Last updated: 24 May 2026 · Effective: 24 May 2026
This Privacy Policy explains how Fassalkart Agri-Tech Private Limited (“Fassalkart”, “we”, “us”) collects, uses, stores, and protects your information when you use the Fassalkart mobile application (the “App”) and the website fassalkart.com (the “Site”). By using the App or Site, you agree to the practices described below.
We comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India, the Information Technology Act, 2000 and the SPDI Rules, 2011, and applicable Google Play and Apple App Store data-handling policies. We never sell your personal data to third parties.
We do not collect: health data, biometric identifiers (other than the photograph on your KYC ID), contacts list, SMS messages, call logs, browsing history outside our App, or background location.
The Fassalkart Android App requests the permissions below. Each permission is requested at the moment it is needed; you can deny or revoke any of them at any time from Android Settings → Apps → Fassalkart → Permissions. Revoking a permission only disables the related feature — the rest of the App continues to work.
android.permission.CAMERA, NSCameraUsageDescriptionkyc/{uid}/ or products/{uid}/) in our secure storage and are
never shared with other users without your action. We do not stream,
record, or access the camera in the background.
ACTION_PICK_IMAGES) or the system “Get Content”
picker on Android 7–12 (which uses ACTION_GET_CONTENT).
These are operating-system-provided pickers that return only
the single photo you tap on.READ_MEDIA_IMAGES, READ_MEDIA_VIDEO,
READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE,
or any other “broad photo and video access” permission, and
therefore cannot scan, list, or read any photo in your
gallery other than the one you explicitly hand it. On iOS, the system
Limited Photo Library picker (PHPickerViewController)
behaves identically — only the selected image is returned to the
App.
ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION, NSLocationWhenInUseUsageDescriptionRECORD_AUDIO, NSMicrophoneUsageDescription, NSSpeechRecognitionUsageDescriptionPOST_NOTIFICATIONSINTERNET, ACCESS_NETWORK_STATE, VIBRATE| Service | Purpose | Data shared | Region |
|---|---|---|---|
| Google Firebase (Auth, Firestore, Storage, Cloud Messaging) | Authentication, database, file storage, push notifications | All app data listed in §1 | Google Cloud, primarily asia-south1 (Mumbai). Some services route through other Google regions. |
| Razorpay | Payment processing (UPI, cards, netbanking) | Order amount, contact, payment instrument (entered on Razorpay’s PCI-DSS sheet — never seen by us) | India |
| Google Maps Platform | Map tiles, geocoding, place autocomplete | Approximate location, search query | Google Cloud (global) |
| Google Cloud Vision | Server-side OCR of KYC documents | The submitted KYC image (deleted from the OCR pipeline after processing) | Google Cloud (global) |
| Firebase Cloud Messaging / Apple Push | Push notification delivery | Push token, notification payload | Google / Apple infrastructure |
We do not sell, rent, or trade your personal information to anyone. We share data with the providers above only to the extent strictly required to operate the service, under written data-processing terms.
Some of our processors (Google Cloud, Razorpay’s fraud engine, push-notification gateways) may process data outside India. Where this happens, the transfer is carried out under Google’s and the processor’s standard data-protection commitments and only to the extent permitted by the DPDP Act and any rules issued thereunder. We do not transfer personal data to any country that the Government of India has notified as restricted.
Data in transit is encrypted with TLS 1.2+. Firestore and Storage are protected by
per-user security rules so that users can only read and write their own data. KYC
documents are stored under kyc/{uid}/ paths and can only be read by the
owner and Fassalkart admins. Passwords are hashed by Firebase Auth and never stored
in plaintext. We follow industry-standard practices to protect against unauthorized
access, alteration, disclosure, or destruction.
We will notify the Data Protection Board of India and affected users without undue delay if a personal-data breach is likely to cause significant harm, as required by the DPDP Act.
Fassalkart is intended for users aged 18 and above. We do not knowingly collect personal data from children under 18 without verifiable parental consent. If we learn that we have collected such data without proper consent, we will delete it promptly. Parents or guardians who believe their child has provided personal data to us should contact the Grievance Officer below.
You can delete your Fassalkart account, and the personal data associated with it, in any of these ways:
We will confirm deletion within 30 days. Data we are required to retain by law (KYC for 7 years, GST invoices for 8 years) is retained in a restricted-access archive and is not used for any other purpose.
The Fassalkart website uses essential session cookies to keep you logged in and to analyze which pages are popular. We do not use third-party advertising cookies. The mobile App does not use cookies.
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision. Material changes will be notified in-App and by email at least 7 days before they take effect. Continued use of the App or Site after a change indicates acceptance of the revised policy.
Mr. S. M. Parvej Nowaj — Grievance Officer
Fassalkart Agri-Tech Private Limited
Baur, Palashipara, Nadia District
West Bengal — 741155, India