Privacy Policy
Last updated: 1 June 2026
This Privacy Policy is published in accordance with the Digital Personal Data Protection (DPDP) Act 2023, the Information Technology Act 2000, and the IT (Reasonable Security Practices and Procedures) Rules 2011.
Amarzen Technologies (a sole proprietorship, operating under the "Indikala" brand, referred to as "Indikala", "we", "us", or "our") operates the website indikala.in and related mobile applications. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our platform or make a purchase.
1. Applicability
This Privacy Policy applies to all information collected through the Platform, in email, SMS, WhatsApp, in-app notifications, and other electronic communications sent through or in connection with our Services. This includes information collected from buyers, sellers, and visitors.
This Policy does not apply to information that you provide to, or that is collected by, any third party (such as Razorpay, Delhivery, or Firebase). We encourage you to consult directly with such third parties about their privacy practices before providing them with your information.
2. Data Fiduciary
Under the DPDP Act 2023, Indikala acts as a Data Fiduciary, the entity that determines the purpose and means of processing your personal data.
Entity: Amarzen Technologies (a sole proprietorship)
Email: privacy@indikala.in
3. Information We Collect
We collect the following types of personal data:
- Personal Information: Name, phone number, email address, and delivery addresses provided during registration or checkout.
- Payment Information: Payment details are processed securely through Razorpay. We do not store your card or bank account details on our servers.
- Device & Usage Data: IP address, browser type, device information, pages visited, and interaction patterns to improve our services.
- Location Data: Approximate location based on your delivery address or device location (with your permission) to show relevant stores and estimate delivery.
- Seller KYC Data: If you register as a seller, we collect PAN number, GSTIN, FSSAI registration number (for food sellers), bank account details, store address, and identity verification documents during onboarding. This data is encrypted using AES-256-GCM and stored in a separate secured database table.
- Transaction Data: Order history, purchase amounts, commission calculations, settlement records, TDS/TCS deductions, and payout history for regulatory compliance and financial reconciliation.
4. Purpose & Legal Basis for Processing
We process your personal data based on your consent (obtained at registration and checkout) and for legitimate uses as permitted under the DPDP Act:
- To process and fulfill your orders (contractual necessity)
- To communicate order updates, delivery status, and receipts
- To verify your identity via phone OTP during registration
- To improve our platform, features, and user experience
- To send promotional communications (with your explicit consent, you can opt out at any time)
- To prevent fraud and ensure platform security
- To comply with legal obligations (GST, tax records, consumer protection)
- To calculate and process seller settlements, including commission deductions, GST TCS, and Income Tax TDS as required by law
- To verify seller identity and business credentials (KYC) during onboarding and periodically thereafter
5. Third-Party Sharing
We share your information only as necessary to provide our services:
- Razorpay: For secure payment processing (subject to Razorpay's Privacy Policy).
- Delhivery: Your name, phone number, and delivery address are shared to fulfill shipments.
- Sellers: Relevant order details are shared with the seller to prepare and ship your order.
- Firebase (Google): For authentication via phone OTP.
- Google reCAPTCHA: We use Google reCAPTCHA Enterprise to protect the sign-in flow against bots, fraud, and abuse. reCAPTCHA collects hardware and software information (such as device and application data) and sends it to Google for analysis. The data is used solely for security, fraud, and abuse prevention; it is not used for personalized advertising. Google acts as our data processor for this purpose.
- Cloudflare: For content delivery and platform security.
- Sentry (Functional Software, Inc.): We use Sentry to monitor application errors and operational health. When an unhandled error occurs in our application, technical diagnostic data (error message, stack trace, request URL, browser type, application version) is sent to Sentry's servers in the European Union (Frankfurt, Germany) for our engineering team to investigate and fix. We disable Sentry's default personal-data collection (no IP addresses, cookies, or authentication tokens are sent); only the minimum technical context needed to reproduce the bug is shared. Sentry acts as our data processor solely for the purpose of error tracking and fraud detection in our application.
- Government & Regulatory Authorities: We may share your data with GST authorities, Income Tax department, FSSAI, consumer courts, the Data Protection Board of India, law enforcement agencies, or other government bodies when required by law, regulation, legal process, or enforceable government request.
We do not sell your personal information to any third parties.
6. Cross-Border Data Transfers
Some of our third-party service providers (Firebase/Google, AWS, Sentry) may process or store data on servers located outside India. We ensure that such transfers comply with applicable Indian law. Sentry data is stored in the European Union (Frankfurt). As of May 2026, the Government of India has not restricted data transfers to any specific country. We will update this section if restrictions are notified.
