Part 1
General
Applies to everyone: visitors to this website, shoppers using the Xamip app, and shop owners using the Xamip Business app.
Who we are
Xamip™ is a brand of Wholesphere Ventures LLP, a limited liability partnership registered in India (LLPIN ADA-0037), with its registered office at C/O Naresh Kumar Mali, Kalkaji Talab Road, Sirohi Bhatkra, Kotwali Sirohi, Sirohi - 307001, Rajasthan, India.
Under the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) we are the Data Fiduciary for the personal data described here. You are the Data Principal. The companies listed under who we share data with act as our Data Processors, on our instructions.
We follow the DPDP Act, the Information Technology Act, 2000 and the rules made under it, including the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
What this policy covers
This policy applies to three things:
- This website, xamip.com, including the waitlist form.
- Xamip, the app for shoppers.
- Xamip Business, the app for shop owners and their staff.
Read Part 1 whichever one you use. Then read Part 2 if you are a shopper, or Part 3 if you run a shop.
The apps are not yet publicly released. This policy describes what they do today and applies from the moment you use them.
Data we collect from everyone
Data collected in both apps
- Name, email address, phone number, password
- Creating your account and signing you in. Passwords are stored in hashed form, never in plain text.
- Profile photograph
- Optional. Shown on your own account.
- Device push token and platform (Android or iOS)
- Delivering notifications you have asked for.
- App version, install and app-open events
- Telling you when an update is needed, and basic usage counts.
- In-app activity: screens viewed, shops and offers viewed, searches, category filters, follows and unfollows, time spent
- Understanding what people find useful and improving the product.
- Approximate area (state and city) derived from your location
- Regional relevance, and targeting featured placement bought by shops.
On this website, we collect what you type into the waitlist form - your name, email address, phone number, whether you are joining as a shopper or a shop owner, and your answers to the feature questions - plus the website analytics described under cookies, analytics and tracking.
How we use it
- To create and run your account, and to sign you in securely.
- To show you shops and offers, and to run the features you ask for.
- To send you the notifications and emails you have chosen to receive, and messages we must send about your account, such as verification codes.
- To verify the identity of shop owners before a shop goes live.
- To investigate reports, prevent misuse and keep the platform safe.
- To understand which parts of the product are used, so we can improve them.
- To answer you when you contact us.
- To meet legal obligations and to respond to lawful requests from authorities.
We do not sell your personal data. We do not run advertising on the platform.
Consent and how to withdraw it
We ask for your consent in two ways. Your device asks you directly before the app may use your location or send you notifications - you can say no, and you can change your answer later. For everything else described in this policy, creating an account and continuing to use the service after being given this notice is how consent is given.
We want to be straightforward about a limitation: the apps do not yet keep an itemised, per-purpose record of consent, and there is no separate in-app switch for withdrawing consent to processing other than location and notifications. We are building that. Until it exists, this is how you withdraw consent:
- Turn off the location or notification permission for the app in your device settings. This takes effect immediately.
- Delete your account from within the app. This withdraws consent for everything and starts the deletion process described below.
- Write to the Grievance Officer and tell us what you want stopped. We will action it manually and confirm to you.
Withdrawing consent has consequences. Without location permission the shopper app cannot show you what is nearby, cannot confirm a visit, and its main features stop working. Withdrawing consent does not undo processing we have already lawfully carried out before you withdrew it.
Who we share data with
We share personal data only with the service providers we need to run the platform. They act on our instructions as Data Processors and are not permitted to use your data for their own purposes.
Third parties who process data for us
- Google Firebase Cloud Messaging
- Device push token and notification content, to deliver notifications on Android.
- Apple Push Notification service
- Device push token and notification content, to deliver notifications on iOS.
- Twilio
- Your phone number, to send one-time verification codes.
- Sandbox (api.sandbox.co.in)
- GSTIN and PAN of shop owners, to verify business registration.
- Google Cloud Storage
- Photographs and documents you upload, for storage.
- Google Maps Platform
- Coordinates, to turn them into addresses and area names, and to show maps.
- Our email (SMTP) provider
- Your email address and the content of the message, to send verification codes and account emails.
- Web3Forms
- Waitlist form submissions from this website only.
- Google Analytics
- Website usage, cookie identifiers and IP address, to measure traffic on this website only.
We also disclose data where the law requires it - to a court, a regulator, or a law enforcement agency acting under lawful authority - and where it is necessary to establish or defend a legal claim. If the business is ever transferred, personal data may transfer with it, and this policy will continue to apply until you are told otherwise.
Where data is stored
Your data is held on cloud infrastructure operated by established providers, and we prefer data centres located in India wherever the service allows it. Some of the processors listed above operate globally, so some processing may take place outside India. Where that happens, it is subject to contractual safeguards with the provider and to applicable Indian law, including any restrictions notified by the Government under the DPDP Act.
