Last updated: August 2026

Privacy Policy

How Aashita Technosoft Pvt. Ltd. handles personal data on Supply Chain Directory, under the Digital Personal Data Protection Act 2023.

1. Data fiduciary

Aashita Technosoft Pvt. Ltd., India, is the data fiduciary for personal data processed on Supply Chain Directory. Contact for all privacy matters, including grievances: aashita@aashita.ai.

Supply Chain Directory shares a user account system with SCM Insights, also operated by the Company. Registering on either site creates one account, and this policy applies to it on both.

2. What we collect

Data you give us

  • Account details: full name, email address, mobile number with country code, company name, and GSTIN if you provide one.
  • Support and enquiry messages: anything you send via the contact form or by email.

Data collected automatically

  • Session data: a signed session token stored in your browser to keep you logged in. Sessions are per-site, so signing in here does not sign you in on SCM Insights.
  • Technical logs: IP address, browser type, and request timestamps, used for security, abuse prevention and rate limiting.
  • Usage records: which directory searches and pages your account performs, used to enforce plan limits and detect scraping.

Payment data

Payments are processed by Razorpay. We never receive or store card numbers, CVVs, or UPI credentials. We retain the transaction reference, plan purchased, amount, status, and the site the purchase was made on.

Directory records — an important distinction

The directory itself contains business contact information compiled from published Indian trade filings — company names and their published business email addresses and phone numbers. This is not personal data we have collected from you, and it is not user data. If you represent a listed business and want its record corrected or removed, write to aashita@aashita.ai.

3. Why we process it, and on what basis

  • Creating and running your account — contractual necessity.
  • Providing directory access under your plan — contractual necessity.
  • Processing payments and issuing GST invoices — contractual necessity and legal obligation.
  • Security, fraud prevention and enforcing plan limits — legitimate use.
  • Responding to your enquiries — contractual necessity or consent.
  • Service and transactional emails (activation, password reset, purchase confirmation) — contractual necessity.

4. Who we share it with

We do not sell your personal data. We share it only with:

  • Razorpay — to process payments and issue refunds.
  • Email delivery providers — to send activation, reset and transactional messages.
  • Hosting and infrastructure providers — to run the service.
  • Law enforcement or regulators — where required by Indian law or valid legal process.

5. How long we keep it

  • Account data: for as long as your account exists, and for a reasonable period afterwards to handle disputes.
  • Payment and transaction records: 8 years, as required under the GST Act 2017 and the Income Tax Act 1961.
  • Technical and security logs: typically up to 12 months.
  • Support correspondence: as long as needed to resolve the matter and evidence its resolution.

6. Security

  • Passwords are stored only as salted cryptographic hashes.
  • Sessions use signed, expiring tokens rather than long-lived credentials.
  • Traffic is encrypted in transit over HTTPS.
  • Repeated failed sign-ins trigger temporary account lockout, and resetting your password revokes every existing session.
  • Rate limiting is applied to authentication and enquiry endpoints.

No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the Data Protection Board of India as required under the DPDP Act 2023.

7. Your rights

Under the DPDP Act 2023 you have the right to:

  • Access a summary of the personal data we hold about you;
  • Have inaccurate or incomplete data corrected;
  • Have your data erased where we no longer need it;
  • Nominate someone to exercise your rights if you cannot;
  • Withdraw consent where processing relies on it;
  • Raise a grievance with us, and escalate to the Data Protection Board.

To exercise any of these, write to aashita@aashita.ai. We respond within 30 days. Note that some data must be retained despite an erasure request where the law requires it — tax records being the main example.

8. Cookies and local storage

We use browser local storage to hold your session token so you stay signed in, and the backend sets a session cookie during authentication. These are strictly necessary for the service to function. We do not use advertising or cross-site tracking cookies.

9. Children

Supply Chain Directory is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe we have, contact us and we will delete it.

10. Changes to this policy

We may update this policy. Material changes will be notified by email or an in-product notice, and the "last updated" date above will change. Please also read our Terms of Use.

11. Grievance officer

Complaints about how we handle personal data go to our Grievance Officer at aashita@aashita.ai. We acknowledge within 48 hours and aim to resolve within 30 days. If you remain dissatisfied, you may escalate to the Data Protection Board of India.