Ordermatrix एक early-stage product है, और हम मानते हैं कि क्या लागू है और क्या अभी roadmap पर है — दोनों के बारे में ईमानदार होना ज़रूरी है।
Ordermatrix पर सारा traffic HTTPS के through TLS के साथ serve होता है। आपका customer data, addresses और payments आपके browser और हमारे servers के बीच encrypted रहते हैं।
Secure password hashing (bcrypt) के साथ JWT-based authentication। Tokens हर tenant के लिए scoped होते हैं और logout पर expire हो जाते हैं। Multi-factor authentication roadmap पर है।
आपके account के अंदर, आप control करते हैं कौन क्या देखेगा। Sales, dispatcher और admin जैसी roles orders delete करने या payment reports देखने जैसी sensitive operations को restrict करती हैं।
हम आपके customers के card numbers या UPI credentials कभी store नहीं करते। सारा payment processing Razorpay handle करता है जो PCI-DSS compliant है। हम सिर्फ़ payment status और reference IDs store करते हैं।
Vercel (frontend) और Railway (backend) पर host। Database MongoDB Atlas पर encryption at rest के साथ। Files Cloudflare R2 पर। Industry-standard cloud providers, किसी की desk के नीचे का server नहीं।
MongoDB Atlas automated backups चलाता है। गलती से delete या infrastructure issues होने पर आपका data recoverable है। Higher tiers पर point-in-time recovery available है।
जो भी आप Ordermatrix में डालते हैं — customers, orders, payments, notes — वो आपका है। Full stop।
आप अपना data कभी भी CSV में export कर सकते हैं। अगर subscription cancel करते हैं, हम 90 दिन तक आपका data accessible रखते हैं ताकि आप delete से पहले export कर सकें।
हम आपका customer data sell, share या आपके account चलाने के अलावा किसी और purpose के लिए use नहीं करते। हम उस पर AI models train नहीं करते। हम वो advertisers को नहीं दिखाते।
हम early-stage product हैं। हमारे पास SOC 2 certification नहीं है। ISO 27001 नहीं है। Share करने के लिए third-party penetration test report नहीं है।
जो हमारे पास है: honest engineering practices, एक छोटी team जो security को seriously लेती है, और वही cloud infrastructure जिस पर ज़्यादातर modern SaaS products चलते हैं।
जैसे-जैसे हम बढ़ेंगे, certifications भी आएंगी। जब आएंगी तब हम यह page update करेंगे — पहले नहीं।
अगर आपको कोई vulnerability मिली है, responsibly report कीजिए। हम हर report को seriously लेते हैं और 48 घंटे में reply करते हैं।
[email protected]Data handling और आपके rights के बारे में: