This policy explains what personal data Diemeco ("we") collects through Diemeco, why, who sees it, and what control you have. We handle personal data in line with India's Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.
1. What we collect
- Account: your mobile number (used to sign in with a one-time code or an early-access pass), and the email address you confirm for notices.
- Profile: name, company or workshop name, city, logo, description, GSTIN and PAN where you give them, machines, materials and processes.
- Requirements and files: what you post, drawings, CAD files, images and documents you upload.
- Messages and quotations you send or receive on the Platform, and reviews.
- Payments: the credits you asked for, the amount, date and status, and your receipt. When you pay by UPI, we also see what any UPI payment shows the receiver: the payer's name, UPI ID and transaction reference, and any payment screenshot you choose to send us. We never ask for your UPI PIN, card or bank login.
- WhatsApp: when you ask for credits or an early-access pass, we contact you on WhatsApp at the number you sign in with, and keep what is needed to complete that request.
- Usage and security: notifications, preferences, audit records of important actions (such as payments and verification decisions), and technical data such as IP address needed to keep the service secure and to limit abuse.
2. Why we use it
- To create and secure your account, and to match Clients with suitable Workshops.
- To show a Workshop the requirement details it has paid credits to unlock, and to let users message and quote.
- To process purchases, issue invoices and receipts, keep tax records and prevent fraud.
- To verify GST details, handle reports, and enforce our Terms.
- To send you notices about your account, messages, quotations and payments.
We do not sell your personal data.
3. Who sees what
- Other users: a Workshop's public profile (name, city, machines, reviews, verification badge) is visible to Clients. A Client's requirement is visible to matching Workshops only in the detail the Client allows; contact and file details are revealed to Workshops that unlock or are approved. Files marked view-only are shown as watermarked images, never as the original.
- Service providers (data processors) who process data for us, only on our instructions and under written terms: Supabase (database, authentication and file storage, in Mumbai, India), Vercel (application hosting, in Mumbai, India), an SMS provider that delivers sign-in codes, WhatsApp (Meta) for payment requests and passes, an email provider that delivers our notices, and the push-notification services of your phone or browser, if you turn alerts on. Some of these providers may process data outside India. When we add a provider, such as an online payment provider, we will name it here first.
- Authorities where the law requires it, or to protect rights, safety or against fraud.
4. Cookies, counts, alerts and emails
We use only the cookies needed to keep you signed in, to remember your language and theme, and to protect the service. We do not use advertising cookies. We keep anonymous counts of visits to our public pages (which page, roughly where the visit came from, and the language), with no cookie and no personal identifier. If you turn on phone alerts, we store the address your device gives us so that we can send notifications, and you can turn them off at any time. Every email we send has a one-click link to stop emails, and you can change email settings on your Profile.
5. How long we keep it
- Account and profile data: while your account is active. When you delete your account, your profile details are removed within 30 days, except the records listed below.
- Uploaded files: deleted after the requirement is removed (with a short technical delay).
- Payment screenshots and WhatsApp messages about a payment: deleted within 90 days after the payment is confirmed or the request is closed.
- Receipts and payment records: 8 years, as tax and accounting law requires.
- Security and access logs: at least 1 year, as the Digital Personal Data Protection Rules, 2025 require, then deleted.
6. Your rights
You may ask to access, correct or delete your personal data, withdraw consent where we rely on it, and nominate someone to exercise these rights for you. Many corrections you can make yourself in your profile. Deleting data we must keep by law (such as invoices) may not be possible until the retention period ends. Write to the Grievance Officer below: we acknowledge within 24 hours and respond within the time the law prescribes. If you are not satisfied, you may complain to the Data Protection Board of India.
7. Security
Data is encrypted in transit; files are kept in private storage and released only through short-lived secure links; access to records is restricted by the database itself, not only by the application. No system is perfectly secure, so please protect your phone and do not share codes. If a breach affecting your data occurs, we will tell you without delay and report it to the Data Protection Board of India within 72 hours, as the law requires.
8. Children
The Platform is for business use by adults. We do not knowingly collect data from anyone under 18.
9. Changes
We may update this policy and will show the new date above. If a change is significant we will tell you in the Platform.
10. Consent, children and complaints
When you sign in we record which version of the Terms and Privacy Policy you accepted, and when. When you create a Workshop or Client profile we record that you accepted the Workshop Agreement or the Client Agreement. You can withdraw consent by deleting your account, though some records must be kept as section 5 explains. See our Grievance Policy for how to complain and what to expect.
11. Contact and Grievance Officer
Grievance Officer: Amish Pathan, Diemeco, Dudh Sagar Road, Rajkot, Gujarat, India, 360003. Email: support@diemeco.com.