Setwala Setwala
Browse Collections Sell Designs ๐ŸŽช Venue Planner Login Get Started
Legal

Privacy Policy

Last updated: 21 June 2025  ยท  Your privacy matters to us.

This Privacy Policy explains how Setwala ("we", "our", "us") collects, uses, stores, shares, and protects your personal information when you use our platform. We comply with the Information Technology Act 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 ("SPDI Rules"), and applicable data protection principles. Please read this policy carefully.

Table of Contents

  1. Who We Are & How to Contact Us
  2. Information We Collect
  3. How We Use Your Information
  4. Legal Basis for Processing
  5. Cookies & Tracking Technologies
  6. Third-Party Services & Sharing
  7. Creator-Specific Data
  8. Children's Privacy
  9. Data Retention
  10. Security of Your Data
  11. Your Rights & Choices
  12. Cross-Border Data Transfers
  13. Changes to This Policy
  14. Grievance Officer

1. Who We Are & How to Contact Us

Setwala is a digital marketplace platform that enables creators to sell event industry digital assets to buyers worldwide. For data protection purposes, Setwala acts as the Data Controller for personal data you provide to us, and as a Data Processor for data processed on behalf of Creators in respect of their customers.

If you have any questions, concerns, or complaints about this Privacy Policy or our data practices, please contact our Grievance Officer as described in Section 14.

2. Information We Collect

2.1 Information You Provide Directly

CategoryExamplesWho Provides It
Account & Identity DataFull name, email address, password (hashed), profile photo, usernameAll Users
Contact DataEmail address, phone number (if provided)All Users
KYC & Financial DataPAN card number, bank account number, IFSC code, bank name, account holder name, UPI ID, GST numberCreators only
Payment DataTransaction IDs, payment method type, billing details processed by payment gatewayBuyers
Creator Content DataUploaded Digital Assets, product descriptions, tags, pricing, preview imagesCreators only
Communication DataSupport tickets, messages, feedback, dispute communicationsAll Users
Profile DataCreator bio, portfolio links, social media handles, creator profile descriptionCreators

2.2 Information We Collect Automatically

CategoryExamples
Usage & Activity DataPages visited, search queries, products viewed, downloads, purchase history, wishlist items, session duration
Device & Technical DataIP address, browser type and version, operating system, device identifiers, screen resolution, time zone
Log DataAccess logs, error logs, API request logs (retained for security and debugging)
Cookie & Tracking DataSession cookies, preference cookies, analytics identifiers (see Section 5)
Transaction DataOrder history, payout history, subscription history, UTR numbers

2.3 Sensitive Personal Data or Information (SPDI)

Under the SPDI Rules 2011, financial information such as bank account numbers, PAN numbers, and UPI IDs collected from Creators constitutes Sensitive Personal Data. We collect this data solely for the purpose of processing payouts and fulfilling tax compliance obligations. We implement heightened security measures for SPDI as described in Section 10.

We do not collect passwords in plain text. We do not collect biometric data, health information, sexual orientation, religious beliefs, or other SPDI categories not listed above.

2.4 Information from Third Parties

We may receive limited information about you from third-party service providers such as payment gateways (Razorpay), analytics providers (Google Analytics), and fraud detection services. We use this information only for the purposes described in Section 3.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Account Management: To create, maintain, and secure your account; to verify your identity and eligibility;
  • Marketplace Operations: To facilitate transactions between Creators and Buyers; to process payments and payouts; to manage subscriptions;
  • KYC & Compliance: To verify Creator identity and financial information; to deduct and remit TDS; to fulfil regulatory and legal obligations;
  • Platform Improvement: To analyse usage patterns, diagnose technical problems, and improve features, performance, and security;
  • Personalisation: To display relevant products, recommendations, and search results;
  • Communications: To send transactional emails (order confirmations, payout notifications, security alerts); to send marketing communications where you have opted in;
  • Safety & Fraud Prevention: To detect, investigate, and prevent fraud, chargebacks, abuse, and other prohibited conduct;
  • Legal Compliance: To comply with applicable laws including tax laws, court orders, and regulatory requests;
  • Dispute Resolution: To investigate and resolve disputes between Users or with Setwala;
  • Customer Support: To respond to your enquiries, complaints, and support requests.

We do not sell your personal data to third parties for their independent marketing purposes.

