Epomart Privacy Policy
For our Product Marketplace and On-Demand Service Marketplace.
1. Introduction
Epomart Technologies Private Limited (“Epomart”, “we”, “us”, “our”) operates a marketplace platform (website and mobile applications) that connects:
- Users with independent third-party Sellers for the purchase of Products; and
- Users with independent third-party Service Providers for booking on-demand and scheduled Services such as electrician work, home/room cleaning, home decoration, and other approved categories.
This Privacy Policy explains what personal data we collect from Users, Sellers, and Service Providers, why we collect it, how it is used and shared, and the choices and rights available to you.
2. Who This Policy Applies To
This Policy applies to all participants within the Epomart ecosystem:
- Users / Customers: Individuals who browse, search, purchase physical products, or book in-person and on-demand services through the Platform.
- Sellers: Independent merchant partners who list, promote, and sell goods on the Platform.
- Service Providers: Independent skilled professionals and agencies who list, accept bookings for, and perform on-demand services (e.g., technicians, cleaning personnel, home stylists).
Each category may have specific data practices tailored to their marketplace role, detailed throughout this policy.
3. Information We Collect
3.1 Information You Provide
- Account details: Name, mobile phone number, email address, password, and optional profile photograph.
- Address details: Shipping and delivery addresses for product orders, and residential or office premise addresses for service provider visits.
- Payment information: UPI ID, tokenized debit/credit card credentials (via RBI-authorized payment gateways — we never store raw 16-digit card numbers or CVV codes), and bank account / IFSC details for Seller and Service Provider payouts.
- KYC / Verification documents: Government identity proof, PAN, GSTIN, and business registration for Sellers; government ID, address proof, police verification / background-check consent, and trade certifications for Service Providers.
- Transaction history: Invoices, orders placed, service appointments booked, and payment transaction IDs.
- Communications: Messages exchanged via in-app chat with Sellers/Service Providers, customer care tickets, and support call recordings (with prior notice) for quality and safety.
- Feedback & Reviews: Ratings, photographs, and written reviews submitted regarding products or services.
3.2 Information Collected Automatically
- Device Information: Device model, OS version, unique hardware identifiers, IP address, and browser characteristics.
- Location Data: Precise or approximate GPS coordinates. Location is utilized for discovering nearby merchants and technicians, estimating delivery times, preventing fraud, and enabling live en-route tracking of service providers.
- Usage Logs: Search queries, page views, browsing durations, click patterns, and crash diagnostics.
3.3 Information from Third Parties
We may receive background verification and credential checks from accredited screening agencies (for service professionals), transaction status confirmations from banking partners, and package transit updates from integrated courier networks.
4. How We Use Your Information
We process personal information for lawful and legitimate purposes:
- To create, authenticate, and maintain user, seller, and service provider profiles.
- To fulfill product purchases, schedule service appointments, and generate GST-compliant tax invoices.
- To enable mutual real-time location sharing during an active booking window so customers can track incoming technicians and technicians can navigate to the premise.
- To conduct identity and criminal background verifications to safeguard community trust and premise safety.
- To resolve support escalations, disputes, warranty queries, and grievance tickets.
- To deliver transactional SMS, WhatsApp, push notifications, and OTP alerts.
- To detect, investigate, and prevent payment fraud, bot attacks, and terms violations.
- To adhere to legal obligations under Indian tax, corporate, and intermediary statutes.
6. Data Retention
We retain personal information for the period your account remains active and as required to deliver marketplace services, settle financial accounts, resolve consumer grievances, and satisfy statutory tax and commercial record retention mandates (typically 7 to 8 years for financial books under Indian law).
KYC and background documentation for partners are maintained throughout their tenure on the Platform and for a reasonable statutory period following deactivation.
7. Your Rights and Choices
Under applicable privacy laws, notably the Digital Personal Data Protection Act, 2023, you hold the following rights:
To exercise any of these rights, submit a written request to privacy@epomart.in.
9. Location Data — Special Note for Home Services
Because categories such as electrical work, deep cleaning, and appliance repair require home visits, exact customer addresses and live GPS coordinates are shared with assigned technicians only during the active booking window.
We require all customers to inspect the in-app digital verification badge of the visiting professional before granting entry. Users can report any security or behavioral discrepancy 24/7 through our customer helpline or emergency SOS support.
10. Data Security
We enforce comprehensive technical, administrative, and physical measures in conformity with Rule 8 of the Information Technology (SPDI) Rules, 2011. These include 256-bit SSL/TLS transmission encryption, secure tokenization of payment credentials, role-based database access, and continuous intrusion monitoring.
11. Children’s Privacy
Epomart does not knowingly solicit or collect personal information from individuals under 18 years of age. If a parent or guardian becomes aware that a minor has submitted personal information without supervision, contact us immediately for prompt deletion.
12. Grievance Officer / Data Protection Contact
In compliance with the Information Technology Act, 2000 and the DPDP Act, 2023, the contact details of the designated Grievance Redressal Officer are as follows:
13. International Data Transfers
Our core database servers reside within the territory of India. Where specific cloud infrastructure partners utilize distributed global content networks, we ensure appropriate data transfer safeguards and contractual clauses conform to DPDP Act specifications.
14. Changes to This Policy
We may periodically amend this Privacy Policy to reflect technical revisions or legislative developments. Material amendments will be highlighted through website banner notices, in-app updates, or direct email communication. The “Effective Date” at the top indicates when the latest edition entered into force.
15. Contact Us
For questions, data requests, or privacy concerns, please contact our team:

