Every product on Aadaten passes the Mother Filter™ — 1,347 ingredients checked, before it earns a Jain Verified badge.
Effective Date: 1 June 2026
Last Reviewed: May 2026
Governing Law: Republic of India — Mumbai Courts
Platform: www.aadaten.com
This Privacy Policy describes how Aadaten Private Limited ("Aadaten", "We", "Us", "Our"), a company incorporated under the Companies Act, 2013 with CIN U47912MH2026PTC469786, collects, uses, processes, discloses, stores, and protects the personal data of Users of the Platform at www.aadaten.com, the Aadaten mobile applications (Customer App and Vendor App), WhatsApp communities, exhibitions, retail stores, restaurant, and cloud kitchen operations (collectively, the "Platform" or "Services").
Aadaten is the Data Fiduciary as defined under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules") for all personal data collected through or in connection with the Platform.
This Policy is compliant with: the Digital Personal Data Protection Act, 2023; the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011; the Consumer Protection (E-Commerce) Rules, 2020; and applicable FSSAI regulations for food businesses.
This Policy applies to: (a) all registered and guest Users of aadaten.com and the Aadaten apps; (b) Sellers and Vendors onboarded on the Platform; (c) Exhibition visitors and stall exhibitors; (d) Restaurant and Cloud Kitchen customers; (e) WhatsApp Community members; (f) Enterprise and wholesale buyers; (g) Subscribers under the Global Vision vertical; and (h) any person whose personal data is processed by Aadaten in connection with any of the above.
Identity data: Full name, date of birth, gender.
Contact data: Email address, mobile number, postal address (delivery and billing).
Account data: Username, password (hashed), profile photograph (optional).
Transaction data: Order history, invoices, payment method details (card last 4 digits only — full card data is processed by Razorpay, our PCI-DSS compliant payment gateway; Aadaten does not store full card data).
Seller/Vendor data: Business name, PAN, GST number, bank account details for payouts, FSSAI license, product information.
Exhibition data: Stall registration details, business information, emergency contact.
Dietary preference data: Jain compliance level, dietary restrictions (classified as sensitive personal data under DPDP Act — collected only with explicit consent).
Device and technical data: IP address, browser type, device model, operating system, unique device identifiers.
Usage data: Pages visited, products viewed, search terms, time spent, click behaviour.
Location data: Approximate location derived from IP address; precise location only if you grant permission via the app for delivery purposes.
Cookie and tracking data: See Cookie Policy.
Payment confirmation data from Razorpay.
Login data if you use Google or Facebook OAuth for account creation (name, email, profile picture).
Aadaten processes personal data only on the following lawful bases under the DPDP Act:
Consent: For marketing communications, dietary preference storage, non-essential cookies, and any processing beyond the core transaction. You may withdraw consent at any time without prejudice to prior processing.
Contractual necessity: Processing required to fulfil your order, process your return, operate your Seller account, or deliver booked services.
Legal obligation: Processing required to comply with GST, FSSAI, RBI, Consumer Protection, and other applicable Indian laws.
Legitimate interests: Fraud detection, security, abuse prevention, platform analytics — only where your rights do not override our interests.
Consent for minors (under 18): Aadaten does not knowingly collect personal data from persons under 18 years of age without verifiable parental consent. Accounts may only be created by adults under the Indian Contract Act, 1872.
To process, fulfil, and communicate about orders, returns, refunds, and deliveries.
To operate your Seller account, process payouts, and manage compliance.
To provide customer support and resolve disputes or grievances.
To send transactional communications (order confirmations, shipping updates, invoices) via SMS, email, and WhatsApp.
To send marketing communications (new arrivals, offers, exhibition invitations) only if you have consented. You may opt out at any time.
To improve, personalise, and secure the Platform.
To comply with applicable laws, court orders, or regulatory requirements.
To detect and prevent fraud, abuse, and security threats.
