This policy explains what personal data Zippsite collects, why, who we share it with, how long we keep it, and what you can ask us to do with it. Zippsite is commerce software: Sellers use it to run their own online Stores, and Buyers use those Stores to buy from those Sellers. This policy applies alongside our Terms of Service and Buyer and Seller Agreement.
1. About this policy
1.1 This Privacy Policy explains how Zippsite Technologies Private Limited (“Zippsite”, “we”, “us”, “our”), CIN U63122KA2025PTC211609, handles personal data when you use Zippsite — our website at zippsite.com, the Stores published on it, our applications, and the Instagram and messaging integrations we provide.
1.2 It applies to Sellers, to Buyers, including people who buy without an account, and to visitors.
1.3 We are the Data Fiduciary for the personal data described here, within the meaning of the Digital Personal Data Protection Act, 2023. This policy is written to meet that Act and the Digital Personal Data Protection Rules, 2025, together with the Information Technology Act, 2000 and the rules under it.
1.4 It sits alongside our Terms of Service and Buyer and Seller Agreement, and prevails over both on anything to do with personal data.
1.5 It replaces the Privacy and Data Policy previously shown in the product, and is meant to formalise and expand it rather than contradict it. Two commitments carry over unchanged: we do not sell your personal data, and we honour deletion requests.
2. Who we are and how to reach us
Company: Zippsite Technologies Private Limited
Registered office: Om Chambers, Binnamangala Stage 1, Indiranagar, Bengaluru, Karnataka 560038, India
CIN: U63122KA2025PTC211609
General contact: [email protected]
Privacy and data requests: [email protected]
Our Grievance Officer's details are in Clause 20.
3. What we collect
We collect what we need to run the software. What we hold about you depends on how you use it.
If you create an account
- Your name, email address and phone number.
- Sign-in identifiers — a Google account identifier if you use Google sign-in, or a verified phone number if you sign in by one-time password. We never receive your Google password.
If you buy
- Your phone number, and a browser session identifier if you buy without an account.
- Delivery addresses you enter, and the recipient name and contact number for each.
- Your inquiries, offers and counter-offers, the negotiation history, and the orders you place.
- Invoices, payment status, and anything you raise about an order.
- Proof of payment you upload, where you pay a Seller directly.
- Reviews and ratings you submit.
If you run a Store
- Business name, business phone number and registered business address.
- GSTIN and, where you are not registered under GST, your enrolment identifier.
- PAN, collected for payment KYC.
- Bank account details for payouts. These are held by our payment provider; we hold a reference to your linked account, not your account credentials.
- Your Store, products, variants, categories, prices, images and Store Policies.
- Your orders, invoices, settlements and deductions.
If you connect an Instagram account
Covered in full in Clause 6.
Automatically, as you use Zippsite
- IP address, browser type and version, device type and operating system.
- Pages viewed, actions taken, timestamps, referring pages and error logs.
- Cookies and similar identifiers — see Clause 12.
3.1 What we never collect. We do not collect complete payment card numbers, CVV codes, UPI PINs or banking passwords — those go straight to our payment provider. We will never ask you for a one-time password.
4. Why we use your data
| Purpose | What this involves |
|---|---|
| Running the software | Creating and securing your account, publishing Stores, running inquiries and negotiation, forming orders, and giving you your history. |
| Payments and settlement | Passing our payment provider what it needs to collect payment, deduct fees and settle Sellers. |
| Fulfilling orders | Sharing delivery details with the Seller and the courier, generating labels, and providing tracking. |
| Invoicing and tax | Generating invoices and meeting our tax obligations. |
| Support | Answering your questions, looking into problems with an order, and running our grievance process. |
| Safety and fraud prevention | Detecting fraud, abuse, counterfeit listings and misuse, and enforcing our terms. |
| Communication | Sending you transactional messages about your inquiries and orders by email, SMS or WhatsApp. |
| Improving the software | Understanding how it is used, fixing problems and building features. We use aggregated and de-identified data for this wherever we can. |
| Legal compliance | Meeting obligations under tax, consumer protection and data protection law, and responding to lawful requests. |
4.1 We rely on your consent where processing is not necessary to provide what you asked for. Where it is necessary to perform our agreement with you, to meet a legal obligation, or for a legitimate use permitted under the Digital Personal Data Protection Act, 2023, we rely on that instead and say so in the notice we give you.
