Privacy Policy
Last Updated: December 2025 | Version 1.0
1. Information We Collect
We collect only the information necessary to operate the platform and provide our services. Below is what we collect and why:
Account & Authentication:
• Phone number: For OTP-based login authentication and sending order status updates via SMS.
• Email address: For account recovery, important notifications, and dispute communications.
• Password: Encrypted and stored securely to protect your account access.
• Name: To identify you in transactions and display on your public profile.
Profile & Personalization:
• Profile picture: Optional, to help buyers and sellers recognize each other during transactions.
• Bio: Optional, to let you describe yourself or your selling style.
• City: To show relevant local listings and enable regional filtering for buyers.
Transaction & Payment:
• UPI address: To process manual payouts for your sold items.
• Delivery address: Shared with the seller only when you place an order, so they can ship the product to you.
• Order details: Product information, pricing, and delivery status to facilitate transactions.
• Payment records: Transaction history for order tracking, refunds, and tax compliance (retained for 7 years as required by law).
Listings (For Sellers):
• Product images: To display your items to potential buyers.
• Product descriptions and prices: To provide accurate information to buyers.
• Shipping details: Tracking ID, courier name, and parcel photos to verify shipment and resolve disputes.
Communication:
• In-app messages: To enable buyer-seller communication about transactions.
• Support queries: To provide customer support and resolve issues.
• Dispute submissions: To review and resolve delivery disputes fairly.
Device & Usage Data:
• Device model and OS version: To ensure app compatibility and fix technical issues.
• App usage patterns: Features used, search queries, and listings viewed to improve the user experience and recommend relevant products.
• Crash reports: To identify and fix bugs that affect app stability.
Location Data (With Your Consent):
• Approximate location (from device GPS): Used ONLY to show nearby products and reels. This location data is NOT shared with other users.
Cookies & Analytics:
• Session data: To keep you logged in and remember your preferences.
• Analytics: To understand how users interact with the app and identify areas for improvement.
2. How We Use Your Information
We use the collected information to:
1. Operate and improve the Thrifteast platform.
2. Facilitate transactions between Buyers and Sellers.
3. Authenticate user identity and prevent fraudulent activity.
4. Process payments and manage refunds.
5. Provide customer support and dispute resolution.
6. Send transactional notifications (order updates, interest expressed, etc.). Note: We do not send promotional or marketing communications.
7. Comply with legal obligations and enforce Thrifteast's Terms & Conditions.
3. How We Share Your Information
We do not sell or rent your personal data to third parties. Your information is only shared as described below:
With Other Users (Buyers and Sellers):
When you engage in a transaction, the following information is visible to the other party:
• Username, name, and profile picture
• City (not exact address)
• Product listing details (for sellers)
• Delivery address (shared with seller ONLY when you place an order, so they can ship the product to you)
• Order status and delivery updates (for active transactions)
Note: Your phone number, email, UPI address, and GPS location are NEVER shared with other users.
With Service Providers (For Platform Operations):
We share limited data with trusted third-party services to operate the platform:
• Cloud Database & Storage Providers:
- Stores app data including profiles, listings, orders, and messages
- Hosts product images and user-uploaded content
- Data stored in secure servers located in India or nearby regions
• Payment Gateway Providers:
- Processes payments securely using industry-standard encryption
- We do NOT store your full payment card details or UPI PIN
- Only transaction records (amount, status, order ID) are stored
• Push Notification Services:
- To send order updates and important alerts to your device
- Data shared: Device token, notification content
• Analytics & Crash Reporting Services:
- To identify and fix app crashes
- To understand how users interact with the app and improve user experience
- Data shared: Device type, app version, crash logs, and usage patterns
• SMS Service Providers:
- To send OTP codes for login authentication
- To send order status updates via SMS
- Data shared: Phone number and message content only
For Legal Compliance and Safety:
We may disclose your information when required by law or to protect our platform:
• In response to valid legal requests (court orders, subpoenas)
• To comply with tax regulations (financial records retained for 7 years)
• To prevent fraud, abuse, or security threats
• To enforce our Terms & Conditions and protect user safety
Business Transfers:
If Thrifteast is involved in a merger, acquisition, or sale of assets, your data may be transferred to the new owner. You will be notified of any such change, and the same privacy protections will continue to apply.
4. Data Retention
We retain your information as long as your account is active or as necessary to comply with legal obligations.
Account Deletion:
• Accounts with no transaction history: Your account will be permanently deleted after a 30-day grace period.
• Accounts with orders/payments: Your personal information (name, email, phone, addresses) will be anonymized immediately upon deletion. However, financial records (orders and payments) are retained for 7 years for tax compliance as required by Indian law. This anonymization is DPDPA-compliant when legal obligations require retention.
Data Retention Periods:
• Financial records (orders, payments): 7 years (anonymized but retained for tax compliance)
• Profile data: 30-day grace period, then permanent deletion if no orders
• Notifications: 90 days, then auto-deleted
• Reservations: 30 days, then auto-deleted
You may request account deletion at any time through the app settings. The deletion process will follow the above retention policies based on your account history.
5. Data Security
We implement strong technical and organizational measures to protect your data from unauthorized access, alteration, or disclosure.
Sensitive information such as passwords and payment credentials are encrypted and transmitted securely.
However, no method of internet transmission or storage is 100% secure, and Thrifteast cannot guarantee absolute security.
