Indian Spice Shop / IN Mails
Privacy Policy for IN Mails
Last updated: July 17, 2026
Developer and grievance contact:
global@indianspiceshop.com
This Privacy Policy applies to Indian Spice Shop, the IN Mails Android/PWA mailbox app, and the related staff portals used for business communication and export sourcing workflows.
Services covered by this policy
- IN Mails is a restricted-access mailbox and workflow app for authorized staff users.
- The app supports business email, drafts, favorites, contacts, product proposals, marketing emails, supplier RFQs, quote requests, contact messages, CRM/activity notes and task chat.
- The public website supports Indian food export sourcing information, multilingual product pages, contact forms, quote request forms and WhatsApp/email inquiry actions.
- Access is not public. App-store reviewers may receive temporary testing credentials separately by email.
Information we collect
- Account and access data such as username, role, portal access, login status, trusted-device and 2FA settings.
- Email and mailbox data such as sender, recipient, subject, message body, attachments, folders, drafts, sent emails, favorites, read/unread state and delivery logs.
- Contacts and business records such as name, company, email, phone, country, address, notes, imported contact sheets and staff ownership.
- Buyer enquiry and quote request data such as product, quantity, packing, destination port, buyer message, verification status and submission time.
- CRM, activity timeline, task chat, staff notes, supervisor remarks, to-do items and audit history.
- Notification data such as browser push subscriptions, Appilix/Firebase user identity, device notification tokens and delivery status.
- Technical and security data such as IP address, browser, device type, language preference, logs, rate limits and anti-spam checks.
How we use information
- To operate mailbox, CRM, supplier RFQ, product proposal, contact manager, message and quote request workflows.
- To send and receive business emails and notifications for new emails, messages, quote requests and assigned tasks.
- To verify contact or quote submissions with email OTP where enabled and reduce fake or spam enquiries.
- To maintain communication history, staff accountability, audit logs and follow-up records.
- To protect accounts, detect abuse, improve reliability and troubleshoot service issues.
Emails, contacts, attachments and CRM data
- Emails and contacts are stored so authorized users can continue business conversations, reply, forward, prepare proposals and maintain follow-up records.
- Attachments may be stored on the private server or configured archive storage. File names, sizes and references may be kept in MySQL.
- Authorized senior staff may see staff communication records where required for supervision, business continuity, support and compliance. Staff visibility is restricted by permissions.
Notifications and device data
- The app may use browser Push API, VAPID, Appilix Push API or Firebase Cloud Messaging for operational alerts.
- Notification identity is used to target the correct authorized staff user.
- Users can disable notifications from browser, device or app settings.
Data sharing
- We do not sell personal or business contact data.
- Data may be shared only with authorized internal users, hosting providers, email service providers, notification service providers, archive storage providers and relevant suppliers or buyers when required for a business workflow.
- We may disclose information if required by law, security review, fraud prevention, dispute handling or protection of our services.
Storage, retention and security
- Messages, quote requests, contacts, emails, CRM records, task notes and notification logs may be stored in MySQL and server storage.
- Records may be retained for business follow-up, audit, security, dispute handling and legal compliance unless deletion is requested and is legally and operationally possible.
- We use role-based access, login controls, 2FA options, CSRF protection, protected folders and database-backed permissions to reduce unauthorized access.
Your choices
- Website visitors may request correction or deletion of contact details by using the contact page or emailing the grievance contact above.
- Staff users should ask the authorized account manager to update, disable or remove account access.
- Users should not submit highly sensitive personal information unless it is necessary for the business enquiry.