Privacy Policy
Last updated 12 August 2026
This Privacy Policy describes how Big Market 360 Private Limited, F211, Express Zone Commercial Hub, B wing, Malad East, Mumbai-400063, India. ("we", "us") collects, uses, and protects personal data through the Trade Mongo website and platform (the "Service"). This policy is intended to be consistent with the Digital Personal Data Protection Act, 2023 (DPDP Act) and its supporting rules.
1. Data we collect
- Account data: name, email, phone number, business name, GSTIN, PAN, business address, role (buyer / supplier), password (stored hashed).
- Profile and content data: product listings, images, RFQs, quotes, messages you send through the Service.
- Verification documents: GST certificate, PAN card, incorporation documents, address proof, authorisation letters.
- Transactional metadata: the RFQs you view or respond to, the suppliers you shortlist, quotes exchanged.
- Device and usage data: IP address, browser type, pages visited, referrer, approximate location derived from IP, cookies (see section 8).
- Communications: support tickets, grievance escalations, and any correspondence with our team.
2. Why we process it
- To provide, operate, and improve the Service.
- To verify supplier identity and business status against government registries.
- To match Buyers and Suppliers and surface relevant listings.
- To detect and prevent fraud, abuse, and security incidents.
- To comply with legal obligations, including tax, KYC, and regulatory reporting.
- To communicate with you about the Service, and — with your consent — to send marketing.
3. Legal basis (DPDP Act)
We process personal data on the basis of your consent, on the basis of it being necessary to perform a contract with you (the Service), and on the basis of legitimate uses expressly permitted by the DPDP Act (such as fraud prevention and legal compliance).
4. Sharing
We do not sell personal data. We share it only:
- with verification partners and government portals we query to verify GSTIN / PAN;
- with service providers who host our infrastructure, send our emails, or process payments — bound by written data-processing terms;
- with counterparty Users as reasonably needed for a transaction (a Buyer's business name and city are shared with a Supplier when the Buyer sends an RFQ, and vice versa);
- with law enforcement or regulators where compelled by valid legal process, or as necessary to protect the rights, safety, or property of the Company, Users, or the public.
5. Retention
We retain personal data for as long as your account is active and for a further period as required by applicable law (typically 8 years for tax records under Indian law). Verification documents are retained for 7 years after account closure. You may request earlier deletion; where we can honour that request without breaching legal obligations, we will.
6. Your rights
Under the DPDP Act you have the right to:
- access and receive a summary of the personal data we hold about you;
- correct inaccurate or misleading data;
- erase data we no longer need to hold;
- withdraw consent where processing is consent-based;
- nominate an individual to exercise these rights on your behalf in the event of death or incapacity;
- file a grievance with our grievance officer (see section 10) and, if unresolved, escalate to the Data Protection Board of India.
To exercise these rights, email [email protected] from the email address associated with your account.
7. Cross-border transfers
Where personal data is processed outside India by a hosting or infrastructure provider, we ensure equivalent safeguards through contractual data-processing terms and, where applicable, take steps consistent with any restrictions notified by the Central Government under the DPDP Act.
8. Cookies and similar technologies
We use cookies and similar technologies for authentication, security, preferences (language, saved location), and analytics. Essential cookies cannot be disabled. Analytics cookies are only set with your consent where applicable.
9. Security
We use encryption in transit (TLS), at-rest encryption for secrets (AES-256-GCM), password hashing with scrypt, rate limiting, and audit logging. No system is perfectly secure, and we do not warrant that a breach will never occur.
10. Grievance officer
Grievance officer: designated in accordance with the DPDP Act and IT Rules 2021. Email: [email protected] Postal address: Grievance Officer, Big Market 360 Private Limited, F211, Express Zone Commercial Hub, B wing, Malad East, Mumbai-400063, India
We acknowledge grievances within 48 hours and aim to resolve them within 15 days.
11. Changes to this policy
We may update this policy from time to time. Material changes will be notified through the Service or by email at least 15 days before they take effect. The version and effective date at the top of this page always reflect the currently binding text.