DPDP Compliance
Last updated 1 September 2026
How NinetyLoop supports compliance with India’s Digital Personal Data Protection (DPDP) Act, 2023. This page is a plain-language summary, not legal advice.
1. Roles
For data a shop collects from its shoppers, the shop is the Data Fiduciary and NinetyLoop is a Data Processor acting on the shop’s documented instructions. For your own account data, NinetyLoop is the fiduciary.
2. Consent & notice
The customer journey captures purpose-specific consent (transactional vs marketing) with a timestamped, append-only consent record, so a shop can show what was agreed and when.
3. Opt-out honoured fast
Marketing opt-outs are recorded and enforced automatically — a customer who opts out of marketing stops receiving campaign messages within seconds.
4. Data minimisation & purpose
We collect only what the journey needs, keep transactional and marketing purposes separate, and do not repurpose data beyond what the shop authorises.
5. Rights fulfilment
Shops can access, correct, export and delete customer records from the product, so data-principal requests can be actioned quickly.
6. Security & residency
Personal data is stored in India, phone numbers are encrypted at rest, access is role-based and audited, and deletions are soft (recoverable within retention) with a full audit trail.
7. Breach posture
We maintain logging and monitoring to detect and respond to incidents and will support fiduciaries with any notification obligations.
8. What we do not claim
We state only compliance measures we actually operate. We do not display certifications we have not earned; any future certification will be added here once genuinely held.
Questions about this document? Email privacy@ninetyloop.app or call +91 80000 90090.