We use essential cookies to keep you signed in and to secure checkout, and optional cookies for personalization. See our Privacy Policy and Cookie Policy.

Data Security & Protection

Version 2.2 · Effective 2026-09-09

Suffle Online

Operated by Naucera Travel Private Limited

1. Purpose and Scope

Suffle Online is committed to protecting the confidentiality, integrity, availability and appropriate use of information processed through its marketplace, applications, websites, AI features, seller systems, connected services and supporting infrastructure.

This Policy describes the security and protection controls and practices that Suffle Online intends to apply to personal data, account information, seller information, order and transaction records, documents, communications, connected-account data and other information processed through Suffle.

This Policy is a security and protection document. Detailed privacy choices, data categories, lawful bases, notices, retention and individual rights are addressed in the Suffle Online Privacy Policy.

2. Company and Contact

Suffle Online is operated by Naucera Travel Private Limited.

Website: www.suffleonline.com

General Support / Grievance Email: info@flyshoppy.com

Grievance Officer: Mr. Roopal Jain, Managing Director

Grievance Officer Mobile: 9707669981

Grievance Officer Email: info@flyshoppy.com

Registered/Business Address: 707, N. T. Road, Nalbari-781435 (Assam), India.

3. Security Principles

Suffle applies a risk-based security approach and seeks to maintain appropriate technical and organisational safeguards.

Core principles include data minimisation, least-privilege access, authentication, segregation of duties, secure development, monitoring, resilience, controlled disclosure, incident response and accountability.

Security controls may be strengthened or adjusted as the platform, threats, applicable law and technology evolve.

4. Data Covered by this Policy

Depending on the service used, security controls may apply to account and profile information; contact information; seller and business verification information; order, shipping and return information; payment and settlement records; customer-uploaded customization files; documents; communications; connected-app and authorised email data; AI inputs and outputs; support records; logs and security telemetry; and other information processed for Suffle services.

Not all categories are collected from every user. Processing depends on the feature, role, permissions and lawful purpose.

5. Data Classification

Suffle may classify information according to sensitivity and operational risk. Examples include public marketplace content, internal operational information, confidential seller/customer information, authentication/security information, and highly sensitive information requiring restricted handling.

Access and protection requirements may vary according to the classification, legal obligations and business need.

6. Encryption and Protection in Transit

Suffle intends to use appropriate encryption and secure transport mechanisms for data transmitted over networks, including authenticated and encrypted connections where appropriate.

Encryption is not represented as an absolute guarantee against every attack. Controls are selected according to risk, system architecture and applicable requirements.

7. Encryption, Masking and Protection at Rest

Where appropriate, Suffle may use encryption, masking, tokenisation, obfuscation, hashing or equivalent safeguards for stored information and secrets.

Sensitive credentials and security secrets are subject to restricted storage and access controls. Payment authentication secrets such as CVV, UPI PIN, ATM PIN, payment PIN and banking passwords should never be provided to Suffle.

8. Authentication and Account Security

Suffle may use passwords, OTPs, OAuth, session controls, multi-factor authentication or other authentication mechanisms depending on the service.

Authentication credentials and session secrets must not be exposed to AI systems, sellers, unauthorised employees or other customers.

Users are responsible for maintaining the confidentiality of their credentials and promptly reporting suspected account compromise.

9. Least Privilege and Access Control

Access to systems and information is intended to follow least-privilege and need-to-know principles.

Administrative access should be restricted, authenticated, logged and reviewed according to role and risk.

Seller accounts must be isolated so a seller can access only information authorised for that seller. Customers must not be able to access another customer's private data.

10. Segregation of Marketplace Data

Suffle uses central systems for products, sellers, carts, orders, payments, fulfilment, returns, refunds and settlements.

Multi-seller transactions may use a master order with seller-specific sub-orders. Seller access must be restricted to the seller's own sub-order and authorised operational information.

Customer customization files, private documents and other restricted material must not become public product media merely because they are uploaded during an order or request.

11. Payment and Financial Information

Suffle separates marketplace order payments from WhatsApp/software subscription billing.

Razorpay is used for Suffle payment processing as configured for the platform. Payment verification must be performed server-side and must not rely solely on a browser success screen.

Suffle should not store or expose full payment authentication secrets such as CVV, UPI PIN, ATM PIN, payment PIN or banking passwords.

