AiMonk
legal ━ DPDP Act 2023 · IT Rules 2021 · SLG

Privacy Policy

Last updated 27 August 2026. How AiMonk collects, uses, and protects personal data under Indian law.

This page is general information about our current practices. It is not legal advice and is not a substitute for counsel review. Statutory rights under the DPDP Act and other Indian laws remain unaffected.

1. Who we are (Data Fiduciary)

This policy is issued by AiMonk (“we”, “us”), an unincorporated team based in Siliguri, West Bengal, India. We are not yet registered as a company. For this website (aimonk.io) and the AiMonk hosted ecommerce platform, we act as the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”).

If you shop on a brand's storefront hosted on AiMonk, that merchant is typically the Data Fiduciary for your order and account data. We process that data as their Data Processor (technology provider) on their documented instructions, except where Indian law requires us to process it ourselves (for example security logs, abuse prevention, or a lawful request).

2. Scope and law that applies

This notice covers personal data processed in India in connection with:

  • the public marketing site and contact forms;
  • merchant signup, admin console, billing, and support;
  • hosted storefronts, checkout, and related platform operations.

Personal data is processed primarily under the DPDP Act and DPDP Rules. Other Indian laws also apply where relevant, including the Information Technology Act, 2000; the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021; CERT-In directions on cyber incident reporting and logs; the Consumer Protection Act, 2019 and Consumer Protection (E-Commerce) Rules, 2020; GST and tax record-keeping rules; and TRAI / DLT requirements for commercial SMS. This policy does not use EU “legitimate interest” as a ground of processing.

3. Personal data we collect

We collect only what is needed for the purposes below. Categories include:

  • Identity and contact — name, email, phone, company, store name and subdomain, when you enquire, sign up, or are invited as staff.
  • Account and authentication — login credentials (stored as hashes), session tokens, optional email verification, and phone OTP for storefront or COD verification.
  • Merchant business data — GSTIN, legal name, invoice address, support contacts, and similar fields you enter in admin (needed for invoices and consumer-facing legal pages).
  • Commerce data on hosted stores — shipping address, order contents, payment status (not full card numbers; cards/UPI are handled by Razorpay or Stripe), COD flags, and return requests.
  • Communications — messages you send us; transactional email, SMS, and WhatsApp events (delivery status) when a merchant has enabled those channels.
  • Technical and security logs — IP address, user agent, timestamps, referrer, and similar server logs used to operate, secure, and debug the service.

We do not sell personal data. We do not use advertising pixels or cross-site tracking on the marketing site at present. Optional analytics on a merchant storefront load only after cookie consent on that store.

4. Why we process it (notice of purposes)

  • Respond to sales, demo, and support enquiries.
  • Create and administer merchant accounts, trials, and staff access.
  • Host storefronts, carts, checkout, orders, invoices, and admin tools.
  • Enable India-native payments (UPI, cards, netbanking, wallets, COD) via licensed payment aggregators, and shipping via the carrier the merchant connects.
  • Send transactional notices the merchant configures (order, shipping, OTP) over email, SMS, or WhatsApp.
  • Bill SaaS subscriptions, prevent fraud and abuse, and keep the platform secure.
  • Meet legal duties (GST invoices and books, tax, accounting, cyber-security logging, and responding to lawful government or court requests).

5. Grounds of processing under the DPDP Act

We process personal data only as permitted by the DPDP Act, including:

  • Consent — for example when you submit a contact form, create an account, or accept non-essential cookies. You may withdraw consent as easily as you gave it by emailing privacy@aimonk.io or using in-product controls. Withdrawal does not affect processing already completed, or processing we must continue under law.
  • Certain legitimate uses (DPDP Act, section 7) — including providing or securing a service you have requested; detecting and investigating unlawful activity; and complying with any law or court / government order in India.

Where we act as a Data Processor for a merchant, their privacy notice and checkout terms govern the customer relationship. Merchants must give Data Principals a DPDP-compliant notice on their store.

6. Cookies and similar technologies

Essential cookies and similar storage run the site and shops (session, cart, login, security, load balancing). They are necessary to provide the service you request. On merchant storefronts, optional analytics (for example GA4 or Meta Pixel, if the merchant enabled them) load only after you accept the cookie banner. You can change your mind by clearing site data in your browser. See also the storefront cookie banner and this policy.

