Privacy Policy
1. Introduction & Overview
Nextrive Technologies ("Nextrive", "we", "our", or "us") respects your privacy and is dedicated to safeguarding personal and organizational data. This Privacy Policy describes how we collect, process, store, disclose, and protect personal and organizational information collected through our multi-tenant SaaS e-commerce platform and related portals.
2. Information We Collect
Account & Identity Information: Names, business email addresses, contact numbers, organization legal name, tax identifiers, billing addresses, and job titles provided during account creation or invitation acceptance.
Transaction & Commerce Data: Order history, quotation negotiations, sample requests, invoice records, delivery addresses, and payment confirmation statuses (Note: Sensitive card data is tokenized and processed directly by PCI DSS certified gateways).
Platform Usage & Technical Logs: IP addresses, browser types, device fingerprints, session durations, system logs, API calls, and error tracking metrics gathered to protect tenant isolation and maintain system security.
3. Legal Bases and How We Use Your Data
We process information under legitimate business interests, contractual necessity, and statutory compliance for the following purposes:
Providing, maintaining, and enhancing multi-tenant SaaS features, catalog workflows, and order fulfillment systems.
Processing transactions, generating commercial invoices, and triggering automated status alerts via Email, SMS, or WhatsApp.
Enforcing strict multi-tenant data boundaries, detecting suspicious intrusion attempts, and preventing fraudulent orders.
Complying with tax reporting, statutory accounting, and regulatory obligations
4. Tenant Data Isolation & Protection Measures
Our architecture utilizes database-level query scoping and AsyncLocalStorage context filtering to guarantee that organizational data belonging to one tenant remains completely isolated from other tenants.
We implement industry-standard encryption protocols (TLS/HTTPS in transit, AES-256 at rest for sensitive configurations), strict role-based access control (RBAC), and ongoing vulnerability assessments.
5. Sharing and Third-Party Sub-Processors
We do not sell, rent, or trade your personal or tenant data to third parties. We disclose data solely to authorized sub processors necessary to deliver platform operations, including:
Payment Processing: Razorpay, PhonePe, and integrated banking switches.
Communication & Notifications: Google OAuth/Gmail (Email dispatch), Twilio (SMS & WhatsApp notifications).