गोपनीयता नीतिPrivacy Policy
नेपालीमा
यो नीतिले बजार साथी (Bazaar Sathi) वेबसाइट, बजार साथी ग्राहक एप, बजार साथी | उत्पादक (Bazaar Sathi | Utpadaak) एप, बजार साथी | पार्टनर (Bazaar Sathi | Partner) कन्सोल र फोन अर्डर प्रयोग गर्दा dZi फाउन्डेसनले तपाईंको व्यक्तिगत जानकारी कसरी सम्हाल्छ भन्ने कुरा बताउँछ। यो पढ्न सजिलो होस् भनेर लेखिएको हो: कुनै कुरा स्पष्ट भएन भने हामीलाई सोध्नुहोस्।
1. को जिम्मेवार छ
- dZi फाउन्डेसन ([TO CONFIRM: registered legal name of the operating entity (for example dZi Foundation)] का रूपमा दर्ता; दर्ता नं. [TO CONFIRM: company or NGO registration number]; [TO CONFIRM: registered address]) ले तपाईंको व्यक्तिगत जानकारी किन र कसरी प्रयोग गर्ने भनेर निर्णय गर्छ। यस नीतिमा “dZi”, “हामी” भनेको त्यही संस्था हो।
- हामी व्यक्तिगत जानकारी व्यक्तिगत गोपनीयता सम्बन्धी ऐन, २०७५ (सन् 2018) र विद्युतीय कारोबार ऐन, २०६३ (सन् 2008) अनुरूप सम्हाल्छौँ।
- प्रश्न, अनुरोध र उजुरी: [TO CONFIRM: contact email for privacy, legal and deletion requests] · [TO CONFIRM: contact phone number]। गुनासो सुन्ने अधिकारी: [TO CONFIRM: grievance officer: name, role and direct contact]।
2. हामीले के जानकारी सङ्कलन गर्छौँ
सेवाका लागि चाहिने जानकारी मात्र हामी सङ्कलन गर्छौँ। यो तपाईंबाट, तपाईंसँग काम गर्ने मानिसहरूबाट (जस्तै उत्पादकलाई दर्ता गर्ने सङ्कलक, वा तपाईंलाई सामान पुर्याउने व्यक्ति) र तपाईंको डिभाइसबाट आउँछ।
- खाता र साइन इन। तपाईंको मोबाइल नम्बर (SMS कोडले जाँचिएको); नाम; वैकल्पिक रूपमा इमेल ठेगाना र पासवर्ड (नुन मिसाएको ह्यास (salted hash) का रूपमा मात्र राखिने) वा Google खाताको परिचय नम्बर र इमेल; तपाईंको भाषा; मार्केटिङ सन्देशबारे तपाईंको छनोट; र तपाईंले कुन सर्त कहिले स्वीकार गर्नुभयो भन्ने अभिलेख — संस्करण, मिति, भाषा र त्यो आएको इन्टरनेट ठेगाना (IP)।
- अर्डर र डेलिभरी। डेलिभरी ठेगाना (प्राप्तकर्ताको नाम, फोन, प्रदेश, जिल्ला, पालिका, वडा, टोल र ल्यान्डमार्क, र तपाईंले चाहे नक्सा पिन); तपाईंले के अर्डर गर्नुभयो, मूल्य, बिजक, भुक्तानीको अवस्था र सन्दर्भ नम्बर; डेलिभरीको प्रगति र असफल प्रयासका कारण; र ढोकामा डेलिभरीको प्रमाण — पार्सल बुझ्ने व्यक्तिको नाम, हस्ताक्षर वा पार्सलको फोटो, समय, र फोनले स्थान पत्ता लगाउन सके ठाउँ।
- सामान फिर्ता र रकम फिर्ता। सामान, तपाईंको कारण र टिप्पणी, तपाईंले पठाएका पाँचवटासम्म फोटो, हाम्रो निर्णय र फिर्ता रकम।