4.2 Marketing. Transactional messages about your inquiries and orders are part of the service. We send promotional messages only if you have agreed, and you can opt out any time. Opting out of promotional messages does not stop transactional ones, which you need in order to use the service.
5. Buying without an account
5.1 You can browse a Store, make an inquiry, negotiate and buy without creating an account. We then identify you by a browser session identifier and the phone number you give us, and collect the same order-related data as for a registered buyer, because we need it to complete the purchase and get the goods to you.
5.2 We show you this policy and ask you to accept it before your first inquiry as a guest, so your consent is recorded even though you have no account.
5.3 If you later create an account and verify the same phone number, we link your guest activity to it. We match on the phone number alone, so do not use a number that is not yours.
5.4 Worth knowing. Guest activity is tied to your browser session and phone number. Clear your browser data or switch device and you may not see it again until you verify the number. We keep the underlying order records either way, because we need them for invoicing and tax.
6. Instagram and Meta data
This applies only to Sellers who connect an Instagram business account, and to the people who interact with them through it.
6.1 What we receive. The Instagram business account identifier and username; profile information for that account; media the Seller chooses to import, including images and captions; comments on that Seller's posts matching keyword triggers the Seller has set; and the business messages sent and received through the automation the Seller has switched on.
6.2 Why. Only to provide the integration features the Seller has enabled — importing media as products, matching comments against that Seller's own triggers, and sending the replies that Seller configured.
6.3 What we never do with it. We do not sell Instagram data. We do not use it for third-party advertising. We do not use it to build profiles of people for anything unrelated to that Seller's Store. We do not share it with other Sellers.
6.4 If you commented on a Seller's post and got an automated message, we hold your Instagram username, the comment that matched, and the message thread. That Seller set up the automation and is responsible for what it says. You can ask the Seller to stop, and you can ask us — see Clause 20 — and we will act on it.
6.5 A Seller can switch off individual triggers, disable the automation, or disconnect the account entirely at any time.
6.6 Deauthorisation and deletion. We support Meta's deauthorisation and data-deletion callbacks. If you remove the Zippsite integration from your Instagram account, or send a deletion request through Meta, we delete the access tokens, imported media references, conversation data and automation configuration for that connection. You can also ask us directly at the address in Clause 20.
6.7 What survives. We keep records of orders that actually happened, and their invoices, because tax and consumer protection law requires it. Those are order records, not Instagram data.
6.8 Meta operates under its own terms and privacy policy, which govern what Meta does on its own platform. We have no control over that.
7. Automated processing and AI features
7.1 Sellers can enable an AI assistant that responds to buyer inquiries and negotiates on their behalf. Where it is active, we tell the buyer, and the buyer can ask to deal with the Seller directly.
7.2 It processes the inquiry and negotiation thread, the product and pricing information for that Store, and the parameters the Seller set. It does not receive payment credentials.
7.3 We also offer tools that suggest product names and descriptions for Sellers, generated from their own listing content and images.
7.4 We use automated systems to detect fraud, abuse and prohibited listings. Where one flags something, a person reviews it before we suspend an account, unless we need to act immediately to prevent harm.
7.5 Training. We may use aggregated and de-identified data to improve the software. We do not use the content of a Seller's negotiations to train models offered to that Seller's competitors in any form that could identify the Seller, its buyers, its pricing or its margins.
7.6 You can ask us for a human review of any automated decision that materially affects you.
8. Payment information
8.1 Payments made through checkout are processed by our payment provider, which is regulated as a payment aggregator by the Reserve Bank of India. Card, UPI and net-banking credentials are collected by and stay with that provider. We do not store complete card details.
8.2 We receive the payment status, a transaction reference, the amount, the method used, and the outcome of any refund or chargeback. We use this to reconcile orders, settle Sellers and look into problems.
8.3 Seller KYC information — PAN, business type, registered address and GSTIN — is collected for and shared with our payment provider so it can verify the Seller and make payouts. Payout bank details are held by that provider.
8.4 If you pay a Seller directly. Where you pay outside checkout and upload proof, the proof you upload is stored and shared with that Seller so they can confirm receipt. A screenshot can show far more than the payment — account numbers, balances, unrelated transactions. Upload only what evidences the payment and mask the rest. We hold it only to evidence the transaction and to help if there is a problem with the order.
