Back to home

EasyShipy Privacy Policy

Version Draft — Effective [DATE — not yet published]

This is an internal working draft, not a finalised policy. It contains placeholder fields marked ⚖ throughout and has not been reviewed by counsel. Do not rely on this page as an accurate description of EasyShipy's actual data-handling practices.

1. Scope and Roles

This Policy applies to personal data processed through the EasyShipy Platform, including data relating to:

  • Sellers — businesses and individuals who register on the Platform to ship goods;
  • Buyers — recipients of Seller shipments, whose data is provided to EasyShipy by Sellers, not collected directly from Buyers in most cases;
  • Website visitors — including anonymous visitors to the public tracking page and marketing site.

For Seller data, EasyShipy generally acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act").

For Buyer data provided by Sellers for shipment fulfilment, EasyShipy's role is more complex — functionally closer to a processor acting on the Seller's instructions for certain purposes (arranging delivery), while also independently determining some processing purposes such as fraud prevention and platform analytics.

⚖ This dual role requires an explicit legal characterisation from qualified counsel — the DPDP Act does not have a formal "processor" category identical to other jurisdictions' frameworks, and how obligations split between EasyShipy and the Seller for Buyer data needs deliberate legal determination.

2. Personal Data We Collect

From Sellers, at registration and KYC

  • Name, email address, phone number
  • Company name, business type, GSTIN, PAN
  • Bank account number, IFSC code (for COD settlement)
  • KYC documents — PAN card, GST certificate, address proof
  • Login credentials, via Firebase Authentication

From Sellers, about Buyers (for shipment fulfilment)

  • Buyer name, phone number, email address, where provided
  • Delivery address
  • Order details — product description, declared value, COD amount
⚖ Because this category is data about a third party collected from the Seller, notice-and-consent requirements need careful legal thought — EasyShipy has no direct relationship with the Buyer at the point of collection.

Collected automatically

  • IP address, device and browser information
  • Usage data — pages visited, actions taken on the Platform
  • Cookies — including the session/authentication cookie used to keep Sellers logged in

3. How We Use Personal Data

  • To create and manage Seller accounts, and verify KYC
  • To create, route, and track Shipments
  • To calculate and collect shipping charges, COD settlement, and refunds
  • To send Shipment notifications to Buyers where the Seller has enabled these
  • To detect and prevent fraud
  • To comply with legal and regulatory obligations
  • To improve the Platform

4. Who We Share Personal Data With

  • Courier Partners — Buyer name, address, and phone are shared to enable physical delivery.
  • Communication providers — for sending Shipment notifications by SMS, WhatsApp, or email.
  • Payment processor — for processing Seller wallet recharges. EasyShipy does not itself store full card details.
  • Authentication provider — for Seller login and identity verification.
  • Cloud storage provider — for storing KYC documents, held privately and not publicly accessible.
  • Regulators and law enforcement — where required by law.
  • Analytics provider, if integrated — for platform usage analytics.
⚖ Every recipient in this section needs to be confirmed against what is actually integrated and currently live before publishing — an inaccurate processor list is itself a compliance gap under the DPDP Act's notice requirements, not just an accuracy issue.

EasyShipy does not sell personal data.

Each third party listed above processes data under its own privacy terms; where EasyShipy has a contract with a processor, that contract should require appropriate data-protection commitments.

5. Cross-Border Data Transfer

The DPDP Act generally permits transfer of personal data outside India except to countries restricted by the Central Government.

⚖ If any processor above stores or processes data outside India, that needs explicit disclosure here, reviewed against whatever restricted-country list is in force at the time of publishing. This is a clause that can go stale and needs periodic re-review, not a one-time draft.

6. Data Retention

Personal data is retained only as long as necessary for the purposes described in this Policy, or as required by law, including tax, GST, and financial record-keeping obligations.

⚖ Specific retention periods per data category — KYC documents, transaction records, Buyer delivery data, communication logs — need to be defined explicitly rather than left as a general principle. A vague "as long as necessary" without defined periods is weaker than a specific schedule under regulatory scrutiny.

7. Data Principal Rights

Subject to the DPDP Act and its rules, a Data Principal has the right to:

  • Access — obtain a summary of personal data being processed;
  • Correction and completion — request correction of inaccurate or incomplete data;
  • Erasure — request erasure of data no longer necessary for the stated purpose, subject to legal retention requirements;
  • Grievance redressal — raise a complaint about processing;
  • Nominate — nominate another individual to exercise these rights in case of death or incapacity.

To exercise these rights, contact [PRIVACY EMAIL].

8. Cookies

EasyShipy uses at minimum an essential session/authentication cookie required for Sellers to remain logged in.

⚖ Any additional cookies — analytics, marketing, or preference cookies — must be disclosed here individually, along with whether each is essential or requires consent. This needs an actual technical audit of what is currently running on the live site, not an assumption in either direction.

9. Grievance Officer

Name: [GRIEVANCE OFFICER NAME] Email: [grievance@easyshipy.com] Address: [ADDRESS]

⚖ This can be, and commonly is, the same Grievance Officer named in the Seller Terms of Service — confirm that consolidation is appropriate rather than assuming it by default.

10. Children's Data

EasyShipy's Platform is intended for use by businesses and adults. EasyShipy does not knowingly collect personal data from children as defined under the DPDP Act.

⚖ Confirm whether Buyer data collected via Sellers could plausibly include minors as delivery recipients, and reach an explicit, documented conclusion rather than leaving this unaddressed.

11. Security

EasyShipy implements reasonable technical and organisational measures to protect personal data.

⚖ List the actual current measures — access controls, encryption in transit, private storage for KYC documents — rather than a generic claim.

12. Data Protection Board Complaints

A Data Principal who is not satisfied with EasyShipy's response to a grievance may file a complaint with the Data Protection Board of India, in accordance with the DPDP Act and its rules.

13. Changes to This Policy

EasyShipy may update this Policy from time to time.

⚖ Describe the actual notice mechanism for material changes — in-app notification, email to registered Sellers, or another method.

14. Contact

For questions about this Policy: [privacy@easyshipy.com]