private limited company incorporated under the Companies Act, 2013, CIN U62010TZ2026PTC040753, registered office at 5/185-1, Munnar Road, Pallapalayam, Udumalpet, Tiruppur, Tamil Nadu 642112, India (“HeyMachi”, “we”, “us”), handles personal data in connection with the HeyMachi platform: the HM Business merchant app (app.heymachi.ai), the HeyMachi customer app on Android, iOS and the web (app-cust.heymachi.ai), merchant storefronts and QR table ordering pages powered by HeyMachi, and our website heymachi.ai (together, the “Platform”). HeyMachi is a brand of Hey Machi AI Private Limited.

We comply with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), and we are preparing for full compliance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”). Terms such as “Data Fiduciary”, “Data Processor”, “Data Principal” and “consent” have the meanings given in the DPDP Act.

This Policy covers four groups of people:

This Policy should be read with our Merchant Terms of Service and Customer Terms of Use.

2. Summary

3. Our two roles: processor for merchants, fiduciary for our own services

When we act for a merchant (Data Processor). Each merchant using HeyMachi decides what it records about its own customers, employees, patients and suppliers and why. For that data the merchant is the Data Fiduciary and we are its Data Processor. We process it only on the merchant’s instructions under our Data Processing Addendum (available to merchants in the HM Business app and on request), and we do not use it for our own purposes. If you are a customer or employee of a merchant and want to access, correct or erase what the merchant holds about you, please contact that merchant. If you contact us, we will pass your request to the merchant promptly and help the merchant respond.

When we act for ourselves (Data Fiduciary). We decide the purposes and means, and are responsible, for:

4. Personal data we handle

A merchant may also record information about you at its own counter, such as your birthday, anniversary, gender, preferences, notes, or business name and GSTIN for a B2B invoice. That is the merchant’s record, handled by us as its processor.

Our platform administrators can, for support purposes and only with a time-limited (30-minute) authorisation, access a merchant account as if they were a merchant user. Every such access is logged and is subject to the controls in our Merchant Terms of Service.

The merchant that engages you is the Data Fiduciary for your delivery data and must give you a notice about location tracking. Rider location is shown to the customer only during that customer’s active delivery.

5. Why we use personal data and on what basis

We use personal data for which we are the Data Fiduciary only for the purposes below. Where we rely on consent, you can withdraw it at any time (Section 12); withdrawal does not affect processing already done.

We do not use personal data for automated decisions that produce legal or similarly significant effects on you. The loyalty network uses automated risk scores to detect points fraud; a flagged transaction is held for review by a person, and you can dispute it.

6. Children

7. Artificial intelligence features

Machi, the merchant AI assistant. Merchants can ask Machi questions about their business, and Machi can read and, where the merchant allows, update records such as sales, products, customers, employees, attendance, leave and salaries. To answer, Machi sends the merchant’s question and the relevant records to a third-party AI model provider, currently OpenAI or Anthropic, as chosen for the merchant. This may include customer names, phone numbers, purchase history and employee details.

Document scanning. Merchants can photograph supplier bills, invoices and menus. These images are sent to OpenAI’s vision model to extract text, or processed on our own servers with open-source OCR software.

Our commitments. We use AI providers only under business terms that:

  1. prohibit the provider from using the data to train its models;
  2. limit the provider’s retention of the data to no more than 30 days, for abuse monitoring; and
  3. require security at least equal to ours.

We send only the records needed to answer the request, and, where technically feasible, we mask sensitive identifiers such as Aadhaar, PAN, bank account numbers and health information before sending. AI output may be inaccurate; merchants must check it before relying on it.

Stored conversations. Machi conversations are stored in the merchant’s account so the merchant can review them. Voice input is converted to text on the merchant’s device.

Model improvement. We may use samples of Machi requests to improve Machi only after removing all personal data and merchant-identifying information so that they are no longer personal data. We do not use customers’ data from merchant records to train any AI model.

We do not use AI to detect emotion or sentiment, to profile customers, or to make decisions about individuals.

8. Sharing and sub-processors

We share personal data only as follows:

Payments you make to a merchant for an order are processed by an RBI-authorised payment aggregator and settled to the merchant’s bank account. HeyMachi does not receive or hold customer payments for orders.

9. Transfers outside India

Our main servers and databases are in India. Some sub-processors in Section 8 process data outside India, in particular AI providers in the United States and backup storage, which may be in Singapore. Under Section 16 of the DPDP Act, transfers are permitted except to countries the Central Government restricts by notification. We transfer only what is needed, under contracts with appropriate protections, and we will stop transfers to any restricted country.

10. How long we keep personal data

Data we process for a merchant is kept according to the merchant’s instructions and settings. When a merchant leaves HeyMachi we return or delete its data within 90 days, except where law requires us to keep it.

11. Security

We use reasonable security practices modelled on ISO/IEC 27001, including: encryption in transit (TLS); encryption of backups (AES-256) and of secrets such as payment gateway keys and delivery PINs; database row-level security separating each merchant’s data; hashed passwords, PINs and OTPs; optional two-factor authentication for merchant users; role-based access; logged and time-limited administrator access; and monitoring.

No system is perfectly secure. If a personal data breach affects you, we will inform you and the Data Protection Board of India as the DPDP Act and DPDP Rules require, and we report cyber security incidents to CERT-In within six hours. Where the breach concerns data we process for a merchant, we will inform the merchant without undue delay so that it can notify you.

12. Your rights and how to exercise them

For data for which we are the Data Fiduciary, you have the right to:

How. Email sales@heymachi.ai, or write to the Grievance Officer. To delete your account, follow the steps at heymachi.ai/delete-account. We will verify your identity by OTP to your registered mobile number.

Timeline. We will acknowledge your request within 48 hours and respond within 30 days, and in any case within the period prescribed under the DPDP Rules.

Merchant data. For records a merchant holds about you, contact the merchant. You can also send the request through the app; we will forward it to every merchant you have transacted with and tell you which merchants we forwarded it to.

Complaints to the Data Protection Board. If you are not satisfied with our response, you may complain to the Data Protection Board of India, in the manner the Board prescribes, after first using our grievance process.

13. Storage on your device

We do not use cookies for advertising or analytics on heymachi.ai or in our apps, and we do not use third-party analytics or advertising SDKs. The customer and merchant web apps use your browser’s local storage to keep you signed in and to remember your cart, language and settings. This is strictly necessary for the service. Signing out clears your sign-in data; you can clear the rest in your browser settings.

The mobile apps may ask for these device permissions, each only when you use the related feature:

You can change permissions in your device settings.

14. Grievance Officer and contact

More ways to reach us are on our Contact and Grievance Officer page.

15. Changes to this Policy

We will post any change on this page with a new effective date and, for material changes, notify you in the app or by message before the change takes effect. Where a change requires fresh consent, we will ask for it.