Legal
Privacy policy
Draft — pending legal review; not legal advice.
This page describes how the platform works today. It has not yet been approved by counsel, and bracketed items such as [Company legal name] are placeholders the operator still has to fill in. Last updated .
1.Who we are
The marketplace is operated by [Company legal name], [registered address], the data fiduciary for the personal data described here. Our grievance officer is [grievance officer name and email].
When a vendor sends us data about its customers so we can attribute sales, the vendor decides what it shares with us; the respective roles of the vendor and the marketplace are [to be set out in the vendor agreement].
2.What we collect
- Account data — your name, email, optional phone, organisation name, website and partner type; your password (stored only as a one-way hash); two-factor settings; team memberships and roles.
- Consent records — which version of this notice and of program terms you accepted, and when.
- Verification data — for vendors, the business profile and documents submitted for review (GSTIN is stored as a keyed hash plus a masked value); for partners, KYC information and documents, and the bank account or UPI ID used for payouts, which is verified with our payout provider.
- Partner activity — programs joined, links, coupons, leads and deals you submit (including the prospect’s company and contact details you choose to share with the vendor), commissions, withdrawals, disputes and support tickets.
- Sales data from vendors — for each payment a vendor reports: amounts, dates, plan and subscription ids, and customer identifiers such as organisation name, domain, GSTIN and email. Identifiers needed only for matching are stored as keyed hashes.
- Tracking data — when a tracking link is followed: time, program, a keyed hash of the IP address and browser user agent, the referring site’s host and a random visitor id (see the cookie policy).
- Contact form — name, email, optional company and phone, your message, and a keyed hash of your IP address and browser.
- Security logs — sign-ins, sessions and an audit log of changes, with hashed IP addresses and browsers.
3.Why we use it
- To run your account and keep it secure, including fraud and abuse detection (for example self-referrals and shared payout accounts).
- To verify vendors and partners before they can sell, apply to programs or receive payouts.
- To attribute sales, calculate commissions, keep the commission ledger and pay partners.
- To handle disputes, support tickets, contact messages and privacy requests.
- To send service emails and in-app notifications about your account, programs, commissions and payouts.
- To meet legal, tax and accounting obligations.
We do not sell personal data and do not use it for third-party advertising. The lawful basis for each purpose is [to be confirmed by counsel].
5.How long we keep it
We keep account data while your account is active. Financial and audit records — commissions, the ledger, payouts, tax deductions and audit logs — are kept for as long as the law requires and are never edited or deleted; erasing an account anonymises the personal data attached to them instead.
Some data is reduced automatically by retention jobs, for example: contact details on leads that were lost or rejected are removed after a set period; closed contact-form messages have the sender’s details removed; raw webhook payloads are purged after processing; expired sign-in tokens are purged. The periods are configured by the operator — currently [retention schedule to be published].
6.Your rights
Signed-in users can use Account → Privacy to:
- download a copy of their personal data (access);
- ask for a correction (you can also edit your name and phone yourself);
- request erasure — reviewed by our team; your personal data is anonymised, while records the law requires us to keep are retained (an organisation’s last owner must transfer ownership first);
- raise a grievance;
- withdraw a consent you gave (some consents are needed to keep using the service, and we will tell you if so).
Each request shows the date by which we will respond. Without an account, use the contact form or write to [privacy contact email]. If you are not satisfied with our response you may approach the Data Protection Board of India.
7.Security
Connections to the site use HTTPS in production; sensitive fields such as integration secrets are encrypted at rest; documents are stored privately and only reviewers can download them, with every download logged. Access inside the platform follows roles, and every organisation sees only its own data. Sensitive finance actions need a second person to approve.
8.Children
The marketplace is for businesses and professionals. It is not intended for anyone under 18, and we do not knowingly collect their data.
9.Where data is processed
Data is stored and processed in [hosting region(s)].
10.Changes to this policy
When this policy changes we will update the date above. How registered users are told about material changes is [to be decided by the operator].