1. Introduction & Overview
At Livka (“Livka”, “we”, “our”, or “us”), we respect your privacy and are dedicated to transparent, responsible data stewardship. Livka is a software-as-a-service (SaaS) platform that enables independent businesses, creators, and boutiques to create online product catalogs and facilitate WhatsApp customer orders.
This Privacy Policy describes our practices regarding the collection, use, storage, disclosure, and protection of personal data under applicable data protection regulations in India, including the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000.
By accessing the Livka website, registering for an account, using our dashboard, or interacting with a storefront hosted on our platform, you acknowledge the data practices described in this policy.
2. Information We Collect
We strictly collect information necessary to deliver, maintain, secure, and operate our software services. We categorize collected information as follows:
A. Merchant Account Information
When you register as a merchant on Livka, we collect credentials and identity details required to establish and authenticate your account:
- Identity Data: Full name, profile avatar URL (if provided), and email address.
- Authentication Data: Passwords (securely hashed, salted, and processed via Supabase Auth; Livka never stores plain-text passwords) and session authorization tokens.
- Referral Data: Optional referral codes used during registration to attribute platform rewards.
B. Merchant Store Configuration Information
To generate your digital storefront and manage your catalog, we process the business information you enter into your merchant settings and website editor:
- Store Details: Store name, custom subdomain slug (e.g.,
https://{slug}.livka.in), business category, store description, and opening hours. - Business Contact Points: WhatsApp business telephone number, Instagram handle, studio/store address, city, and postal pincode.
- Fulfillment Settings: Fulfillment mode preferences (delivery and pickup, pickup only, or delivery only), delivery fees, minimum order thresholds, and studio pickup instructions.
- Catalog & Media Assets: Product titles, descriptions, categories, prices, compare-at prices, inventory counts, product variants (SKUs, options), and image files uploaded to Cloudflare R2 storage.
- Page Layouts: Custom block compositions created in the website builder (hero banners, product grids, testimonials, and about sections).
C. Storefront Customer Information
Livka provides checkout forms on merchant storefronts to structure customer orders. When an end-consumer places an order on a merchant storefront, our platform processes:
- Contact Details: Customer full name, phone number, and optional email address.
- Delivery Information: Doorstep delivery address, city, and postal pincode (when home delivery is selected).
- Order Details: Selected products, variant choices, item quantities, subtotal, delivery fee, order notes, unique order number, and timestamp.
D. Technical & Telemetry Information
When you interact with our website or storefronts, we collect limited technical telemetry to guarantee platform security and power merchant dashboard metrics:
- First-Party Analytics Events: Internal telemetry capturing
page_view,product_view,add_to_cart,checkout_started, andwhatsapp_checkoutevents linked to anonymous session identifiers. - Server Access Logs: Standard HTTP request logs including IP addresses, browser types, user agents, operating systems, referring URLs, and error timestamps.
3. How We Use Information
We use the information we collect strictly for legitimate business and operational purposes:
| Purpose | Data Categories Utilized |
|---|---|
| Platform Provisioning & Hosting | Merchant account details, store configurations, products, and page blocks to render storefronts on unique subdomains. |
| Order Ingestion & WhatsApp Forwarding | Customer contact information, delivery addresses, and cart selections to create database order records and format pre-filled WhatsApp order slips. |
| Merchant Directory & Dashboard | Order records and customer contact history presented to the store owner within their private administrative dashboard. |
| Subscription Billing | Merchant email, store identifier, and subscription status processed via Dodo Payments for Livka Pro subscriptions. |
| Security & Abuse Prevention | IP logs, authentication attempts, and database queries to protect against brute-force attacks, unauthorized access, and malicious scripts. |
| Legal & Regulatory Compliance | Transaction histories and communication records retained to comply with applicable statutory requirements under Indian law. |
4. Merchant vs. Customer Data (Crucial Separation of Roles)
A critical principle of Livka’s architecture is the distinction between our role as a software platform and our merchants’ roles as independent business operators:
- The Merchant is the Data Fiduciary / Controller: The merchant decides what products to sell, sets store policies, and determines how customer data collected through their storefront is handled. Merchants must provide their own privacy disclosures to their buyers.
- Livka is the Data Processor / Service Provider: Livka processes storefront customer information solely on behalf of the merchant, following the merchant’s automated instructions (storing the order, updating inventory, and formatting the WhatsApp order slip).
No Platform Monetization of Customer Data: Livka does not sell, lease, trade, or monetize merchant customer lists, phone numbers, or shopping histories. We do not use merchant customer data for third-party marketing or cross-merchant retargeting.
5. How Information Is Shared & Third-Party Service Providers
We do not sell personal data. We disclose personal data only to verified service providers who perform critical infrastructure functions on our behalf, under strict contractual obligations of confidentiality:
- Supabase Inc.: Provides cloud PostgreSQL database hosting, automated backups, and tokenized identity authentication. Data is protected by PostgreSQL Row Level Security (RLS) policies.
- Cloudflare, Inc. (Cloudflare R2): Provides global distributed cloud object storage for merchant product images, banners, and logos, and provides DDoS mitigation and CDN edge caching.
- Dodo Payments: Acts as our authorized merchant of record and payment processing gateway for Livka Pro subscriptions. When you purchase a subscription, payment credentials are submitted directly to Dodo Payments under their security standards.
