Buyer platform · festovee.com
Privacy Policy
Applicable to festovee.com and the Festovee buyer mobile application.
Last updated: 3 August 2026 · Version 1.1
Festovee Internet Private Limited (“Festovee”, “Company”, “we”, “us” or “our”) respects your privacy and is committed to protecting the personal data of every person who visits or transacts on our buyer platform at festovee.com (the “Platform”). This Privacy Policy explains what personal data we collect from buyers, why we collect it, how we use, share, secure and retain it, and the rights and choices available to you under Indian law. It is published in accordance with the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, the Information Technology Act, 2000 and rules thereunder, and the Consumer Protection (E-Commerce) Rules, 2020.
1. Who we are and our role
Festovee operates a business-to-business (B2B) online marketplace that connects verified factories, manufacturers and suppliers (“Sellers”) with retailers, MSMEs, distributors and other business buyers (“Buyers”, “you”). For the personal data we collect from Buyers to operate the Platform, provide our services and comply with law, we act as a Data Fiduciary (equivalent to a data controller) under the DPDP Act. We also act as an intermediary and a marketplace e-commerce entity in respect of listings and transactions between Buyers and Sellers.
2. Scope and your consent
This Policy applies to all Buyers and visitors of the Platform. By creating an account, placing an enquiry or order, or otherwise using the Platform, you confirm that you have read and understood this Policy. Where the law requires consent, we obtain it through a clear affirmative action (such as ticking an unchecked consent box) before processing your personal data. We do not rely on pre-ticked boxes or bundled consent. You may withdraw your consent at any time as described in Section 13.
This Policy forms part of, and should be read together with, our Buyer Terms & Conditions. It does not apply to the independent privacy practices of Sellers or third-party service providers, who are responsible for their own compliance.
3. Definitions
“Personal Data” means any data about an individual who is identifiable by or in relation to such data. “Processing” means any operation performed on personal data, including collection, storage, use, sharing and erasure. “Data Principal” means the individual to whom the personal data relates. “Sensitive Personal Data or Information” (SPDI) has the meaning given under the IT (Reasonable Security Practices) Rules, 2011, and includes financial information such as bank account, card or payment instrument details, and passwords.
4. Personal data we collect
We collect only the data that is necessary for the purposes described in this Policy. Depending on how you use the Platform, this may include:
- Identity & account data: full name, business/trade name, designation, username, password (stored in hashed form), profile photo (if provided), and account preferences.
- Contact data: email address, mobile and telephone numbers, billing address, and shipping/delivery addresses.
- Business & tax data: GSTIN, business registration details, and other business identifiers required to raise valid tax invoices and process bulk B2B orders.
- Transaction & order data: products enquired about or ordered, order value and quantity, order history, delivery status, communications with Sellers, returns, refunds and support tickets.
- Payment data: details necessary to process payments. As explained in Section 9, full card/bank credentials are collected and stored by RBI-authorised payment gateways, not by us.
- Technical & usage data: IP address, device identifiers, browser type, operating system, log data, pages viewed, search terms, and cookie identifiers.
- Communications: records of your correspondence with us or with Sellers through the Platform, feedback, reviews, and responses to surveys.
We do not knowingly collect special-category data beyond what is described above. Please do not share unnecessary sensitive information with us or with Sellers through the Platform.
5. How we collect your data
We collect personal data (a) directly from you when you register, place enquiries or orders, contact support, or fill in forms; (b) automatically through cookies and similar technologies when you use the Platform; and (c) from third parties such as Sellers, logistics partners, payment gateways, and government/verification databases (for example, GSTIN verification), to the extent permitted by law.
6. Purposes and lawful basis of processing
We process your personal data for the following purposes, on the basis of your consent and/or for “certain legitimate uses” permitted under the DPDP Act (such as performing a service you have requested or complying with a legal obligation):
- to create and manage your account and verify your identity;
- to enable you to browse listings, place enquiries and orders, and communicate with Sellers;
- to process payments, generate invoices, and arrange fulfilment, shipping and delivery;
- to manage returns, refunds, cancellations and after-sales support;
- to provide customer service and respond to your grievances;
- to detect, prevent and address fraud, security incidents, and prohibited or illegal activity;
- to send you transactional communications and, where you have consented, marketing communications;
- to personalise and improve the Platform, our products and services;
- to comply with applicable laws, tax obligations, and lawful requests by public authorities.
We will not use your personal data for a new purpose that is incompatible with the above without providing you notice and, where required, obtaining fresh consent.
7. Cookies and similar technologies
We use cookies, web beacons and similar technologies to keep you signed in, remember your preferences, measure usage, and improve the Platform. Strictly necessary cookies are required for the Platform to function. You can control non-essential cookies through your browser settings or our cookie preferences tool where available. Disabling certain cookies may affect Platform functionality.
8. How we share your data
We do not sell your personal data. We share it only as necessary and as described below:
- Sellers: to fulfil your orders and enquiries, we share the details a Seller needs (such as name, delivery address, contact number, and order details).
