FurnishMate Tech Private Limited("Nexus", "we", "us", or "our") operates the FurnishMate software-as-a-service platform, website, mobile application, and related services (collectively, the "Service").
This Privacy Policy explains our principles and practices regarding the collection, use, processing, storage, and protection of personal data. Our operations are structured in accordance with applicable data protection laws, including India's Digital Personal Data Protection Act, 2023 (DPDP Act).
1. Roles and Responsibilities
Under applicable data protection frameworks, the distinction between a Data Fiduciary and a Data Processor governs how data is managed:
- Nexus as Data Fiduciary: We act as the Data Fiduciary regarding the personal information of our direct account holders (shop owners, business administrators, and registered staff).
- Nexus as Data Processor: For all business and customer data you input into the Service (such as end-customer names, phone numbers, site measurements, custom furnishing orders, and delivery addresses), you act as the Data Fiduciary. Nexus processes this information strictly as a Data Processor on your behalf to deliver the Service.
2. Categories of Data Collected
In accordance with data minimization principles, we collect only data necessary for service delivery:
- Account & Identity Data: Name, verified mobile phone number, login credentials, and user role.
- Organization Data: Business name, address, GSTIN, shop configuration, and staff permissions.
- Operational Data: Quotations, orders, fabric measurements, catalog items, vendor registry, and service tickets.
- Technical & Log Data: Device type, operating system, IP address, access timestamps, and security audit logs.
Data We Do Not Collect or Sell
- We do not sell, rent, or monetize your personal or business data to advertisers or third-party brokers.
- We do not engage in third-party cross-site advertising tracking.
- We do not collect unauthorized device telemetry, personal contact lists, or background biometric data.
3. Essential Cookies & Session Storage
We utilize only essential, first-party cookies and local storage tokens strictly required for user authentication, session security, and CSRF protection. We do not use third-party tracking or advertising cookies.
4. Lawful Grounds for Processing
We process personal and organizational data on the following bases:
- Contractual Performance: Creating accounts, processing billing, and delivering furnishing ERP workflows.
- Consent: Sending transactional notifications via SMS, WhatsApp, or email when requested.
- Legal Compliance: Maintaining financial transaction records and GST-compliant invoicing histories.
- Legitimate Security Interests: Detecting unauthorized intrusions, preventing brute-force attacks, and maintaining audit trails.
5. Sub-Processors & Infrastructure
We partner with vetted infrastructure providers who adhere to strict confidentiality and security standards:
- Cloud Hosting & Database: Enterprise cloud database servers with Row Level Security (RLS) tenant isolation.
- Payment Processing: PCI-DSS compliant payment gateways (Razorpay). Nexus does not store credit card numbers or UPI PINs.
- Communications: Verified SMS and messaging service providers for OTP delivery and transactional order alerts.
6. Artificial Intelligence & Data Privacy
Where AI-assisted features (such as quotation auto-estimation or document parsing) are enabled:
- Proprietary shop data and customer records are processed strictly for the immediate request.
- We do not use, nor permit third-party AI models to use, your customer data to train public foundational AI models.
7. Data Sovereignty & Storage
Our primary production databases and operational data stores are hosted in enterprise data centers located within India.
8. Data Retention & Erasure
We retain account data for as long as your account remains active. When you initiate an account deletion or submit a data erasure request:
- Active operational data is scheduled for permanent deletion within 30 days.
- Aggregated tax and billing transaction records may be retained strictly as mandated by applicable statutory accounting regulations.
9. Your Rights under the DPDP Act
As a Data Principal, you are entitled to:
- Access & Summary: Review the personal data processed within your account.
- Correction & Updating: Correct inaccurate or outdated account information.
- Erasure: Request the deletion of your account and personal data.
- Grievance Redressal: Submit inquiries or complaints directly to our designated Privacy & Grievance Officer.
10. Grievance Officer & Contact Information
In accordance with the DPDP Act, 2023 and the Information Technology Rules, 2021:
Grievance Officer:Data Protection & Privacy Officer
Organization: FurnishMate Tech Private Limited
Email: [email protected]
Address: Mumbai, Maharashtra, India
