Selling on Yamunaa
Data and privacy for sellers
For sellersUpdated 29 September 2026 Draft for review, final copy from legal
To fulfil orders, sellers see some shopper data: a name, a delivery address and sometimes a masked phone number. That data belongs to the shopper and is shared with you for one purpose only, to deliver the order. Data protection laws, such as UK GDPR, EU GDPR, US state privacy laws like the CCPA, and India’s DPDP Act, apply to you as they apply to us. Misuse is a severe violation.
What you can see
- Shopper name and delivery address, for shipping labels and invoices.
- A masked phone number that connects through Yamunaa, for delivery issues only.
- Order history with your store, for service and returns.
- Aggregated, anonymous insights about your listings and followers.
What's not allowed
- Contacting shoppers outside Yamunaa for marketing, feedback or any other reason.
- Adding shoppers to WhatsApp groups, SMS lists or email lists.
- Copying, exporting, selling or sharing shopper data with anyone, including other businesses.
- Keeping shopper data longer than needed. Delete printed labels and exported files after the return window.
- Using data to find shoppers on social media or visit them.
- Scraping Yamunaa for data about shoppers, sellers or prices.
Keeping data safe
- Give staff their own Seller Hub logins with only the access they need. Never share a password.
- Turn on two-step verification for all Seller Hub accounts.
- Shred printed labels and invoices you do not need.
- Tell us within 6 hours if you suspect shopper data from Yamunaa was lost or stolen. Some reporting deadlines are very short, such as 72 hours under GDPR and 6 hours for CERT-In in India.
Examples
Allowed
- Calling a shopper through the masked number because the rider cannot find their building.
- Asking followers on your brand page to sign up for your newsletter on Yamunaa.
Not allowed
- Sending a Diwali offer by WhatsApp to every shopper who ever ordered.
- Sharing a customer list with a sister company.
- Leaving a box of printed shipping labels in the building’s bin.
What happens if you break this policy
- Misusing shopper data is a severe violation and can lead to immediate suspension.
- Unsolicited contact outside Yamunaa counts as a strike and removes access to masked calling.
- We may be required to report data misuse to data protection regulators, such as the ICO in the UK, EU supervisory authorities or the Data Protection Board of India.