Privacy Policy

Effective date: 28 September 2026

This Privacy Policy explains how BAGBROS, operated by VYNSAR ENTERPRISES, handles personal information through bagbros.in, the Bagbros customer Android app and the Bagbros Admin Android app.

Who is responsible and how to contact us

VYNSAR ENTERPRISES, K-1, Sanjay Gandhi Puram, Indira Nagar, Lucknow 226016, Uttar Pradesh, India. GSTIN: 09AAZFV4142M1Z8. For privacy questions, corrections, complaints or deletion requests, email support@bagbros.in. Please use the subject “Bagbros privacy request”.

Information we collect

  • Account information: name, email, username, phone number, password hash and sign-in/session records. With Google sign-in, we receive your Google account identifier and basic account information such as name and verified email; we do not receive your Google password.
  • Shopping and delivery information: cart contents, saved addresses, PIN code, selected delivery service, orders, discounts, payment status and references, invoices, returns and shipment tracking. PIN codes help suggest your city and state; the app does not need GPS location for this.
  • Communications: support requests, replies and information you choose to send us. Verification codes and transaction emails are used to confirm accounts, COD orders and important order activity.
  • App and security information: notification registration tokens, notification choices, app type, device notification availability, IP addresses and service/security logs. The admin app also records authorised store-management activity and product media selected for upload.
  • Website information: cookies and similar storage needed for login, cart and preferences. Reviews or comments you publish can be visible to other visitors. External content and services may receive browser/network information when you use them.

Why we use it

We use this information to provide accounts and shopping features, verify requests, process and deliver orders, produce invoices, support customers, prevent misuse, maintain service reliability and meet accounting or legal obligations. If you choose promotional notifications, we also send offers, coupons and sale announcements. If you separately choose cart reminders, we use your cart activity to remind you about unfinished shopping.

Push notifications and your choices

Push delivery uses Google Firebase Cloud Messaging. Firebase uses an app installation identifier and notification token to deliver messages. Notifications require device permission where applicable. In the customer app, open Account → Notifications to control order updates, support replies, offers and cart reminders. Offers and cart reminders are optional and off until you enable them. You can change these choices or disable notifications in Android Settings at any time. Choosing not to receive marketing does not prevent shopping. Essential verification and transaction emails may still be sent.

Cart reminders are delayed after activity, limited in frequency and stopped when our system records checkout or an empty cart. Prices, availability and coupon eligibility are always checked at checkout. A notification does not reserve stock or guarantee an offer.

Service providers and sharing

We share the information needed to provide the service with hosting and email providers (including Hostinger), Google for sign-in and Firebase messaging, Razorpay for online payments, Shiprocket and delivery partners for fulfilment, and support tools used by Bagbros. Our store runs on WordPress/WooCommerce. Providers may process information outside India under their own terms and privacy notices. We may also disclose necessary records to professional advisers, authorities or other recipients when required by law or to address fraud and disputes.

Payment details entered into Razorpay checkout are processed by Razorpay and its payment partners. Bagbros receives payment references and status; we do not store your full card number, CVV or UPI PIN. Never send these or account passwords to support. The native apps do not include advertising or Google Analytics SDKs.

Storage, security and retention

We use encrypted network connections, restricted administrative access and protected authentication storage. No system can guarantee absolute security. Account data is kept while needed to provide your account. We retain order, tax, invoice and payment records as required for accounting, applicable law, refunds and dispute resolution, including when eligible account data is deleted. Support and security records are retained only while needed for those purposes. Expired app authentication/verification records are cleaned up, and inactive notification registrations are removed after 90 days without an update. Backup copies may persist until their normal replacement cycle and are restricted from routine use.

Delete your Bagbros account or request your data

You can request deletion without reinstalling the app: email support@bagbros.in from your registered email address with the subject “Delete my Bagbros account”. State that you want your account and associated personal data deleted. Do not include a password or payment credentials. If you cannot access that email, contact us for identity verification.

Alternatively, in the customer app choose Account → Request account deletion and confirm with your account password. We verify ownership, remove eligible account/profile data and notification registrations, and explain any records that must be retained for legal, accounting, security or unresolved transaction reasons. You may also request access, correction or a copy of your personal data by emailing support. Uninstalling the app alone does not delete your account. Store-owner accounts require assisted closure so that customer and business records are handled appropriately.

Children and updates

The apps are not intended for children to create accounts or make purchases independently. A parent or guardian should manage purchases for children. Contact us if a child has submitted personal information without appropriate permission. We may update this policy when our services or requirements change; the current version and effective date will be published here.

Native payment SDK information

If you choose prepaid payment, the Razorpay Android checkout SDK and its payment partners may process payment details, contact information supplied for checkout, transaction events, device and app identifiers, compatible payment-app information, and diagnostic or crash information to provide payments, prevent fraud and maintain payment reliability. These SDK records are distinct from the payment references retained by the store. The payment SDK can access an advertising identifier where the device permits it; our Android apps do not request the Android 13 advertising-ID permission, so that identifier is zeroed on those devices. This does not add advertising to the app. Choosing cash on delivery avoids opening prepaid checkout.

Staff administration app

The admin app is available only to authorised staff. It uses staff names, email addresses, account and session identifiers, security and audit activity to authenticate access and manage the store. Customer information, orders, support messages, campaign emails, product content, images and files entered through the workspace are used only for the selected store operations. Staff information and session or activity records are required for secured administration; media uploads and individual operational submissions are made when those features are used. Contact the support address on this page to request access, correction or deletion; business and security records may be retained where required.

Teenage customers and supervised purchases

The customer app is intended for teenage and adult shoppers aged 13 and above. Customers under 18 should involve a parent or guardian, and purchases or payments must be authorised by an adult. The app is not designed for unsupervised accounts or purchases by children under 13.

Cart