- भुक्तानी। हामी कार्ड, बैंक वा वालेटको विवरण वा PIN पाउँदैनौँ र राख्दैनौँ। eSewa, Khalti, ConnectIPS र Fonepay ले भुक्तानी सफल भयो कि भएन, रकम र सन्दर्भ नम्बर हामीलाई जनाउँछन्। डेलिभरीमा नगद भुक्तानी डेलिभरी गर्ने व्यक्ति वा कर्मचारीले अभिलेख गर्छन्।
- उत्पादक र साझेदार। तपाईंको नाम, फोन, लिङ्ग (तपाईंले भनेमा) र घरपरिवारको विवरण (पालिकाको दर्ता नम्बर, भए); वडा र पालिका; जग्गा, पशुपालन र तपाईंले आपूर्ति गर्न सक्ने कुरा; उत्पादन योजना र चरणका फोटो; सङ्कलन रसिद (तौल, ग्रेड, मूल्य, कटौती, समय र, सङ्कलकले रोजे, रसिद लेखिएको ठाउँ); कमाइ, पेस्की र भुक्तानी; भुक्तानीका लागि तपाईंको बैंक वा वालेट खाता (खातावालाको नाम र नम्बर — भुक्तानी फाइलबाहेक अरू सबैले ढाकिएको रूप मात्र देख्छन्); र प्रमाणीकरणका लागि परिचयपत्रका कागजात (नागरिकता प्रमाणपत्र, राष्ट्रिय परिचयपत्र, PAN, राहदानी वा बैंकको पत्र), जसलाई dZi का कर्मचारीले हरेक पहुँचको अभिलेख राख्ने नियन्त्रित भण्डारणमा अपलोड गर्छन्।
- घरको स्थान। उत्पादकको घरको GPS बिन्दु उत्पादकको अभिलेख गरिएको सहमतिमा मात्र, सङ्कलन मार्ग र वडा प्रतिवेदनका लागि राखिन्छ। यो कहिल्यै सार्वजनिक गरिँदैन। सहमति फिर्ता लिए वडाको केन्द्रबिन्दु मात्र प्रयोग हुन्छ।
- सार्वजनिक उत्पादक प्रोफाइल। तपाईंले खोले मात्र: तपाईंको नाम वा समूह, वडा, कथा र फोटो। तपाईंको फोन नम्बर कहिल्यै देखिँदैन।
- सन्देश र सहायता। dZi का कर्मचारी, सङ्कलक र केन्द्रसँगको कुराकानीमा सन्देश, फोटो र भ्वाइस नोट (दुई मिनेटसम्म); सहायता टिकट र कल-ब्याक अनुरोध (तपाईंको नम्बर र मन पर्ने समय)।
- एआई सहायक। तपाईंले सहायकलाई लेखेको कुरा र उसका उत्तर। साइन इन गरेका मानिसका लागि कुराकानी 30 दिन राखिन्छ; साइन इन नगरेका आगन्तुकको कुराकानी हामी राख्दैनौँ (केवल तपाईंको आफ्नै ब्राउजरमा रहन्छ)। तपाईंले “मानिससँग कुरा” (Talk to a person) छान्नुभयो भने कुराकानी सहायता टिकटमा सारिन्छ र टिकटसँगै राखिन्छ।
- डिभाइस र सुरक्षा डेटा। डिभाइसको प्रकार र नाम, अनियमित डिभाइस कुञ्जी, पुश नोटिफिकेसन टोकन, साइन इन गर्दा र मुख्य कामहरूमा तपाईंको IP ठेगाना र ब्राउजर वा एपको विवरण, तपाईंको खातामा साइन इन भएका डिभाइसको सूची, र बारम्बार अनुरोध सीमित गर्ने गणक। हाम्रा सर्भरले अनुरोधका लग राख्छन्।
- मार्केटिङ र स्रोत। तपाईं अभियान वा निमन्त्रणाको लिङ्कबाट आउनुभयो भने हामी कहाँबाट आउनुभयो (जस्तै अभियानको नाम वा निमन्त्रणा कोड) भन्ने कुरा तपाईंले खाता नखोलेसम्म तपाईंको डिभाइसमा (वेबसाइटमा बढीमा 30 दिन) सम्झन्छौँ र तपाईंले खाता खोल्दा एक पटक अभिलेख गर्छौँ। तपाईंले Meta (Facebook वा Instagram) को विज्ञापनमा लिड फारम भर्नुभयो भने तपाईंले लेखेको कुरा (जस्तै नाम, फोन र इमेल) Meta ले हामीलाई दिन्छ। समाचार र अफर तपाईंले सहमति दिएमा मात्र पठाउँछौँ — छुट्टै बाकस, जुन सुरुमा बन्द हुन्छ।
