Loading ChaiSaab
Getting your page ready...
Getting your page ready...
September 2026
This page describes how ChaiSaab protects your data. It is an overview — not a formal audit certificate or legal opinion. For privacy rights, see our Privacy Policy. Privacy Policy.
ChaiSaab is a shop commerce platform — orders, inventory, loyalty tokens, and chat. We are not a bank or wallet. Payments to shops are mostly shop-direct (UPI / QR). This page summarises how we protect your data and what we are still improving.
| Question | Answer |
|---|---|
| Are we SOC 2 certified? | Not yet for ChaiSaab itself. We run on AWS, which publishes independent SOC reports. |
| Is data encrypted? | Yes in transit (HTTPS / WSS). Sensitive data and most files use AES-256 at rest. |
| Are passwords safe? | Yes — one-way bcrypt hashing; we never store plain passwords. |
| Are payment gateway secrets safe? | Yes — encrypted in our database; keys live in secure server config. |
| Can I use passkeys? | Yes — optional passwordless sign-in with device biometrics or PIN. |
Formal certifications describe independent audit of controls — not a substitute for an audit report.
| Standard | ChaiSaab status | What it means for you |
|---|---|---|
| SOC 1 Type II | Not pursued | Not required today — we do not hold customer funds as a payment processor. |
| SOC 2 Type II | Not certified yet | On our roadmap if enterprise customers require it. |
| AWS SOC 2 / ISO 27001 | Inherited via AWS | Hosting and storage run on independently audited AWS services. |
| PCI DSS | Partial / delegated | Card payments go through gateways; we do not store card numbers or CVV. |
| Layer | Location & protection |
|---|---|
| Primary servers | AWS ap-south-1 (Mumbai, India). Encrypted disks. Secrets in AWS SSM. |
| Database | PostgreSQL on dedicated encrypted storage. |
| Files & media | Amazon S3 — shop media, private KYC, customer miniapp saves. |
| AWS SES — no India TRAI registration required for email. | |
| SMS | AWS SNS — India TRAI/DLT registration in progress. |
| Future regions | Japan, Thailand planned — regional privacy rules apply before local PII is stored there. |
| Measure | Status | Detail |
|---|---|---|
| Encryption in transit | Active | HTTPS for API; secure WebSockets (WSS) in production. |
| Encryption at rest | Active | Encrypted database disks; AES-256 for sensitive fields and key S3 objects. |
| Password storage | Active | bcrypt one-way hashing. |
| Gateway & MFA secrets | Active | AES-256-GCM in database; master key in secure server config. |
| Access control | Active | You see only your account data; shopkeepers see only their shop. |
| Retention | Active | Security logs kept at least 180 days; tax/order records up to 7 years where required. |
| Delete my account | Partial | Supplier & Living: request deletion in account settings. Shopkeeper/customer self-delete rolling out; contact privacy@chaisaab.com for data rights. |
| Control | Customers | Shopkeepers | Admins |
|---|---|---|---|
| Session tokens | Short-lived (15 min) + refresh | Same | Same |
| Cookie storage | httpOnly, Secure, SameSite | Same | Same |
| CSRF protection | On state-changing requests | Same | Same |
| Account lockout | After repeated failed logins | Same | Same |
| Passkeys (WebAuthn) | Optional | Optional | Optional |
| Extra verification (MFA) | Optional | On sensitive changes | Required for admin console |
| Email verified at signup | Yes (email OTP) | Yes | Invite / setup flow |
| Phone SMS OTP at signup | Pending TRAI/DLT | Where enabled | — |
Live order updates, chat, and notifications use encrypted connections when you use HTTPS.
| Topic | How we protect it |
|---|---|
| Transport | WSS (TLS) in production — same encryption as the website. |
| Authentication | Same login token as the API; role-based rooms only. |
| Origin checks | Only allowed website origins can connect in production. |
| Message limits | Maximum message size capped to reduce abuse. |
We log token transfers and P2P activity on our servers — not anonymous cash-like transfers.
| Flow | Server audit | Notes |
|---|---|---|
| In-app token transfer | Yes | Amount, parties, and IP logged. |
| WebSocket chat relay | Yes | Messages subject to retention and takedown policy. |
| Offline order sync | Yes | Device syncs via HTTPS; no silent off-books orders. |
| NFC / BLE offline tokens | Not offered | Blocked until compliance review complete. |
| Asset | Who can see it | Protection |
|---|---|---|
| Shop banner & logo | Public (shop page) | Malware scan on upload. |
| Payment QR image | Public (scan to pay) | By design — contains UPI/payment address, not platform secrets. Scanned on upload. |
| KYC / verification documents | Shop owner + admin only | Private bucket, short-lived signed links, admin access audited. |
| Expense & workforce docs | Shop owner only | Private paths; malware scan on upload. |
| Asset | Access | Protection |
|---|---|---|
| Miniapp cloud saves | You only (subscription required) | Private path per customer; AES-256; 20 MB quota. |
| Session audio (miniapps) | Your session only | Encrypted storage; not public. |
| Topic | How it works |
|---|---|
| Shop payment QR upload | Shop owner only; file type and size checked; malware scanned. |
| QR visibility | Public so customers can scan — this is your payment address, not an API secret. |
| Platform gateway keys | Encrypted in database; set by admin or shopkeeper in settings; never shown in the app UI after save. |
| Customer card data | Not stored by ChaiSaab — handled by payment gateways. |
| Cash / UPI at shop | Recorded as payment method; shop verifies receipt. |
We maintain privacy notices, grievance contacts, and a law-enforcement request process. Regional rules apply based on your market.
| Market | Framework | Status |
|---|---|---|
| India (live) | IT Act, IT Rules, DPDP, CERT-In | Core controls implemented; grievance officer details being finalised in public notices. |
| Thailand (planned) | PDPA, Computer Crime Act | Privacy annex drafted; launch requires counsel review. |
| Japan (planned) | APPI | Privacy annex drafted; cross-border transfer agreements before local PII. |
| Singapore / Malaysia | PDPA | Annex drafts available. |
We believe in being transparent about gaps — not claiming perfection.
| Gap | Our plan |
|---|---|
| ChaiSaab SOC 2 report | Readiness project when scale requires. |
| India TRAI/DLT for SMS | Complete registration before phone SMS OTP at scale. |
| Self-delete & data export | Expand self-service deletion and download across all account types. |
| Public legal placeholders | Finalise grievance officer and registered company details. |
| P2P marketing at scale | Legal counsel sign-off before promotion. |
| Purpose | |
|---|---|
| Privacy & data rights | privacy@chaisaab.com |
| Grievance & complaints | contact@chaisaab.com |
| Law enforcement (lawful orders) | legal@chaisaab.com |
| Security incidents | security@chaisaab.com |
September 2026 · v1.2
This page is an overview of security and compliance measures. It is not a SOC audit report or legal opinion.
© 2026 ChaiSaab Pvt Ltd. All rights reserved.