Financial records, payment status, refunds, commissions and settlements must be protected with appropriate access controls and audit trails.

12. Secrets, API Keys and Tokens

API keys, OAuth tokens, session tokens, webhook secrets, encryption keys and other credentials must be treated as confidential security material.

Secrets should not be placed in public source code, public logs, customer-visible interfaces, AI prompts or seller dashboards.

Where third-party integrations are enabled, credentials should be scoped to the minimum permissions required and revoked when no longer required.

13. Connected Apps and Accounts

Connections to third-party apps and accounts must use legitimate authentication or authorisation mechanisms supported by the provider.

Suffle will not intentionally bypass CAPTCHA, MFA, OTP, provider security controls or access restrictions.

Raw third-party passwords should not be exposed to Suffle AI or administrative users. Connection status must be based on verifiable authentication/authorisation state.

14. Email and Gmail Data Security

Where a user voluntarily connects an email account, Suffle should use authorised mechanisms such as OAuth where supported.

Access should be limited to the permissions required for the enabled feature. Relevant extracted information should be protected under the same security controls as other Suffle data.

Email credentials and OAuth secrets must not be exposed to AI, sellers or unauthorised personnel.

15. AI and Automated Processing Security

Suffle uses one central Super AI / Universal AI architecture across applicable features. Security controls must apply to AI inputs, outputs, connected data and tool permissions.

AI must not be granted unrestricted access to customer, seller, payment or administrative data merely because it is capable of processing text.

AI must not be used to invent payment success, balances, prices, availability, tracking, refunds, provider status, certifications or other factual system states.

Sensitive actions should require appropriate backend authorisation and, where required, explicit user confirmation or human/admin approval.

16. Logging, Monitoring and Audit Trails

Suffle may maintain security, access, administrative, application and transaction logs to detect misuse, investigate incidents, maintain service integrity and satisfy applicable legal requirements.

Logs should be protected against unauthorised modification and access and should contain only information reasonably necessary for their purpose.

Security-relevant administrative actions, policy changes, payment verification events, order state changes and other material operations should be auditable.

17. Vulnerability Management and Secure Development

Suffle should use secure development practices appropriate to the platform, including code review, dependency management, vulnerability identification, patching and controlled deployment.

Critical security weaknesses should be prioritised according to risk.

Third-party components and services should be evaluated for security and operational suitability before material use.

18. Malware and File Security

Uploaded files, including seller documents, product media and customer customization files, may be subject to file-type validation, size limits, malware scanning and access controls.

Customer customization images/files are private to the relevant request/order unless the customer separately authorises another use.

Product showcase media and customer-provided customization media must remain logically distinct.

19. Backup, Availability and Recovery

Suffle should maintain appropriate backups and recovery capabilities for critical systems and information.

Backups should be protected from unauthorised access and should be tested periodically where appropriate.

Recovery priorities should reflect service criticality, data integrity, customer impact and applicable legal obligations.

20. Incident Detection and Response

Suffle maintains an incident-response approach intended to identify, contain, investigate, remediate and learn from security incidents.

Potential incidents may include unauthorised access, credential compromise, malware, data leakage, service compromise, suspicious administrative activity or loss of availability.

Response actions may include account/session protection, access revocation, system isolation, forensic investigation, restoration, remediation and communication where required.

21. Personal Data Breaches

Where a personal data breach occurs, Suffle will assess the nature, scope, impact and applicable legal requirements and take appropriate response measures.

Where legally required, notifications or other communications will be made through the applicable channels and within the required timelines.

Suffle will maintain appropriate records of incidents and response actions.

22. CERT-In and Legal Cybersecurity Requirements

Suffle intends to comply with applicable cybersecurity requirements, including requirements that may apply under the Information Technology Act, CERT-In directions and other applicable laws or regulations.

Where applicable, Suffle will maintain required logs, incident-response records and reporting mechanisms and cooperate with competent authorities in accordance with law. CERT-In's directions include requirements concerning incident reporting, ICT-system logs and related cybersecurity practices. citeturn0search0turn0search26

23. Data Processors and Service Providers

Suffle may use service providers such as hosting, cloud, payment, messaging, analytics, security, communication and other technology providers.

