Last updated September 2026
This Privacy Policy explains how NarneTech Software Solutions ("NarneTech", "we", "us", "our") collects, uses, shares and protects your personal data when you visit narnetech.shop, sign up for a store, or use our platform. We are committed to processing your personal data in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules made under it, as applicable in India.
In the language of the DPDP Act, you are the Data Principal and, for the data described in this policy, NarneTech is the Data Fiduciary.
NarneTech Software Solutions, Vijayawada, Andhra Pradesh, India. You can contact us about this policy or your personal data at any time:
We collect only what we need to provide and improve the service:
Under the DPDP Act we process personal data on the basis of your consent or for certain legitimate uses permitted by the Act. We use your data to:
We ask for your consent through a clear affirmative action (for example, ticking a box or submitting the signup form after reading this notice). Your consent is limited to the purposes described here, and we will not process your data for anything incompatible without asking you again.
We do not sell your personal data. We share it only with trusted service providers ("Data Processors") who help us run the platform, under contracts that require them to protect it and use it only for us:
We may also disclose data where required by law, a court, or a lawful government request, or to protect our rights, users and the public.
We keep your personal data only for as long as your account is active and as needed for the purposes above. After you cancel, we retain your store data for 30 days so you can export or reactivate it, after which it is deleted or anonymised — except records we are required to keep for legal, tax or accounting reasons (for example, GST invoices). When the purpose is served and no law requires retention, we erase your personal data.
We use reasonable security safeguards, including encryption of sensitive credentials (AES-256), HTTPS/TLS in transit, access controls, tenant data isolation, activity logging and regular backups. No system is perfectly secure, but in the event of a personal data breach we will notify the Data Protection Board of India and affected Data Principals as required by the DPDP Act.
Under the DPDP Act, you have the right to:
To exercise any right, email [email protected]. We may need to verify your identity before acting on a request. You are responsible for providing accurate information and not impersonating others when making a request.
Our platform is intended for businesses and adults. We do not knowingly process the personal data of children (under 18) without verifiable consent of a parent or lawful guardian, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has given us data without such consent, please contact us and we will delete it.
If you have any concern about how we handle your personal data, please contact our Grievance Officer:
We will acknowledge and respond within the timelines prescribed under the DPDP Act. If you are not satisfied with our response, you may raise the matter with the Data Protection Board of India. See our Grievance Redressal page for the full process.
Your data is primarily stored and processed in India. Where a service provider processes data outside India, we do so only to the extent permitted by the DPDP Act and applicable rules, and we take steps to ensure it remains protected.
We may update this Privacy Policy from time to time. Material changes will be posted on this page with a revised "last updated" date, and where required we will seek your consent again.
Questions about this policy? Email [email protected] or message us on WhatsApp at +91 88852 58951. See also our Terms & Conditions and Cookie Policy.