Skip to main content
Version 1.0Effective: 1 April 2026DPDP Act 2023 Compliant

Privacy Policy

This Privacy Policy explains how Original Collectors ("we", "us", "our") collects, processes, stores, and protects your personal data. We are committed to safeguarding your privacy in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and applicable rules thereunder.

Your rights at a glance: You have the right to access, correct, and erase your personal data. You may withdraw consent at any time. You may nominate a representative for your data rights. Contact us at privacy@originalcollectors.com.

1. Data Fiduciary — Who We Are

Original Collectors is the Data Fiduciary as defined under the Digital Personal Data Protection Act, 2023. We determine the purposes and means of processing your personal data. We are operated from India and our services are primarily directed at users in India, though accessible internationally.

Data Fiduciary

Original Collectors

Contact Email

privacy@originalcollectors.com

Grievance Officer

grievance@originalcollectors.com

Jurisdiction

India

2. Personal Data We Collect

2.1 Data You Provide Directly

Account RegistrationName, email address, password (hashed), username, display name
Profile InformationBio, avatar/photo, region, preferred currency, collector interests
KYC VerificationLegal name, city, phone number, government ID document (for high-value transactions)
Vault / Collection DataItem descriptions, photos, purchase price, estimated values, condition notes
Marketplace ListingsItem title, description, asking price, location, shipping preferences, payment channels you accept
Messages & PostsContent of direct messages, feed posts, community posts, and comments
Transaction RecordsAgreed price, payment channel chosen, shipping details, tracking ID, shipment proof photo
Support & GrievancesContent of communications with our support or moderation team

2.2 Data Collected Automatically

Device & BrowserIP address, browser type and version, operating system, device identifiers
Usage DataPages visited, features used, clicks, session duration, referral URL
Log DataServer logs including timestamps, error reports, API request logs
Cookies & Local StorageSession tokens, preference settings, feature flags (see Clause 8)

2.3 Data from Third Parties

OAuth ProvidersIf you sign in via Google or another OAuth provider: name, email, profile photo (only what you authorise)
Payment ProcessorsTransaction confirmation status from Razorpay/Stripe — we do not store card or banking details
AI ServicesResponses from OpenRouter AI (item descriptions, tags) — no personal data is sent to AI providers
Sensitive Personal Data: We collect government ID documents only as part of KYC verification for high-value transaction facilitation. These are stored with enhanced security controls and are not used for any other purpose. We do not collect biometric, financial account, or health data.

3. Purposes and Legal Basis for Processing

Under the DPDP Act 2023, we process your personal data for specified, legitimate purposes with your consent ("deemed consent" where the purpose is reasonably expected given the service context), or as required by law. The following table sets out our processing purposes:

PurposeData UsedLegal Basis
Account creation and authenticationEmail, password hash, usernameContract performance / Consent
Providing vault, marketplace, and community featuresAll profile and content dataContract performance
KYC verification for transaction facilitationLegal name, phone, government IDLegal obligation / Consent
Sending transactional notifications (OTPs, alerts)Email, phone numberContract performance
Improving Platform features via usage analyticsUsage data (anonymised/aggregated)Legitimate interest
AI-powered description and taggingItem metadata (no personal identifiers)Consent (opt-in feature)
Fraud prevention and safety enforcementAccount activity, IP, reportsLegitimate interest / Legal obligation
Responding to legal requests from authoritiesAs specified in requestLegal obligation
Subscription billingEmail, transaction confirmation statusContract performance
Marketing communications (opt-in only)Email, notification preferencesConsent

4. Data Sharing and Disclosure

4.1 With Other Users (Necessary for Service)

Your public profile (display name, username, avatar, collector tier) is visible to other Platform users. Your vault items and posts are visible as per your own privacy settings. Transaction counterparties can see the information you provide in a transaction record.

4.2 With Service Providers (Data Processors)

SupabaseCloud database and authentication. Data stored on Supabase's infrastructure (AWS us-east-1).
Cloudflare R2Media file storage for vault images and user avatars. Data stored on Cloudflare's infrastructure.
RazorpayPayment gateway for INR subscription billing. Processes subscription confirmation only.
StripePayment gateway for international subscriptions. Processes subscription confirmation only.
OpenRouter / Mistral AIAI text generation for item descriptions and tagging. No personal data is included in AI prompts (per our design).
Email Service ProviderTransactional emails (OTPs, notifications). Receives your email address only.

All service providers are contractually bound to process data only on our instructions, maintain appropriate security, and not use your data for their own purposes.

4.3 Legal Disclosures

We may disclose your personal data to government authorities, law enforcement, or courts when required by law, court order, or to protect the rights and safety of our users or the public. We will notify you of such disclosures where legally permitted to do so.

4.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity. You will be notified at least 30 days before any such transfer, with the right to delete your account before the transfer takes effect.

4.5 No Sale of Personal Data

We do not sell, rent, or trade your personal data to any third party for their own commercial purposes.

