Legal & Transparency

Information Security Policy

How Singh Traders protects customer data and secures our website, app, and payment systems.

Last Updated: September 8, 2026

1. Purpose & Scope

This Information Security Policy describes the technical and organizational measures Singh Traders applies to protect customer data and secure our website (singhtrader.in), our mobile application, and the systems that process online payments. It applies to all data collected, transmitted, or stored through these channels.

2. Encryption & Transport Security

  • All traffic to our website, mobile app, and API is encrypted in transit over HTTPS, using auto-renewing TLS certificates.
  • Our servers send HTTP Strict-Transport-Security (HSTS) headers, so browsers only ever connect over HTTPS.
  • Additional security response headers (X-Content-Type-Options, X-Frame-Options, Referrer-Policy) are applied to guard against common web attacks such as content-sniffing and clickjacking.

3. Payment Security

Online payments are processed through RBI-authorised payment aggregators (SBI ePay, Razorpay) using an aggregator-hosted checkout — the aggregator's own secure page collects card, UPI, and net banking details directly.

  • We do not collect, transmit, or store card numbers, card expiry dates, CVV, UPI PINs, or net banking credentials on our own servers.
  • Every payment transaction is recorded with a status and reference for reconciliation and audit purposes.

4. Application & Access Security

  • Staff and admin access to our systems is authenticated and restricted by role — team members can only access the functions relevant to their role.
  • Rate limiting is applied to publicly reachable, unauthenticated endpoints (such as login and payment callback routes) to guard against automated abuse.
  • Application secrets and credentials (API keys, encryption keys) are stored as encrypted environment configuration, never committed to source code.

5. Infrastructure Security

  • Our application and database servers are hosted on Amazon Web Services (AWS) and are not directly reachable from the internet except through the secured, encrypted application endpoints.
  • Firewall rules restrict network access to only the ports and services required to operate.
  • Deployments are containerized and released through an automated, auditable deployment pipeline.

6. Monitoring, Logging & Patch Management

  • Transaction and system activity logs are retained to help establish a clear audit trail and assist in dispute resolution.
  • Software dependencies are periodically reviewed and updated to address known security vulnerabilities.
  • Security configurations are reviewed as part of our ongoing development process.

7. Data Retention & Third-Party Services

Personal and transaction data is retained only as long as necessary to provide our services and to meet accounting, tax, and legal record-keeping obligations. Where third-party services are used (payment aggregators, messaging, cloud hosting), data is shared with them only to the extent required to deliver the service — see our Privacy Policy for details.

8. Reporting a Security Concern

If you believe you have found a security vulnerability or issue affecting our website, app, or payment systems, please report it to us directly so we can investigate promptly:

📧 Email: admin@singhtrader.in (Subject line: "Security Concern")
📞 Phone / WhatsApp: +91 99737 41675

9. Policy Review

This policy is reviewed periodically and updated as our systems, services, and applicable regulatory requirements evolve. Any changes will be reflected on this page with an updated "Last Updated" date.

10. Contact Us

Singh Traders
Saidnagar, SH 50, near Vishwakarma Mandir, Laheriasarai, Darbhanga, Bihar 846001, India
📞 Phone: +91 99737 41675📧 Email: admin@singhtrader.in