PixelLab Media · Legal
Privacy Policy
How PixelLab OMS collects, uses and protects personal data.
- Last updated
- 4 October 2026
- Applies to
- PixelLab OMS
PixelLab Media operates PixelLab OMS, a multi-vendor order management and shipping platform. This policy explains what personal data the platform processes, why it is processed, who it is shared with, and the rights you have over it.
PixelLab OMS is used by two distinct groups. Operators are PixelLab Media staff who administer the platform on behalf of client brands. Vendors are those brands — the manufacturers and sellers whose catalogues, inventory and orders are managed through the platform. Both act as controllers of their own data, and the categories below explain what is processed on whose behalf.
01Information we collect
We collect only the data required to operate order management and logistics. The categories below are the complete set.
- Fulfilment data — AWB and tracking numbers, courier assignment, pickup IDs, scheduled pickups, manifests, and tracking scan history including RTO and NDR events.
- Files you upload — order CSV imports and per-SKU cost sheets, retained with filename, size, row count and uploader.
- Technical data — inbound webhook payloads, idempotency keys, IP address and user agent captured at sign-in, and application error logs.
- Communications — the content of support emails sent to our privacy or support mailboxes.
- Account data
- Full name, email address, a bcrypt-hashed password, system role, account status and optional avatar. Plaintext passwords are never stored.
- Organisation and KYC data
- Registered business name, brand or display name, contact person and phone, GSTIN, PAN, settlement bank details (account number, IFSC code, account holder name), and uploaded KYC documents (GST certificate, PAN card, cancelled cheque, address proof).
- Warehouse data
- Pickup address, city, state, PIN code, contact phone, working days and hours, return address, and the linked Shiprocket pickup location identifier.
- Commerce data
- Orders and line items: Shopify and Shiprocket order IDs, customer name, phone and email, shipping address, SKU, quantity, price, discount, shipping and COD amounts, payment method and payment status, HSN code, and parcel weight and dimensions.
- Product and inventory data
- Catalogue metadata (SKU, title, MRP, selling price, cost, weight, dimensions, HSN code, GST rate), available and committed stock, low-stock thresholds, and an append-only ledger of every stock movement.
02Where this data comes from
Most personal data is not typed into our forms. It arrives automatically from the systems a vendor has already connected.
- Shopify — orders, line items and customer details are pulled through the store's Admin API and received through signed order webhooks.
- Shiprocket — shipment status, AWBs and tracking scans arrive through webhooks; we also read from Shiprocket when you run a manual sync.
- You — account details, KYC submissions, warehouse details and uploaded files are entered directly.
03How we use personal data
- Performance of a contract — to fulfil orders, generate shipping labels and manifests, schedule courier pickups, sync tracking back to Shopify, and manage your account.
- Legitimate interests — to detect and resolve fulfilment exceptions, prevent duplicate shipments, guard against fraud and abuse, and maintain the security and integrity of the platform.
- Legal obligation — to retain transaction and tax records where Indian law requires it, and to respond to valid legal process.
- Consent — for optional notifications you have explicitly enabled, which you may withdraw at any time from your notification preferences.
04How we protect personal data in the product
Customer contact details are treated as sensitive by default rather than exposed for convenience.
- Customer phone numbers and email addresses are masked throughout the interface.
- Revealing a customer's phone number is a separate, permission-gated action that writes an immutable audit record naming the operator, the order, the stated reason and the timestamp.
- Shipping labels and pickup manifests are held in private object storage and served only through short-lived signed URLs that expire. They are never served from a public path.
- KYC documents are stored in the same private bucket, and are never embedded in a page or returned through an API response.
05Who we share data with
We do not sell personal data. We share it only with the sub-processors required to operate the platform, and only to the extent needed for their function. The current list appears below; we notify you in advance before it changes.
Separately, your connected Shopify store and your linked Shiprocket account receive data as part of their own operation. Those transfers are governed by your agreements with Shopify and Shiprocket rather than by this policy.
