Legal

Privacy Policy

Last updated: 4 June 2026

This Privacy Policy explains how DigiDukaanCard (“we”, “us”, “our”), operated by [Entity] with registered office at [Address], India, collects, uses, discloses, retains and protects personal data when you visit or use the DigiDukaanCard website, applications and services (the “Service”).

This Policy is published in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Consumer Protection (E-Commerce) Rules, 2020.

1. Who we are (Data Fiduciary)

For the purposes of the DPDP Act, [Entity] is the Data Fiduciary in respect of personal data processed through the Service. Contact: support@digidukaancard.com.

2. Scope & applicability

This Policy applies to all users of the Service whether located in India or abroad, and to personal data collected online (website, apps) and offline (support, onboarding) by us.

3. Personal data we collect

(a) Information you provide

  • Account data — name, mobile number, email address, password (stored as a one-way hash), business details.
  • Business profile data — business name, address, category, working hours, services, images, testimonials, gallery, social links, payment-method labels and any other content you publish on your card.
  • Enquiry / lead data — name, phone, email and message submitted by visitors through forms on your business card.
  • Communications — emails, support tickets, WhatsApp messages and feedback you send to us.
  • Payment data — when you subscribe to a paid plan, payment is processed by a third-party payment gateway. We do not store full card numbers, CVV or net-banking credentials; we only retain a transaction reference, plan, amount, GST and status.

(b) Information we collect automatically

  • Usage & device data — IP address, approximate location derived from IP, browser type, operating system, device identifiers, referring URL, pages viewed and timestamps.
  • Cookies, local storage & similar technologies — strictly necessary cookies for sign-in and security, preference cookies (language, theme), and aggregate analytics.

(c) Information from third parties

Where you sign in using a third-party identity provider (such as Google), we receive your basic profile (name, email, profile photo) from that provider in accordance with its terms.

We do not knowingly collect “sensitive personal data or information” (passwords, financial credentials, health, biometric, sexual orientation, etc.) beyond what is strictly required.

4. Purpose & lawful basis

We process personal data only for the following purposes and on the lawful bases set out below:

  • To create and operate your account, deliver the Service, and authenticate you — performance of contract.
  • To publish your business card and process visitor enquiries — your consent and certain legitimate uses under s.7 of the DPDP Act.
  • To process subscription payments, raise GST invoices and meet tax obligations — legal obligation.
  • To send service notices, security alerts and transactional emails — legitimate use.
  • To send marketing communications — only with your opt-in consent, which you may withdraw any time.
  • To detect, prevent and investigate fraud, abuse and security incidents — legitimate use.
  • To improve, debug and develop the Service using aggregated, de-identified data.

5. Consent & withdrawal

Where processing is based on your consent, the consent notice is presented to you in clear and plain language, and includes the items required by s.6 of the DPDP Act. You may withdraw consent at any time by writing to grievance@digidukaancard.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and may prevent us from providing parts of the Service.

6. Children

The Service is intended for users who are 18 years or older. We do not knowingly process personal data of children (persons below 18) or persons with disability who have a lawful guardian, except with verifiable consent of the parent or lawful guardian as required under s.9 of the DPDP Act. We will not undertake tracking, behavioural monitoring or targeted advertising directed at children.

7. How we share personal data

We do not sell personal data. We share data only with:

  • Service providers / Data Processors acting on our written instructions, including: cloud hosting and database, transactional email, SMS / WhatsApp messaging, payment gateways, customer support, error monitoring and analytics.
  • AI translation provider — for the multilingual feature, the text fields of your published business card may be sent to an AI translation service strictly for the purpose of returning translated text. No account credentials are shared.
  • Authorities — where required by Indian law, court order, or to comply with a lawful direction from a government agency under s.6/8 of the IT Act or the Code of Criminal Procedure.
  • Successors — in connection with a merger, acquisition or sale of assets, subject to confidentiality.

Visitor-submitted enquiries are made available only to the business card owner.

8. Cross-border transfer

Some of our processors may store or process data outside India. We transfer personal data outside India only to jurisdictions that are not restricted by the Central Government under s.16 of the DPDP Act, and we put contractual safeguards in place with each processor.

9. Data retention

  • Account & business profile — for as long as your account is active, and up to 3 years after closure for legal, tax and audit purposes.
  • Enquiries / leads received by business owners — up to 24 months from receipt, unless deleted earlier by the owner.
  • Payment & GST records — minimum 8 years, as required under the Goods and Services Tax law and Income-tax Act.
  • Server, security and access logs — up to 12 months.

Data no longer required is securely deleted or irreversibly anonymised.

10. Security safeguards

We follow “reasonable security practices and procedures” within the meaning of s.43A of the IT Act and the SPDI Rules. Safeguards include: HTTPS / TLS in transit, encryption at rest by our cloud provider, hashed passwords, role-based access control, row-level security on the database, least-privilege service keys, audit logging, periodic backups and an incident-response process.

In the event of a personal data breach we will notify the Indian Computer Emergency Response Team (CERT-In) within the time specified by CERT-In's directions, and the Data Protection Board of Indiaand affected Data Principals as required under s.8(6) of the DPDP Act.

11. Your rights as a Data Principal

Subject to the DPDP Act, you have the right to:

  • obtain a summary of the personal data we process and the processing activities;
  • correction, completion, updating and erasure of your personal data;
  • withdraw consent at any time;
  • nominate another individual to exercise your rights in the event of death or incapacity;
  • grievance redressal by writing to our Grievance Officer;
  • escalate unresolved grievances to the Data Protection Board of India.

To exercise these rights, write to grievance@digidukaancard.com. We will respond within the timelines prescribed by law. You will not be charged a fee for reasonable requests.

12. Cookies & tracking

We use only essential cookies and a small number of preference cookies. We do not use third-party advertising cookies. You can clear cookies and local storage from your browser at any time; doing so may sign you out and reset your preferences.

13. Third-party links

Business cards may contain links to third-party websites (WhatsApp, Maps, social networks, payment apps, etc.). We are not responsible for the privacy practices of those websites. Please review their policies.

14. Changes to this Policy

We may update this Policy from time to time. The “Last updated” date at the top will reflect the latest revision. Material changes will be notified to you by email or by an in-app notice at least 7 days before they take effect, where feasible.

15. Grievance Officer (IT Rules, 2021)

In accordance with Rule 3(2) of the IT (Intermediary Guidelines) Rules, 2021 and s.13(3) of the SPDI Rules:

  • Name: [Grievance Officer]
  • Designation: Grievance Officer
  • Email: grievance@digidukaancard.com
  • Address: [Address], India
  • Hours: Mon–Fri, 10:00–18:00 IST (excluding public holidays)

We will acknowledge a complaint within 24 hours and dispose of it within 15 days of receipt, in accordance with the IT Rules, 2021.

16. Governing law & jurisdiction

This Policy is governed by the laws of India. Subject to the dispute-resolution clause in our Terms of Service, courts at [City], India shall have exclusive jurisdiction.

17. Contact us

General queries: support@digidukaancard.com
Privacy / data protection: grievance@digidukaancard.com

Disclaimer. This document is a general template intended to help small businesses comply with applicable Indian privacy laws. It does not constitute legal advice. Please have it reviewed by qualified Indian legal counsel and replace the bracketed placeholders before going live.