We are not going to claim more than that. As of the date of this policy the platform is not yet in public operation, and we will update this section with specifics once the production deployment is fixed.
How we protect data
- Data sent between your device and our systems is encrypted in transit using TLS.
- Passwords are stored as salted hashes. We cannot read your password.
- Identity documents and verification photographs are stored separately from your public listing and are reachable only by authorised personnel who need them to complete a verification.
- Access to production systems is restricted and requires authentication.
- Deleting your account requires you to re-authenticate - your password plus a one-time code - so that nobody else can delete it for you.
No system is completely secure. We cannot guarantee that data will never be compromised, and we do not ask you to rely on such a guarantee. If a personal data breach occurs, we will notify the Data Protection Board of India and affected users as required by the DPDP Act.
Retention, deletion and what happens to your reviews
We keep personal data for as long as your account exists, and afterwards only for as long as we need it for the purposes in this policy or for a period required by law.
You can delete your account yourself, from account settings in either app. You will be asked to confirm your identity first. When you delete your account:
- Your registered devices and pending notifications are removed straight away, and the account can no longer be used to sign in.
- Your account record is marked as deleted and then permanently deleted after 90 days. The 90-day window exists so that an account deleted by mistake or by someone else can be recovered, and so we can meet legal and audit obligations.
- Records we are required by law to retain - for example records relating to a payment or a legal claim - are kept for the period the law requires, and no longer.
Your reviews stay published
Your rights as a Data Principal
Under the DPDP Act you have the following rights.
- Right to access
- A summary of the personal data we hold about you, how we are processing it, and the identities of the processors we have shared it with.
- Right to correction and completion
- Have inaccurate or misleading data corrected, incomplete data completed, and outdated data updated. Most of this you can do yourself in the app.
- Right to erasure
- Ask us to erase your personal data where it is no longer needed for the purpose it was collected for. Deleting your account is the direct route.
- Right to grievance redressal
- Complain to us first, through the Grievance Officer below. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
- Right to nominate
- Nominate another person to exercise these rights on your behalf if you die or become incapable of exercising them yourself. There is no in-app form for this yet - write to the Grievance Officer with the nominee's name and contact details and we will record it against your account.
- Right to withdraw consent
- Described under consent above, along with what stops working if you do.
To exercise a right, write to the Grievance Officer from the email address or phone number on your account. We may need to confirm it is really you before we act, particularly for erasure. We will not charge you for this.
You also have duties under the DPDP Act: do not impersonate someone else, do not suppress material information when giving us data that must be verified, and do not file false or frivolous complaints.
Age requirement
Both apps are for people aged 18 or over. The service is not offered to anyone who is “incompetent to contract” within the meaning of the Indian Contract Act, 1872, which includes minors.
We set the line at 18 deliberately. The shopper app processes precise location, infers physical visits, and records in-app behaviour. Under the DPDP Act anyone under 18 is a child, and tracking and behavioural monitoring of children is not permitted. We would rather not offer the service to under-18s than do that.
We do not knowingly collect personal data from anyone under 18. If we learn that an account belongs to a minor, we will terminate it and delete the data. If you believe a minor has given us data, tell the Grievance Officer and we will act.
Changes to this policy
We will update this policy when what we do changes, or when the law changes. The “last updated” date at the top always reflects the current version. If a change materially affects how we use your personal data, we will tell you in the app or by email before it takes effect, rather than relying on you noticing this page.
Grievance Officer
In accordance with the DPDP Act and Rule 3(2)(a) of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the following officer handles privacy questions, requests to exercise your rights, and complaints.
Grievance Officer
Manikant Singh
Designated Partner & Grievance Officer
Wholesphere Ventures LLP
C/O Naresh Kumar Mali, Kalkaji Talab Road, Sirohi Bhatkra,
Kotwali Sirohi, Sirohi - 307001, Rajasthan, India
We acknowledge a grievance within 24 hours of receiving it, aim to resolve it within 15 days, and will resolve it within 30 days in any event. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India.
Part 2
For Shoppers
Additional disclosures for the Xamip app. Read this together with Part 1.
Precise location
Read this one properly
We use your location to show you shops and offers near where you actually are, to sort results by distance, to apply the search radius you have chosen, and to work out the state and city you are in so we can show regionally relevant content.
Your device asks for location permission before the app can use it. You can refuse, and you can revoke it at any time in your device settings. If you do, the app cannot show you what is nearby - that is the core of what it does. You can still drop a pin on the map to browse a different area manually.
Your live location is never shown to shops or to other shoppers.
