Official Data Protection & Privacy Documentation — Mitra Mobile

Privacy Policy & Data Security Charter

Last Updated: September 2026 Data Policy: Zero Data Selling Guarantee Compliance: DPDP Act & IT Act 2000 (India)

1. Overview & Privacy Commitment

At Mitra Mobile (accessible via mitramobile.com and our Android application), protecting the privacy and confidentiality of your personal and commercial business information is our foremost priority. This Privacy Policy details the strict procedures we follow to collect, encrypt, store, and process your information in compliance with the Information Technology (IT) Act, 2000, the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection (DPDP) Act, 2023 of India.

2. Information We Collect

We collect only the minimum necessary information required to authenticate user sessions, calculate tiered shipping rates, and dispatch mobile spare parts orders:

  • Identity & Contact Information: Your primary Indian mobile phone number (verified through automated SMS OTP), full name, and optional business name.
  • Delivery Addresses: Shipping street address, landmark, town/city, state, and 6-digit postal pin code for courier routing.
  • Transactional Records: Order identifiers, ordered spare part SKUs, quantity discount tiers applied, invoice generation logs, and UPI payment transaction reference numbers (RRN).
  • Device & Telemetry Data: Cryptographic device authentication hashes, operating system version, and IP addresses logged solely for session security and anti-fraud rate-limiting.
NO PAYMENT CARD DATA RETENTION: Mitra Mobile does NOT store or process your complete credit card numbers, debit card numbers, CVVs, or bank net banking passwords. All payment transactions are executed securely through RBI-authorized payment gateway providers.

3. Zero Third-Party Data Monetization Guarantee

ABSOLUTE DATA MONETIZATION GUARANTEE: Mitra Mobile does not sell, rent, lease, trade, or distribute your phone number, addresses, purchasing history, or personal identifiers to any third-party advertisers, marketing agencies, or data brokers.

Your contact details are used exclusively for essential operational communications related to your Mitra Mobile account, such as order confirmation SMS, shipment dispatch tracking updates, and automated UPI cancellation notifications.

4. Lawful Purpose of Data Processing

Your information is processed strictly for legitimate operational purposes:

  • Order Fulfillment: Picking, packing, bench dry-testing verification, and handing over consignments to courier logistics partners.
  • Wholesale Tier Computation: Calculating automated volume discounts for repair technicians and retail repair workshops.
  • Customer Support & Warranty Claims: Verifying continuous unboxing video submissions and technician dry-testing photos.
  • Financial Compliance & Invoicing: Generating GST-compliant sales invoices and processing UPI refunds.

5. Cryptographic Security & Infrastructure Safeguards

Mitra Mobile deploys enterprise-grade administrative, technical, and physical security measures to protect user data from unauthorized access or destruction:

  • Transport Layer Security (TLS): All communications between the Mitra Mobile application, web portal, and backend databases are encrypted using modern TLS 1.3 encryption.
  • HMAC API Integrity: Network requests between the mobile client and backend servers are authenticated using SHA-256 keyed-hash message authentication codes (HMAC) to prevent packet tampering.
  • Encrypted Credential Storage: Device tokens and administrative keys are stored using industry-standard AES-256 bit encryption algorithms.
  • Role-Based Access Control (RBAC): Access to customer shipping addresses and order histories is strictly restricted to authorized warehouse dispatch and support personnel.

6. Data Retention & Indian Residency

In accordance with Indian regulatory mandates, all transactional, shipping, and audit log data is stored in secure Indian data center facilities with audit timestamps maintained in Indian Standard Time (IST, UTC+05:30).

We retain transaction and invoicing records for the statutory period mandated under Indian Goods and Services Tax (GST) and financial accounting laws, after which they are systematically archived or anonymized.

7. User Rights & Self-Service Account Deletion

Under the Digital Personal Data Protection Act, 2023, you have full ownership and rights over your personal data:

  • Right to Access & Correct: You may review and update your delivery addresses, contact names, and profile information at any time within the Mitra Mobile application.
  • Right to Withdraw Consent & Delete Account: Users may request complete deletion of their account and associated profile data by submitting an in-app request or by writing to mitramobileofficial@gmail.com with the subject line "Account Deletion Request". Upon verification, your profile data will be permanently purged within 14 business days, subject to regulatory tax record obligations.

8. Grievance Redressal Officer

In accordance with Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the details of the Grievance Officer for data protection matters are provided below:

Mitra Mobile Grievance & Compliance Cell

Designation: Grievance Officer — Data Protection
Official Email: mitramobileofficial@gmail.com
Postal Address: Mitra Mobile, Bangalore, Karnataka, India
Response Timeline: Within 48 business hours of receipt