6. Your Rights and Choices (DPDPA 2023)
Under India's Digital Personal Data Protection Act (DPDPA) 2023, you have the following rights:
1. Right to Access: You can access all your personal data stored by Thrifteast. Use the "Export My Data" feature in Privacy Settings to download your complete data in JSON format. The export includes:
• Profile information (with profile picture URLs)
• Orders and payment history
• Consent records
• Grievances submitted
• Product interests and cart items
• Reservations made
• Reels created (with video and cover image URLs)
• Reports submitted
• Feedback and feedback votes
• Seller data (if applicable): products (with cover and media URLs), payouts, and transfers
2. Right to Correction: You can update or correct your personal information at any time through your profile settings.
3. Right to Deletion: You can request account deletion at any time. See Section 4 (Data Retention) for details on how deletion is processed based on your account history.
4. Right to Withdraw Consent: You can withdraw your consent for data processing at any time through the Consent Management section in Privacy Settings. Note: Withdrawing consent for Privacy Policy or Terms may limit your ability to use the app.
5. Right to Grievance Redressal: You can file a grievance regarding your data through the "Grievances" feature in Privacy Settings. Grievances can be submitted for:
• Data Access Requests
• Data Correction Requests
• Data Breach Reports
• Consent-Related Issues
• Other Privacy Concerns
Your grievance will be automatically acknowledged immediately upon submission. We will resolve it within 30 days as per DPDPA requirements. You will receive notifications when your grievance status is updated.
6. Right to Nominate: You can nominate another person to exercise your rights in case of death or incapacity (as per DPDPA provisions).
All requests can be made through the Thrifteast app (Privacy Settings) or by contacting our Grievance Officer at: thrifteast.help@gmail.com
7. Children's Privacy
Thrifteast is intended for users aged 18 and above. We do not knowingly collect personal data from minors. If we learn that a minor has registered, the account will be deleted promptly.
8. Third-Party Links
Our app or website may contain links to third-party websites or services. Thrifteast is not responsible for the content, privacy, or security practices of such third parties.
9. DPDPA 2023 Compliance
Thrifteast is fully compliant with India's Digital Personal Data Protection Act (DPDPA) 2023. This includes:
Consent Management:
• All data processing is based on explicit consent, which you provide during registration.
• Two types of consent are required: Privacy Policy and Terms & Conditions.
• Consent is recorded with version numbers, timestamps, and policy URLs.
• You can view, manage, accept, and withdraw your consents at any time through the Consent Management feature in Privacy Settings.
• When policies are updated, you will be notified and prompted to provide fresh consent for the new version.
• Withdrawing consent for Privacy Policy or Terms & Conditions will limit certain app features until you provide consent again.
Data Processing:
• We only collect and process data necessary for providing our services.
• Data is processed lawfully, fairly, and transparently.
• We implement appropriate technical and organizational measures to protect your data.
Grievance Redressal:
• We have a dedicated grievance redressal system accessible through Privacy Settings > Grievances.
• Grievances are automatically acknowledged immediately upon submission.
• All grievances are resolved within 30 days as per DPDPA requirements.
• You can track your grievance status and view responses through the Grievance History tab.
• You will receive in-app notifications when your grievance status is updated (pending → in_progress → resolved/rejected).
• All grievances are logged and tracked for compliance purposes.
• Admins monitor grievances for compliance, with automated alerts for overdue or unacknowledged cases.
Data Export:
• You can export all your personal data at any time through Privacy Settings > Export My Data.
• The export is generated as a PDF document with all your data organized in tables.
• Media URLs (images, videos) are included as clickable links in the PDF.
• The PDF can be saved to your device or shared via your device's native share functionality.
• Buyers can also download individual order invoices from the Orders screen.
• All export requests are logged in the audit trail for compliance.
Audit Logging:
• All data access and modifications are logged in an audit trail.
• Export requests are automatically logged with timestamps.
Data Breach Notification:
• In the event of a data breach, we will notify affected users and the Data Protection Board as required by DPDPA.
For any DPDPA-related queries or to exercise your rights, contact our Grievance Officer at: thrifteast.help@gmail.com
10. Policy Updates
We may update this Policy periodically to reflect changes in our practices or legal requirements. The updated version will be posted on our website with a revised "Last updated" date.
When we update the Privacy Policy or Terms & Conditions:
• The version number will be incremented (e.g., Version 1.0 → Version 1.1).
• You will be notified of the update through an in-app notification or banner.
• For significant changes: You will be prompted to review the updated policy and provide fresh consent. A notification will appear in the app directing you to review and accept the new version.
• For minor updates: You will be notified, and your continued use of the app after the notification constitutes acceptance of the updated Policy.
• You can review your consent history and policy versions at any time in Privacy Settings > Consent Management.
Your previous consent remains valid for the version you accepted. When a new version is released, you will need to provide fresh consent for the new version to continue using the app.
If you do not accept the updated Privacy Policy or Terms & Conditions, the following features will be limited:
• Creating new product listings (sellers)
• Making purchases or placing orders (buyers)
• Creating or posting reels
• Updating your profile information
• Adding items to cart or expressing interest
• Making reservations
• Processing payments or payouts
You will still be able to:
• Browse and search products (read-only)
• View product details and profiles
• View your existing orders and listings
• Access Privacy Settings to review and accept updated policies
• Export your data or file grievances
• Delete your account
You can review and accept updated policies at any time through Privacy Settings > Consent Management, after which all features will be restored.
Continued use of our Services after being notified of policy updates (and after providing fresh consent for new versions, if required) constitutes acceptance of the updated Policy.
Thrifteast Grievance Officer (DPDPA 2023)
Response Time: Within 30 days as per DPDPA requirements