9. Messages between Buyers and Sellers
9.1 Zippsite carries direct messages between buyers and Sellers and messages tied to a specific order. We store them.
9.2 We do not read messages routinely. We access them where necessary to look into a problem with an order, respond to a report of abuse or fraud, meet a legal obligation, or protect someone's safety.
9.3 Messages may be produced as evidence where we look into a problem, in a grievance, or where the law requires.
9.4 Do not send payment credentials, one-time passwords or identity documents through messaging. No genuine Zippsite staff member will ask you for a one-time password.
10. Who we share your data with
10.1 We do not sell personal data. We share it only as set out below.
| Who | What they get | Why |
|---|---|---|
| The Seller you buy from | Your name, delivery address, phone number and order details | To fulfil your order. What they may do with it is in Clause 11. |
| The buyer who buys from you | Your business name, address, contact details and rating | So buyers know who they are buying from, as the law requires. |
| Our payment provider | Payment and KYC information as described in Clause 8 | To collect payment, verify Sellers and make payouts. |
| Courier and logistics providers | Recipient name, delivery address and phone number | To collect and deliver the order. |
| Cloud hosting and storage providers | Data processed on our behalf, including uploaded images | To host and run the software. |
| Analytics providers | Usage and device data, aggregated or pseudonymised where we can | To understand usage and improve the software. |
| Customer support tooling | Your contact details and what you tell us | To answer your questions and track issues. |
| Meta | Only what is needed to operate a Seller's connected Instagram integration | To send and receive messages through that Seller's own account. |
| Professional advisers and auditors | Only what is necessary | For advice, audit, and legal claims. |
| Authorities and courts | What we are lawfully required to disclose | To meet a legal obligation or valid request. |
| An acquirer | Data relevant to the transaction | If we are involved in a merger or sale of assets. We will tell you before your data becomes subject to a different policy. |
10.2 We name categories rather than companies because our providers change from time to time. If you want to know who currently handles a particular function, or who we have shared your data with, write to [email protected] and we will tell you.
10.3 We require the providers we engage to process personal data only on our instructions, keep it secure, and not use it for their own purposes.
11. What Sellers may do with your details
11.1 When you buy, the Seller gets your name, delivery address and phone number so they can send you the goods. Under the Buyer and Seller Agreement that Seller must:
- (a) use your details only to fulfil your order and handle anything arising from it;
- (b) not use them for marketing or profiling, and not contact you about anything else — including not adding you to a WhatsApp broadcast list, a mailing list or a customer database;
- (c) not sell, publish or pass them to anyone else, except a courier so far as needed to deliver;
- (d) keep them secure and tell us promptly if they are exposed; and
- (e) delete them once they are no longer needed, unless the law requires otherwise.
11.2 If a Seller misuses your details, tell us at the address in Clause 20. We can suspend them and take the action set out in the Buyer and Seller Agreement. A Seller who misuses your data is also accountable in their own right under the Digital Personal Data Protection Act, 2023, and you can complain about them to the Data Protection Board of India.
12. Cookies
12.1 We use cookies and similar technologies to keep you signed in, remember your session including a guest session, keep things secure, and understand how the software is used.
12.2 Essential cookies are needed for it to work — without them you cannot stay signed in or complete a purchase. Analytics cookies are used only where you allow them.
12.3 You can control cookies in your browser. Blocking essential ones will stop parts of the software working.
13. How long we keep your data
13.1 We keep personal data only as long as we need it for the purpose we collected it for, to meet a legal obligation, to sort out a problem with an order, or to enforce our agreements.
13.2 In broad terms:
- (a) order records, invoices and tax records are kept for the period tax and companies law requires, which is several years;
- (b) account details are kept while your account is open and for a period afterwards, so you can come back and so anything outstanding can be resolved;
- (c) inquiries, negotiation history and messages are kept for as long as they may be needed to resolve a problem with an order;
- (d) Seller KYC data is kept for as long as payment and anti-money-laundering requirements demand;
- (e) Instagram tokens and connection data are deleted on disconnection or on a deletion request;
- (f) proof-of-payment uploads are kept only as long as needed to evidence the transaction; and
- (g) technical and usage logs are kept for a short period for security and debugging.
13.3 If you want to know the specific period that applies to a particular kind of data about you, write to [email protected] and we will tell you.
13.4 When a period ends we delete the data or irreversibly anonymise it. Anonymised data, which can no longer identify you, may be kept for analysis.
