IndiSell Reach

Privacy Policy

Last updated 13 September 2026

IndiSell Reach (“Reach”, “we”, “us”) is a WhatsApp and Instagram marketing and customer-conversation platform operated by Remold Technologies (“Remold”), a partnership firm registered in India (GSTIN 24ABNFR4980N1ZE) and the company behind the IndiSell brand. This policy explains what personal data we collect, how and why we use it, who we share it with, and the choices and rights you have. It is written to align with India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the requirements of the platforms we build on.

Our two roles

We act in two capacities:

As a Data Fiduciary (controller) for the account data of the businesses that sign up for Reach — your business details, the login and profile of your team members, and billing records.

As a Data Processor for the personal data of your customers that you bring into or generate through Reach — the phone numbers, names, message content and order data of the people you converse with. For that data you are the Data Fiduciary; we process it only on your instructions, to provide the service. You are responsible for having a lawful basis (such as opt-in consent) to message those customers.

What we collect

Account & team data: business name, your name, email, role, and password (stored only as a secure hash).

Customer conversation data: contact phone numbers, names, tags and attributes; the content of messages and media you send and receive; delivery, read and reply status; opt-in and opt-out state.

Commerce data: orders, carts, coupons and product data — either entered in Reach or synced from stores you connect (Shopify, WooCommerce, IndiSell and others).

Payment data: when you collect payments from your customers, or pay for your Reach subscription, the payment is processed by our payment partners. We receive transaction status and references; we do not collect or store full card numbers, CVV, UPI PINs or bank credentials — those are handled by the gateway on PCI-DSS-compliant systems.

Technical data: IP address, device and browser information, and server logs needed to run and secure the service. A single session cookie keeps you signed in; we do not use advertising or cross-site tracking cookies.

How we use it

To deliver the service: send and receive WhatsApp and Instagram messages on your behalf, run campaigns and automations, power the shared inbox, bot flows and the AI assistant, process orders and payments, show analytics, and provide support. We use account and billing data to operate your subscription, and technical data to keep the platform secure and reliable. We do not sell your data or your customers’ data, and we do not use it for our own advertising.

Consent & marketing

Marketing messages may be sent only to people who have opted in, as required by WhatsApp’s and Meta’s policies. Recipients can opt out at any time (for example by replying STOP); we record that and stop messaging them. You are responsible for obtaining and honouring consent for the customers you upload or message.

WhatsApp & Meta data

We process WhatsApp and Instagram data through the Meta WhatsApp Cloud API and Instagram Messaging API, under Meta’s terms. Access tokens for your connected numbers are encrypted at rest. Data you exchange through these channels is also subject to Meta’s own privacy policy.

AI processing

When you enable the AI assistant or AI features (such as reply suggestions or template generation), the relevant message or prompt content is sent to our AI providers to generate a response. We use providers that do not train their models on data sent through their business APIs. AI features are optional and can be turned off in your settings.

Who we share it with (sub-processors)

We share data only with the providers needed to run Reach, and only as needed:

• Meta Platforms — WhatsApp Cloud API and Instagram Messaging.
• Payment gateways — Easebuzz and Razorpay, to collect payments.
• AI providers — to generate assistant replies and drafts.
• Hosting & database — our cloud infrastructure and managed database providers.
• Communications — email and operational-alert providers.

We also disclose data where required by law, to enforce our terms, or to protect the rights and safety of users. We do not otherwise share your data with third parties.

International transfers

Some of our providers (for example certain AI or infrastructure services) may process data outside India. Where that happens we rely on appropriate safeguards and transfer only what is necessary to provide the service, consistent with the DPDP Act and any restrictions notified by the Government of India.

Security

We protect data with encryption in transit (TLS), encryption at rest for sensitive credentials such as channel access tokens, hashed passwords, access controls, and least-privilege practices. No system is perfectly secure, but we work to protect your data and will notify you and the relevant authority of a reportable breach as required by law.

Retention & deletion

We keep data while your account is active and as needed to provide the service and meet legal, tax and accounting obligations. You can delete individual contacts, messages, campaigns and products in-app, and request full deletion of your workspace at any time — see our Data Deletion page. On a verified request we complete workspace deletion within 30 days.

Your rights

Subject to applicable law, you may request to access, correct or update, or erase your personal data; withdraw consent; nominate another person to exercise your rights in the event of death or incapacity; and raise a grievance. To exercise any of these, email us from your registered address. Businesses can also action most of these directly in the dashboard.

Grievance Officer & contact

In line with the DPDP Act and the Information Technology rules, you can raise any privacy question, request or complaint with our Grievance Officer, and we will acknowledge and resolve it within the timelines the law requires:

Grievance Officer, Remold Technologies
B-6002, Ascon Plaza, Anand Mahal Road, Adajan, Surat, Gujarat 395009, India
Email: hello@indisell.io
GSTIN: 24ABNFR4980N1ZE

Children

Reach is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children; if you believe a child’s data has reached us, contact us and we will delete it.

Changes to this policy

We may update this policy as the service and the law evolve. We will change the “last updated” date above and, for material changes, notify you in-app or by email.

Contact

Product questions or support: support@indisell.io. Privacy requests and grievances: hello@indisell.io.

This document is provided for transparency and does not constitute legal advice. Remold Technologies recommends having independent counsel review it against your specific circumstances.