4. Legal Basis for Processing

Our legal basis for processing your personal information includes:

  • Contract Performance: Processing necessary to fulfil our obligations under our Terms & Conditions (account creation, transaction processing, payouts);
  • Legal Obligation: Processing required by Indian law (TDS deduction, KYC compliance, regulatory reporting);
  • Legitimate Interests: Processing for fraud prevention, security, Platform improvement, and analytics, balanced against your privacy rights;
  • Consent: For marketing communications and non-essential cookies โ€” you may withdraw consent at any time.

5. Cookies & Tracking Technologies

5.1 What We Use Cookies For

Setwala uses cookies and similar tracking technologies for the following purposes:

Cookie TypePurposeExamples
EssentialRequired for the Platform to function. Cannot be disabled.Session authentication, CSRF protection tokens, shopping cart, login state
FunctionalRemember your preferences to enhance experience.Language preference, display settings
AnalyticsUnderstand how Users interact with the Platform to improve it.Google Analytics (anonymised)
MarketingTrack campaign effectiveness and display relevant content. Requires consent.Google Tag Manager parameters
Third-Party ChatEnable live chat support functionality.Tawk.to session cookies

5.2 Managing Cookies

You can control or delete cookies through your browser settings. Disabling essential cookies will impair the Platform's functionality. For analytics and marketing cookies, you may opt out at any time. Opting out of Google Analytics is available at tools.google.com/dlpage/gaoptout.

5.3 Do Not Track

Some browsers transmit a "Do Not Track" signal. Setwala does not currently respond differently to Do Not Track signals. We are committed to implementing recognised privacy standards as they mature.

6. Third-Party Services & Sharing

6.1 When We Share Your Data

We do not sell your personal data. We share it only in the following circumstances:

  • Payment Processors (Razorpay): We share necessary transactional data with our payment gateway to process payments. Razorpay's privacy practices are governed by their own privacy policy. We do not share full card details โ€” these are processed directly by the gateway;
  • Analytics Providers (Google Analytics): We share anonymised, aggregated usage data with Google Analytics to understand Platform usage patterns;
  • Live Chat (Tawk.to): Your name and email may be shared with Tawk.to to pre-populate your support chat session;
  • Tax Authorities: We are required by law to report Creator earnings and remit TDS to Indian tax authorities (Income Tax Department, GST authorities);
  • Law Enforcement & Government Bodies: We will disclose data in response to valid legal process, court orders, regulatory requests, or when required to protect the safety of persons or property;
  • Business Transfers: In the event of a merger, acquisition, restructuring, or sale of Setwala's assets, your data may be transferred to the acquiring entity subject to equivalent data protection commitments;
  • Professional Advisors: We may share data with our legal, accounting, or auditing advisors under strict confidentiality obligations;
  • With Your Consent: For any other purpose, only with your explicit consent.

6.2 Creator Visibility

Creator profile information (name, profile photo, bio, portfolio) is publicly visible on the Platform. Financial data (bank account, PAN, UPI) is never displayed publicly and is accessible only to authorised Setwala personnel with a legitimate need.

6.3 Buyer Visibility to Creators

Creators receive anonymised order information. Buyers' full names and email addresses are not shared with Creators except where required for customer support, dispute resolution, or as required by law.

7. Creator-Specific Data Protections

We recognise that Creators entrust us with sensitive business and financial information. We take the following additional steps to protect Creator data:

  • Bank account details and PAN numbers are encrypted at rest and are never displayed in full within the admin interface;
  • Access to Creator financial data is restricted to a minimum number of authorised Setwala personnel;
  • All data access by Setwala staff is logged and audited;
  • Creator Digital Assets stored on our servers are protected against unauthorised access through access control and server-level security;
  • We do not use Creator Digital Assets for any purpose other than operating the Platform (hosting, delivery, marketing previews as authorised by the Creator);
  • KYC documents are stored securely and destroyed when no longer required by law.

8. Children's Privacy

Setwala is not directed at children under the age of 18 years. We do not knowingly collect personal information from anyone under 18. If we become aware that we have inadvertently collected information from a person under 18, we will promptly delete such information and terminate the account. If you believe a child has registered on our Platform, please contact us at privacy@setwala.com.

