Effective date: 5 July 2026 Version: 2.0 Data Fiduciary: Singapuram Hariesh Kumar, an individual carrying on business as a sole proprietor under the trade name "Craftolin" Principal place of business: Gopal Nagar, Malkajgiri, Hyderabad, Telangana 500047, India (complete postal address available on written request to support@craftolin.com) Grievance Officer: Singapuram Hariesh Kumar — support@craftolin.com
1. Introduction and Scope
1.1 This Privacy Policy describes how Craftolin collects, uses, discloses, retains, and protects personal data, and the rights available to you in respect of that personal data.
1.2 This Policy is issued in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000, and the rules made thereunder, and forms part of the Terms and Conditions.
1.3 This Policy applies to the Craftolin customer and partner mobile applications for Android and iOS, the Craftolin web applications, the craftolin.com website, and the backend services supporting them (together, the "Platform").
1.4 Capitalised terms not defined in this Policy have the meaning given to them in the Terms and Conditions.
2. Definitions
2.1 In this Policy:
"Data Fiduciary" means the person who alone or in conjunction with others determines the purpose and means of processing personal data, being the Operator identified above.
"Data Principal" means the individual to whom the personal data relates, being you.
"personal data" means any data about an individual who is identifiable by or in relation to such data.
"processing" means a wholly or partly automated operation performed on personal data, including collection, recording, organisation, storage, retrieval, use, disclosure, erasure, and destruction.
3. Data Fiduciary and Contact
3.1 The Data Fiduciary in respect of personal data processed through the Platform is Singapuram Hariesh Kumar, carrying on business as a sole proprietor under the trade name "Craftolin".
3.2 The Grievance Officer appointed for the purposes of the DPDP Act and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 is:
| Name | Singapuram Hariesh Kumar |
| Designation | Grievance Officer |
| Address | Gopal Nagar, Malkajgiri, Hyderabad, Telangana 500047, India |
| support@craftolin.com | |
| Hours | Monday to Saturday, 10:00 to 18:00 IST, excluding public holidays |
4. Personal Data We Process
4.1 Data you provide directly
| Category | Particulars | Applies to |
|---|---|---|
| Account and identity | Name, email address, telephone number, role, profile photograph | All users |
| Customer delivery profile | Address line, street, city, state, PIN code | Customers |
| Partner business profile | Business name, description, business email, telephone and WhatsApp numbers, business address, Instagram, YouTube and website links, logo and profile images, delivery coverage settings and estimated delivery times | Partners |
| Listing content | Product names, descriptions, prices, categories, subcategories, hashtags, item keywords, delivery timelines, availability, and product images | Partners |
| Requirement particulars | Quantity, required delivery date, delivery city and PIN code, customisation details where applicable, event type | Customers |
| Contact telephone number | The mobile number supplied when submitting a Requirement. Supply of this number is mandatory. See clause 4.4. | Customers |
| Delivery Details | Delivery address line, landmark, contact telephone number, and optionally a contact email address, supplied after the Agreement Code is verified. Supply of the address line and telephone number is mandatory before an Order can be created. See clause 4.4. | Customers |
| Payment record entries | Payment mode, total amount, advance amount, amount received, and balance amount, recorded by users for their own record-keeping | All users |
| Saved events | Event type, event name, event date, and notes saved by a Customer for gifting reminders. See clause 4.5. | Customers |
| Reviews and ratings | Rating, review text, and delivery-time feedback | All users |
4.2 Data collected automatically
| Category | Particulars |
|---|---|
| Device push token | The Firebase Cloud Messaging token for each device, and the device platform (Android or iOS) |
| Platform activity | Product views, wishlist actions, and interaction with the Requirement and Order workflow |
| Transaction history | Requirements, Orders, status changes, and associated timestamps generated through your use of the Platform |
4.3 Data received from third parties
4.3.1 Where you sign in using Google, we receive from Firebase Authentication your basic Google account identity, comprising your name, email address, and Google or Firebase user identifier.
4.4 Disclosure of Customer contact information to Partners
4.4.1 The Platform provides no messaging service. Consequently, a Customer's mobile number is a mandatory field when submitting a Requirement, and is disclosed to the Partner concerned upon submission so that the Partner may contact the Customer.
