Privacy Policy
Last updated: 14 May 2026
Fieldr Sports Pvt Ltd ("Fieldr", "we", "us") respects your privacy. This policy explains what personal data we collect, how we use it, and the rights you have as a Data Principal under India's Digital Personal Data Protection Act 2023 ("DPDP Act"), the Information Technology Act 2000 with the SPDI Rules 2011, and the Consumer Protection Act 2019.
1. Data Fiduciary
Fieldr Sports Pvt Ltd, a company registered in India, is the Data Fiduciary for your personal data. Our Data Protection Officer can be reached at dpo@fieldr.example or at the registered office in Bengaluru, Karnataka.
2. What we collect
- Account & buyer profile: name, email, phone, company, GSTIN, billing/shipping address.
- Order & payment metadata: products purchased, RFP responses, transaction IDs (we never see full card numbers — payments are processed by RBI-authorised, PCI-DSS certified gateways).
- Device & usage: IP address, browser, pages visited, referrer, error logs.
- Approximate location: only with your explicit opt-in, coarsened to ~1 km, used to surface nearby vendors.
- Communications: support tickets, vendor messages, marketing preferences.
3. Why we use it
- To operate the marketplace, fulfil orders, and provide RFP matching (performance of contract).
- To secure the platform, prevent fraud, and improve features (legitimate use under DPDP Act §7).
- To send marketing, set non-essential cookies, and use your location — only with your consent under DPDP Act §6.
- To comply with Indian tax law, KYC obligations, and lawful directions from authorities.
4. Sharing
We share data with verified vendors when you submit an RFP or place an order, with payment processors, logistics partners, KYC providers, cloud infrastructure hosted in India, and authorities where legally required. We do not sell personal data and do not share it for cross-context behavioural advertising.
5. Data localisation
Personal data of Indian users is stored on servers located in India. Where any limited processing happens outside India (for example, anti-fraud checks), it is done only in countries not restricted by the Central Government under the DPDP Act, and under contractual safeguards.
6. Retention
Account data is kept while your account is active and for up to 8 years after closure to satisfy the Income-tax Act, GST law and the Companies Act. Marketing data is deleted within 30 days of withdrawal of consent. Server logs are kept for 90 days.
7. Your rights as a Data Principal
Under the DPDP Act you have the right to access, correct, update and erase your personal data, the right to grievance redressal, and the right to nominate another person to exercise your rights in case of death or incapacity. Submit any request via our Data Rights portal.
8. Security
We use TLS 1.3 in transit, AES-256 at rest, role-based access, and periodic security testing aligned to the CERT-In directions of 28 April 2022. Despite reasonable safeguards, no system is 100% secure — we will notify you and the Data Protection Board of India of qualifying breaches without undue delay.
9. Children
The marketplace is B2B and not directed at users under 18. Consistent with the DPDP Act, we do not knowingly process the personal data of children without verifiable parental consent.
10. Grievance Officer
In line with the IT Rules 2021, our Grievance Officer is reachable at grievance@fieldr.example. We acknowledge complaints within 24 hours and resolve them within 15 days. If unsatisfied, you may approach the Data Protection Board of India.