- फोटो। उत्पादक वा कर्मचारीले अपलोड गरेका सामानका फोटो सार्वजनिक हुन्छन्। तपाईंले अपलोड गर्ने तस्बिरबाट हामी स्थान र क्यामेराको डेटा (EXIF) हटाउँछौँ।
हामी हाम्रा एप वा वेबसाइटमा विज्ञापन वा एनालिटिक्स सफ्टवेयर प्रयोग गर्दैनौँ, र अरू कम्पनीका एप र वेबसाइटहरूमा तपाईंलाई पछ्याउँदैनौँ।
3. हामी यसलाई कसरी प्रयोग गर्छौँ
- सेवा चलाउन: तपाईंको खाता बनाउन र सुरक्षित राख्न, अर्डर लिन र पुर्याउन, भुक्तानी, सामान फिर्ता र रकम फिर्ता सम्हाल्न, उत्पादकलाई भुक्तानी गर्न र सहायता दिन।
- सेवा सुरक्षित राख्न: ठगी र दुरुपयोग रोक्न, कोड र सन्देशको सीमा लागू गर्न र घटनाको छानबिन गर्न।
- तपाईंलाई चाहिने जानकारी दिन: कोड, अर्डर र भुक्तानीको जानकारी र भुक्तानी सूचना, SMS, पुश नोटिफिकेसन र एपभित्रको सन्देशबाट। समाचार र अफर तपाईंको सहमतिमा मात्र।
- कानुनी दायित्व पूरा गर्न: कर बिजक, लेखा र हामीले राख्नुपर्ने अन्य अभिलेख।
- सेवाको योजना र सुधारका लागि: तपाईंलाई नचिनाउने गणना र प्रवृत्ति, स्थानीय सरकारलाई दिने समष्टिगत प्रतिवेदनसहित (तल हेर्नुहोस्)।
हामी व्यक्तिगत जानकारी तपाईंको सहमतिमा, तपाईंका अर्डर र तपाईंसँगको सम्झौता पूरा गर्न, र कानुनले आवश्यक वा अनुमति गरेको अवस्थामा प्रयोग गर्छौँ।
5. जानकारी कहाँ राखिन्छ
हाम्रा प्रणाली [TO CONFIRM: hosting provider and country] मा होस्ट गरिएका छन्। माथि उल्लेख गरिएका केही सेवा प्रदायक (जस्तै Expo, र एआई सहायक चालु हुँदा OpenRouter वा Anthropic) ले नेपालबाहिर जानकारी प्रशोधन गर्छन्। व्यक्तिगत जानकारी विदेश जाँदा सेवा दिन मात्र, सेवा प्रदायकको सर्तअनुसार जान्छ। [TO CONFIRM: counsel to confirm any rule on sending personal information abroad]
6. कति समयसम्म राख्छौँ
| जानकारी | कति समयसम्म राखिन्छ |
|---|---|
| तपाईंको खाता र प्रोफाइल | तपाईंको खाता खुला रहेसम्म। मेटाउने अनुरोध स्वीकृत भएपछि यसलाई पहिचानरहित बनाइन्छ (खाता मेटाउने तरिका हेर्नुहोस्)। |
| साइन इन कोडको लग | कोड 5 मिनेटसम्म मात्र चल्छ; लगको प्रविष्टि 7 दिनपछि मेटिन्छ। |
| अनुरोध गणक (बारम्बार अनुरोधको सीमा) | समय सकिएपछि मेटिन्छ। |
| एपभित्रका नोटिफिकेसन | 90 दिन। |
| एआई सहायकसँगको कुराकानी | प्रत्येक सन्देशको 30 दिनपछि; कुराकानीको शीर्षक पनि सँगै जान्छ। |
| कुनै अभिलेखमा नजोडिएका अपलोड (परिचयपत्रका कागजात, सामान फिर्ताका फोटो, डेलिभरीका फोटो, उत्पादनका फोटो) | 24 घण्टापछि आफैँ मेटिन्छ (उत्पादनका फोटो 72 घण्टा)। |
| मेटाउन चिन्ह लगाइएका अभिलेखका फोटो र कागजात | चिन्ह लागेपछि स्वचालित सफाइद्वारा छिट्टै भण्डारणबाट हटाइन्छ। |
