Privacy Policy

Last updated: 1 January 2024 Β· Version: v2024.1

DPDP Act 2023 Compliant

1. About This Policy

This Privacy Policy describes how Bael Trade Pvt. Ltd. (β€œwe”, β€œus”, β€œour”, β€œCompany”) collects, uses, stores, and processes your personal data in compliance with the Digital Personal Data Protection Act 2023 (DPDP Act), the IT Act 2000 (Section 79), Consumer Protection (E-Commerce) Rules 2020, and UIDAI Aadhaar guidelines.

By using our platform you confirm that you have read and agree to this policy. This policy applies to all users β€” Sellers, Buyers, and visitors.

2. Data We Collect

CategoryData PointsLegal Basis (DPDP)
IdentityName, email, mobile, password hashΒ§7(a) β€” Contract performance
Business (Seller)GST Number, PAN, IEC, Udyam, company nameΒ§7(b) β€” Legal obligation (GST Act, FEMA)
AadhaarLast 4 digits ONLY β€” full Aadhaar never storedUIDAI circular β€” minimal data principle
KYC DocumentsPhotos/scans of certificates (encrypted at rest)Β§7(b) β€” Legal obligation (PMLA 2002)
TransactionOrders, payments, invoices, wallet balanceΒ§7(b) β€” Legal obligation (IT Act, GST Act)
UsagePages visited, search queries, click eventsΒ§6 β€” Explicit consent (Analytics)
CommunicationsMessages, enquiries, support ticketsΒ§7(a) β€” Contract performance
TechnicalIP address, device type, browser, session tokensΒ§7(a) β€” Essential for security

3. How We Use Your Data

  • Account creation & management β€” Creating your seller/buyer profile, enabling login, and maintaining session security.
  • KYC verification β€” Verifying your business identity with GSTN, DGFT, and Income Tax APIs as required by applicable law.
  • Marketplace operations β€” Processing orders, payments (via Razorpay), issuing GST-compliant invoices, and revealing buyer contact details.
  • Communications β€” Sending transactional emails, SMS OTPs, and in-app notifications related to your account activity.
  • Marketing (with consent) β€” Promotional emails, product recommendations, and market updates. You may withdraw this consent at any time.
  • Analytics (with consent) β€” Improving platform performance, understanding feature usage. Fully anonymized after withdrawal.
  • Legal compliance β€” Retaining financial records for 7 years as required by the GST Act, IT Act, and PMLA.

5. Data Sharing & Third Parties

We do not sell your personal data. We share data only in the following circumstances:

  • Government APIs: GSTN (GST verification), DGFT (IEC verification), Income Tax portal (PAN verification) β€” required for KYC.
  • Payment Gateway: Razorpay receives payment card/UPI data directly; we do not store raw payment credentials.
  • Cloud Infrastructure: Supabase (database, encrypted at rest), Vercel/Railway (application hosting) β€” data processed within India.
  • SMS Gateway: MSG91 processes mobile numbers for OTP delivery only.
  • Legal Requirement: Law enforcement or regulatory authorities when legally mandated.

6. Data Retention

Data TypeRetention PeriodLegal Basis
Account / Profile PIIUntil deletion request, then anonymizedDPDP Act Β§13
Financial records (invoices, GST)7 years from transaction dateGST Act Β§36, IT Act
KYC documents (raw scans)Until account deletion, then hard-deletedUIDAI guidelines
Audit logs7 yearsIT Act Β§7A
Consent recordsLifetime of account + 3 yearsDPDP Act Β§6
Session tokensUntil logout or 7 days, whichever firstSecurity requirement
Analytics data (anonymized)2 years, fully aggregatedWith explicit consent

7. Security Measures

  • AES-256-GCM encryption for all PII fields stored in database.
  • Passwords hashed with bcrypt (12 rounds) β€” plaintext never stored.
  • HTTPS/TLS 1.3 enforced on all endpoints.
  • JWT tokens with 4-hour expiry; refresh tokens stored hashed.
  • Role-based access control β€” only authorized staff can access your data.
  • Regular penetration testing and security audits.
  • Full Aadhaar numbers are never collected or stored per UIDAI circular dated 28.05.2024.

8. Children's Privacy

Our platform is intended for businesses only. We do not knowingly collect personal data from individuals under 18 years of age. If you are under 18, please do not use this platform or provide any personal information.

9. Changes to This Policy

We may update this policy to reflect changes in law or our practices. Material changes will be notified via email and in-app notification at least 15 days before they take effect. Your continued use after the effective date constitutes acceptance.

βš–οΈ Grievance Officer (DPDP Act Β§13 β€” Mandatory Disclosure)

Appointed under the Digital Personal Data Protection Act 2023. You may approach the Grievance Officer for any complaint or query regarding your personal data. A response will be provided within 72 hours as mandated by law.

Name

Rajesh Kumar

Designation

Grievance Officer

Phone

+91-80-4567-8901

Address

Bael Trade Pvt. Ltd., MG Road, Bengaluru β€” 560001, Karnataka, India

File a Grievance β†’