Where required and appropriate, contractual arrangements should require security safeguards, confidentiality, restricted processing and cooperation with incident response.

Service providers should receive only the data and access reasonably required for the service.

24. Employee, Contractor and Administrator Security

Personnel with access to confidential information should receive appropriate access permissions and security responsibilities.

Administrative privileges should be restricted and reviewed. Personnel should not use customer or seller data for unrelated personal purposes.

Confidential information must remain protected after employment, engagement or access termination to the extent applicable.

25. Seller Security Responsibilities

Sellers must protect their Suffle accounts, authorised users, devices and information and must not attempt to access another seller's or customer's information.

Sellers must not upload passwords, OTPs, payment PINs, banking passwords or other prohibited authentication secrets into product, order, support or customization fields.

Sellers are responsible for maintaining appropriate security of information they independently control outside Suffle.

26. Customer Security Responsibilities

Customers should use strong, unique credentials where passwords are used, protect OTPs and authentication devices, and avoid sharing account access.

Customers should report suspected unauthorised access, fraudulent activity, lost devices or compromised credentials promptly.

Customers should not upload sensitive authentication secrets to Suffle.

27. Data Retention and Secure Disposal

Information should be retained only for as long as necessary for the relevant purpose, legal obligations, dispute resolution, security, accounting, fraud prevention or other legitimate operational requirements.

When information is no longer required, Suffle should securely delete, anonymise, de-identify or otherwise dispose of it where appropriate and technically feasible.

Specific retention periods are addressed in the Privacy Policy and relevant specialized policies.

28. Security Testing and Continuous Improvement

Suffle may conduct security reviews, vulnerability assessments, penetration testing, configuration reviews, access reviews and other assurance activities appropriate to risk.

Security controls may be changed as threats, technology, architecture, legal requirements and business operations evolve.

29. Responsible Disclosure

Security researchers and users who identify a suspected vulnerability should report it responsibly through the available support or security contact channel and provide sufficient information to help investigation.

Do not exploit, access, alter, destroy, exfiltrate or disclose other users' information while testing or reporting a suspected vulnerability.

Reports should avoid unnecessary exposure of personal or confidential data.

30. Limitations and Security Disclaimer

No online service can guarantee absolute security. Suffle will implement reasonable and appropriate safeguards but cannot guarantee that every attack, vulnerability, outage, human error or third-party compromise will be prevented.

Nothing in this Policy limits rights or obligations that cannot legally be excluded.

31. Relationship with Other Policies

This Policy should be read with the Suffle Online Privacy Policy, Terms & Conditions, Connected Apps & Accounts Policy, Gmail/Email Data Policy, Payment Information Policy, Suffle AI Terms, AI Tracking / Automated Processing Notice, WhatsApp / Business Messaging Policy, Document Policy and other applicable policies.

Where a specialised policy provides more specific security or handling rules for a feature, those rules apply to that feature in addition to this Policy.

32. Policy Changes

Suffle may update this Policy when its security practices, technology, services, legal obligations or risk environment changes.

Material changes may be communicated through appropriate channels. The effective version should be maintained in Suffle's central legal/policy system.

33. Legal and Implementation Note

This Policy is intended to describe Suffle's security framework and should not be treated as a representation that every listed control has already been technically deployed unless the relevant system documentation confirms deployment.

The platform should implement and test the controls described here before representing them as operational security measures.

This Policy should be reviewed by qualified Indian legal counsel and, where appropriate, an information-security professional before publication and before activating material new data-processing or connected-service features.

Key Security Commitments

·       Least-privilege access and role-based isolation for customers, sellers and administrators.

·       Protection of sensitive credentials and prohibition on exposing OTPs, PINs, CVV, banking passwords and similar secrets.

·       Server-side verification for marketplace payment state and auditable financial events.

·       Security controls for connected accounts, uploaded files, AI processing, logs, backups and incident response.

·       No guarantee of absolute security; safeguards are risk-based and continuously improved.

Regulatory / Reference Sources Used for Drafting

·       Digital Personal Data Protection Act, 2023 — Ministry of Electronics and Information Technology / Government of India.

·       Digital Personal Data Protection Rules, 2025 — Ministry of Electronics and Information Technology / Government of India.

·       CERT-In Directions under Section 70B of the Information Technology Act, 2000, dated 28 April 2022.