TecnoMate logo
Back to Home

Privacy Policy

Last updated: 21 March 2026

TecnoMate acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act) where applicable, and complies with the Information Technology Act, 2000, and rules issued thereunder. This policy explains how we collect, use, store, and share personal data in connection with our website and services in India.

1. Scope and Legal Framework

This policy applies to personal data processed when you visit tecnomate.in (and related domains we operate), use our mobile web experience, create an account, purchase products, subscribe to communications, or interact with support or AI-assisted features. It should be read with our Terms of Service and Cookie Policy.

We align our practices with Indian law, including the DPDP Act, 2023 (when provisions are notified and effective), the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules) where still relevant, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (as applicable), RBI directions on payment data, and the Consumer Protection (E-Commerce) Rules, 2020 where they concern data practices.

2. Categories of Personal Data

We may process the following, depending on how you use the Site:

  • Identity and contact: name, email, phone, delivery and billing addresses, GSTIN (if provided for business purchases).
  • Account and authentication: login identifiers, profile photo URL if you use social login, session tokens.
  • Transaction data: order history, product selections, payment status, transaction references from our payment aggregator—not full card numbers or CVV.
  • Communications: messages you send to support, feedback, survey responses, and call or chat records where retained.
  • Technical and usage data: IP address, device type, browser, operating system, approximate location derived from IP, pages viewed, referring URLs, crash logs, and timestamps.
  • Marketing preferences: opt-in or opt-out flags, newsletter subscription status.
  • AI interactions: text you submit to chat, search, or troubleshooting tools; derived embeddings or logs needed to run the service; outputs shown to you. Do not submit special categories of data (e.g. health, biometrics, government ID numbers) unless a form explicitly requires it for a legal purpose.

3. Purposes and Lawful Grounds for Processing

We process personal data to:

  • Register accounts, fulfil orders, arrange delivery, and provide customer support
  • Process payments, address fraud risk, and meet accounting and tax obligations
  • Operate, secure, debug, and improve the Site and infrastructure
  • Provide AI-assisted features (recommendations, search, chat, content personalisation) and measure their quality
  • Send transactional messages (order updates) and, where you consent, marketing communications
  • Comply with court orders, lawful requests from authorities, and applicable law
  • Enforce our terms, protect rights, safety, and property

Under the DPDP Act, we rely on consent where required, and on legitimate uses permitted by law (such as voluntary provision of data for specified purposes, compliance with law, employment/safety where relevant, or certain business operations as defined in the Act) where applicable. You may withdraw consent for non-essential processing subject to legal retention requirements.

4. AI, Automated Processing, and Generated Content

We use artificial intelligence and machine-learning systems (our own and third-party) to generate or assist with text, recommendations, search ranking, customer support drafts, and similar features. Processing may include:

  • Sending your prompts or queries to model providers to generate responses
  • Logging interactions for security, abuse detection, quality improvement, and debugging
  • Creating aggregated or de-identified analytics that do not identify you as an individual

AI outputs may be inaccurate; do not include passwords, full payment details, or highly sensitive secrets in free-text AI fields. Third-party AI providers may process data under their agreements and may operate infrastructure outside India; we use contractual and technical measures to limit use to service provision. See our Terms for disclaimers on AI-generated site content.

5. Cookies and Similar Technologies

We use cookies, pixels, local storage, and similar technologies as described in our Cookie Policy, including for essential site function, analytics, advertising (e.g. Google AdSense), and preferences. You can manage cookies through browser settings; essential cookies may be required for checkout and login.

6. Sharing and Disclosure

We do not sell your personal data. We may share data with:

  • Payment aggregators (e.g. Razorpay) for processing payments per RBI norms
  • Logistics partners for shipping and delivery status
  • Cloud hosting, email, analytics, and AI vendors under contracts requiring confidentiality and purpose limitation
  • Advertising partners (e.g. Google) subject to their policies and your ad settings
  • Professional advisers (lawyers, auditors) under confidentiality
  • Authorities when required by law, court order, or to protect rights and safety
  • Successors in a merger, acquisition, or asset sale, with notice where required

7. Cross-Border Transfers

Primary business and data processing are oriented toward India. Some subprocessors (including AI, analytics, or cloud providers) may store or process data in other countries. Where the DPDP Act requires, we will ensure transfers meet prescribed conditions (e.g. adequacy, consent, or standard contractual safeguards as notified).

8. Retention

We retain personal data only as long as necessary for the purposes above, including statutory retention periods (tax, company law, payment regulations), dispute resolution, and security. Order and invoice records may be kept for periods required under Indian law. When retention ends, we delete or anonymise data where feasible.

9. Security

We implement reasonable technical and organisational measures consistent with the IT Act and SPDI Rules guidance, including encryption in transit for the Site, access controls, and secure payment flows. No system is perfectly secure; you should protect your credentials and devices.

10. Your Rights (Data Principal)

Subject to the DPDP Act and other applicable law, you may have the right to access, correct, update, or erase your personal data; obtain a summary of processing; withdraw consent for processing based on consent; nominate a representative; and grievance redressal including appeal to the Data Protection Board of India when established. You may also have rights under the IT Act and Consumer Protection framework for certain complaints.

To exercise rights, email [email protected]. We may verify identity before fulfilling requests. We may refuse requests that are manifestly unfounded, excessive, or prohibited by law.

11. Grievance Officer

For privacy-related complaints under Indian rules, contact our Grievance Officer: email [email protected], phone +91 91303 50359, addressing correspondence to TecnoMate, Chandrangan Phase 1, Ambegaon BK, Pune, Maharashtra 411046, India. We will endeavour to respond within timelines required by applicable law once the DPDP Act rules specify them; until then, within a reasonable period not exceeding 30 days for substantive replies where feasible.

12. Children

Our Site is not directed at children under 18 (or lower age if defined under applicable child-online rules). We do not knowingly collect personal data from children without verifiable parental consent where required. If you believe we have collected a child’s data improperly, contact us for deletion.

13. Advertising & Google AdSense

We use Google AdSense and related services. Google and partners may use cookies and similar technologies to show personalised ads. You can manage ad personalisation at Google Ads Settings and learn how Google uses partner site data at Google’s partner sites policy.

14. Automated Decision-Making

We may use automated systems (including AI) to rank search results, suggest products, or detect fraud. These processes do not produce legal or similarly significant effects solely by automated means in a way that denies you a contract without human review for escalations; for fraud holds or compliance blocks, you may contact support for review.

15. Changes to This Policy

We may update this Privacy Policy to reflect legal, technical, or business changes. Material changes will be indicated by updating the “Last updated” date and, where required, through notice on the Site or email. Continued use after updates constitutes acceptance where law allows.

16. Contact

Privacy enquiries: [email protected]. General: Contact.