| अर्डर, भुक्तानी, रकम फिर्ता, बिजक, उत्पादकलाई भुक्तानी र लेखाका अभिलेख | [TO CONFIRM: retention period — 7 years is the design default], कर र लेखा नियमले चाहेबमोजिम। खाता मेटिएपछि यी तपाईंको नामबिना राखिन्छन्, तर जारी भएको कर बिजकमा ग्राहकको नाम र छापिएको ठेगाना रहन्छ। |
| सन्देश र सहायता टिकट (फोटो र भ्वाइस नोटसहित) | विवाद समाधानका लागि [TO CONFIRM: retention period]। |
| डेलिभरी अभिलेख (डेलिभरी प्रमाणसहित) | [TO CONFIRM: retention period]। |
| सुरक्षा र अडिट लग | [TO CONFIRM: retention period]। |
| तपाईंका सहमतिको अभिलेख | तपाईंले के सहमति दिनुभयो भनेर देखाउन चाहिएसम्म। |
| ब्याकअप | ब्याकअप [TO CONFIRM: backup retention in days] दिन राखिन्छ र त्यसपछि मेटिन्छ। |
7. तपाईंका छनोट र अधिकार
- तपाईंले हामीसँग तपाईंबारे के जानकारी छ भनेर सोध्न, त्यसलाई सच्याउन वा मेटाउन भन्न र दिइसकेको सहमति फिर्ता लिन सक्नुहुन्छ।
- यी मध्ये धेरै कुरा तपाईं आफैँ गर्न सक्नुहुन्छ: डेलिभरी ठेगाना र साइन इन तरिका सम्पादन गर्ने, आफ्ना डिभाइस हेर्ने र साइन आउट गराउने, नोटिफिकेसन र मार्केटिङ छनोट बदल्ने, उत्पादकको घरको स्थान राख्ने सहमति फिर्ता लिने (उत्पादक एप: प्रोफाइल → घरको स्थान), र खाता मेटाउन अनुरोध गर्ने।
- अरू कुराका लागि, वा एप प्रयोग गर्न नसके, [TO CONFIRM: contact email for privacy, legal and deletion requests] मा लेख्नुहोस्। पहिले तपाईं को हुनुहुन्छ भनी प्रमाणित गर्न हामी भन्न सक्छौँ। हामी [TO CONFIRM: response time, for example 30 days] भित्र जवाफ दिन्छौँ।
- सन्तुष्ट हुनुभएन भने हाम्रा गुनासो सुन्ने अधिकारीलाई भन्नुहोस्; व्यक्तिगत गोपनीयता सम्बन्धी ऐन, २०७५ (सन् 2018) अन्तर्गत अधिकार भएको निकाय वा अदालतमा पनि जान सक्नुहुन्छ।
8. खाता मेटाउने
तपाईं एप (बजार साथी: Account → Security → Delete my account; उत्पादक: प्रोफाइल → सुरक्षा → खाता मेटाउनुहोस्) वा वेबसाइटमा खाता मेटाउन अनुरोध गर्न सक्नुहुन्छ। dZi का कर्मचारीले प्रत्येक अनुरोधको समीक्षा गर्छन्। के मेटिन्छ, के र किन राखिन्छ र कति समय लाग्छ भन्ने कुरा खाता मेटाउने तरिका मा छ।
9. सुरक्षा
- हाम्रो वेबसाइट, एप र सर्भरसँगको सम्पर्क इन्क्रिप्टेड (HTTPS) हुन्छ। पासवर्ड नुन मिसाएको ह्यास (salted hash) का रूपमा मात्र राखिन्छ।
- साइन इनमा छोटो समय चल्ने एक्सेस टोकन र तपाईंको डिभाइससँग बाँधिएको कुञ्जी प्रयोग हुन्छ, र तपाईं आफ्ना सत्र हेर्न र अन्त्य गर्न सक्नुहुन्छ।
- कर्मचारीका कन्सोलमा दोस्रो चरण (प्रमाणक एप) चाहिन्छ र कर्मचारीले आफ्नो भूमिकाले अनुमति दिएको मात्र देख्छन्। सहायता टोलीले कुनै खाता पढ्न मात्र मिल्ने गरी, सीमित समयका लागि र कारणसहित हेर्न सक्छ, र त्यस्तो हरेक हेराइको अभिलेख राखिन्छ।
