YoIndie · Legal
Privacy Policy
In effect from
This policy explains what personal data YoIndie ("we", "us") collects when you use YoIndie, why we collect it, who else sees it, and what you can do about it.
We are the controller of that data. You can reach us at contact@yoindie.com, or by post at 1 Example Street, Bengaluru, Karnataka 560001, India.
The short version
- We collect what an account needs to exist and what a payment needs to clear. Nothing is collected to sell.
- We do not sell personal data, and we do not share it for cross-context behavioural advertising.
- We set one cookie, and it is the one that keeps you signed in.
- You can ask us for a copy of your data, or for your account to be deleted, and we will do it within 30 days at no charge.
What we collect
What you give us
| Data | When |
|---|---|
| Name and email address | When you create an account |
| Password, stored only as a one-way hash | If you choose an email-and-password sign-in |
| Phone number | If you sign in with a one-time code, or add one later |
| Profile photo | If you upload one |
| Billing name, address and tax identifiers | When you buy something |
| The content of your messages | When you contact support |
| Email address, on its own | If you join the waitlist before we have launched |
We never see or store your card number. Card details are entered on the payment provider's own form and go directly to them; we receive a token, the last four digits, and whether the charge succeeded.
What we record automatically
- Session records — a session identifier, the time you signed in, your IP address and your browser's user-agent string, for each device you are signed in on. Changing your password signs out every other device.
- Security counters — a short-lived count of recent attempts, keyed to an IP address or an account, so that sign-in and one-time codes can be rate-limited. These expire within minutes.
- Operational logs — errors and request metadata, kept briefly to diagnose faults.
We do not run analytics, advertising or session-recording scripts. If you add any, this section has to change.
What we get from others
If you sign in with Google, GitHub or Apple, that provider tells us your name, email address and profile photo, and confirms the sign-in. We do not receive your password and we cannot act on your account there.
If you pay, the payment provider tells us whether the payment went through. Those updates arrive as signed webhooks.
Why we use it, and on what legal basis
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Creating your account and signing you in | Performance of a contract |
| Taking payment and issuing receipts | Performance of a contract; legal obligation |
| Sending service email — receipts, password resets, notices | Performance of a contract |
| Keeping the service secure and rate-limited | Legitimate interests (preventing abuse and fraud) |
| Responding to your support requests | Performance of a contract; legitimate interests |
| Keeping accounting and tax records | Legal obligation |
| Deciding when to let you in, and emailing your invite, if you joined the waitlist | Consent |
Where we rely on consent — the waitlist — you can withdraw it at any time by asking us, and we will delete your address. Withdrawing does not affect anything we did before you asked.
Cookies
We set one cookie: the session cookie that keeps you signed in. It is
HttpOnly (JavaScript cannot read it), Secure in production, and
SameSite=Lax. Removing it signs you out; there is no way to use an account
without it.
We do not set analytics or advertising cookies, which is why there is no cookie banner. Adding one of those changes that, and in the EU and UK it requires consent before the script loads — not a banner that assumes it.
Who else sees your data
We share personal data with the service providers below, each of which processes it on our instructions and for the purposes listed. This table reflects what is actually configured on this deployment.
| Recipient | Purpose | What it receives | Location |
|---|---|---|---|
| Vercel Inc. | Application hosting and content delivery | IP address, request metadata, anything sent in a request | Global |
| Neon Inc. | Managed PostgreSQL database | All stored account data | Region you selected |
| Resend (Plus Five Five, Inc.) | Transactional and announcement email delivery | Email address, name, message content | United States |
Beyond those, we disclose personal data only when the law requires it, to establish or defend a legal claim, or — if the business is ever sold or merged — to the acquirer, who would be bound by this policy until they gave you notice of a new one.
Where your data goes
Our providers operate internationally, so your data may be processed outside the country you live in, including in the United States. Where personal data leaves the UK or the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses or the UK Addendum, together with the provider's own safeguards.
How long we keep it
- While your account is open, we keep your account data.
- After you delete your account, we erase it within 30 days, apart from what we are required to keep.
- Invoices and payment records are kept for as long as tax and accounting law requires — commonly seven years — because we are not permitted to delete them on request.
- Session records and rate-limit counters expire on their own, in days and minutes respectively.
- A waitlist address is kept while we are invite-only, because it is how we know whether to let you in. It is used only for messages about your access, such as your invite — no newsletter, no drip sequence, and it is never passed to anyone else. Once we open to everyone, addresses that never became an account are deleted within 30 days. Ask us at any time and we will remove it sooner.
How we protect it
Passwords are hashed with a slow, salted algorithm and are never stored or logged in a readable form. Traffic is encrypted in transit. Payment webhooks are signature-verified before we read them, and recorded once so that a replay cannot be counted twice. Endpoints that send a message or spend money are rate limited. Administrative actions are checked on the server on every request, never by hiding a button.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the relevant regulator within the time the law allows — 72 hours under the GDPR.
Your rights
Wherever you live, you can ask us to:
- give you a copy of the personal data we hold about you;
- correct anything that is wrong;
- delete your account and its data;
- restrict or object to a particular use;
- export your data in a portable, machine-readable format;
- withdraw consent you previously gave.
Your name, email address, phone number and photo can be changed yourself on the settings page, and take effect immediately. For anything else — a copy of your data, or deletion of your account — write to contact@yoindie.com. We answer within 30 days and we do not charge for it.
If you are in the UK or the EEA, you also have the right to complain to your national data protection authority. We would rather you came to us first, but that right stands regardless.
If you are in India, the Digital Personal Data Protection Act, 2023 gives you rights of access, correction, erasure and grievance redressal, and the right to nominate someone to exercise them if you die or become incapacitated. Our Grievance Officer can be reached at contact@yoindie.com; if you are not satisfied with the outcome you may approach the Data Protection Board of India.
If you are in California, you have the right to know, delete and correct your personal information, and to opt out of its sale or sharing. We do not sell or share personal information, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.
Children
YoIndie is not for children. We do not knowingly collect personal data from anyone under 16 — or under 18 where local law sets that bar, as India's DPDP Act does. If you believe a child has given us data, tell us and we will delete it.
Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always shows the current version.
Contact
YoIndie1 Example Street, Bengaluru, Karnataka 560001, India
contact@yoindie.com