Privacy Policy
Version 1.0 · Effective <effective-date> · This notice is given under India's Digital Personal Data Protection Act, 2023 ("DPDP Act").
Shekuthi ("we") operates this marketplace, on the website and in the mobile app. For the personal data described here, we act as the Data Fiduciary. We keep data collection to the minimum needed to run the service, and we do not sell personal data.
1. Who to contact
Privacy questions and grievances: K Hika Zhimomi, contact@shekuthi.in. Address: Chümoukedima, Nagaland.
2. Personal data we collect
- Registered users (sellers, drivers, collectors, skilled workers, volunteers): name, email, phone number, a hashed password, your role, and role-specific details such as your district and, for drivers, a base of operation.
- Guest bookings and errands (buyers, who never register): the contact name and phone number you provide, plus any notes you add.
- Listings and profiles you create, and images you upload (listings, shop details, a volunteer profile photo).
- Verification visits: the volunteer's report, checklist answers, notes, photographs and, if given, a location point for the site.
- Usage and device data needed to operate the service securely, such as authentication tokens and, if you enable notifications, a device push token.
We do not ask for government identifiers, and we do not collect payment credentials — payments never pass through the platform.
3. Why we use it
- To create and secure your account and let you sign in.
- To publish what you choose to list and connect you with the other party.
- To let a seller reach a buyer about a booking, and support guest lookups by code and phone.
- To coordinate transport and errands through the areas a driver declares.
- To record and display verification visits and their outcomes.
- To send you service notifications you have asked for.
- To keep the service safe, prevent abuse, and meet legal obligations.
We process personal data on the basis of your consent, and for the limited legitimate uses the DPDP Act permits (for example, security, and where you have made data public by listing it).
4. Consent
Where we rely on consent, we ask for it clearly before we collect the data, tell you the purpose in plain language, and record the consent with the version of the notice you saw and the time you gave it. You can withdraw consent at any time from your profile or by contacting us; withdrawing may mean we can no longer provide the related part of the service.
5. Guests and contact details
Buyers use the platform as guests. The contact name and phone number you give for a booking or errand are used only to coordinate that booking or errand, and are shared only with the seller or the assigned driver. They are stored encrypted.
6. What is shown publicly
Some fields are public by design and visible to anyone:
- A seller's shop name, listings and descriptions.
- A driver's name, area and the transport categories they choose, along with the contact number they add to their work profile so buyers can call them.
- A skilled worker's name, area and the trades they list.
- A volunteer's name and photo as it appears on a verification badge and its story.
You control these fields: change or remove them in your profile, and they stop being shown.
7. Sharing
We never sell personal data and we do not share it for advertising. We share it only:
- between the parties to a booking, errand or job, to the extent needed to carry it out;
- with service providers who host and run the platform for us, bound to use it only for that purpose;
- where the law requires it, or to protect rights and safety.
8. How long we keep it
We keep personal data only as long as needed for the purpose it was collected, or as the law requires. Guest booking and errand contact details, unused media and expired consents are cleared by scheduled retention sweeps. When you delete your account, we remove or anonymise your personal data; integrity records that name other people (such as a verification badge's volunteer name) are kept only as a snapshot, without contact details.
9. Security
Personal data is encrypted in transit and at rest, sensitive fields use encryption with separate lookup indexes, passwords are stored only as hashes, and access is limited by role. If a personal data breach occurs, we will notify the Data Protection Board of India and affected users as the DPDP Act requires.
10. Where your data is stored
We aim to keep personal data within India. Where any processing happens outside India, we do so only as the DPDP Act and any government restriction permits.
11. Your rights
Under the DPDP Act you have the right to:
- Access a summary of your personal data and how it is processed. Export a machine-readable copy from your profile.
- Correct and keep your data accurate — edit your profile at any time.
- Erase your data — delete your account from your profile; we carry it out end to end.
- Withdraw consent for any purpose you previously agreed to.
- Nominate someone to exercise these rights on your behalf in the event of death or incapacity — contact our grievance officer to record a nominee.
- Complain — raise a grievance with our grievance officer first, and you may approach the Data Protection Board of India if you are not satisfied.
We will respond to a request within the time the DPDP Act allows. Export and deletion are available directly in the app and on the website.
12. Children
The platform is for people aged 18 and over. We do not knowingly collect personal data of children. If we learn that we have, we will delete it. If you believe a child has given us data, contact the grievance officer.
13. Cookies and local storage
We use only what the service needs to work: a session cookie to keep you signed in on the website, and secure local storage for your sign-in token in the app. We do not use advertising or cross-site tracking cookies, and we run no third-party analytics.
14. Changes
If this notice changes, we publish a new version and effective date here, and where the change is material we ask for your consent again.
15. Contact
K Hika Zhimomi · contact@shekuthi.in.