- परिचयपत्रका कागजात, सामान फिर्ता र डेलिभरीका फोटो र उत्पादनका फोटो नियन्त्रित (restricted) भण्डारणमा राखिन्छन् र छोटो समयका लिङ्कबाट मात्र खोलिन्छन्; परिचयपत्रको कागजात खोलिएको हरेक पटकको अभिलेख राखिन्छ। बैंक र वालेट नम्बर ढाकेर (masked) देखाइन्छ।
- कुनै प्रणाली पूर्ण सुरक्षित हुँदैन। तपाईंको खाता जोखिममा छ जस्तो लागे एपबाट आफ्ना डिभाइस साइन आउट गरी हामीलाई सम्पर्क गर्नुहोस्।
10. बालबालिका
यो सेवा 16 वर्षमुनिका बालबालिकाका लागि होइन र हामी जानीजानी उनीहरूको जानकारी सङ्कलन गर्दैनौँ। 16 वर्षमुनिको बालबालिकाले हामीलाई जानकारी दिएको हो भन्ने लागे हामीलाई भन्नुहोस्; हामी त्यो मेटाउँछौँ। 18 वर्षमुनिकाले आमाबुबा वा संरक्षकसँग मिलेर सेवा प्रयोग गर्नुपर्छ।
12. यस नीतिमा परिवर्तन
यो नीति परिवर्तन गर्दा हामी माथिको संस्करण नाम र लागू हुने मिति अद्यावधिक गर्छौँ। महत्त्वपूर्ण परिवर्तन भएमा तपाईंले अर्को पटक साइन इन गर्दा नयाँ संस्करण स्वीकार गर्न हामी अनुरोध गर्छौँ।
13. सम्पर्क र उजुरी
- संस्था: dZi फाउन्डेसन, [TO CONFIRM: registered legal name of the operating entity (for example dZi Foundation)] का रूपमा दर्ता (दर्ता नं. [TO CONFIRM: company or NGO registration number])
- ठेगाना: [TO CONFIRM: registered address]
- इमेल: [TO CONFIRM: contact email for privacy, legal and deletion requests] · फोन: [TO CONFIRM: contact phone number]
- गुनासो सुन्ने अधिकारी: [TO CONFIRM: grievance officer: name, role and direct contact]
हाम्रा सर्त तथा शर्त पनि हेर्नुहोस्।
In English
This policy explains how dZi Foundation handles personal information when you use the Bazaar Sathi website, the Bazaar Sathi customer app, the Bazaar Sathi | Utpadaak producer app, the Bazaar Sathi | Partner console and phone orders. It is written to be read: if something here is unclear, ask us.
1. Who is responsible
- dZi Foundation, registered as [TO CONFIRM: registered legal name of the operating entity (for example dZi Foundation)] (registration no. [TO CONFIRM: company or NGO registration number]; [TO CONFIRM: registered address]), decides why and how your personal information is used. In this policy “dZi”, “we” and “us” mean that organisation.
- We handle personal information in line with the Individual Privacy Act, 2075 (2018) and the Electronic Transactions Act, 2063 (2008).
