This policy explains what personal data Diemeco ("we") collects through Diemeco, why, who sees it, and what control you have. We handle personal data in line with India's Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.
1. What we collect
- Account: your mobile number (used to sign in with a one-time code), and the email address you confirm for invoices.
- Profile: name, company or workshop name, city, logo, description, GSTIN and PAN where you give them, machines, materials and processes.
- Requirements and files: what you post, drawings, CAD files, images and documents you upload.
- Messages and quotations you send or receive on the Platform, and reviews.
- Payments: which plan you bought, amount, date, status and Razorpay's order and payment reference. We do not receive or store your card, UPI or bank details; Razorpay collects them directly.
- Usage and security: notifications, preferences, audit records of important actions (such as payments and verification decisions), and technical data such as IP address needed to keep the service secure and to limit abuse.
2. Why we use it
- To create and secure your account, and to match Clients with suitable Workshops.
- To show a Workshop the requirement details it has paid credits to unlock, and to let users message and quote.
- To process purchases, issue invoices and receipts, keep tax records and prevent fraud.
- To verify GST details, handle reports, and enforce our Terms.
- To send you notices about your account, messages, quotations and payments.
We do not sell your personal data.
3. Who sees what
- Other users: a Workshop's public profile (name, city, machines, reviews, verification badge) is visible to Clients. A Client's requirement is visible to matching Workshops only in the detail the Client allows; contact and file details are revealed to Workshops that unlock or are approved. Files marked view-only are shown as watermarked images, never as the original.
- Service providers (data processors) who process data for us, only on our instructions and under written terms: Supabase (database, authentication and file storage, hosted in Mumbai, India), Vercel (application hosting), Twilio (sending one-time codes by SMS), Razorpay (payments; Razorpay also acts on its own account as a payment provider), Resend (sending email), Cloudflare (bot protection at sign-in) and the push-notification services of your phone or browser, if you turn alerts on. Some of these providers may process data outside India.
- Authorities where the law requires it, or to protect rights, safety or against fraud.
4. Cookies, counts and alerts
We use only the cookies needed to keep you signed in, to remember your language and theme, and to protect the service. We do not use advertising cookies. We keep anonymous counts of visits to our public pages (which page, roughly where the visit came from, and the language), with no cookie and no personal identifier. If you turn on phone alerts, we store the address your device gives us so that we can send notifications, and you can turn them off at any time.
5. How long we keep it
- Account and profile data: while your account is active, and for a limited period after deletion.
- Uploaded files: deleted after the requirement is removed (with a short technical delay).
- Invoices, payment and audit records: retained as long as tax, accounting and dispute-resolution rules require, typically several years.
6. Your rights
You may ask to access, correct or delete your personal data, withdraw consent where we rely on it, and nominate someone to exercise these rights for you. Many corrections you can make yourself in your profile. Deleting data we must keep by law (such as invoices) may not be possible until the retention period ends. Write to the Grievance Officer below and we will respond within a reasonable period, and in any case within the time the law prescribes.
7. Security
Data is encrypted in transit; files are kept in private storage and released only through short-lived secure links; access to records is restricted by the database itself, not only by the application. No system is perfectly secure, so please protect your phone and do not share codes. If a breach affecting your data occurs we will notify you and the authorities as the law requires.
8. Children
The Platform is for business use by adults. We do not knowingly collect data from anyone under 18.
9. Changes
We may update this policy and will show the new date above. If a change is significant we will tell you in the Platform.
10. Consent, children and complaints
When you sign in we record which version of the Terms and Privacy Policy you accepted, and when. When you create a Workshop or Client profile we record that you accepted the Workshop Agreement or the Client Agreement. You can withdraw consent by deleting your account, though some records must be kept as section 5 explains. See our Grievance Policy for how to complain and what to expect.
11. Contact and Grievance Officer
Grievance Officer: Amish Pathan, Diemeco, Dudh Sagar Road, Rajkot, Gujarat, India, 360003. Email: support@diemeco.com.