06How long we keep data
We keep data only as long as it is needed for the purpose it was collected, then delete or irreversibly anonymise it.
- Webhook and idempotency logs
- Automatically purged after 30 days.
- Order, product and fulfilment data
- Retained while the store remains connected and the vendor relationship is active, then deleted on request or at the end of the engagement.
- Password reset tokens
- Single-use and expire automatically; a superseded token is invalidated immediately.
- API keys and push subscriptions
- Expire automatically and can be revoked at any time.
- KYC and banking records
- Retained for the period Indian tax and accounting law requires, then deleted.
07Security measures
Security is enforced in depth rather than by policy alone.
- All data is transmitted over encrypted connections (TLS).
- Passwords are hashed with bcrypt and are never stored or logged in plaintext.
- Courier account passwords are encrypted at rest using AES-256-GCM. When the encryption key is absent, the platform refuses to store credentials rather than falling back to plaintext.
- Access is governed by role-based permissions on every server action and API route; a vendor sees only their own orders, warehouses and catalogue.
- Inbound webhooks are verified against the sending store's own secret and checked against an idempotency record, so a replayed webhook cannot create a duplicate shipment.
- Label and manifest generation uses atomic claim locks, so two concurrent requests cannot produce two labels for one order.
- Sessions are revalidated against the database on a short interval, so deactivating an account takes effect promptly rather than at token expiry.
08Your rights
Subject to the data protection framework applicable to us in India, you may request:
- Access — a copy of the personal data we hold about you, and confirmation of what we process.
- Correction — rectification of inaccurate data, including a wrong address that would misroute a parcel.
- Erasure — deletion of your personal data, subject to records we must retain for tax or legal compliance.
- Grievance redressal — escalation of an unresolved concern to our privacy contact.
- Withdrawal of consent — for any optional processing, from your notification preferences or by contacting us.
- Nomination — in the event of your death or incapacity, nomination of a person to exercise these rights.
09Security incidents
If we become aware of a breach of personal data we will notify affected vendors and, where the law requires it, the relevant supervisory authority, without undue delay and with a description of the likely consequences and the measures taken.
10Children
PixelLab OMS is a business platform and is not directed at children. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us data, contact us and we will delete it.
11Changes to this policy
We update this policy when our processing changes; the date at the top of this page always reflects the latest revision. Where a change materially affects your rights, we will notify you by email or in-product before it takes effect.
12Contact us
For any privacy question, access request or complaint, email privacy@pixellab.media. We aim to acknowledge privacy requests promptly and to resolve them within the timeframe required by applicable law.
Sub-processors
These providers process data strictly on our instructions. Each entry is an integration that is genuinely active in the platform.
| Provider | Purpose | Data involved |
|---|---|---|
| Shopify | Sales channel — source of order, customer and product data | Customer name, phone, email, shipping address, order lines, payment method and status, product catalogue |
| Shiprocket | Courier and logistics partner — booking, labels, tracking | Shipment address, contact phone, parcel weight and dimensions, AWB, tracking scans |
| Cloudflare R2 | Private object storage for shipping labels, manifests and KYC documents | Label and manifest PDFs, uploaded GST / PAN / cancelled cheque / address proof documents |
| Vercel | Application hosting and infrastructure | Request metadata, IP address, session cookies, application logs |
| Resend | Transactional email delivery (password reset, notifications) | Recipient email address, email subject and message body |
| Inngest | Durable background job execution (bulk labels, manifests, pickups, syncs) | Job parameters and target order identifiers needed to run the task |
| Google Maps / Photon | Address autocomplete and reverse geocoding when adding a warehouse or pickup location | Partial address text or device coordinates entered by the operator, and the structured address returned |
| Pusher | Real-time updates for background tasks and order status changes | Channel identifiers, event payload for the requesting user |
Document version: last updated 4 October 2026.