Visit detection
The most sensitive thing we do
We do this for one reason: so that only people who genuinely went to a shop can review it. Roughly two hours after a detected visit the app asks you to confirm whether you visited. Only then can you write a review. This is what makes Xamip reviews mean something, and it is not possible without inferring visits.
What this means in practice, stated plainly:
- We hold a history of shops you have been detected at, with timestamps.
- We use it to gate reviews, to prevent review fraud, and to investigate reports about fake reviews.
- We do not publish your visit history. Shops are not told who visited or when. Other shoppers cannot see it.
- We do not sell it, and we do not use it for advertising.
- If you turn off location permission, visit detection stops and you will not be able to write new reviews.
- Deleting your account deletes your visit history along with the rest of your account data, on the timetable described above. Reviews you already published remain, as explained above.
Preferences and follows
We store the preferences you set - your search distance, your minimum discount, and the categories you are interested in - and use them to filter your feed. We store the shops you follow and which of them you have allowed to notify you, and use that to decide what alerts to send. You can change all of this in the app at any time.
Reviews, ratings and reports
Reviews are public. Your rating, your written review, the tags you pick and your display name and profile photograph appear on the shop’s page, where anyone using the app can read them. Do not put anything in a review that you do not want to be public.
If you report a shop or a listing, we keep your report and the account it came from so we can investigate. We do not show the shop who reported them. We may share the substance of a report with the shop in order to get their side of it.
Reviews survive account deletion, re-attributed to “Deleted Account”. This is set out in full under retention and deletion.
Your choices in the app
- Browse without an account. You can look around before signing up.
- Turn location permission off. Discovery and visit detection stop.
- Turn notifications off, entirely or per shop.
- Edit your profile, and change your phone number or email with a one-time code.
- Delete your account yourself, from account settings.
Part 3
For Businesses
Additional disclosures for the Xamip Business app. Read this together with Part 1.
Account details
We collect your name, email address, phone number and password to create your owner account, and verify your phone number with a one-time code.
Verification with PAN and GST
Before a shop goes live we verify who is behind it. If you have business registration, we collect:
Documented verification route
- PAN number, the name as printed on the PAN, date of birth, and a photograph of the PAN card
- Statutory identity verification of the person responsible for the shop.
- GSTIN and trade name
- Confirming the business is registered and that the trade name matches.
PAN and GSTIN are checked against official records through our verification provider, Sandbox (api.sandbox.co.in). Your PAN number and your date of birth are never shown on your public shop listing.
Assisted verification
Most small shops in India have no GST registration and no business paperwork. Rather than exclude them, we offer a second route, where a member of our team verifies you in person or over a call. On this route we collect:
Assisted verification route
- Aadhaar number
- Identity verification. See the section below, which applies specifically to Aadhaar.
- Voter ID (optional)
- An additional identity check where you choose to give it.
- A photograph of you
- Confirming the person on the ID is the person applying.
- A photograph of the shop
- Confirming the shop exists at the location given.
- A photograph of you at your shop
- Connecting the verified person to the verified shop.
- A signed declaration document
- Your written statement that you run this shop and that the details you have given are true.
These documents are reviewed by a person on our team. They are stored separately from your public listing and are used only to decide whether to approve the shop, to re-check it if something is disputed, and to respond to a lawful request from an authority.
How we handle Aadhaar
Aadhaar
Aadhaar numbers are treated as sensitive personal information under the IT Rules, 2011 and are subject to the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016. We handle them accordingly: restricted access, no publication, and deletion along with the rest of your account data when you delete your account, except where we are required to retain a verification record by law.
Your public shop listing
The following is published and visible to anyone using the app: your shop name, category, description, contact number, website, address, shop photographs, your offers with their discounts, terms, dates and images, your opening status, and the ratings and reviews shoppers leave for you.
You control this content and you can edit or remove it in the app. Anything you publish is public. Do not put personal information in a listing that you would not want strangers to have.
Shop location and movable shops
We store your shop’s exact coordinates so that shoppers nearby can find you and get directions. These coordinates are public - that is the point of the listing.
If you mark your shop as movable, because you trade from a cart, stall or vehicle, the app updates your trading location as you move it. That location is public while your shop is open. Turn your shop to closed and it leaves discovery.
Staff accounts
If you give a staff member their own login, we collect their name, email address and phone number to create their account. You are responsible for telling them their data is being given to us and what it is used for. Staff accounts have limited permissions and cannot see verification documents.
Spotlight and website enquiries
If you enquire about Spotlight placement or ask us to build you a website, we keep your enquiry, your contact phone number and the commercial notes from our conversation, so we can respond and manage the arrangement. There is no payment gateway in the app and we do not hold card or bank details from you. Any payment is made directly to our bank account, against an invoice.
