Every product on Aadaten passes the Mother Filter™ — 1,347 ingredients checked, before it earns a Jain Verified badge.
Effective Date: 1 June 2026
Last Reviewed: May 2026
Governing Law: Republic of India — Mumbai Courts
Platform: www.aadaten.com
This Data Safety & Security Policy ("Data Safety Policy") establishes Aadaten Private Limited's technical and organisational framework for protecting personal data processed on or through the Platform. This Policy supplements the Privacy Policy and is compliant with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the DPDP Rules, 2025, the Information Technology Act, 2000, and the RBI Tokenization Circular.
Aadaten classifies data into the following tiers for security purposes:
Tier 1 — Highly Sensitive
Payment data (processed by Razorpay), Seller bank details, DPDP-special-category data (dietary preferences, health data)
Tier 2 — Personal Data
Name, email, phone, address, order history, login credentials
Tier 3 — Operational Data
Platform analytics, server logs, aggregated business data
Tier 4 — Public Data
Product listings, published policies, public-facing content
Aadaten processes all payment transactions through Razorpay, a PCI-DSS Level 1 certified payment gateway.
Aadaten does NOT store full credit/debit card numbers, CVV codes, or card PINs. Only the last 4 digits of a card may be displayed for reference.
All card data is tokenised at source per RBI's Card-on-File Tokenization guidelines (Circular RBI/2021-22/40). Tokens are stored by Razorpay, not by Aadaten.
UPI transactions are processed through Razorpay's UPI gateway. VPA (Virtual Payment Addresses) are not stored by Aadaten beyond the transaction record.
Encryption in transit: All data transmitted between the User and the Platform is encrypted using TLS 1.2 or higher (HTTPS enforced on all pages).
Encryption at rest: Sensitive database fields (passwords, OTPs) are stored using industry-standard hashing (bcrypt or equivalent). Seller bank account details are encrypted at rest.
Access controls: Role-based access control (RBAC) ensures that Platform staff access only the data necessary for their function. No single employee has unrestricted access to the full User database.
Password security: Aadaten enforces minimum password complexity requirements. Passwords are never stored in plaintext.
OTP-based authentication: Aadaten uses OTP-based second-factor authentication for Seller accounts and high-value transactions.
Vulnerability management: Aadaten conducts periodic security reviews of the Platform and addresses critical vulnerabilities within 7 days of detection.
Third-party processor obligations: All third-party data processors (cloud hosting, analytics, email platforms) are bound by data processing agreements that require them to maintain security standards equivalent to or higher than those in this Policy.
In the event of a personal data breach:
Aadaten will assess the breach within 6 hours of detection.
In accordance with DPDP Rules 2025, Aadaten will report ALL personal data breaches to the Data Protection Board of India (DPBI) — irrespective of their severity — within the timeframe prescribed by the Rules (as notified).
Affected Data Principals will be notified without undue delay, with a description of the breach, the categories of data affected, and the remedial measures taken.
Aadaten will maintain a Breach Register documenting all incidents, even those resolved without external notification.
NOTE: Penalties under the DPDP Act for failure to report a breach or for inadequate security measures may extend up to ₹250 crore.
Aadaten stores all personal data of Indian Users on servers located within the Republic of India, in compliance with applicable Indian data localisation requirements and the DPDP Act. Any cross-border processing is governed by the mechanisms described in the Privacy Policy, Section 7.
Aadaten does not retain personal data beyond the periods specified in the Privacy Policy (Section 8). Upon the expiry of the retention period, or upon receipt of a verified erasure request:
Digital records are securely deleted using industry-standard deletion protocols.
Physical documents (where applicable) are shredded.
Backups containing personal data are purged within 90 days of the primary deletion.
Users are responsible for: maintaining the confidentiality of their account credentials; immediately reporting any suspected unauthorised access to their account to legalsupport@aadaten.com; ensuring the accuracy of personal data they provide; and not sharing OTPs, passwords, or account access with third parties.
For the Aadaten Vendor App and Customer App on Google Play Store, the Data Safety section is maintained in accordance with this Policy. The app collects: name, email, phone number, location (delivery only, with permission), order history, and payment tokens. The app does NOT share user data with third parties for advertising purposes without explicit consent.
For data safety concerns, suspected breaches, or access requests: legalsupport@aadaten.com | Subject: "Data Safety — [Issue Type]"
Aadaten Private Limited | CIN: U47912MH2026PTC469786 | www.aadaten.com
Quick Query
Send a short query and the team can reach out from here.
Quick Query
You need to Sign in to view this feature
This address will be removed from this list