Your privacy matters. Learn how we collect, use, and protect your data.
This Privacy Policy explains how Travozen handles your personal data under Article 13 of the GDPR when you use our website, mobile app, or services as a construction-materials and machinery marketplace. Last revised: July 2026.
1Who We Are
Travozen is a multi-vendor construction-materials and machinery marketplace operated by [LEGAL ENTITY NAME] (registration number [COMPANY REGISTRATION / CIN], GSTIN [GSTIN]), with its registered office at [REGISTERED ADDRESS]. For the purposes of Article 13(1)(a) of the GDPR, this entity is the controller of the personal data described below. We have appointed a Data Protection / Grievance Officer, reachable at [DPO / GRIEVANCE OFFICER EMAIL].
2Personal Data We Collect
We collect personal data in three ways, and we keep it to what is necessary to run the marketplace.
Data you provide: name, email, phone, delivery and billing addresses, GST number, account credentials, and order or quotation details.
Data collected automatically: IP address, device identifiers, browser type, timestamps, and how you interact with our pages.
Data from third parties: payment status from Razorpay, delivery updates from our logistics partner Porter, and information from vendors fulfilling your orders.
3Lawful Basis for Processing
Under Article 6(1) of the GDPR we rely on: performance of a contract (Article 6(1)(b)) to create your account and fulfil orders; legitimate interests (Article 6(1)(f)) to prevent fraud and understand how the marketplace is used, balanced against your rights; consent (Article 6(1)(a)) for marketing messages and non-essential cookies; and legal obligation (Article 6(1)(c)) to keep GST and tax records.
4How We Use Your Data
We use your data to operate the marketplace and support you, matching each purpose to a lawful basis above.
Create and manage your account and process your orders
Take payments through Razorpay and issue GST invoices
Arrange delivery through our logistics partner and keep you updated
Send transactional messages, and marketing only where you have consented
Detect fraud, secure the platform, and meet legal obligations
5Sharing of Personal Data
We do not sell your personal data. We share it only with the recipients needed to complete your order: the vendor fulfilling it, our payment processor Razorpay, our logistics partner Porter, our hosting and email providers, our analytics provider, and public authorities where the law requires.
6International Transfers
Where a service provider processes your data outside your country, we rely on appropriate safeguards under Article 46 of the GDPR, such as Standard Contractual Clauses together with supplementary measures, so your data keeps an equivalent level of protection.
7Data Retention
We keep your personal data while your account is active. After account closure it is soft-deleted and permanently purged within 90 days by an automated process. Financial and GST invoice records are retained for the longer period required by applicable tax and accounting law, and backups are held for no more than 90 days.
8Your Rights
You can exercise the following rights by contacting us, and we will respond within 30 days (Article 12(3) of the GDPR):
Access your data — Article 15
Correct inaccurate data — Article 16
Erase your data — Article 17
Restrict processing — Article 18
Receive your data in a portable format — Article 20
Object to processing — Article 21
Withdraw consent at any time — Article 7(3)
Complain to the supervisory authority, [SUPERVISORY AUTHORITY] — Article 77
9Cookies
We use cookies and similar technologies to keep you signed in, remember preferences, and measure usage. You can manage non-essential cookies at any time. See our Cookies Policy for the full list and legal basis.
10Children
Travozen is intended for business and professional buyers and is not directed at children. Consistent with Article 8(1) of the GDPR, we do not knowingly process the data of anyone under 16, and we delete such data if we become aware of it.
11Security
We protect your data with encryption in transit (TLS), encryption at rest for sensitive fields, strict access controls on a need-to-know basis, and regular backups. No system is completely secure, but we work to keep your data safe.
12Breach Notification
If a personal data breach is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours of becoming aware of it (Article 33 of the GDPR). Where the breach is likely to result in a high risk to you, we will inform you without undue delay (Article 34).
13Changes to This Policy
We may update this policy from time to time. We will notify you by email of material changes; other updates take effect when posted with a revised date.
14Contact
For any privacy question or to exercise your rights, contact [LEGAL ENTITY NAME] at [PRIVACY / GRIEVANCE EMAIL], or our Data Protection / Grievance Officer at [DPO / GRIEVANCE OFFICER EMAIL], or write to us at [REGISTERED ADDRESS].
Questions about your privacy?
Contact our privacy team at [PRIVACY / GRIEVANCE EMAIL] or write to [LEGAL ENTITY NAME], [REGISTERED ADDRESS].
Cookie Notice
We use cookies to enhance your experience and analyze site traffic. You can choose to accept all cookies or only essential ones.