Indian Spice Shop

WhatsApp

Indian Spice Shop / IN Mails

Privacy Policy for IN Mails

Last updated: July 17, 2026

Developer and grievance contact: global@indianspiceshop.com

This Privacy Policy applies to Indian Spice Shop, the IN Mails Android/PWA mailbox app, and the related staff portals used for business communication and export sourcing workflows.

Services covered by this policy

  • IN Mails is a restricted-access mailbox and workflow app for authorized staff users.
  • The app supports business email, drafts, favorites, contacts, product proposals, marketing emails, supplier RFQs, quote requests, contact messages, CRM/activity notes and task chat.
  • The public website supports Indian food export sourcing information, multilingual product pages, contact forms, quote request forms and WhatsApp/email inquiry actions.
  • Access is not public. App-store reviewers may receive temporary testing credentials separately by email.

Information we collect

  • Account and access data such as username, role, portal access, login status, trusted-device and 2FA settings.
  • Email and mailbox data such as sender, recipient, subject, message body, attachments, folders, drafts, sent emails, favorites, read/unread state and delivery logs.
  • Contacts and business records such as name, company, email, phone, country, address, notes, imported contact sheets and staff ownership.
  • Buyer enquiry and quote request data such as product, quantity, packing, destination port, buyer message, verification status and submission time.
  • CRM, activity timeline, task chat, staff notes, supervisor remarks, to-do items and audit history.
  • Notification data such as browser push subscriptions, Appilix/Firebase user identity, device notification tokens and delivery status.
  • Technical and security data such as IP address, browser, device type, language preference, logs, rate limits and anti-spam checks.

How we use information

  • To operate mailbox, CRM, supplier RFQ, product proposal, contact manager, message and quote request workflows.
  • To send and receive business emails and notifications for new emails, messages, quote requests and assigned tasks.
  • To verify contact or quote submissions with email OTP where enabled and reduce fake or spam enquiries.
  • To maintain communication history, staff accountability, audit logs and follow-up records.
  • To protect accounts, detect abuse, improve reliability and troubleshoot service issues.

Emails, contacts, attachments and CRM data

  • Emails and contacts are stored so authorized users can continue business conversations, reply, forward, prepare proposals and maintain follow-up records.
  • Attachments may be stored on the private server or configured archive storage. File names, sizes and references may be kept in MySQL.
  • Authorized senior staff may see staff communication records where required for supervision, business continuity, support and compliance. Staff visibility is restricted by permissions.

Notifications and device data

  • The app may use browser Push API, VAPID, Appilix Push API or Firebase Cloud Messaging for operational alerts.
  • Notification identity is used to target the correct authorized staff user.
  • Users can disable notifications from browser, device or app settings.

Data sharing

  • We do not sell personal or business contact data.
  • Data may be shared only with authorized internal users, hosting providers, email service providers, notification service providers, archive storage providers and relevant suppliers or buyers when required for a business workflow.
  • We may disclose information if required by law, security review, fraud prevention, dispute handling or protection of our services.

Storage, retention and security

  • Messages, quote requests, contacts, emails, CRM records, task notes and notification logs may be stored in MySQL and server storage.
  • Records may be retained for business follow-up, audit, security, dispute handling and legal compliance unless deletion is requested and is legally and operationally possible.
  • We use role-based access, login controls, 2FA options, CSRF protection, protected folders and database-backed permissions to reduce unauthorized access.

Your choices

  • Website visitors may request correction or deletion of contact details by using the contact page or emailing the grievance contact above.
  • Staff users should ask the authorized account manager to update, disable or remove account access.
  • Users should not submit highly sensitive personal information unless it is necessary for the business enquiry.