YoIndie

YoIndie · Legal

Privacy Policy

In effect from

This policy explains what personal data YoIndie ("we", "us") collects when you use YoIndie, why we collect it, who else sees it, and what you can do about it.

We are the controller of that data. You can reach us at contact@yoindie.com, or by post at 1 Example Street, Bengaluru, Karnataka 560001, India.

The short version

  • We collect what an account needs to exist and what a payment needs to clear. Nothing is collected to sell.
  • We do not sell personal data, and we do not share it for cross-context behavioural advertising.
  • We set one cookie, and it is the one that keeps you signed in.
  • You can ask us for a copy of your data, or for your account to be deleted, and we will do it within 30 days at no charge.

What we collect

What you give us

DataWhen
Name and email addressWhen you create an account
Password, stored only as a one-way hashIf you choose an email-and-password sign-in
Phone numberIf you sign in with a one-time code, or add one later
Profile photoIf you upload one
Billing name, address and tax identifiersWhen you buy something
The content of your messagesWhen you contact support
Email address, on its ownIf you join the waitlist before we have launched

We never see or store your card number. Card details are entered on the payment provider's own form and go directly to them; we receive a token, the last four digits, and whether the charge succeeded.

What we record automatically

  • Session records — a session identifier, the time you signed in, your IP address and your browser's user-agent string, for each device you are signed in on. Changing your password signs out every other device.
  • Security counters — a short-lived count of recent attempts, keyed to an IP address or an account, so that sign-in and one-time codes can be rate-limited. These expire within minutes.
  • Operational logs — errors and request metadata, kept briefly to diagnose faults.

We do not run analytics, advertising or session-recording scripts. If you add any, this section has to change.

What we get from others

If you sign in with Google, GitHub or Apple, that provider tells us your name, email address and profile photo, and confirms the sign-in. We do not receive your password and we cannot act on your account there.

If you pay, the payment provider tells us whether the payment went through. Those updates arrive as signed webhooks.

PurposeLegal basis (UK/EU GDPR)
Creating your account and signing you inPerformance of a contract
Taking payment and issuing receiptsPerformance of a contract; legal obligation
Sending service email — receipts, password resets, noticesPerformance of a contract
Keeping the service secure and rate-limitedLegitimate interests (preventing abuse and fraud)
Responding to your support requestsPerformance of a contract; legitimate interests
Keeping accounting and tax recordsLegal obligation
Deciding when to let you in, and emailing your invite, if you joined the waitlistConsent

Where we rely on consent — the waitlist — you can withdraw it at any time by asking us, and we will delete your address. Withdrawing does not affect anything we did before you asked.

Cookies

We set one cookie: the session cookie that keeps you signed in. It is HttpOnly (JavaScript cannot read it), Secure in production, and SameSite=Lax. Removing it signs you out; there is no way to use an account without it.

We do not set analytics or advertising cookies, which is why there is no cookie banner. Adding one of those changes that, and in the EU and UK it requires consent before the script loads — not a banner that assumes it.

Who else sees your data

We share personal data with the service providers below, each of which processes it on our instructions and for the purposes listed. This table reflects what is actually configured on this deployment.

RecipientPurposeWhat it receivesLocation
Vercel Inc.Application hosting and content deliveryIP address, request metadata, anything sent in a requestGlobal
Neon Inc.Managed PostgreSQL databaseAll stored account dataRegion you selected
Resend (Plus Five Five, Inc.)Transactional and announcement email deliveryEmail address, name, message contentUnited States

Beyond those, we disclose personal data only when the law requires it, to establish or defend a legal claim, or — if the business is ever sold or merged — to the acquirer, who would be bound by this policy until they gave you notice of a new one.

Where your data goes

Our providers operate internationally, so your data may be processed outside the country you live in, including in the United States. Where personal data leaves the UK or the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses or the UK Addendum, together with the provider's own safeguards.

How long we keep it

  • While your account is open, we keep your account data.
  • After you delete your account, we erase it within 30 days, apart from what we are required to keep.
  • Invoices and payment records are kept for as long as tax and accounting law requires — commonly seven years — because we are not permitted to delete them on request.
  • Session records and rate-limit counters expire on their own, in days and minutes respectively.
  • A waitlist address is kept while we are invite-only, because it is how we know whether to let you in. It is used only for messages about your access, such as your invite — no newsletter, no drip sequence, and it is never passed to anyone else. Once we open to everyone, addresses that never became an account are deleted within 30 days. Ask us at any time and we will remove it sooner.

How we protect it

Passwords are hashed with a slow, salted algorithm and are never stored or logged in a readable form. Traffic is encrypted in transit. Payment webhooks are signature-verified before we read them, and recorded once so that a replay cannot be counted twice. Endpoints that send a message or spend money are rate limited. Administrative actions are checked on the server on every request, never by hiding a button.

No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the relevant regulator within the time the law allows — 72 hours under the GDPR.

Your rights

Wherever you live, you can ask us to:

  • give you a copy of the personal data we hold about you;
  • correct anything that is wrong;
  • delete your account and its data;
  • restrict or object to a particular use;
  • export your data in a portable, machine-readable format;
  • withdraw consent you previously gave.

Your name, email address, phone number and photo can be changed yourself on the settings page, and take effect immediately. For anything else — a copy of your data, or deletion of your account — write to contact@yoindie.com. We answer within 30 days and we do not charge for it.

If you are in the UK or the EEA, you also have the right to complain to your national data protection authority. We would rather you came to us first, but that right stands regardless.

If you are in India, the Digital Personal Data Protection Act, 2023 gives you rights of access, correction, erasure and grievance redressal, and the right to nominate someone to exercise them if you die or become incapacitated. Our Grievance Officer can be reached at contact@yoindie.com; if you are not satisfied with the outcome you may approach the Data Protection Board of India.

If you are in California, you have the right to know, delete and correct your personal information, and to opt out of its sale or sharing. We do not sell or share personal information, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.

Children

YoIndie is not for children. We do not knowingly collect personal data from anyone under 16 — or under 18 where local law sets that bar, as India's DPDP Act does. If you believe a child has given us data, tell us and we will delete it.

Changes

If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always shows the current version.

Contact

YoIndie
1 Example Street, Bengaluru, Karnataka 560001, India
contact@yoindie.com