This policy describes what data Tripzygo OMS handles, why, where it is stored, who can reach it, and when it is deleted. It is written for the product it covers: an order management system that processes marketplace order data on behalf of sellers.
Tripzygo OMS is operated by Tripzygo Rovara Travels Private Limited (“Tripzygo”, “we”, “us”), registered in India. Our contact details are at the end of this policy and on the Contact page.
For data relating to your own business account — your name, email, company details, billing records — we act as the controller. For marketplace order data that flows through the system, including buyer names and delivery addresses, we act as a processor on your instructions: you decide why it is processed, and we process it only to provide the OMS functionality you have subscribed to.
We collect four categories of data, and nothing beyond what the features require.
When you connect a marketplace channel, we retrieve the orders placed on that channel. This includes the marketplace order identifier, order date, items and quantities, order value and payment mode, dispatch deadline, order status, courier and tracking identifiers, and return or RTO status.
Order data also contains buyer personal information supplied by the marketplace: the buyer’s name, delivery address, and the contact phone number or masked number required for delivery. We retrieve it because a shipping label cannot be produced without it. We do not enrich it, cross-reference it against other datasets, or use it to build any profile of the buyer.
Your SKUs, product titles, channel listing identifiers, stock quantities per location, buffers, and the stock movement ledger. This data is yours and is used to keep availability consistent across your connected channels.
Channels are connected through each marketplace’s own authorisation flow. You sign in at the marketplace, not with us, and grant Tripzygo OMS access to the specific scopes the integration needs. We receive and store the resulting access and refresh tokens. We do not ask for, and have no use for, your marketplace seller-panel password.
Where a marketplace integration requires API keys rather than an OAuth flow, those keys are treated with the same protections as tokens, described in section 4.
Your name, business name, email address, phone number, GSTIN and billing address; the user accounts and roles you create; and technical records generated by using the application, including login timestamps, IP address at login, audit log entries for changes made in the system, and integration logs recording the API calls we make on your behalf and their outcomes.
Payments are processed by a payment provider. We receive a transaction reference and the last four digits of the instrument used; we do not receive or store full card numbers.
This website sets no advertising or tracking cookies. A single session cookie is used to keep you signed in to the application. We do not run third-party advertising or analytics scripts on oms.tripzygo.in.
We use the data solely to provide the OMS functionality described on this site. Specifically: to retrieve and display your orders in one queue; to update order status back to the marketplace; to reserve and synchronise stock across your channels; to generate shipping labels, manifests, packing slips and invoices; to track returns and RTO shipments and record quality-check outcomes; to match settlement reports against orders and flag deductions and short payments; to run dispatch-deadline clocks and send SLA alerts; and to produce the reports and exports you request.
We also use account data to administer your subscription, issue invoices, respond to your support requests, and send service notices such as an integration failure, a scheduled maintenance window or a security advisory. Service notices are not marketing; we do not send marketing email to buyers, and we do not send it to sellers who have not asked for it.
Aggregate, non-identifying operational metrics — such as total API call volume or error rates per integration — are used to keep the service reliable.
What we never do with this data
We do not sell it. We do not rent, licence or trade it. We do not use buyer personal information for advertising, marketing, remarketing or profiling. We do not use one seller’s data to benefit another seller. We do not train machine-learning models on your order data or your buyers’ personal information. We do not use marketplace data for any purpose other than operating the features you have subscribed to.
All application data is stored encrypted at rest using AES-256 encryption. This covers the primary database, file storage holding generated labels, manifests and imported settlement reports, and database backups.
Our application servers, databases and backups are hosted on infrastructure provided by Hostinger, in Hostinger data centres located in India. Order data, inventory data, credentials and backups remain within Indian data centres. We do not replicate this data to regions outside India.
Backups are taken on a regular schedule, encrypted, and retained for a rolling 30-day window before being destroyed. Backup restoration is a controlled operation performed only to recover from failure or data loss.
Each seller account’s data is logically separated, and every query in the application is scoped to the account of the signed-in user. One customer cannot read another customer’s orders, inventory, credentials or settlements.
In transit. All traffic to the application and all calls between Tripzygo OMS and marketplace APIs use TLS 1.2 or higher. Plain HTTP requests to oms.tripzygo.in are redirected to HTTPS. Internal service-to-service traffic is likewise encrypted.
