Data Protection & Privacy Practices
Policy details regarding data minimization, access control, courier limits, and retention periods.
Effective Date: 24 August 2026
10.1 Data minimisation
BuyDesi should collect only the information reasonably required for the relevant purpose, such as account creation, order fulfilment, payment, delivery, customer support, security and legal compliance.
10.2 Access controls
Access to customer and seller information should be role-based. Seller users should see only the information necessary to fulfil authorised orders. Internal staff access should follow least-privilege principles.
10.3 Courier data
Only the shipment information needed by the selected/assigned courier should be transmitted for pickup, transportation, delivery, tracking, returns or support.
10.4 Seller restrictions on customer data
Sellers must not copy, sell, export, scrape, independently market to or otherwise misuse customer data received through BuyDesi.
10.5 Security
BuyDesi should use reasonable safeguards including secure authentication, access control, encryption where appropriate, logging, backups, vulnerability management and incident-response procedures appropriate to the system and risk.
10.6 Retention and deletion
BuyDesi should define retention periods for accounts, orders, invoices, payment records, support records, seller documents and security logs based on legal, tax, operational and contractual requirements.
10.7 User requests
BuyDesi should provide mechanisms for applicable requests relating to correction, access, consent withdrawal or other rights recognised by applicable law.
10.8 Data incidents
BuyDesi should maintain an internal process for identifying, containing, investigating and responding to suspected personal-data or security incidents, including applicable notifications required by law.
10.9 Third-party processors
Contracts with payment providers, courier partners, cloud providers, analytics providers, communication providers and other processors should define security, confidentiality, permitted processing and data-handling responsibilities as appropriate.
10.10 Privacy governance
The final privacy programme should be aligned with the laws and rules applicable to BuyDesi at the time of launch and should be reviewed when the business introduces new categories, new data uses, new partners or new technology.
