Privacy Policy
Last updated: May 23, 2026
This Privacy Policy explains how Panery ("we," "us," or "our") collects, uses, shares, and protects personal information when you use https://www.panery.org and related services (the "Service"). It should be read together with our Terms of Service.
1. Who We Are
Panery operates the Service described at https://www.panery.org. For privacy-related requests, contact us at contact@panery.org.
Where we process personal data on behalf of an organization (for example, data about that organization's members or vendors), we act as a processor for the organization's business purposes, and the organization remains responsible for its own compliance obligations toward those individuals.
2. Scope
This Policy applies to visitors, registered users, organization members, and billing contacts. It does not cover third-party websites, apps, or services linked from the Service (including OAuth providers, payment pages, or Discord)—those are governed by their own policies.
The Service is intended for business users, not children. We do not knowingly collect personal information from anyone under 18.
3. Information We Collect
We collect information in the following categories:
Account and profile
Information you provide when registering and maintaining your account, such as:
- Email address, password (stored in hashed form by our auth provider), and optional OAuth identifiers (e.g., GitHub or Google subject IDs).
- Account type (Agent or Vendor), display name, phone, bio, and profile image where you supply them.
- MFA enrollment metadata (e.g., whether MFA is enabled); secrets and TOTP seeds remain with our auth infrastructure.
- Account lifecycle status (active, disabled, deletion scheduled) and related timestamps.
Organization and operations
Data created while using workspaces, including:
- Organization name, membership, roles (including owner), and invitations.
- Product catalogs, pricing, orders, status history, notes, and settlement records.
- Marketplace visibility settings and inter-organization relationships where enabled.
- Payout or billing details you enter for subscriptions (processed by our payment partner).
Content you upload
Files such as COD receipts or attachments submitted through our upload provider. We store references, metadata, and URLs needed to display them within the Service.
Communications
Support messages, emails we send (e.g., verification, billing, security notices), and information you provide when contacting contact@panery.org or community channels such as Discord (which has its own privacy policy).
Automatically collected
When you use the Service, we and our providers may collect:
- Device and browser type, IP address, approximate location derived from IP, timestamps, and pages or features used.
- Authentication session cookies and similar technologies required for sign-in and security.
- Analytics events (e.g., via Vercel Analytics) to understand performance and usage in aggregate.
- Security signals from CAPTCHA (hCaptcha) to reduce abuse; hCaptcha may process interaction data under its policy.
- Error and diagnostic logs where configured (e.g., for reliability monitoring).
4. How We Use Information
We use personal information to:
- Provide, authenticate, and secure the Service (including MFA and CAPTCHA).
- Operate organizations, orders, settlements, and marketplace features you enable.
- Process subscriptions and payments through Razorpay.
- Send transactional communications via our email provider (e.g., Resend).
- Respond to support requests and improve documentation.
- Monitor, prevent, and investigate fraud, abuse, and security incidents.
- Comply with law, enforce our Terms, and protect rights and safety.
- Analyze aggregated usage to improve reliability and product design.
5. Legal Bases (where applicable)
If you are in a jurisdiction that requires a legal basis (such as the EU/UK GDPR or India's Digital Personal Data Protection Act, 2023), we rely on one or more of the following as appropriate:
performance of a contract (providing the Service you requested); legitimate interests (security, fraud prevention, product improvement balanced against your rights); consent (where we ask for it explicitly, such as optional marketing if offered); and legal obligation (tax, accounting, or lawful requests).
7. International Transfers
We and our subprocessors may process data in India and other countries where they operate. When transferring personal data internationally, we rely on appropriate safeguards permitted by law (such as standard contractual clauses or equivalent mechanisms offered by our providers).
8. Retention
We retain personal information for as long as your account or organization is active and as needed to provide the Service, then for periods required by law or legitimate business needs (billing records, dispute resolution, security logs).
Account deletion scheduled in settings typically executes after a 30-day grace period; organization termination may use a 14-day grace period before deletion of organization-scoped data.
After deletion, we may retain anonymized or aggregated data and minimal logs that no longer identify you, where permitted.
9. Security
We implement technical and organizational measures appropriate to the nature of the data, including encryption in transit, access controls, row-level security in our database where applicable, and MFA support. No method of transmission or storage is completely secure; you are responsible for protecting your credentials and devices.
If you believe your account has been compromised, contact contact@panery.org promptly.
10. Your Rights and Choices
Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability or withdrawal of consent where processing is consent-based.
You can update profile fields in account settings, manage MFA, cancel scheduled account deletion during the grace period, and control organization membership through authorized admin flows.
To exercise privacy rights, email contact@panery.org with sufficient detail to verify your identity. We will respond within timelines required by applicable law (including reasonable periods under India's DPDP Act where it applies).
You may lodge a complaint with a supervisory authority in your jurisdiction if you believe processing violates applicable law.
12. Third-Party Links and OAuth
If you sign in with GitHub or Google, those providers receive information according to their policies and share profile identifiers with us as permitted by your authorization.
Payment flows may redirect to Razorpay-hosted experiences. Uploaded files are stored via Uploadthing. Review those providers' privacy policies for details beyond our control.
13. Changes to This Policy
We may update this Privacy Policy. The "Last updated" date at the top will change, and material updates may be communicated by email or in-product notice. Continued use after the effective date indicates acceptance of the updated Policy.
14. Contact
Privacy questions or requests: contact@panery.org.
For organization-specific data about you held on behalf of an employer or partner organization, you may also contact that organization directly.