Privacy Policy
Compliant with the Digital Personal Data Protection (DPDP) Act, 2023 and IT Rules 2021.
1. Introduction
At Wesker, we take your privacy and the security of your personal data seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, in compliance with the Digital Personal Data Protection (DPDP) Act, 2023.
2. Data We Collect
We collect the minimum amount of data necessary to provide our intermediary services:
- Identity Data: Name, email address, phone number.
- Financial Data: Bank account details for seller payouts (processed securely via regulated gateways).
- Verification Data: For sellers, government ID (PAN/GSTIN) and Liveness Verification photos for KYC compliance.
- Usage Data: Anonymized interaction metrics and IP addresses for security auditing.
3. How We Use Your Data
Your data is strictly used for the following operational purposes:
- Facilitating secure transactions and escrow holding between Buyers and Sellers.
- Verifying the identity of sellers to prevent fraud on the platform.
- Resolving disputes and managing order fulfillment.
- Complying with legal obligations, including tax reporting and law enforcement requests.
4. Data Sharing and Third Parties
We do not sell your personal data. We may share your data with:
- Counterparties: Buyers will receive the Seller's basic contact details for order fulfillment. Sellers receive Buyer shipping details.
- Payment Processors: To facilitate secure checkout and payouts.
- Law Enforcement: If required by valid legal process or to protect the safety of our users.
5. Your Data Rights (DPDP Compliance)
Under the DPDP Act, you possess the right to:
- Access the personal data we hold about you and download your portable JSON/ZIP archives.
- Request correction of inaccurate or incomplete data.
- Withdraw your consent at any time.
- Request the erasure of your data ("Right to be Forgotten") via a 30-day statutory cooling queue, subject to our legal retention obligations.
To exercise any of these statutory rights self-serve, visit your Privacy & Data Governance Settings.
6. Data Security and Retention
We use enterprise-grade encryption to protect your personal data in transit and at rest. We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy or to comply with our legal, tax, or accounting obligations (refer to statutory retention schedule).
7. Contact Us
If you have questions about this policy or wish to exercise your data rights, please contact our Data Protection Officer at privacy@wesker.in.
8. Statutory Grievance Redressal Officer (Rule 3(2) IT Rules 2021)
In accordance with Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the details of the designated Grievance Officer are set out below:
Chief Grievance & Compliance Officer (Mr. Vikrant Sharma, Adv.)
Acknowledgment within 24 hours of complaint receipt. Unlawful content takedowns executed within36 hours under Rule 3(1)(d). Formal grievance redressal finalized within 15 days. For ticket filing, visit our Grievance Desk.
9. Statutory Version History & Audit Changelog
| Version | Effective Date | Summary of Changes | Statutory Basis |
|---|---|---|---|
| 2026.1 | August 20, 2026 | Integrated DPDP Act 2023 purpose-specific consent ledger, explicit 7-day inspection window & escrow refund guarantees under Consumer Protection (E-Commerce) Rules 2020, and automated CAD/AI moderation disclosures under IT Rules 2021. | DPDP Act 2023, CP (E-Commerce) Rules 2020, IT Rules 2021 |
| 2025.2 | November 15, 2025 | Initial Intermediary liability disclosures under Section 79 of IT Act 2000, Grievance Officer appointment, and RBI escrow milestone protections. | IT Act 2000, Section 79, IT Rules 2021 |