Privacy Policy

Last updated: 21 July 2026 · Draft aligned to the Digital Personal Data Protection Act, 2023 — for review by qualified legal counsel before publication.

1. What we collect and why

Account data (name, email, phone, password hash — or your Google account identifier if you sign in with Google): to create and secure your account. Profile and listing data you choose to publish (headline, skills, business details, GST number if you request verification): to operate the directory and profiles — this data is public by design. Content (questions, answers, articles, reviews, messages): to run the community; private messages are visible only to their participants and our moderation processes when reported. Transaction data (orders, invoices, subscription status, shipping details for marketplace orders): to deliver paid services and meet tax obligations. Technical data (session cookies, IP, device information, logs): for security, rate-limiting and abuse prevention.

2. Payments

Payments are processed by Razorpay. DSI never receives or stores your card number, UPI PIN or banking credentials. We receive only the payment confirmation and identifiers needed to reconcile your order.

3. What we do not do

We do not sell personal data. We do not share it with third parties except: payment processing (Razorpay), email delivery, hosting infrastructure, and where required by law. Vendors receive the shipping name, phone and address you enter for their orders — only for fulfilment.

4. Your rights under the DPDP Act, 2023

You may access a summary of your personal data, correct inaccurate data, and request erasure of your account and associated personal data (subject to records we must retain, such as tax invoices). You may withdraw consent for optional processing — for example, one-click unsubscribe works in every newsletter we send. To exercise any right, contact the grievance officer below; we will respond within the timelines prescribed by law.

5. Retention and security

Account data is retained while your account is active and deleted or anonymised on verified erasure requests, except invoices and transaction records retained per Indian tax law. Passwords are stored only as modern one-way hashes; uploads are re-encoded server-side; access to production systems is restricted and logged.

6. Cookies

We use a session cookie (sign-in state, CSRF protection) and a remember-me token if you opt in. We do not run third-party advertising cookies.

7. Grievance officer

[NAME], Grievance Officer — [EMAIL] — [ADDRESS]. (To be completed before publication; required under Indian law.)