Privacy Policy

Privacy Policy

Exactly what personal data Nirmaan collects, why, who sees it, how long we keep it, and the rights you have over it under the DPDP Act, 2023.

Effective 15 August 2026Version 2.0

This page is not ready to publishSome legally required details are still placeholders. Fill them in lib/legal.ts before launch — every field marked in red below is missing.

On this page12

1.What this notice covers#

This notice explains how Nirmaan handles your personal data when you use our website, our Android and iOS apps, or talk to our team. Under the Digital Personal Data Protection Act, 2023 we are the Data Fiduciary for that data and you are the Data Principal.

Written to the 2025 Rules, ahead of the deadline

The Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025. Most substantive obligations — notice, consent, security, breach reporting and data principal rights — become enforceable on 14 May 2027. We have written this notice to that standard already, so nothing about how we handle your data has to change when the deadline arrives.

2.Exactly what we collect, and why#

We collect only what the product actually needs. Here is the complete list — nothing is collected that is not on it.

Email address
Why we need it
To sign you in with a one-time code, and to send order and payment updates.
Full name
Why we need it
So suppliers know who they are supplying, and so delivery staff can identify you.
Phone number (where you give it)
Why we need it
So the supplier or our team can call you about a delivery or a callback request.
Delivery pincode and saved addresses
Why we need it
To show materials actually available in your area, and to deliver to the right place.
My Truck contents, requirements (RFQs) and quotes
Why we need it
To run the marketplace — matching you to suppliers who can supply what you asked for.
Orders, payments and invoices
Why we need it
To process your order, settle the supplier, handle refunds and meet tax and accounting law.
Supplier documents — GST certificate, shop or trade licence, Aadhaar (suppliers only)
Why we need it
To verify that a business is real and entitled to trade before its store goes live. Stored in a private bucket, never publicly accessible.
Device and usage data — pages viewed, searches run, a first-party anonymous device id, app version, crash reports
Why we need it
To fix bugs, keep the platform secure, and understand which areas and categories have demand we do not yet serve.
Preferences — language, light or dark theme, notification permission
Why we need it
So the app behaves the way you set it, on every device you sign in on.
Support and callback conversations
Why we need it
To answer your question, and to keep a record if it becomes a grievance or a dispute.
What we do not collect

We do not collect your card number, UPI PIN, CVV or bank login — those go straight to Razorpay and never touch our servers. We do not track your continuous GPS location; we only use the pincode you choose. We do not buy personal data from data brokers, and we do not sell yours.

4.Who else sees your data#

Suppliers. When you post a requirement, matching suppliers in your area see the material, quantity, unit and area — not your identity. When you place an order or accept a quote, the supplier fulfilling it sees your name, delivery address and phone number, because they cannot deliver without them. Suppliers may use those details only to fulfil your order.

Service providers. These companies process data on our instructions, for the purposes below and nothing else:

Razorpay Software Private Limited
What they do for us
Payment processing and settlement to suppliers (Razorpay Route)
Where
India
Supabase
What they do for us
Database and file storage (catalogue images, supplier documents)
Where
India / Singapore
Google Firebase Cloud Messaging
What they do for us
Push notifications to your phone or browser
Where
Global
Google Analytics
What they do for us
Aggregate usage measurement on the website
Where
Global
Sentry
What they do for us
Crash and error diagnostics from the app
Where
United States
Resend
What they do for us
Sending transactional email (login codes, order updates)
Where
United States

Law enforcement and courts. We disclose data only against a lawful order or a legally valid request, and only what that order actually requires. Where we are permitted to tell you, we will.

Business transfer. If Nirmaan is ever acquired or merged, your data may transfer to the new owner, who will remain bound by this notice. We will tell you before that happens.

We never sell your personal data, and we do not share it with advertisers for behavioural advertising.

5.Cookies, app storage and notifications#

  • Essential cookies keep you signed in and remember your area, language and theme. The site does not work without them.
  • Analytics measure aggregate usage so we can see which categories and areas have unmet demand. This is measurement, not profiling for ads.
  • Push notifications are sent only after you allow them, and only for things that matter to you — a quote arriving, an order status change, a payment confirmation. Turn them off any time in your device settings.
  • The mobile app stores your session and preferences locally on your device so it opens fast and works on a weak connection.

6.How long we keep it#

Account details and preferences
Kept for
While your account is open, then 180 days after closure (IT Rules, 2021, Rule 3(1)(h))
Orders, payments, invoices
Kept for
8 years, as required by tax and companies law
Supplier verification documents
Kept for
While the store is active, then 3 years
Requirements and quotes
Kept for
3 years from the last activity on them
Support and grievance records
Kept for
3 years from closure of the complaint
Analytics events
Kept for
26 months, after which only aggregate counts remain

7.How we protect it#

  • All traffic between your device and us is encrypted in transit (HTTPS/TLS).
  • Sign-in uses one-time codes and short-lived session tokens. We do not store passwords, because there are none.
  • Supplier identity documents go into a private storage bucket reachable only through short-lived signed links — never a public URL.
  • Access to production data is limited to the people who need it, and sensitive administrative actions are written to an audit log.
  • Payment webhooks are accepted only after a cryptographic signature check — an unverified payment message is never acted on.

No system is perfectly secure. If a personal data breach occurs, we will notify each affected person and the Data Protection Board of India as required by the DPDP Rules, 2025, describing what happened, what data was involved and what you should do.

8.Your rights over your data#

Under the DPDP Act, 2023 you have the following rights. Write to our privacy contact below and we will act on a valid request within 30 days.

  • Access — a summary of the personal data we hold about you and who we have shared it with.
  • Correction — fix anything inaccurate, complete anything missing, update anything stale. Most of this you can do yourself in Profile.
  • Erasure — ask us to delete your personal data where we no longer need it and no law requires us to keep it.
  • Grievance redressal — a readily available means of complaining to us about how we handled your data.
  • Nomination — nominate another person to exercise these rights on your behalf if you die or become incapacitated.

If you are not satisfied with how we handle your request, you may complain to the Data Protection Board of India.

Data protection contact

Data Protection Contact

9.Children#

Nirmaan is a trade platform for adults and is not directed at anyone under 18. We do not knowingly collect a child’s personal data. Under the DPDP Act we would need verifiable parental consent to do so, and we do not track or profile children or show them behavioural advertising. If you believe a child has created an account, tell us and we will delete it.

10.Where your data is stored#

Our database and file storage are hosted in India or Singapore. A few service providers listed above operate outside India — crash diagnostics and email delivery in particular. Where data leaves India we transfer it only to countries not restricted by the Central Government under section 16 of the DPDP Act, and only under contractual terms that keep our obligations intact.

11.Changes to this notice#

The version number and effective date at the top of this page tell you which version applies. If we change what we collect or why, we will tell you in the app and by email before the change takes effect, and where the law requires it we will ask for your consent again.

12.Contact#

Data protection contact

Data Protection Contact

Grievance Officer

Name to be addedDesignation to be added
Phone number to be added
Address to be added

Language of this documentThis document is published in English and Hindi so it can be read in the language you are most comfortable with. If the two versions ever differ in meaning, the English version governs.

Version history

  • v2.015 August 2026Rewritten as a DPDP-compliant notice: itemised data table, named processors, retention periods, data principal rights and nomination, breach reporting.
  • v1.01 June 2026First published version.