14. Your rights
Under the Digital Personal Data Protection Act, 2023 you have the rights below. They cost nothing to use and we will respond within the time the law allows.
14.1 Access — ask what we hold about you, what we do with it, and who we have shared it with.
14.2 Correction — have inaccurate or incomplete data corrected. You can change most account details yourself.
14.3 Erasure — ask us to delete your data. Clause 15 explains what we can and cannot delete.
14.4 Withdraw consent — as easily as you gave it. Withdrawal does not undo what we did before, and may mean we can no longer provide parts of the service.
14.5 Complain — to us first, under Clause 20. If you are not satisfied, or we do not respond in time, you can complain to the Data Protection Board of India.
14.6 Nominate — name someone to exercise your rights if you die or become incapacitated.
14.7 To use a right, write to us at [email protected] from the email address or phone number on your account, or use the tools in the product. We may ask you to verify your identity — only as much as we need, and not for anything else.
15. Deleting your data
15.1 Ask us at the address in Clause 20, use Meta's data-deletion flow for Instagram data, or close your account in the product.
15.2 What we delete: your account profile, saved addresses and preferences, Store content not tied to a completed order, Instagram tokens and configuration, imported media not used in a completed order, and messages not needed for an unresolved order.
15.3 What we keep, and why. We cannot delete records of orders that actually happened. Invoices, order records, payment records and tax data have to be kept for the periods in Clause 13 because tax, companies and consumer protection law requires it. We also keep what we need to resolve an open problem or defend a legal claim. We keep those restricted — used only for that, not to contact you or profile you.
15.4 If you run a Store with orders in progress, unsettled amounts or an unresolved problem, we will finish those first and tell you what is outstanding.
15.5 We act on a deletion request within the time the law allows and confirm when it is done.
16. How we protect your data
16.1 We use technical and organisational safeguards appropriate to the risk, including encryption in transit, access controls limiting staff access to what each role needs, logging of access to sensitive records, and regular review of our practices.
16.2 Payment credentials are handled by our payment provider under its own regulated obligations, not by us.
16.3 No system is completely secure. If a breach happens that is likely to affect you, we will tell you and the Data Protection Board of India as the law requires, and explain what happened and what you can do.
16.4 You help by keeping your credentials private, never sharing a one-time password, and telling us promptly if you think someone else has got into your account.
17. Children
17.1 Zippsite is for people aged 18 and over. We do not knowingly collect data from children.
17.2 If we learn we hold a child's personal data without the verifiable consent the law requires, we will delete it. Tell us at the address in Clause 20 if you think we do.
17.3 We do not carry out tracking, behavioural monitoring or targeted advertising directed at children.
18. Where your data is processed
18.1 Your data is processed primarily in India. Zippsite is an Indian company, our users are in India, and we keep processing here wherever we reasonably can.
18.2 Some of it may be processed outside India. The Service is built on infrastructure and tools provided by others — hosting, storage, analytics and customer support among them — and some of those providers operate from, or hold data on servers in, other countries. Where that is how a provider works, your data is processed there too.
18.3 Wherever it goes, the same protections follow it. We transfer personal data outside India only in a manner permitted by the Digital Personal Data Protection Act, 2023, and never to a country the Central Government has restricted for this purpose. We require every provider to handle your data only on our instructions, to keep it secure, and to protect it to the standard set out in this policy. Moving data across a border does not lower what we owe you, and it does not change any of your rights under Clause 14.
18.4 If you want to know where a particular kind of data about you is held, write to [email protected] and we will tell you.
19. Changes to this policy
19.1 We may update this policy. Material changes take effect not less than fifteen (15) days after we tell you through the product or by email, unless the law requires sooner.
19.2 Where a change means we need your consent, we will ask for it rather than assume it.
19.3 We keep previous versions and will send you one on request.
20. Complaints
For any question or complaint about how we handle your data, contact our Grievance Officer, appointed under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021:
Name: Syed Aezaz Ahmed
Designation: Co-founder and Director
Email: [email protected]
Address: Om Chambers, Binnamangala Stage 1, Indiranagar, Bengaluru, Karnataka 560038, India
20.1 We acknowledge complaints within forty-eight (48) hours and aim to resolve them within one (1) month.
20.2 If you are not satisfied with our response, or we do not respond in time, you can complain to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023, or to any other authority open to you.