Trust & Legal
Security & TrustYour data stays yours.

This page exists because you should be able to answer, in your own words, exactly what happens to your data when you connect a store to Yazoh. Here's the honest version.

What Yazoh can do
  • Read your store's products, customers, orders, and inventory data
  • Analyze that data to calculate scores, detect risks, and generate insights
  • Answer your questions using that data through the Owner AI
What Yazoh cannot do
  • Change your prices, stock levels, or order statuses
  • Access another tenant's data, or let another tenant access yours
  • Sell or share your data with third parties
How your data is protected
  • Encrypted at rest and in transit
  • Isolated per store — every tenant's data is walled off from every other tenant's, enforced at the database and application layer
  • Access-controlled — every internal action that touches your account is logged
Data PrivacyA plain-English summary of how we handle your data.

This page is a plain-language companion to our formal Privacy Policy — written so you don't have to parse legal language to understand the basics. The Privacy Policy remains the binding legal document; if the two ever conflict, the Privacy Policy governs.

  • We collect only what's needed to run your store and generate intelligence products, customers, orders, inventory
  • We do not sell your data, ever, to anyone
  • Your data is never used to train models shared with other tenants
  • If you disconnect a store or cancel your account, your synced data is deleted within [X] days — confirm and publish this exact number before launch
  • You can request a copy of your data, or request deletion, at any time — process and contact method to be confirmed legally/compliance
Legal Documents — Structure & Required Sections

The four pages below are binding legal documents. This section provides the standard structure each one needs — not final text. Have a lawyer familiar with Indian law (DPDP Act) and the laws of any other country you sell into (e.g. GDPR for EU customers) draft or review the actual language before publishing.

This page is a plain-language companion to our formal Privacy Policy — written so you don't have to parse legal language to understand the basics. The Privacy Policy remains the binding legal document; if the two ever conflict, the Privacy Policy remains the binding legal document.

Privacy Policy — required sections
  • What data is collected (from merchants, and from their end customers via Customer AI)
  • How data is used, stored, and for how long
  • Third parties data is shared with (e.g. the AI model provider) and why
  • User rights — access, correction, deletion, portability
  • Data retention and deletion timelines upon cancellation
  • Jurisdiction-specific disclosures — DPDP Act (India), GDPR (if serving EU customers), CCPA (if serving California customers)
  • Contact details for privacy requests
Terms & Conditions — required sections
  • Description of services and what's explicitly excluded (e.g. no autonomous purchasing in this version)
  • Subscription terms, billing, and cancellation policy — should match the confirmed pricing plan exactly
  • Acceptable use restrictions
  • Limitation of liability, especially regarding AI-generated insights — insights are informational, not guaranteed business advice
  • IP ownership — clarify the merchant owns their data; Yazoh owns the platform, scoring algorithms, and AI orchestration
  • Termination conditions and data handling upon termination
Acceptable Use Policy — required sections
  • Prohibited uses of the platform (e.g. connecting stores you don't own or have authorization for)
  • Restrictions on abusing the AI credit system or reverse engineering the AI orchestration
  • Consequences of violation — suspension, termination