7. Sharing with processors and others

We share personal data only with parties who need it to run AiMonk or because the law requires it, under contracts that require confidentiality and DPDP-aligned safeguards. Typical categories:

  • Cloud hosting, storage, and email delivery in or from India and, where used, other regions;
  • Payment aggregators (Razorpay, Stripe) — they process payments under their own licences and policies;
  • SMS, WhatsApp, and notification providers the merchant or platform enables (for example MSG91, Interakt, Twilio, Resend);
  • Shipping aggregators the merchant connects (for example Shiprocket, Delhivery);
  • Optional AI features (Anthropic) when a merchant uses storefront or launch assistants;
  • Professional advisers, auditors, and authorities when required by Indian law.

8. Cross-border transfers

The DPDP Act allows transfer of personal data outside India except to countries or territories the Central Government notifies as restricted. Core production databases and object storage for this platform are intended to run in India (currently AWS Asia Pacific / Mumbai). Some subprocessors (payments, email, AI, error monitoring) may process limited data in other countries. We will not transfer personal data to a restricted jurisdiction if the Government so notifies.

9. Retention

We keep personal data only as long as needed for the purpose collected, or as Indian law requires, then delete or anonymise it. Illustrative periods: marketing contact-form leads up to 24 months; security and access logs in line with CERT-In directions (typically 180 days, longer if an incident is under investigation); GST and books of account for the statutory period (generally six years from the end of the relevant financial year); merchant account data for the life of the contract plus a short wind-down so you can export. Court, tax, or law-enforcement holds override ordinary deletion.

10. Security and personal data breaches

We use reasonable security safeguards as required of a Data Fiduciary (including TLS in transit, access control, and tenant isolation at the database layer). No method of transmission or storage is fully secure. If a personal data breach is likely to affect Data Principals, we will take steps required under the DPDP Act and Rules, which may include informing the Data Protection Board of India and affected individuals, and we will follow CERT-In incident reporting where those directions apply.

11. Your rights as a Data Principal

Subject to the DPDP Act (including legal retention), you may:

  • access a summary of personal data we hold about you and the processing activities;
  • correct inaccurate or incomplete personal data;
  • erase personal data that is no longer necessary for the stated purpose, unless law requires us to keep it (for example tax invoices);
  • withdraw consent where processing is consent-based;
  • nominate another individual to exercise rights in the event of death or incapacity, as the Act provides;
  • have a grievance redressed by us, and thereafter approach the Data Protection Board of India as provided under the Act and Rules.

To exercise rights for the AiMonk platform or this website, email privacy@aimonk.io. Shoppers on a hosted store should contact that merchant first (details on the store's privacy and contact pages); we will assist the merchant as processor where needed.

12. Children

Under the DPDP Act a child is a person under 18 years. AiMonk accounts and the marketing site are intended for persons 18 or older who can contract under Indian law. We do not knowingly track or target advertising at children. Merchants must not use the platform to offer goods or collect personal data from children except with verifiable parental consent and in line with the DPDP Act (including the bar on tracking / behavioural monitoring of children).

13. Grievance officer

In accordance with the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDP Act, you may reach our Grievance Officer at:

Grievance Officer
AiMonk
Siliguri, West Bengal, India
Email: grievance@aimonk.io · Privacy: privacy@aimonk.io

We will acknowledge a grievance within 24 hours and aim to resolve it within 15 days of receipt, as required for intermediaries under the 2021 Rules. DPDP grievance timelines prescribed in the Rules will also be followed. If you are not satisfied, you may escalate as provided under the DPDP Act to the Data Protection Board of India.

14. Governing law

This policy is governed by the laws of India. Subject to the DPDP Act (including the Board's jurisdiction over data protection complaints), courts at Siliguri, West Bengal have exclusive jurisdiction over disputes arising from this website and the AiMonk platform terms.

15. Changes

We may update this policy when our processing or the law changes. Material changes will be posted on this page with a new “Last updated” date. Where the DPDP Act requires a fresh notice or consent, we will provide it.

Questions? privacy@aimonk.io · Terms of Service · Contact.