Privacy Policy
What data we handle, why we handle it, and what you can ask us to do about it. Written to be read, not to be skipped.
Last updated: 21 August 2026 · Applies to OpsTower (opstower.in)
1.Who we are
OpsTower is an operations platform for direct-to-consumer brands, operated by OpsTower, a proprietorship of Atul Kumar Saini registered under Udyam Registration No. UDYAM-DL-05-0090612 ("we", "us", "our"). We provide WhatsApp marketing, shipment and NDR management, auto-fulfillment, mobile apps, returns and reviews modules to businesses that sell online.
This policy explains what personal data we handle, why, and what rights you have. It applies to our website (opstower.in), our application (app.opstower.in) and related services.
2.Two different roles — please read this first
Our platform involves two distinct kinds of personal data, and our responsibilities differ for each.
- Account data — information about you, our business customer (your name, email, workspace). For this data we are the data fiduciary (controller): we decide how it is used, and this policy governs it.
- Workspace data — information about your own customers that you upload or connect to the platform (their phone numbers, names, order and delivery details, messages, reviews). For this data we are a data processor acting only on your instructions. You remain responsible for having a lawful basis and valid consent to collect it and to message those people.
3.What we collect
The table below covers everything the platform stores. Categories vary by which modules you enable.
| Category | Examples | Why |
|---|---|---|
| Account data | Name, email, password (hashed), workspace name, role | Create and secure your account |
| Integration credentials | Meta WhatsApp API tokens, Shopify Admin API tokens, Shiprocket credentials | Connect your tools so the modules work |
| Workspace data | Your customers' phone numbers, names, tags, opt-out status | Send campaigns and support conversations you initiate |
| Message data | WhatsApp message content, delivery and read status | Deliver campaigns, power your shared inbox |
| Order & shipment data | Order references, AWB numbers, courier, delivery status, NDR reasons, COD flag | Shipment tracking and NDR actions |
| Usage & technical data | Log-in events, actions taken in the app, IP address, browser type | Security, audit trails, troubleshooting |
We do not collect payment card details. We do not knowingly collect sensitive personal data such as health, biometric or financial account information, and you should not upload such data to the platform.
4.How we use data
- To provide the service — sending the campaigns you configure, syncing your orders and shipments, running the rules you create.
- To secure the service — authentication, fraud prevention, audit logging of sensitive actions such as campaign sends and NDR decisions.
- To support you — responding to your questions, diagnosing issues you report.
- To improve the service — understanding which features are used, in aggregate. We do not sell personal data, and we do not use your workspace data to train models or to market to your customers.
5.Consent and lawful basis
We process your account data on the basis of the contract between us and, where required, your consent. You may withdraw consent at any time by closing your account, though we may retain limited records where the law requires it.
For workspace data, you are responsible for obtaining valid consent from your customers before adding them to the platform or messaging them. This is not merely a legal formality: WhatsApp requires prior opt-in for business-initiated messages, and messaging people who have not opted in can get your number blocked by Meta.
6.Sharing and sub-processors
We share data only with the service providers needed to operate the platform, and only to the extent required. We do not sell personal data to anyone.
| Provider | What it handles | Where |
|---|---|---|
| Meta Platforms (WhatsApp Business Platform) | Delivery of WhatsApp messages you send | Global |
| Shopify | Your store's order and customer data, read via API | Global |
| Shiprocket | Shipment booking, tracking and NDR actions | India |
| Hosting provider | Application servers and database | India |
| Payment processor | Subscription billing, when enabled | India |
7.Where data is stored
Our application servers and database are hosted in India. Some sub-processors, notably Meta, operate globally and may process message data outside India in order to deliver it. Where data crosses borders we rely on the protections offered by those providers' own terms.
8.How we protect data
- Integration credentials (your Meta, Shopify and Shiprocket tokens) are encrypted at rest using AES-256-GCM, and are never displayed back to you or to our staff in readable form.
- Passwords are stored only as bcrypt hashes — we cannot read them.
- All traffic between your browser and our servers is encrypted in transit (TLS).
- Each workspace's data is isolated: every query is scoped to your organisation, so one customer cannot see another's data.
- Sensitive actions — campaign sends, NDR decisions, integration changes, billing changes — are recorded in an audit log.
- Access to production systems is limited to staff who need it to operate or support the service.
- No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority as required by law.
9.How long we keep data
- Account data: for as long as your workspace is active, and up to 90 days after closure to allow recovery.
- Workspace data (contacts, messages, shipments): for as long as you keep it in the platform. You can delete records at any time, and we delete the workspace within 90 days of account closure.
- Audit logs: retained for up to 12 months for security and accountability.
- Records we are legally required to keep, such as invoices, are retained for the period the law prescribes.
10.Your rights
Subject to applicable law, including the Digital Personal Data Protection Act, 2023, you may:
- Ask what personal data we hold about you and why.
- Ask us to correct data that is inaccurate or incomplete.
- Ask us to erase your data, subject to legal retention requirements.
- Withdraw consent, or ask us to stop a particular processing activity.
- Nominate another person to exercise these rights on your behalf in the event of death or incapacity.
- Complain to us first, and to the Data Protection Board of India if we do not resolve it.
11.If you are an end-customer of one of our users
If you received a WhatsApp message, a return request or a review invitation powered by our platform, the business that contacted you — not us — decides what data is held and why. Please contact that business directly to exercise your rights.
You can stop marketing messages at any time by replying with an opt-out to that business's WhatsApp number; our platform records opt-outs and excludes those numbers from future campaigns. If you cannot reach the business, write to us and we will pass your request on.
12.Cookies
We use a small number of strictly necessary cookies to keep you signed in and to keep the application secure. We do not use advertising cookies on the application. Our public website may use privacy-respecting analytics and, if we advertise, conversion measurement provided by the ad platform.
13.Children
Our service is intended for businesses and is not directed at children. We do not knowingly collect personal data of children under 18.
14.Changes to this policy
We may update this policy as the product evolves. If a change is material we will notify workspace owners by email or in the application before it takes effect. The date at the top of this page always reflects the current version.
15.Contact and grievance redressal
For any question about this policy, or to exercise your rights, contact our Grievance Officer: Atul Kumar Saini, Proprietor & Grievance Officer, opstowerindia@gmail.com.
Postal address: 1st Floor, 227, Creative Heights Apartment, Block A, Fresh Basket Lane, Rohini, Delhi – 110042. We aim to acknowledge requests within 72 hours and resolve them within 30 days.