Privacy Policy
Last updated: May 4, 2026
1. What we collect
- Identity: name, email, phone, government IDs (GSTIN / PAN / FSSAI / etc.) provided during KYC.
- Bank account details for payouts (account number stored encrypted; only last-4 visible).
- Operational data: orders, payments, inventory movements, fulfillment events.
- Device + access logs: IP, user-agent, login timestamps, audit events.
2. How we use it
To run the marketplace: identity verification, order routing, fulfillment, settlement, fraud signal monitoring, support, and product improvement. We do not sell your personal data.
3. Sharing
We share data with vetted processors (payment gateways, logistics providers, SMS/email vendors, cloud infra) under data-processing agreements. We share with regulators when legally required.
4. Retention
KYC + financial records: retained per Indian regulatory minimums (typically 8 years). Operational logs: retained 24 months unless under audit. Account closure: PII anonymized within 30 days; the audit trail itself remains in append-only form for traceability.
5. Your rights
You may request access to, correction of, or deletion of your personal data by writing to privacy@strongnation.in. We respond within statutory timelines. Account closure is subject to clearing open financial obligations.
6. Security
Data in transit: TLS 1.2+. Data at rest: AES-256 with a managed KMS. Access scoped by RBAC v2 role assignments; sensitive operations require step-up OTP. Bank account numbers are envelope-encrypted.
7. Children
The Platform is not intended for users under 18.
8. Changes
Material changes will be notified in-app and via email at least 14 days before they take effect, where practicable.
9. Contact
Privacy questions: privacy@strongnation.in. Grievance officer details will be published with the binding version.