Trade Rede is operated by Snyte Private Limited

Privacy Notice

Version 1.0 · Last updated 12 August 2026

DPDP Act 2023

Trade Rede is the Data Fiduciary for the personal data described here. You are the Data Principal. This notice explains what we collect, why we collect it, how long we keep it, who we share it with, and how you can access, correct, erase or restrict it. It is written to meet the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025.

You can manage every consent and exercise your rights from Account settings → Privacy.

1. Personal data we collect and why

Data itemPurpose of processing
Full nameTo identify you on your account, quotations, orders and invoices.
Email addressTo sign you in, send order updates and answer your requests.
Phone numberTo send delivery OTPs and let our team reach you about an order.
Business name and business typeTo show your business to counterparties and to issue correct tax documents.
Employee count and year of establishmentTo display business scale on your public supplier profile.
Registered and delivery addressTo determine place of supply for GST and to deliver goods.
GSTINFor tax compliance, place-of-supply calculation and invoice generation.
PANFor statutory verification of your business identity.
KYC documents (GST certificate, PAN card, address proof, Aadhaar, licences)To verify that buyers, suppliers and partners are genuine registered businesses, as required by law.
Bank or UPI payout detailsTo pay commissions and settle supplier payouts.
Transaction history (RFQs, quotes, orders, payments, invoices)To operate the marketplace and retain statutory tax records.
Communication records (messages, attachments, support tickets)To provide chat, resolve disputes and evidence what was agreed.
IP address, device identifier, browser typeFor security, fraud prevention, rate limiting and access logging.

We do not knowingly process data of children under 18 and we do not use your data for automated profiling or targeted advertising.

3. Your rights as a Data Principal

RightWhat it meansTimeline
Right to access informationDownload a machine-readable copy of the personal data we hold about you.Immediately in-app; within 90 days if requested by email
Right to correctionCorrect inaccurate or incomplete data from your profile and KYC forms.Within 90 days
Right to erasureDelete your account and personal data, except records we must keep by law (for example tax records for 7 years).Within 90 days
Right to grievance redressalComplain to our Grievance Officer about how your data is handled.Acknowledged in 7 days, resolved in 30 days
Right to nominateNominate another person to exercise your rights in case of death or incapacity.Register the nomination with the Grievance Officer

Use Download my data and Delete my account in Account settings, or raise an access, correction, erasure or grievance request there and we will track it to closure.

4. Storage and retention

Data typeRetention periodReason
KYC documents7 yearsTax law compliance
Transaction history (orders, invoices, payments)7 yearsTax law compliance
User profile dataUntil account deletionService delivery
Consent recordsLife of the data + 3 yearsAudit proof of consent
Audit logs3 yearsSecurity audit
Access logs1 yearSecurity audit

After the retention period ends the data is erased or irreversibly anonymised. Tax and KYC records survive account deletion only for as long as Indian tax law requires.

5. Security safeguards

  • Encryption at restAll database contents and uploaded documents are encrypted at rest by our managed cloud infrastructure.
  • Encryption in transitEvery request is served over HTTPS/TLS with HSTS enabled.
  • Role-based access controlRow-level security policies restrict each record to its owner, its counterparty, or an administrator.
  • Private document storageKYC documents and invoices live in private buckets reachable only through short-lived signed links.
  • Audit logsAdministrative and transaction-changing actions are written to an append-only audit trail.
  • Access logsViews, edits, exports and deletions of personal data are logged with time, IP address and device.
  • Rate limitingSensitive actions such as uploads, exports and order requests are throttled per account.
  • Breach responseDetected breaches are registered, reported to the Data Protection Board of India within 72 hours, and affected users are notified.

6. Sharing and cross-border transfers

We share personal data only with the counterparty to your transaction (a buyer sees the supplier they order from and vice versa), our payment gateway for settlement, our logistics partners for delivery, and our cloud hosting, database and email providers as Data Processors under contract. We never sell your data.

Our infrastructure providers may store or process data on servers outside India. Such transfers are made only to countries not restricted by the Central Government under Section 16 of the DPDP Act, and are covered by contractual safeguards that hold the processor to the same standards of confidentiality and security we apply ourselves.

7. Personal data breaches

If a personal data breach affects your data, we intimate the Data Protection Board of India without delay and file the detailed report within 72 hours, and we notify you directly with the nature and extent of the breach, its likely consequences, the measures we have taken, and the steps you should take to protect yourself.

8. Grievance Officer

Grievance Officer, Trade Rede

Email: privacy@traderede.com

Phone: +91 90000 00000

Address: Trade Rede, GS Road, Guwahati, Assam 781005, India

We acknowledge every grievance within 7 days and resolve it within 30 days. If you are not satisfied, you may complain to the Data Protection Board of India.