Legal

DPDP Compliance

Last updated 1 September 2026

How NinetyLoop supports compliance with India’s Digital Personal Data Protection (DPDP) Act, 2023. This page is a plain-language summary, not legal advice.

1. Roles

For data a shop collects from its shoppers, the shop is the Data Fiduciary and NinetyLoop is a Data Processor acting on the shop’s documented instructions. For your own account data, NinetyLoop is the fiduciary.

2. Consent & notice

The customer journey captures purpose-specific consent (transactional vs marketing) with a timestamped, append-only consent record, so a shop can show what was agreed and when.

3. Opt-out honoured fast

Marketing opt-outs are recorded and enforced automatically — a customer who opts out of marketing stops receiving campaign messages within seconds.

4. Data minimisation & purpose

We collect only what the journey needs, keep transactional and marketing purposes separate, and do not repurpose data beyond what the shop authorises.

5. Rights fulfilment

Shops can access, correct, export and delete customer records from the product, so data-principal requests can be actioned quickly.

6. Security & residency

Personal data is stored in India, phone numbers are encrypted at rest, access is role-based and audited, and deletions are soft (recoverable within retention) with a full audit trail.

7. Breach posture

We maintain logging and monitoring to detect and respond to incidents and will support fiduciaries with any notification obligations.

8. What we do not claim

We state only compliance measures we actually operate. We do not display certifications we have not earned; any future certification will be added here once genuinely held.

Questions about this document? Email privacy@ninetyloop.app or call +91 80000 90090.