- Questions, requests and complaints: [TO CONFIRM: contact email for privacy, legal and deletion requests] · [TO CONFIRM: contact phone number]. Grievance officer: [TO CONFIRM: grievance officer: name, role and direct contact].
2. What we collect
We collect only what the service needs. It comes from you, from people who work with you (for example a collector who registers a producer, or a person who delivers to you) and from your device.
- Account and sign-in. Your mobile number (checked with an SMS code); your name; optionally an email address and a password (kept only as a salted hash) or a Google account identifier and email; your language; your choice on marketing messages; and a record of the terms you accepted and when — the version, date, language and the internet address (IP) it came from.
- Orders and delivery. Delivery addresses (recipient name, phone, province, district, municipality, ward, tole and landmark, and a map pin if you choose to add one); what you ordered, prices, invoices, payment status and references; delivery progress and the reasons for failed attempts; and, at the door, proof of delivery — the name of the person who received the parcel, a signature or a photo of the parcel, the time, and the place when the phone has a location fix.
- Returns and refunds. The items, your reason and note, up to five photos you send, our decision and the refund.
- Payments. We do not receive or keep card, bank or wallet credentials or PINs. eSewa, Khalti, ConnectIPS and Fonepay tell us whether a payment succeeded, the amount and a reference. Cash on delivery is recorded by the delivery person or staff.
- Producers and partners. Your name, phone, gender (if you tell us) and household details (including a Palika registration number, if you have one); ward and municipality; land, livestock and what you can supply; production plans and stage photos; collection receipts (weights, grades, prices, deductions, the time and, if the collector chooses to record it, the place where the receipt was written); earnings, advances and payouts; your bank or wallet account for payouts (holder name and number — everyone except the payout file sees only a masked form); and identity documents for verification (citizenship certificate, national ID, PAN, passport or bank letter), which dZi staff upload to restricted storage that logs every access.
- Home location. A GPS point for a producer’s home is kept only with the producer’s recorded consent, for collection routes and ward reports. It is never made public. If consent is withdrawn, only the centre point of the ward is used.
- Public producer profile. Only if you switch it on: your name or group, ward, story and photo. Your phone number is never shown.
- Messages and support. Messages, photos and voice notes (up to two minutes) in conversations with dZi staff, collectors and centres; support tickets and call-back requests (your number and preferred time).
- AI assistant. What you type to the assistant and its answers. For signed-in people the chat is kept for 30 days; for signed-out visitors we do not store it (only your own browser keeps it). If you choose “Talk to a person”, the conversation is copied into a support ticket and kept with it.
- Device and security data. Device type and name, a random device key, your push-notification token, your IP address and browser or app details when you sign in and on key actions, the list of devices signed in to your account, and counters that limit repeated requests. Our servers keep logs of requests.
- Marketing and attribution. If you arrive through a campaign or invitation link we remember where from (for example the campaign name or an invitation code) on your device until you create an account — on the website for at most 30 days — and record it once, when you create an account. If you fill in a lead form in a Meta (Facebook or Instagram) advertisement, Meta passes us what you entered (for example name, phone and email). We send news and offers only if you opt in — a separate box that is off by default.
- Photos. Product photos uploaded by producers or staff are public. We remove location and camera data (EXIF) from images you upload.
We do not use advertising or analytics software in our apps or on our website, and we do not track you across other companies’ apps and websites.
3. How we use it
- To run the service: create and secure your account, take and deliver orders, process payments, returns and refunds, pay producers and give support.
- To keep the service safe: prevent fraud and abuse, enforce limits on codes and messages, and look into incidents.
- To tell you what you need to know: codes, order and payment updates and payout notices, by SMS, push notification and in-app message. News and offers only with your consent.
- To meet legal duties: tax invoices, accounting and other records we must keep.
- To plan and improve the service: counts and trends that do not identify you, including the aggregate reports we give to local governments (see below).
We use personal information with your consent, to carry out your orders and our agreement with you, and where the law requires or allows it.