Credentials. Marketplace OAuth access and refresh tokens are encrypted with AES-256 before they are written to storage and are never stored in plaintext. Decryption keys are held separately from the encrypted data, in a managed secret store, and are not accessible to application users or to our own staff through the application. Tokens are decrypted only in memory, at the moment an authorised API call is made on your behalf. They are never written to application logs, error reports or support tickets. Your Tripzygo OMS account password is stored only as a salted one-way hash and cannot be recovered by us or by anyone else.
Access controls. Access to your data inside the application is governed by the roles you assign. Buyer contact details are restricted to roles that need them for fulfilment. On our side, administrative access to production systems is limited to the small number of staff whose work requires it, granted on a least-privilege basis, protected by multi-factor authentication, reviewed periodically, and revoked when a person’s role changes or they leave. Our staff do not browse customer data; access for a support investigation happens on your request and is logged.
Audit logging. Changes to order, inventory, return and settlement records are recorded with the acting user, timestamp and prior value. Authentication events, permission changes and credential connections or revocations are logged. Account owners can review the audit log for their account. Logs are retained for review and are themselves protected against modification.
Our security measures are described in more detail on the Data Security page, including incident response and vulnerability management.
We do not sell your data, and we do not share it with third parties for their own purposes. There is no advertising network, data broker or marketing partner in this picture.
Data is disclosed in only these circumstances:
Hostinger provides the hosting infrastructure on which the application and database run, in Indian data centres. Hostinger holds the data as our infrastructure provider and does not use it for any purpose of its own. Hostinger is our only subprocessor with access to hosted seller data.
When you confirm, ship or cancel an order, that update is sent to the marketplace it belongs to, using your own authorisation. This is the purpose of the integration. We send only the operation being performed; we do not send one marketplace any data belonging to another.
Where a shipment is booked through a courier integration you have enabled, the delivery details required to produce the label and move the parcel are passed to that courier. Nothing beyond what the shipment requires is sent.
Your billing transactions are handled by a payment provider, which receives only what is needed to take the payment. Separately, we may disclose data where we are legally required to do so by a valid order from a competent Indian authority, or where disclosure is necessary to establish or defend a legal claim. Where we are permitted to inform you of such a request, we will.
If we ever add a subprocessor with access to seller data, this policy will be updated to name it before that access begins, and account owners will be notified by email.
Buyer personal information is purged within 30 days of order delivery. Once an order reaches a final state and the delivery is complete, the buyer’s name, delivery address and contact number are deleted from the order record within 30 days. Where a return or RTO is in progress, purging occurs within 30 days of that case closing, because the address is needed to complete the return. What remains after purging is the non-personal commercial record — order identifier, channel, SKUs, quantities, values, dates, deductions — which is what reconciliation, tax records and reporting actually need.
Order history. Non-personal order records are retained in the application for the period included in your plan — 90 days on Starter, 12 months on Growth, as agreed for Enterprise — and can be exported at any time before that.
Credentials. When you disconnect a channel, or when your account is closed, the stored OAuth tokens for that channel are deleted and, where the marketplace supports revocation, revoked. You can also revoke our access directly from your marketplace seller account at any time.
Full account deletion on request. Write to us from the account owner’s registered email address and we will delete your account data within 30 days of the request. This covers your orders, inventory, returns, settlement records, stored credentials, users and audit logs. Deletion propagates to backups as they age out of the rolling 30-day backup window, after which no copy remains. We retain only the invoices and transaction records we are required to keep under Indian tax and company law, which contain your business billing details and no buyer personal information.
If your subscription lapses without a deletion request, the account is retained in a suspended state for 60 days so you can export your data or resume, and is then deleted on the same basis.
You can access and export your data from within the application at any time. You can ask us to correct your account details, restrict processing, or delete your account data. You can withdraw a channel authorisation whenever you choose, and doing so stops all further processing for that channel.
Where a buyer contacts you about their personal information in an order you fulfilled, you are the seller of record and we will support you in responding, including by deleting or supplying the relevant records on your instruction. Buyers who contact us directly will be directed to the seller who holds the relationship, and we will notify you.
Send any request to gaurangpatel@tripzygo.in. We acknowledge requests within 3 business days and complete them within 30 days. We may ask you to verify that you are the account owner before acting on a deletion request.
Tripzygo OMS is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 18.
If we change this policy, the updated version will be published on this page with a new “last updated” date. Where a change materially affects how we handle your data or adds a subprocessor, we will notify account owners by email before it takes effect.
Questions about this policy, data requests, or anything you believe we have handled incorrectly: