Legal
Privacy Policy
Last updated: July 2026
Samhati is built by Wenesay (wenesay.com). We collect minimal data needed to run the product, process subscriptions, and improve reliability. We do not sell your personal information.
What we collect
When you browse (no account)
- Standard server and CDN logs (IP address, browser type, pages visited)
- Anonymous analytics via our analytics provider (if enabled)
- HttpOnly cookies for tier access after payment (see below)
When you pay for Pro or Research
- Razorpay payment ID and order ID — to verify payment and support billing lookups
- Plan tier (Pro / Research), billing period (monthly / yearly), amount in paise (base + GST), currency
- Bill-to name / email you confirm after payment (for GST tax invoice and receipt) — never taken from Razorpay autofill
- Subscription expiry timestamp — to enforce access duration
- Status (active / expired / refunded)
We store this in our Cloudflare D1 database (`subscriptions` table). Card numbers and UPI IDs are collected by Razorpay under their privacy policy. Payment is processed through Wenesay's Razorpay merchant account. After payment you may optionally confirm a bill-to name (required for GST documents) and email; we store only what you enter there. Tax invoices and optional billing emails are issued by Wenesay (wenesay.com). We do not use Razorpay checkout autofill as your invoice billed-to party.
Browser cookies we set
- `samhati_tier` — your active plan level
- `samhati_tier_expires` — when the plan expires
- `samhati_payment_id` — Razorpay reference to restore entitlement server-side
- `samhati_magic` — short-lived token for secure tier handoff (when used)
Why we store subscription records
- Verify that a payment was captured before unlocking paid features
- Prevent duplicate activation of the same payment
- Support you if you contact us with a Razorpay receipt or payment ID
- Process refunds or disputes when applicable — see Refunds & Cancellations
- Basic financial record-keeping for a digital subscription product
What we do not do
- Sell or rent personal data to third parties
- Require account registration or email for basic use
- Store payment instrument details on our servers
- Send marketing email digests (not part of the product)
Processors & infrastructure
We use Cloudflare (hosting, D1 database, KV cache), Razorpay (payments), and optionally analytics providers on behalf of Wenesay. These processors handle data according to their own policies and our instructions where applicable.
Retention
Subscription records are retained while active and for a reasonable period afterward for accounting and dispute resolution (typically up to 7 years unless a shorter period is required by law). You may request deletion of non-mandatory records by emailing with your Razorpay payment ID — note that we may need to retain minimal records where law requires.
Your choices
- Sign out — clears tier cookies in your browser (navbar when on a paid plan)
- Block cookies — may prevent paid features from working
- Contact us — access, correction, or deletion requests for data we hold
Changes
We may update this policy. Material changes will be reflected in the “Last updated” date. Continued use after changes constitutes acceptance.
Contact
Privacy questions:
Samhati is built by Wenesay (wenesay.com).
This policy describes our practices in plain language. It is not legal advice. Consult a qualified professional for DPDP Act / GDPR compliance review for your jurisdiction.