4.4.2 Following verification of the Agreement Code, the Customer is required to supply Delivery Details. The delivery address line and contact telephone number are mandatory; a landmark and contact email address may also be supplied. These Delivery Details are disclosed to the Partner concerned for the purpose of effecting delivery, and are carried onto the resulting Order record.
4.4.3 A Partner may use a Customer's mobile number and Delivery Details solely for the purpose of discussing, fulfilling, and delivering the Requirement or Order to which they relate. Any other use is prohibited under clause 6.3 of the Terms and Conditions and may result in suspension or termination of the Partner's account.
4.4.4 A Customer who does not wish to disclose a mobile number and delivery address to a Partner should not submit a Requirement to that Partner.
4.5 Saved events are private
4.5.1 Event particulars saved by a Customer under clause 4.1 are private to that Customer. They are not disclosed to any Partner, are not published on any public surface of the Platform, and are used solely to generate reminders to the Customer.
4.6 Data we do not collect
4.6.1 Craftolin does not collect, and the Platform contains no facility to collect:
(a) precise or satellite location data. Location values are city and PIN code typed by you, and are not derived from any device sensor;
(b) your device contacts, calendar, microphone, or biometric data;
(c) payment card numbers, bank account numbers, net-banking credentials, or any other financial account information. Craftolin operates no payment gateway and handles no payment;
(d) government-issued identity documents, including Aadhaar, PAN, passport, or driving licence, whether for verification of Partners or otherwise;
(e) data through any third-party analytics software development kit. The Platform contains no analytics or crash-reporting kit; or
(f) data through any advertising software development kit or advertising identifier. The Platform contains no advertising kit and displays no third-party advertising.
5. Purposes and Lawful Basis of Processing
5.1 We process personal data for the following purposes:
| Purpose | Lawful basis under the DPDP Act |
|---|---|
| Creating, authenticating, and administering your account | Consent |
| Operating the Requirement and Order workflow, including disclosure of contact and delivery particulars between users | Consent, given at the point of submission |
| Displaying Listings, Partner profiles, search results, and discovery features | Consent |
| Generating and delivering push and in-application notifications, including saved-event reminders | Consent |
| Computing ratings, review counts, completion rates, and delivery-time statistics | Consent |
| Storing and delivering images | Consent |
| Applying publishing allowances to Partner accounts | Consent |
| Providing user support and responding to grievances | Consent, and compliance with legal obligation |
| Detecting, investigating, and preventing fraud, abuse, and breaches of the Terms; securing the Platform | Legitimate use under section 7 of the DPDP Act |
| Complying with Applicable Law, and responding to lawful requests from government agencies and courts | Compliance with legal obligation |
| Establishing, exercising, or defending legal claims | Legitimate use under section 7 of the DPDP Act |
6. Notice and Consent
6.1 We obtain your consent at the point at which personal data is collected. Consent is sought through a clear notice describing the personal data to be collected and the purpose of its processing.
6.2 Where you submit a Requirement, the notice presented at that point informs you that your mobile number will be disclosed to the Partner concerned. Submission constitutes consent to that disclosure.
6.3 Where you supply Delivery Details, the notice presented at that point informs you that those particulars will be disclosed to the Partner concerned for the purpose of delivery.
6.4 You may withdraw your consent at any time, with the same ease with which it was given, by contacting the Grievance Officer or by deleting your account. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal, and may limit or prevent your use of the Platform.
6.5 Consent to the disclosure of your mobile number or Delivery Details in respect of a Requirement or Order already transmitted cannot be withdrawn as against the receiving Partner, because that disclosure has already occurred. You may nevertheless require the Partner to cease using those particulars once the transaction is concluded.
