This notice is maintained by Dhandacheck ("we", "us", "Dhandacheck") to describe how personal data is handled on this platform, in line with India's Digital Personal Data Protection Act, 2023 (DPDP Act).

Last updated: 7 August 2026

Privacy Notice

1. Who is the Data Fiduciary

Under the DPDP Act, Dhandacheck is the Data Fiduciary responsible for personal data processed through Dhandacheck. Registered address: A-1060, First Floor, City Centre 2, Ahmedabad, Gujarat, India – 380009. General contact: help@dhandacheck.com.

2. What we collect and why

We collect only what we need to run the service. Each category below has a specific, itemised purpose — we do not re-use data for unrelated purposes without asking you again.

DataPurposeLegal basis (DPDP)
Email addressAccount creation, login, security alerts, grievance repliesConsent + Contract
GSTINVerifying you represent a real business before you can post red flagsConsent
PANIdentity verification for reading and voting on red flagsConsent
Red flags, comments, repliesPublishing your report on the reported business's pageConsent + Legitimate use (public information)
Wallet balance & unlock activityRunning the paid identity-reveal featureContract
Razorpay payment metadata (order ID, status)Processing top-ups; card / UPI details are held by Razorpay, not usContract + Legal obligation (tax)
IP address, device / browser info, logsFraud prevention, rate-limiting, debugging, legal complianceLegitimate use

3. Sharing reporter identity with business owners

When you post a red flag, your identity (name on PAN / GSTIN and email) is not public. It is revealed only in two situations, both disclosed here so your consent is informed:

  • A third-party viewer pays the unlock fee (₹30/reporter). Revenue is shared with you as the reporter.
  • A verified owner of the reported business (GSTIN-matched to the business page) views their own page — they see reporter identities for free, so they can respond to or contest the claim.

By submitting a red flag you consent to this disclosure model. If you do not consent, do not post.

4. Who else we share data with (Data Processors)

  • Hosting & database: Lovable Cloud infrastructure — stores account, content, and logs.
  • Email / OTP provider: to send verification codes and grievance replies.
  • Razorpay: payment processing for wallet top-ups and unlocks.
  • Analytics & error monitoring: aggregated usage and crash reports, no ad tracking.

We do not sell personal data. We do not share it with advertisers or data brokers. We may disclose data when required by an Indian court order, government notice under the IT Act / DPDP Act, or a valid legal process — logged in our grievance register.

5. How long we keep data

  • Account (email, PAN / GSTIN verification records): as long as the account is active, plus 180 days after deletion for fraud / dispute audit.
  • Red flags, comments, replies: retained on the platform until you delete them or a grievance / court order requires removal. Deleted content is soft-deleted for 30 days then purged.
  • Payment records / invoices: 8 years, as required by Indian tax and accounting law.
  • Server & security logs: up to 90 days.

6. Your rights under the DPDP Act

As a Data Principal you have the right to:

  • Access a summary of the personal data we hold about you.
  • Correct or update inaccurate data.
  • Erase your data, subject to legal retention limits above.
  • Withdraw consent at any time (this may end your ability to use certain features).
  • Nominate another person to exercise these rights in the event of your death or incapacity.
  • File a grievance with us and, if unresolved, with the Data Protection Board of India.

To exercise any right, email ak@dhandacheck.com from your registered email. We respond within 30 days.

7. Consent and withdrawal

We ask for specific consent at the point of collection — separately for identity verification (PAN / GSTIN), for posting red flags (which includes the indemnity acknowledgement), for wallet top-ups, and for the identity-reveal model in Section 3. You can withdraw consent by writing to ak@dhandacheck.com; withdrawal is not retroactive to processing already carried out lawfully.

8. Cookies and analytics

We use strictly necessary cookies for login and session management. We use privacy-preserving analytics that do not build cross-site advertising profiles. We do not use third-party ad trackers.

9. Security

Data is transmitted over TLS, stored on managed infrastructure with row-level access controls, and admin access is restricted to named personnel. No system is fully secure — use a strong password and enable account recovery on your email.

10. Children

Dhandacheck is not intended for users under 18. We do not knowingly collect data from minors. If you believe a minor has provided data, email ak@dhandacheck.com and we will delete it.

11. Cross-border transfers

Data is processed in India and, where our infrastructure providers operate globally, in other jurisdictions permitted under the DPDP Act. We do not transfer data to jurisdictions restricted by the Central Government.

12. Changes to this notice

Material changes will be notified to registered users by email at least 14 days before they take effect. The current version is always at this URL with a "Last updated" date.

13. Contacts

  • Data Protection contact (DPDP rights): Aniket Golecha — ak@dhandacheck.com
  • Grievance Officer (IT Rules 2021 — takedowns, unlawful content): Aniket Golecha — grievance@dhandacheck.com
  • General support: help@dhandacheck.com
  • Registered address: A-1060, First Floor, City Centre 2, Ahmedabad, Gujarat, India – 380009