7. Data Security
We use industry-standard security measures including HTTPS encryption, secure authentication tokens (JWT), access controls, and encrypted storage. We also require our third-party processors (Razorpay, Delhivery, AWS) to maintain appropriate security safeguards. However, no method of electronic transmission or storage is 100% secure.
We assume no liability or responsibility for disclosure of your information due to errors in transmission, unauthorized third-party access, or other causes beyond our control. You play an important role in keeping your personal information secure. You should not share your OTP, authentication tokens, or other security credentials with anyone. If we receive instructions using your authenticated session, we will consider that you have authorised those instructions.
8. Data Retention
We retain your personal data only as long as necessary for the purposes stated in this policy, or as required by law (e.g., transaction records must be maintained for 10 years per RBI guidelines, tax records per Income Tax Act). When the purpose is fulfilled or you withdraw consent, we will delete your data unless retention is legally required.
9. Your Rights Under DPDP Act
As a Data Principal, you have the right to:
- Access your personal data held by us
- Correct inaccurate or incomplete information
- Erase your data (request account and data deletion)
- Withdraw consent at any time. Withdrawal is as easy as giving consent. You can manage your consent preferences in your profile settings or by emailing us.
- Nominate another person to exercise your rights in case of death or incapacity
To exercise any of these rights, contact us at privacy@indikala.in. We will respond within a reasonable timeframe.
Response Timeline: We will acknowledge your request within 72 hours and fulfill it within 30 days, or inform you of the reason for any delay. If we cannot fulfill your request due to a legal obligation (e.g., tax record retention), we will inform you of the specific reason.
10. Data Breach Notification
In the event of a personal data breach, we will notify the Data Protection Board of India and affected users without undue delay, as required under the DPDP Act 2023. The notification will include the nature of the breach, the data affected, and the steps we are taking to mitigate the impact.
11. Children's Data
Indikala is intended for users aged 18 and above. We do not knowingly collect personal data from children under 18. If we become aware that a user is under 18, we will take steps to delete their data. If you believe a child has provided us with personal data, please contact us at privacy@indikala.in.
12. Cookies & Local Storage
We use cookies and local storage for the following purposes:
- Essential cookies: To maintain your session, authentication state, and cart data. These are necessary for the platform to function.
- Preference cookies: To remember your language, location, and display preferences.
We do not use third-party advertising or tracking cookies. You can manage cookies through your browser settings, but disabling essential cookies may affect platform functionality.
13. Anonymous & De-identified Data
We may anonymize and/or de-identify information collected from you through the Platform or via other means, including via the use of third-party analytics tools. Once data has been anonymized or de-identified so that it can no longer be used to identify a specific person (whether in combination with other information or otherwise), our use and disclosure of such aggregated and/or de-identified data is not restricted by this Privacy Policy, and it may be used and disclosed to others without limitation for purposes including but not limited to analytics, research, industry reports, and improving our Services.
14. Seller Data Practices
Sellers on Indikala receive buyer personal data (name, phone number, delivery address) solely for the purpose of order fulfillment. Under the DPDP Act 2023, sellers act as data processors when handling buyer data.
Sellers are required by our Seller Terms to:
- Use buyer data only for fulfilling orders and handling returns
- Not share buyer data with any third party
- Not use buyer data for marketing, promotions, or any purpose beyond order fulfillment
- Implement reasonable security measures to protect buyer data
- Delete buyer personal data once the order is fulfilled and the return window has expired, unless retention is required by law
- Notify Indikala immediately in case of any data breach involving buyer data
Indikala is not responsible for how individual sellers handle buyer data beyond enforcing the Seller Terms. If you believe a seller has misused your data, please report it to grievance@indikala.in.
15. Automated Decision-Making
We may use automated systems to:
- Detect and prevent fraudulent transactions or suspicious account activity
- Auto-approve buyer refund requests when a seller is unresponsive beyond the 48-hour response window
- Calculate seller performance metrics that may affect listing visibility
- Flag potentially prohibited or non-compliant product listings for review
If an automated decision significantly affects you, you may request a manual review by contacting us at support@indikala.in. We will review the decision and respond within 15 business days.
16. Grievance Officer
In accordance with the Consumer Protection (E-Commerce) Rules 2020 and the DPDP Act 2023, we have appointed a Grievance Officer:
Name: Grievance Officer, Amarzen Technologies
Email: grievance@indikala.in
Response time: Acknowledgment within 48 hours, resolution within 1 month
You may also file a complaint with the Data Protection Board of India if you believe your data rights have been violated.
17. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with the updated date. Continued use of the platform after changes constitutes your acceptance.
18. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at privacy@indikala.in.