Privacy Policy
Last updated: 16 May 2026
1. Who we are.
Potatoresume is operated by INDPOTATO PRIVATE LIMITED (CIN: U82990PN2024PTC234228), registered at Shop-11, Kedar Housing Co-op Society, Tapovan Road, Pimpri Waghire, Pune, Maharashtra 411017, India.
2. What we collect.
We collect: (a) the email and phone number you submit, (b) your existing CV (PDF or DOCX), (c) the intake form responses (target role, target industry, years of experience, optional job description, optional LinkedIn URL, optional additional notes), (d) payment metadata from Razorpay (payment ID, amount, status — we do not see or store your card details).
3. Why we collect it.
The CV and intake responses are used solely to write your CV. Your email is used to deliver your CV and to communicate about your order. Your phone is used only if we cannot reach you by email. Payment metadata is used to confirm payment and issue refunds where applicable.
4. Who else sees your data.
(a) Razorpay processes payments — they see your email, phone, and payment amount, governed by Razorpay’s own privacy policy. (b) Resend delivers our emails — they see your email address and the email body. (c) Supabase hosts our database and file storage — they store your CV and intake responses, encrypted at rest. (d) Vercel hosts our website — they see standard HTTP request data (IP, user-agent). We do not sell, share, or transfer your data to any other third party for marketing.
5. How long we keep it.
Order data, intake responses, and uploaded CVs are retained for 90 days after delivery to support revision requests and customer service. After 90 days, we delete the uploaded original CV and the delivered PDF from our storage. Order metadata (date, tier, amount) is retained for 7 years for accounting and tax compliance as required by Indian law.
6. Your rights under DPDP Act 2023.
You have the right to: access the data we hold about you, correct inaccuracies, request deletion (subject to the 7-year accounting retention), withdraw consent, and lodge a complaint with the Data Protection Board of India. To exercise any right: email info@potatoresume.com with subject “DPDP Request”. We respond within 30 days.
7. Children’s data.
We do not knowingly serve customers under 18 years of age. If you believe we have collected data from a minor, contact us immediately.
8. Cookies and tracking.
We use minimal first-party cookies for session management (admin login). We do not use third-party advertising trackers or behavioral analytics. We do not run Google Analytics.
9. Security.
We use industry-standard security: HTTPS everywhere, encryption at rest (Supabase), bcrypt password hashing, signed download tokens, no plaintext storage of payment data.
10. Grievance officer.
Per DPDP Act 2023: For any data protection grievance, contact our Grievance Officer at info@potatoresume.com. We respond within 30 days of receipt.
11. Updates to this policy.
We may update this policy. Material changes will be emailed to customers with active orders. Continued use after changes constitutes acceptance.
12. Contact.
info@potatoresume.com · WhatsApp +91 94996 68831
Named after the potato — quick, universal, and made for everyone.