9. Data Retention

We retain your personal data for as long as necessary to fulfil the purposes described in this Policy, or as required by law. Our general retention periods are:

Data TypeRetention PeriodReason
Account & Profile DataDuration of account + 2 years after deletionDispute resolution, legal claims
Transaction & Financial Records7 years from transaction dateTax law compliance (Income Tax Act, GST law)
KYC Documents5 years after account closure or last transactionAML/regulatory requirements
Usage & Log Data12 monthsSecurity monitoring, debugging
Communication & Support Records3 yearsLegal disputes, quality assurance
Marketing Consent RecordsUntil consent withdrawn + 2 yearsProof of consent
Cookies (session)Session durationAuthentication
Cookies (analytics)Up to 2 yearsAnalytics

When your data is no longer required, we securely delete or anonymise it in accordance with our data retention and disposal procedures.

10. Security of Your Data

Setwala implements industry-standard and legally required technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction, including:

  • Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS (HTTPS). HTTP access is redirected to HTTPS.
  • Encryption at Rest: Sensitive personal data including KYC information and financial details are encrypted at rest on our servers.
  • Password Hashing: User passwords are hashed using strong cryptographic algorithms and are never stored in plain text.
  • CSRF Protection: All forms implement CSRF token protection to prevent cross-site request forgery attacks.
  • Access Controls: Internal access to personal data is restricted on a need-to-know basis and all access is logged.
  • Server Security: Our servers are protected by firewalls, intrusion detection systems, and regular security updates.
  • Security Headers: We implement HTTP security headers including Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, and others.
  • Regular Security Reviews: We periodically review and update our security practices.
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and relevant authorities as required by law.

11. Your Rights & Choices

Subject to applicable law, you have the following rights regarding your personal data:

  • Right of Access: You may request a copy of the personal data we hold about you;
  • Right to Correction: You may request correction of inaccurate or incomplete personal data. You can update most information yourself in your account settings;
  • Right to Erasure ("Right to be Forgotten"): You may request deletion of your personal data, subject to our legal obligations to retain certain data (e.g., financial records for tax compliance);
  • Right to Withdraw Consent: Where processing is based on your consent (e.g., marketing emails), you may withdraw consent at any time by clicking "unsubscribe" or contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal;
  • Right to Object to Marketing: You may opt out of marketing communications at any time;
  • Right to Data Portability: You may request a copy of your data in a commonly used, machine-readable format for transfer to another service where technically feasible;
  • Right to Lodge a Complaint: You have the right to lodge a complaint with the relevant data protection authority if you believe your privacy rights have been violated.

To exercise any of the above rights, please contact us at privacy@setwala.com. We will respond within 30 days of receiving your request. We may need to verify your identity before fulfilling your request.

11.1 Marketing Opt-Out

You can unsubscribe from marketing emails by clicking the "Unsubscribe" link in any marketing email. Note that even if you opt out of marketing communications, we will still send you essential transactional notifications (order confirmations, payout alerts, security notices).

12. Cross-Border Data Transfers

Your personal data may be processed and stored on servers located within India or in other countries where our third-party service providers operate (including servers operated by cloud infrastructure providers). Where data is transferred outside India, we take reasonable steps to ensure it is protected to a standard equivalent to Indian data protection requirements. By using the Platform, you consent to such transfers.

Our key third-party processors and their data locations include:

  • Razorpay: India-based payment processor;
  • Google Analytics: USA โ€” governed by Google's standard contractual clauses;
  • Tawk.to: International โ€” Tawk.to's own privacy commitments apply.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Platform features. We will notify you of material changes by: (a) posting the updated policy on this page with a new "Last Updated" date; and (b) sending an email notification to your registered email address. Your continued use of the Platform after the updated policy becomes effective constitutes your acceptance of the changes. We encourage you to review this Policy periodically.

14. Grievance Officer

In accordance with the Information Technology Act 2000 and the SPDI Rules 2011, we have appointed a Grievance Officer to address your privacy-related concerns:

Grievance Officer โ€” Setwala Marketplace
Email: grievance@setwala.com
Privacy Enquiries: privacy@setwala.com
General Support: support@setwala.com
Response Time: Within 30 days of receipt of complaint.

All privacy complaints will be acknowledged within 3 business days and resolved within 30 days of receipt, as required by applicable law. If you are not satisfied with our response, you may escalate your complaint to the relevant regulatory authority.

This Privacy Policy is effective as of 21 June 2025 and governs all personal data processed by Setwala. We are committed to protecting your privacy and processing your data lawfully, fairly, and transparently.