- Logistics and delivery partners: to deliver your orders.
- Payment gateways and financial institutions: to process payments and refunds.
- Service providers (Data Processors): cloud hosting, analytics, communication, KYC/verification and customer-support providers who process data on our behalf under written contracts and only on our instructions.
- Legal and regulatory authorities: where disclosure is required by law, court order, or to protect our rights, users or the public.
- Business transfers: in connection with a merger, acquisition or restructuring, subject to this Policy continuing to apply.
9. Payment data
Online payments on the Platform are processed through payment aggregators and gateways authorised by the Reserve Bank of India (RBI). Your complete card, bank or UPI credentials are collected, transmitted and stored by these RBI-authorised entities in compliance with applicable standards; Festovee does not store your full payment-instrument details on its own servers. Refunds, where applicable, are processed in accordance with RBI guidelines and our Buyer Terms & Conditions.
10. Data retention and erasure
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, tax or reporting requirements. Transaction and tax records are retained for the periods prescribed under applicable law (for example, records required under GST and company law). Certain traffic and security logs are retained for a minimum of one year as required under the DPDP Rules, 2025. When personal data is no longer required and there is no legal obligation to retain it, we will erase it or anonymise it. If your account remains inactive for a prolonged period, we may erase associated personal data after giving you prior notice as required by law.
11. Data security
We implement reasonable security practices and procedures as required under Section 43A of the Information Technology Act, 2000 and the DPDP Act. These include encryption in transit (TLS), access controls, network protection, monitoring, and periodic review of our security posture. While we take these measures seriously, no method of transmission or storage is completely secure, and you are responsible for keeping your login credentials confidential.
12. Your rights as a Data Principal
Subject to applicable law, you have the right to:
- Access a summary of the personal data we process about you and the processing activities;
- Correction, completion and updating of inaccurate or incomplete personal data;
- Erasure of your personal data where it is no longer necessary for the purpose;
- Grievance redressal through the readily available means described in Section 18;
- Nominate another individual to exercise your rights in the event of your death or incapacity.
To exercise these rights, contact our Grievance Officer / Data Protection Officer using the details in Section 18 or use the tools in your account settings. We will respond within the timelines prescribed under applicable law, and in any case within the maximum period permitted under the DPDP Rules, 2025. We may ask you to verify your identity before acting on a request.
13. Withdrawal of consent
Where we process your data on the basis of consent, you may withdraw it at any time by writing to our Grievance Officer / DPO or using account controls. Withdrawal is as easy as giving consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and we may continue to retain and process data where we have another lawful basis (for example, to complete a pending transaction or meet a legal obligation). Withdrawing consent necessary for core services may limit or prevent your use of those services.
14. Children’s data
The Platform is a B2B marketplace intended for use by businesses and persons who are 18 years of age or older. We do not knowingly process the personal data of children (individuals below 18 years) except as permitted by law, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If we learn that we have inadvertently collected a child’s data without verifiable parental consent, we will delete it.
15. Cross-border transfers
We primarily store and process personal data in India. Where personal data is transferred to or accessed from outside India (for example, by a cloud or service provider), we do so in accordance with the DPDP Act and any restrictions notified by the Central Government, and we require appropriate safeguards to protect your data.
16. Third-party links
The Platform may contain links to third-party websites or services, including Seller storefronts and payment pages. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies.
17. Data breach handling
We maintain procedures to detect, investigate and respond to personal data breaches. In the event of a breach affecting your personal data, we will notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines prescribed under the DPDP Act and the DPDP Rules, 2025.
18. Grievance Officer & Data Protection Officer
The officer designated to receive and address data-protection queries, grievances and requests is:
- Name
- Mr. Divyank Kakkar
- Designation
- Director — Grievance Officer & Data Protection Officer
- Company
- Festovee Internet Private Limited
- Grievance email
- support@festovee.com
- Data-protection (DPO) email
- k@festovee.com
- Phone
- +91 74044 52903
- Registered office
- Dehradun, Uttarakhand, India – 248002
We will acknowledge grievances within forty-eight (48) hours and endeavour to resolve them within one (1) month. Rights requests under the DPDP Act are handled within the timelines prescribed under that law.
19. Changes to this Policy
We may update this Policy from time to time to reflect changes in law or our practices. The revised Policy will be posted on the Platform with a new “Effective Date”. Material changes will be communicated where required by law. Your continued use of the Platform after the changes take effect constitutes acceptance of the updated Policy.
20. Contact us
For general queries, email support@festovee.com or info@festovee.com. For data-protection matters, contact our Data Protection Officer at k@festovee.com. For grievances, email support@festovee.com or call +91 74044 52903.
This document has been prepared for Festovee Internet Private Limited and reflects the position of Indian law as at the Effective Date. It is a template intended for review by qualified legal counsel and completion of any highlighted placeholders before publication. It does not by itself constitute legal advice.