7. Disclosure of Personal Data
7.1 Disclosure between users
7.1.1 The following disclosures occur as a necessary incident of the transaction process:
| Disclosed | To | When |
|---|---|---|
| Customer's name and mobile number | The Partner concerned | On submission of a Requirement |
| Customer's Delivery Details | The Partner concerned | On supply, following verification of the Agreement Code |
| Partner's business name, contact person, telephone, WhatsApp number, email, business address, and public Instagram, YouTube, and website channels | The Customer concerned | Upon creation of the Order, simultaneously with the disclosure of the Customer's Delivery Details to the Partner |
| Partner's public profile, including business name, city, links, images, ratings, and statistics | All users | On publication of a Listing |
7.2 Service providers
7.2.1 We disclose personal data to the following processors for the purposes of operating the Platform:
| Provider | Purpose | Categories of data |
|---|---|---|
| Google LLC — Firebase Authentication | User authentication and sign-in | Email address, name, user identifier |
| Google LLC — Firebase Cloud Messaging | Delivery of push notifications | Device push token |
| Cloudflare, Inc. — R2 object storage and content delivery network | Storage and delivery of images | Uploaded images |
| Hosted PostgreSQL database and application hosting | Primary application data store and compute | All structured application data |
7.2.2 Each processor is engaged to process personal data only on our instructions and for the purposes stated.
7.2.3 Craftolin does not sell, rent, or trade personal data, and does not disclose personal data for the purpose of third-party advertising or profiling.
7.3 Legal disclosure
7.3.1 We may disclose personal data where required to do so under Applicable Law, in response to a lawful order, notice, or direction of a court or a government agency authorised to make such request, to enforce the Terms and Conditions, or to protect the rights, property, or safety of Craftolin, our users, or the public.
7.3.2 Where a report of fraud or unlawful conduct is received, we may disclose the account particulars and transaction records within our possession to law enforcement authorities.
7.4 Business transfer
7.4.1 Where the business or assets of the Platform are transferred, including upon incorporation of a company to carry on the business presently carried on by the Operator as a sole proprietor, personal data may be transferred as part of that transaction. Notice of any such transfer will be given in accordance with clause 26 of the Terms and Conditions, and the transferee will remain bound by this Policy until it publishes a replacement.
8. Cross-Border Transfer
8.1 Certain of our processors, including Google and Cloudflare, may process personal data on infrastructure located outside India.
8.2 Such transfers are made in accordance with section 16 of the DPDP Act. We do not transfer personal data to any country or territory in respect of which such transfer has been restricted by the Central Government.
8.3 We take reasonable steps to satisfy ourselves that any such processor maintains security safeguards appropriate to the personal data transferred.
9. Retention
9.1 We retain personal data for so long as your account remains active and for so long as is necessary for the purposes described in clause 5, and thereafter only where retention is required to comply with Applicable Law, to establish, exercise, or defend a legal claim, to resolve a dispute, or to prevent fraud and abuse.
9.2 Transaction records, comprising Requirements, Orders, and reviews, may be retained after account closure in anonymised form in order that the counterparty retains a complete record of its own transactions.
9.3 Where an account is the subject of a report of fraud, unlawful conduct, or a dispute, associated records may be preserved for the period necessary for investigation and for cooperation with law enforcement authorities.
9.4 Our database is backed up nightly to encrypted, access-controlled storage. We retain the seven most recent nightly backups. Personal data that has been deleted may therefore persist within backup media for a period of up to seven days before those backups are cycled out. Backups are used solely for the restoration of the service following a failure, and are never used to repopulate a deleted account.
9.5 Further particulars are set out in the Data Retention Policy.
10. Security Safeguards
10.1 We implement reasonable security safeguards to prevent personal data breach, including:
(a) token-based authentication, with identity tokens issued by Firebase Authentication and verified by our servers on every request;
(b) encryption of data in transit using Transport Layer Security;
(c) role-based access control, restricting access to personal data by reference to user role and to the existence of an active transaction between the users concerned;
(d) direct-to-storage uploads using time-limited presigned URLs, such that image content is transmitted from your device to the storage provider without passing through our application servers;
(e) access-controlled, private object storage for uploaded images; and
(f) encrypted, access-controlled backups.
10.2 No method of transmission or storage is wholly secure. While we take reasonable measures to protect personal data, we cannot guarantee its absolute security.
10.3 In the event of a personal data breach, we will notify the Data Protection Board of India and each affected Data Principal in the manner and within the period prescribed under the DPDP Act.
