1Who we are
ezmarketplaces is a product of Athavita Software Private Limited (CIN U72200KA2022PTC162053), registered at 2nd Main, 1st Cross Road, Industrial Area, BTM Layout 2nd Stage, Bengaluru, Karnataka 560076, India. For the purposes of India's Digital Personal Data Protection Act, 2023 (DPDP), we are a Data Fiduciary for your seller account and a Data Processor for the buyer data we receive from marketplaces on your behalf.
Grievance Officer under DPDP §13: the Director, Athavita Software Private Limited, at the registered address above or support@ezmarketplaces.com. We must respond within the period the Act prescribes.
2What we collect about you, the seller
Your work email, mobile number, password (stored only as a hash), business name and the marketplace channels you connect. Your mobile number is mandatory at sign-up and is used to reach you about your workspace and its channel connections. It is never passed to a marketplace and is not used for marketing.
We also record ordinary operational data: the requests your workspace makes, the channels it syncs, and an audit trail of writes we send to marketplaces on your instruction.
3What we receive about your buyers
When you connect a channel, marketplaces send us orders. Those orders contain buyer names and shipping addresses. We hold that data to run your operations — fulfilment, returns, reconciliation — and for nothing else. We do not build a buyer profile across sellers, we do not sell it, and we do not use it to market anything to anyone.
Buyer email addresses are stored only as a one-way hash. We keep the hash so duplicate orders can be recognised; we cannot recover the address from it.
4How it is protected
- Who at Athavita can see it. Our own employees can open your dashboard only read-only, in a session that shows you a banner while it runs, is written to your audit log with their name and reason, and expires on its own. We do not use contractors or agencies to process your data. Automated jobs (polling, reconciliation, retention) run under the system identity and are logged the same way.
- Buyer names and shipping addresses are encrypted at rest with a key derived per workspace. There is no plaintext copy in the database.
- Marketplace access tokens are encrypted the same way. Every channel connection begins read-only — we cannot alter a listing or a price until you grant write access, per channel.
- Your workspace is isolated at the database level by row-level security, not only by application code.
- Every time a person views a buyer's name or address, that access is written to a tamper-evident audit log recording who, when and why. The log records field names, never values.
- Everything in transit is TLS.
5How long we keep it
Buyer names and addresses: 30 days after an order reaches a final state — delivered, cancelled or returned. This is the limit Amazon's Data Protection Policy imposes on everyone handling its order data, and we apply it to every channel rather than only to Amazon.
Tax records: as long as Indian law requires, presently six years under GST. The order id, items, quantities and amounts survive the erasure above, because those are a statutory record and none of them identifies the buyer once the name and address are gone.
Audit logs: at least 12 months, as required of anyone processing marketplace order data. The audit chain is append-only.
Your seller account: until you close it, plus whatever period tax and contractual obligations require.
6Who else processes it
- Amazon Web Services — hosting and encryption keys. The system is built to run in the Mumbai region (
ap-south-1) so data stays in India. - Vercel — serves this website and relays the dashboard's requests to our API in Mumbai. Your data passes through its edge network in transit and is not stored there.
- Zoho ZeptoMail — sends our transactional e-mail: sign-in codes, ticket replies and security alerts. It sees your e-mail address and the message; never order or buyer data.
- The marketplaces you connect — Amazon, Flipkart, Meesho, Myntra, Ajio, JioMart, Tata CLiQ, Nykaa, Shopify, eBay, Walmart, Etsy, Snapdeal, and the ONDC network. They are the source of the data, not a recipient of anything new.
- AI model providers — used for listing generation, imagery and the assistant. Personal data is redacted before any model call, and your catalogue is never used to train a model, ours or anyone else's.
We will publish a current sub-processor list and give notice before adding one that handles personal data.
7Your rights
Under DPDP you may ask us for access to your personal data, correction of it, and erasure. Write to the Grievance Officer above. Where you are the Data Fiduciary for your buyers and a marketplace sends us a deletion notice on their behalf, we act on it automatically: buyer names and addresses are removed from every affected order, and the statutory record is retained as described in clause 5.
Not yet available: self-service export of your workspace data. It is planned and it is not built, and we would rather say so here than imply otherwise.
8Cookies
A session cookie on the sign-in origin, which is what keeps you signed in. No advertising cookies, no third-party trackers, and no analytics that follow you off this site.
9Changes and breaches
Material changes will be notified in the product before they take effect. If personal data is breached we will notify the Data Protection Board and affected users as DPDP requires. Our breach procedure is written and has not yet been exercised in a drill.