To conduct analytics and business intelligence (in aggregated, anonymised form where possible).
Aadaten does not sell your personal data. We may share it with:
Sellers/Vendors: Only the delivery address, name, and contact number required to fulfil your order from that Seller. We do not share payment or financial data with Sellers.
Logistics partners: Name, address, and contact number for delivery.
Payment processor (Razorpay): Transaction data necessary to process your payment, subject to Razorpay's Privacy Policy.
Technology service providers: Cloud hosting, analytics, email/SMS platforms — bound by data processing agreements.
Legal and regulatory authorities: When required by law, court order, or government direction.
Business transfers: In the event of a merger, acquisition, or restructuring of Aadaten, subject to the acquiring entity honouring this Policy.
Aadaten primarily stores and processes your data in India. Where data is transferred outside India (e.g., to cloud infrastructure providers or analytics platforms with servers abroad), such transfers are made in compliance with the DPDP Act and applicable RBI or sectoral regulations. Aadaten ensures adequate contractual protections are in place for all cross-border transfers.
Transaction and order data: 7 years from the date of the last transaction (for GST and legal compliance).
Account data: Until account deletion + 90 days for technical de-provisioning.
Marketing consent data: Until consent is withdrawn, then deleted within 30 days.
CCTV footage from retail stores: 60 days, then overwritten.
Server logs: 90 days.
Under the DPDP Act, 2023, you have the right to:
Access: Request a summary of the personal data Aadaten holds about you.
Correction: Request correction of inaccurate or incomplete personal data.
Erasure: Request deletion of your personal data, subject to legal retention obligations.
Grievance: Raise a complaint with Aadaten's Grievance Officer (see Section 11).
Nominate: Nominate another person to exercise your rights on your behalf in the event of death or incapacity.
Withdraw consent: Withdraw consent for any processing that relies on consent, at any time.
To exercise any of these rights, write to: legalsupport@aadaten.com with subject line "Data Rights Request — [Your Name]". Aadaten will respond within 72 hours and resolve within 30 days.
Aadaten uses cookies and similar tracking technologies on the website and app. Types of cookies: Essential (cannot be disabled — required for checkout and login), Analytical (Google Analytics — can be opted out), Marketing (Meta Pixel — requires your consent). You may manage cookie preferences via the Cookie Settings link in the website footer. Please refer to our separate Cookie Policy for full details.
In accordance with the Information Technology Act, 2000, the Consumer Protection (E-Commerce) Rules, 2020, and the DPDP Act, 2023, the details of the Grievance Officer are:
Name
Nirav Shah
Designation
Director
Organisation
Aadaten Private Limited
legalsupport@aadaten.com
Address
509, Krishna Bhavan, Ground Floor, S.V.P. Road, Opera House, Mumbai – 400004
Response time
Acknowledge within 48 hours; Resolve within 30 days
If you are dissatisfied with the resolution, you may approach the Data Protection Board of India once established, or the Consumer Disputes Redressal Forum, or the competent court in Mumbai.
Aadaten implements reasonable technical and organisational security measures including: TLS/SSL encryption in transit, hashed password storage, role-based access controls, PCI-DSS compliant payment processing through Razorpay, and periodic security reviews. In the event of a data breach, Aadaten will report to the Data Protection Board as mandated by the DPDP Rules, 2025.
Aadaten may update this Privacy Policy from time to time. Material changes will be notified to registered Users via email and prominent website notice at least 14 days before the change takes effect. Continued use of the Platform after the effective date constitutes acceptance.
This Policy is governed by the laws of the Republic of India. Any disputes shall be subject to the exclusive jurisdiction of courts in Mumbai, Maharashtra.
Aadaten Private Limited | CIN: U47912MH2026PTC469786 | www.aadaten.com
Quick Query
Send a short query and the team can reach out from here.
Quick Query
You need to Sign in to view this feature
This address will be removed from this list