Skip to main content
Data Protection

Privacy Policy

Your privacy matters. Learn how we collect, use, and protect your data.

This Privacy Policy explains how Travozen handles your personal data under Article 13 of the GDPR when you use our website, mobile app, or services as a construction-materials and machinery marketplace. Last revised: July 2026.

1Who We Are

Travozen is a multi-vendor construction-materials and machinery marketplace operated by [LEGAL ENTITY NAME] (registration number [COMPANY REGISTRATION / CIN], GSTIN [GSTIN]), with its registered office at [REGISTERED ADDRESS]. For the purposes of Article 13(1)(a) of the GDPR, this entity is the controller of the personal data described below. We have appointed a Data Protection / Grievance Officer, reachable at [DPO / GRIEVANCE OFFICER EMAIL].

2Personal Data We Collect

We collect personal data in three ways, and we keep it to what is necessary to run the marketplace.

  • Data you provide: name, email, phone, delivery and billing addresses, GST number, account credentials, and order or quotation details.
  • Data collected automatically: IP address, device identifiers, browser type, timestamps, and how you interact with our pages.
  • Data from third parties: payment status from Razorpay, delivery updates from our logistics partner Porter, and information from vendors fulfilling your orders.

3Lawful Basis for Processing

Under Article 6(1) of the GDPR we rely on: performance of a contract (Article 6(1)(b)) to create your account and fulfil orders; legitimate interests (Article 6(1)(f)) to prevent fraud and understand how the marketplace is used, balanced against your rights; consent (Article 6(1)(a)) for marketing messages and non-essential cookies; and legal obligation (Article 6(1)(c)) to keep GST and tax records.

4How We Use Your Data

We use your data to operate the marketplace and support you, matching each purpose to a lawful basis above.

  • Create and manage your account and process your orders
  • Take payments through Razorpay and issue GST invoices
  • Arrange delivery through our logistics partner and keep you updated
  • Send transactional messages, and marketing only where you have consented
  • Detect fraud, secure the platform, and meet legal obligations

5Sharing of Personal Data

We do not sell your personal data. We share it only with the recipients needed to complete your order: the vendor fulfilling it, our payment processor Razorpay, our logistics partner Porter, our hosting and email providers, our analytics provider, and public authorities where the law requires.

6International Transfers

Where a service provider processes your data outside your country, we rely on appropriate safeguards under Article 46 of the GDPR, such as Standard Contractual Clauses together with supplementary measures, so your data keeps an equivalent level of protection.

7Data Retention

We keep your personal data while your account is active. After account closure it is soft-deleted and permanently purged within 90 days by an automated process. Financial and GST invoice records are retained for the longer period required by applicable tax and accounting law, and backups are held for no more than 90 days.

8Your Rights

You can exercise the following rights by contacting us, and we will respond within 30 days (Article 12(3) of the GDPR):

  • Access your data — Article 15
  • Correct inaccurate data — Article 16
  • Erase your data — Article 17
  • Restrict processing — Article 18
  • Receive your data in a portable format — Article 20
  • Object to processing — Article 21
  • Withdraw consent at any time — Article 7(3)
  • Complain to the supervisory authority, [SUPERVISORY AUTHORITY] — Article 77

9Cookies

We use cookies and similar technologies to keep you signed in, remember preferences, and measure usage. You can manage non-essential cookies at any time. See our Cookies Policy for the full list and legal basis.

10Children

Travozen is intended for business and professional buyers and is not directed at children. Consistent with Article 8(1) of the GDPR, we do not knowingly process the data of anyone under 16, and we delete such data if we become aware of it.

11Security

We protect your data with encryption in transit (TLS), encryption at rest for sensitive fields, strict access controls on a need-to-know basis, and regular backups. No system is completely secure, but we work to keep your data safe.

12Breach Notification

If a personal data breach is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours of becoming aware of it (Article 33 of the GDPR). Where the breach is likely to result in a high risk to you, we will inform you without undue delay (Article 34).

13Changes to This Policy

We may update this policy from time to time. We will notify you by email of material changes; other updates take effect when posted with a revised date.

14Contact

For any privacy question or to exercise your rights, contact [LEGAL ENTITY NAME] at [PRIVACY / GRIEVANCE EMAIL], or our Data Protection / Grievance Officer at [DPO / GRIEVANCE OFFICER EMAIL], or write to us at [REGISTERED ADDRESS].

Questions about your privacy?

Contact our privacy team at [PRIVACY / GRIEVANCE EMAIL] or write to [LEGAL ENTITY NAME], [REGISTERED ADDRESS].

Cookie Notice

We use cookies to enhance your experience and analyze site traffic. You can choose to accept all cookies or only essential ones.

Cookies Policy