Privacy Policy
Exactly what personal data Nirmaan collects, why, who sees it, how long we keep it, and the rights you have over it under the DPDP Act, 2023.
This page is not ready to publishSome legally required details are still placeholders. Fill them in lib/legal.ts before launch — every field marked in red below is missing.
On this page12
- 1.What this notice covers
- 2.Exactly what we collect, and why
- 3.Your consent, and how to withdraw it
- 4.Who else sees your data
- 5.Cookies, app storage and notifications
- 6.How long we keep it
- 7.How we protect it
- 8.Your rights over your data
- 9.Children
- 10.Where your data is stored
- 11.Changes to this notice
- 12.Contact
1.What this notice covers#
This notice explains how Nirmaan handles your personal data when you use our website, our Android and iOS apps, or talk to our team. Under the Digital Personal Data Protection Act, 2023 we are the Data Fiduciary for that data and you are the Data Principal.
The Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025. Most substantive obligations — notice, consent, security, breach reporting and data principal rights — become enforceable on 14 May 2027. We have written this notice to that standard already, so nothing about how we handle your data has to change when the deadline arrives.
2.Exactly what we collect, and why#
We collect only what the product actually needs. Here is the complete list — nothing is collected that is not on it.
- Why we need it
- To sign you in with a one-time code, and to send order and payment updates.
- Why we need it
- So suppliers know who they are supplying, and so delivery staff can identify you.
- Why we need it
- So the supplier or our team can call you about a delivery or a callback request.
- Why we need it
- To show materials actually available in your area, and to deliver to the right place.
- Why we need it
- To run the marketplace — matching you to suppliers who can supply what you asked for.
- Why we need it
- To process your order, settle the supplier, handle refunds and meet tax and accounting law.
- Why we need it
- To verify that a business is real and entitled to trade before its store goes live. Stored in a private bucket, never publicly accessible.
- Why we need it
- To fix bugs, keep the platform secure, and understand which areas and categories have demand we do not yet serve.
- Why we need it
- So the app behaves the way you set it, on every device you sign in on.
- Why we need it
- To answer your question, and to keep a record if it becomes a grievance or a dispute.
We do not collect your card number, UPI PIN, CVV or bank login — those go straight to Razorpay and never touch our servers. We do not track your continuous GPS location; we only use the pincode you choose. We do not buy personal data from data brokers, and we do not sell yours.
3.Your consent, and how to withdraw it#
- We process the data above on the basis of the consent you give when you create an account and use the service, and — for orders, invoices and tax records — because the law requires us to keep them.
- Consent is never bundled or pre-ticked. Optional things — push notifications, analytics — are asked for separately and refusing them does not block you from buying.
- You can withdraw consent at any time — turn off notifications in your device settings, or write to our privacy contact to withdraw more broadly. Withdrawing is as easy as giving it. Where we can no longer provide part of the service without that data, we will tell you plainly which part.
- Withdrawal is not retrospective — it does not undo processing that already lawfully happened, and it does not delete records the law requires us to keep.
6.How long we keep it#
- Kept for
- While your account is open, then 180 days after closure (IT Rules, 2021, Rule 3(1)(h))
- Kept for
- 8 years, as required by tax and companies law
- Kept for
- While the store is active, then 3 years
- Kept for
- 3 years from the last activity on them
- Kept for
- 3 years from closure of the complaint
- Kept for
- 26 months, after which only aggregate counts remain
7.How we protect it#
- All traffic between your device and us is encrypted in transit (HTTPS/TLS).
- Sign-in uses one-time codes and short-lived session tokens. We do not store passwords, because there are none.
- Supplier identity documents go into a private storage bucket reachable only through short-lived signed links — never a public URL.
- Access to production data is limited to the people who need it, and sensitive administrative actions are written to an audit log.
- Payment webhooks are accepted only after a cryptographic signature check — an unverified payment message is never acted on.
No system is perfectly secure. If a personal data breach occurs, we will notify each affected person and the Data Protection Board of India as required by the DPDP Rules, 2025, describing what happened, what data was involved and what you should do.
8.Your rights over your data#
Under the DPDP Act, 2023 you have the following rights. Write to our privacy contact below and we will act on a valid request within 30 days.
- Access — a summary of the personal data we hold about you and who we have shared it with.
- Correction — fix anything inaccurate, complete anything missing, update anything stale. Most of this you can do yourself in Profile.
- Erasure — ask us to delete your personal data where we no longer need it and no law requires us to keep it.
- Grievance redressal — a readily available means of complaining to us about how we handled your data.
- Nomination — nominate another person to exercise these rights on your behalf if you die or become incapacitated.
If you are not satisfied with how we handle your request, you may complain to the Data Protection Board of India.
9.Children#
Nirmaan is a trade platform for adults and is not directed at anyone under 18. We do not knowingly collect a child’s personal data. Under the DPDP Act we would need verifiable parental consent to do so, and we do not track or profile children or show them behavioural advertising. If you believe a child has created an account, tell us and we will delete it.
10.Where your data is stored#
Our database and file storage are hosted in India or Singapore. A few service providers listed above operate outside India — crash diagnostics and email delivery in particular. Where data leaves India we transfer it only to countries not restricted by the Central Government under section 16 of the DPDP Act, and only under contractual terms that keep our obligations intact.
11.Changes to this notice#
The version number and effective date at the top of this page tell you which version applies. If we change what we collect or why, we will tell you in the app and by email before the change takes effect, and where the law requires it we will ask for your consent again.
12.Contact#
Grievance Officer
Language of this documentThis document is published in English and Hindi so it can be read in the language you are most comfortable with. If the two versions ever differ in meaning, the English version governs.
Version history
- v2.015 August 2026Rewritten as a DPDP-compliant notice: itemised data table, named processors, retention periods, data principal rights and nomination, breach reporting.
- v1.01 June 2026First published version.