5. Where it is kept
Our systems are hosted [TO CONFIRM: hosting provider and country]. Some of the providers named above (for example Expo, and OpenRouter or Anthropic while the AI assistant is on) process data outside Nepal. When personal information goes abroad it goes only to provide the service, under the provider’s terms. [TO CONFIRM: counsel to confirm any rule on sending personal information abroad]
6. How long we keep it
| Information | How long we keep it |
|---|---|
| Your account and profile | While your account is open. After an approved deletion it is anonymised (see Delete your account). |
| Sign-in code log | The code works for five minutes; the log entry is deleted after 7 days. |
| Request counters (limits on repeated requests) | Deleted when their time window ends. |
| In-app notifications | 90 days. |
| AI assistant conversations | 30 days after each message; the chat title goes with them. |
| Uploads never attached to a record (identity documents, return photos, delivery photos, production photos) | Deleted automatically after 24 hours (72 hours for production photos). |
| Photos and documents of records marked for deletion | Removed from storage soon after, by an automatic clean-up. |
| Orders, payments, refunds, invoices, producer payouts and accounting records | [TO CONFIRM: retention period — 7 years is the design default], as tax and accounting rules require. After account deletion they are kept without your name, except that an issued tax invoice keeps the buyer’s name and printed address. |
| Messages and support tickets (with their photos and voice notes) | [TO CONFIRM: retention period], for dispute resolution. |
| Delivery records (including proof of delivery) | [TO CONFIRM: retention period]. |
| Security and audit logs | [TO CONFIRM: retention period]. |
| Records of your consents | As long as needed to show what you agreed to. |
| Backups | Kept for [TO CONFIRM: backup retention in days] days, then overwritten. |
7. Your choices and rights
- You can ask what we hold about you, ask us to correct it or delete it, and withdraw a consent you gave.
- Much of this you can do yourself: edit your delivery addresses and sign-in methods, see and sign out your devices, change notification and marketing choices, withdraw consent to keep a producer’s home location (Utpadaak app: Profile → घरको स्थान), and ask to delete your account.
- For anything else, or if you cannot use the app, write to [TO CONFIRM: contact email for privacy, legal and deletion requests]. We may ask you to prove who you are first. We reply within [TO CONFIRM: response time, for example 30 days].
- If you are not satisfied, tell our grievance officer; you may also take the matter to the authority or court with power under the Individual Privacy Act, 2075 (2018).
8. Deleting your account
You can ask to delete your account in the apps (Bazaar Sathi: Account → Security → Delete my account; Utpadaak: Profile → Security → Delete my account) or on the website. dZi staff review each request. Delete your account explains what is deleted, what is kept and why, and how long it takes.
9. Security
- Connections to our website, apps and servers are encrypted (HTTPS). Passwords are stored only as salted hashes.
- Sign-in uses short-lived access tokens and a key tied to your device, and you can see and end your sessions.
- Staff consoles need a second step (an authenticator app) and show staff only what their role allows. Support can look at an account only read-only, for a limited time and with a reason, and every such look is logged.
- Identity documents, return and delivery photos and production photos are kept in restricted storage and opened only through short-lived links; every opening of an identity document is logged. Bank and wallet numbers are shown masked.
- No system is perfectly secure. If you think your account is at risk, sign out your devices from the app and contact us.
10. Children
The service is not directed at children under 16 and we do not knowingly collect their information. If you think a child under 16 has given us information, tell us and we will delete it. People under 18 should use the service with a parent or guardian.
12. Changes to this policy
When we change this policy we update the version label and effective date at the top. For an important change we ask you to accept the new version the next time you sign in.
13. Contact and complaints
- Organisation: dZi Foundation, registered as [TO CONFIRM: registered legal name of the operating entity (for example dZi Foundation)] (registration no. [TO CONFIRM: company or NGO registration number])
- Address: [TO CONFIRM: registered address]
- Email: [TO CONFIRM: contact email for privacy, legal and deletion requests] · Phone: [TO CONFIRM: contact phone number]
- Grievance officer: [TO CONFIRM: grievance officer: name, role and direct contact]
See also our Terms and Conditions.