5. Cross-Border Data Transfers

Our primary infrastructure (Supabase and Cloudflare R2) may store data on servers outside India. Where your data is transferred outside India, we ensure adequate protections are in place in compliance with Section 16 of the DPDP Act 2023, including contractual safeguards with our data processors. We will update this clause as the Central Government notifies permitted countries under the DPDP Act.

We will not transfer your personal data to jurisdictions specifically notified as restricted under the DPDP Act 2023 once such notifications are issued by the Central Government.

6. Data Retention

Active account dataRetained for the lifetime of your account
Deleted account data (profile, personal details)Purged within 30 days of account deletion request
Community and feed posts (public)Anonymised on account deletion (author replaced with 'Deleted User') to preserve community integrity
Transaction recordsRetained for 7 years as required for financial record-keeping under Indian law
KYC documentsRetained for 5 years post-transaction completion, then securely deleted
Server logsRetained for 90 days, then deleted
Moderation and ban recordsRetained for 3 years for safety and legal purposes
Backup copiesRetained for up to 60 days after the primary data is deleted

7. Your Rights Under the DPDP Act 2023

As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the following rights:

Right to Access

Request a summary of the personal data we hold about you and the purposes for which it is processed.

Right to Correction and Erasure

Request correction of inaccurate or incomplete data, or deletion of data that is no longer necessary for the original purpose. Note: certain data may be retained as required by law.

Right to Grievance Redressal

Lodge a grievance with our Grievance Officer. If unsatisfied with our response, you may approach the Data Protection Board of India (once constituted).

Right to Nominate

Nominate another individual to exercise your data rights in the event of your death or incapacity.

Right to Withdraw Consent

Withdraw consent for processing based on consent at any time. Withdrawal does not affect processing already carried out. Some services may not be available after withdrawal.

To exercise any of these rights, contact us at privacy@originalcollectors.com. We will respond within 30 days. Identity verification may be required before we fulfil your request.

8. Cookies and Tracking Technologies

8.1 What We Use

Session CookiesEssential — keep you logged in during your session. Cannot be disabled without logging out.
Preference CookiesStore your theme (dark/light), language, and notification settings.
Analytics (Internal)Anonymised usage data collected via our own server logs — no third-party analytics scripts are loaded.

8.2 What We Do Not Use

We do not use third-party advertising trackers, cross-site tracking pixels, or behavioural profiling technologies. We do not sell data to advertising networks.

8.3 Managing Cookies

You may control cookies through your browser settings. Disabling essential cookies will prevent you from using authenticated features. For preference cookies, use the settings panel within the app.

9. Data Security

We implement industry-standard technical and organisational measures to protect your personal data:

  • All data in transit is encrypted using TLS 1.2 or higher
  • Passwords are hashed using bcrypt; we never store plaintext passwords
  • API access is authenticated via short-lived JWTs; admin access requires additional 2FA
  • KYC documents are stored in isolated storage buckets with restricted access
  • Admin actions are logged immutably in a moderation audit trail
  • Access to production data is restricted to authorised personnel on a need-to-know basis
  • We perform regular security reviews and dependency audits

9.1 Data Breach Notification

In the event of a personal data breach that is likely to result in harm to you, we will notify the Data Protection Board of India and affected users as required under the DPDP Act 2023. Notifications will be sent to your registered email address within the statutory timeframe.

10. Children's Privacy

The Platform is not directed at children under 13 years of age. We do not knowingly collect personal data from children under 13 without verifiable parental consent. If we become aware that we have collected personal data from a child under 13 without such consent, we will take steps to delete it promptly.

For users between 13 and 18, parental consent is required. Parents or guardians may contact us at privacy@originalcollectors.com to review, modify, or request deletion of their child's data.

11. Grievance Officer (India — IT Rules 2021 & DPDP Act 2023)

In accordance with Rule 4 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the Digital Personal Data Protection Act, 2023, we have appointed a Grievance Officer for India:

Designation

Grievance Officer

Organisation

Original Collectors

Email

grievance@originalcollectors.com

Acknowledgement Timeline

Within 24 hours of receipt

Resolution Timeline

Within 15 days of receipt

Escalation

Data Protection Board of India (once constituted)

If your grievance is not resolved to your satisfaction within 15 days, you may escalate to the Data Protection Board of India (once the Board is constituted and notified under the DPDP Act 2023).

12. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in law, our practices, or the services we offer. Material changes will be notified via in-app notification and email at least 14 days before the effective date. The version number and effective date at the top of this document will be updated accordingly.

We maintain an archive of previous policy versions. If you would like a copy of a previous version, contact us at privacy@originalcollectors.com.

13. Contact Us

Document version 1.0 · Effective 1 April 2026

Prepared in compliance with: DPDP Act 2023 · IT Act 2000 · IT (Intermediary Guidelines) Rules 2021

Terms of ServiceCommunity Guidelines

© 2026 Original Collectors. All rights reserved. Operated from India.