- Meta Platforms, Inc. (WhatsApp): When a customer submits an order, our software launches WhatsApp using standard deep-links (
wa.me) to transfer the structured order message to the merchant. The subsequent transmission is governed by WhatsApp’s privacy terms. - Legal & Regulatory Authorities: We may disclose personal data if required to do so by applicable law, court summons, or formal order of an Indian government or judicial authority, or to protect the vital security of our platform and users.
6. Data Storage & Technical Security Safeguards
We implement rigorous technical and organizational safeguards designed to protect personal data against accidental loss, unauthorized access, alteration, or disclosure:
- Row Level Security (RLS): Our database employs database-level multi-tenant isolation. Each merchant can query and modify only their own store data, products, orders, and customer records. Public visitors can only access published catalog information.
- Encryption in Transit: All data transmitted between your browser and the Livka platform is encrypted using modern Transport Layer Security (TLS 1.2 / TLS 1.3) protocols.
- Secure Tokenized Sessions: User authentication tokens are stored in secure HTTP cookies configured with
HttpOnly,SameSite=Lax, andSecureflags to prevent cross-site scripting (XSS) and CSRF attacks. - Access Restrictions: Administrative database access is restricted to authorized platform maintainers requiring access for operational support, guarded by multi-factor authentication.
Please note: While we implement industry-standard safeguards, no internet transmission or electronic storage method can be guaranteed to be 100% impenetrable. We encourage merchants to use strong, unique passwords and maintain vigilance against phishing.
7. Data Retention & Preservation
We retain personal data only for as long as reasonably necessary to fulfill the purposes for which it was collected:
- Active Accounts: Merchant account details, store configurations, catalog items, and order histories are retained for the lifetime of your active account.
- Lapsed Subscriptions: If your Livka Pro subscription lapses, your store is unpublished from the public subdomain, but your builder data and catalog remain securely preserved so that you can resume your business without data loss upon re-subscribing.
- Telemetry Logs: Server access logs and aggregated analytics events are periodically pruned or anonymized after operational review.
- Statutory Obligations: Billing and tax-related invoices may be preserved for mandatory statutory periods required under Indian commercial and taxation laws.
9. Your Data Rights Under Indian Law
Under applicable Indian data protection principles, including the Digital Personal Data Protection Act, 2023 (DPDP Act), you have rights regarding your personal information:
- Right of Access: You have the right to confirm whether Livka processes your personal data and to request a summary of the data held.
- Right to Correction: You have the right to update or rectify inaccurate, incomplete, or outdated personal information directly through your dashboard settings.
- Right to Erasure: You have the right to request the deletion of your personal data, subject to legitimate legal and tax-preservation requirements.
- Right to Grievance Redressal: You have the right to register concerns or complaints regarding data processing with our designated contact channel.
Notice to Storefront Customers: If you are a consumer who placed an order on a merchant’s Livka store and wish to access, correct, or delete your contact details, please contact the respective merchant directly. As a data processor, Livka will assist merchants in fulfilling verified customer requests in accordance with our technical capabilities.
10. Account Deletion & Data Purge Process
In our current platform release, full account deletion is processed through our verified administrative support channel:
- Cancel Active Subscriptions: Before requesting deletion, navigate to your merchant dashboard under Billing and cancel any active Livka Pro recurring subscription to prevent further renewal charges.
- Submit Deletion Request: Send an official deletion request from your registered Livka email address to support@livka.in or contact us via our verified Telegram support at @livka_support.
- Verification & Purge: Our support team will confirm your ownership of the account. Upon verification, your profile, store configurations, product catalogs, and associated database records will be permanently purged from active production systems within thirty (30) days, except for records mandated by law for tax or accounting retention.
11. Children’s Privacy
Livka is a commercial business platform intended for adults and legally capable business operators. Our website and services are not directed to children under eighteen (18) years of age. We do not knowingly collect personal data from minors. If we discover that a minor has provided us with personal information without verified parental or guardian consent, we will take prompt steps to delete such data from our systems.
12. Cloud Infrastructure & Hosting Architecture
Livka utilizes distributed enterprise cloud infrastructure provided by Supabase and Cloudflare. While our core business operates in India, cloud data centers, caching edge servers, and content delivery nodes may process or replicate encrypted data globally to ensure high availability, fast storefront loading, and disaster recovery.
All data handling across our infrastructure providers complies with industry-standard encryption protocols and security measures.
13. Third-Party Links & External Tools
Our platform and merchant storefronts may display links to external websites, social profiles (such as Instagram), and external messaging services (such as WhatsApp). Livka does not control, supervise, or endorse the privacy practices of these independent third-party services. We encourage you to review the privacy policies of any external website or service you visit.
14. Updates to This Privacy Policy
We may update this Privacy Policy periodically to reflect technological changes, statutory amendments, or modifications to our software services. When changes occur, the “Last Updated” date at the top of this policy will be revised.
For significant changes that affect how your personal data is handled, we will provide conspicuous notice on the merchant dashboard prior to the changes taking effect. We encourage you to review this page periodically to stay informed about our data protection practices.
15. Contact Us & Grievance Redressal
If you have any questions, concerns, feedback, or grievance requests concerning this Privacy Policy or our personal data handling practices, please contact us through our official platform communication channels:
Livka Privacy & Grievance Redressal:
- Privacy Inquiries & Data Requests: privacy@livka.in
- General Support Email: support@livka.in
- Telegram Official Support: @livka_support
- Instagram Official Channel: @livka.in
- Jurisdiction: Republic of India