11. Your Rights
11.1 Subject to the DPDP Act, you have the following rights:
(a) Right to access information. To obtain a summary of the personal data being processed, the processing activities undertaken, and the identities of the Data Fiduciaries and processors with whom your personal data has been shared.
(b) Right to correction and erasure. To obtain the correction of inaccurate or misleading personal data, the completion of incomplete personal data, the updating of personal data, and the erasure of personal data no longer necessary for the purpose for which it was processed.
(c) Right to grievance redressal. To have recourse to the grievance mechanism described in clause 13 in respect of any act or omission regarding your personal data.
(d) Right to nominate. To nominate any other individual to exercise your rights under the DPDP Act in the event of your death or incapacity.
(e) Right to withdraw consent. As described in clause 6.4.
11.2 Most rights may be exercised directly within the Platform. You may view and correct your account and profile particulars through the profile screens, manage saved events, manage notification preferences through your device settings, and delete your account through Profile, then Account, then Delete Account.
11.3 Requests that cannot be actioned within the Platform, including a nomination under clause 11.1(d), may be made to the Grievance Officer at support@craftolin.com. We verify that a request originates from the account holder before acting upon it.
11.4 Self-service account deletion is available in both mobile applications and both web applications. Deletion may also be requested at https://craftolin.com/account/delete or by email to support@craftolin.com. See the Account Deletion Policy and the Data Deletion Policy.
11.5 Where a request is refused in whole or in part, we will inform you of the reasons.
11.6 If you are not satisfied with the response of the Grievance Officer, you may make a complaint to the Data Protection Board of India in the manner prescribed under the DPDP Act.
12. Your Duties as a Data Principal
12.1 Section 15 of the DPDP Act imposes certain duties upon a Data Principal. In particular, you must:
(a) comply with the provisions of all Applicable Law while exercising your rights under the DPDP Act;
(b) not impersonate another person while providing personal data for a specified purpose;
(c) not suppress any material information while providing personal data for any document, identifier, or address issued by the State;
(d) not register a false or frivolous grievance or complaint; and
(e) furnish only such information as is verifiably authentic when seeking correction or erasure.
13. Grievances
13.1 A grievance concerning the processing of your personal data may be submitted by email to support@craftolin.com, marked for the attention of the Grievance Officer.
13.2 We will acknowledge receipt of your grievance within twenty-four hours of receipt, and will dispose of it within fifteen days of receipt.
13.3 We maintain a record of each grievance received, the action taken, and the date of that action.
14. Children
14.1 The Platform is intended for and available only to persons who have attained eighteen years of age.
14.2 We do not knowingly process the personal data of any child. We do not undertake tracking or behavioural monitoring of children, and we display no targeted advertising.
14.3 If you believe that a child has provided personal data to us, contact the Grievance Officer and we will take steps to erase it.
15. Cookies and Similar Technologies
15.1 Our web applications use browser local storage, session storage, and cookies necessary for authentication and session management, principally those set by Firebase Authentication.
15.2 We use no advertising cookies, no third-party tracking cookies, and no cross-site analytics cookies.
15.3 Further particulars are set out in the Cookie Policy.
16. Notifications and Communications
16.1 We send push notifications through Firebase Cloud Messaging and in-application notifications in respect of Requirement and Order events, and in respect of reminders for events you have saved, which are dispatched approximately fifteen days and seven days before the event date.
16.2 You may disable push notifications through your device settings. Communications necessary for the operation of the Platform, including those relating to security, legal changes, and transactions, may continue to be sent.
17. Amendment of this Policy
17.1 We may amend this Policy from time to time. The revised Policy takes effect upon publication, save that where an amendment is material we will give reasonable advance notice by in-application notification, email, or other reasonable means.
17.2 The effective date and version number at the head of this Policy indicate when it was last revised.
18. Contact
18.1 Questions concerning this Policy, and requests to exercise your rights, should be addressed to:
| Grievance Officer | Singapuram Hariesh Kumar |
| support@craftolin.com | |
| Address | Gopal Nagar, Malkajgiri, Hyderabad, Telangana 500047, India |
| Acknowledgement | Within twenty-four hours of receipt |
| Disposal | Within fifteen days of receipt |