Privacy Policy

Tech Udyam Solutions Private Limited, operating www.printster.in ("Printster", "we", "us", "our"), is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, how we protect it and the rights you have under Indian law, including the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Information Technology Act, 2000 read with the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. Effective Date: 01 Jan 2025.

  1. Who We Are (Data Fiduciary)
    • Tech Udyam Solutions Private Limited, S-548A, 1st Floor, School Block, Shakarpur, Laxmi Nagar, Delhi 110092, India. CIN U72900DL2016PTC303004. GSTIN 07AAFCT8420M2ZY.
    • Contact: print@printster.in / +91-9643230482. Privacy queries: privacy@printster.in. Grievance: gaurav@printster.in.

  2. Personal Data We Collect
    • Identity and contact data: name, e-mail, mobile number, billing and shipping addresses.
    • Account data: username, password (stored only in salted-hash form), preferences, communication settings.
    • Order data: file metadata, print settings, special instructions, order history, GSTIN (for B2B Customers).
    • Payment data: payment method tokens, transaction reference. We do NOT store full card numbers, CVV or net-banking credentials. These are handled by PCI-DSS compliant payment service providers.
    • Customer Content: files (PDF, DOCX, DOC, PPT, PPTX, JPG, PNG, ZIP) uploaded for printing. Content of files is processed solely to fulfil the Order and is deleted in accordance with the retention schedule below.
    • Communications: e-mails, chat messages, call recordings (where notified), survey and feedback responses.
    • Device and usage data: IP address, device identifiers, browser type, operating system, language, referring URL, pages visited, clicks, time on page.
    • Cookies and similar technologies: see the Cookies section below.
    • Data from third parties: payment gateway response (success / failure status, masked card / UPI handle); courier partners (delivery status, geo-pincode, signature confirmation); authentication providers if You sign in via Google or another single-sign-on (basic profile data only).
    • Sensitive personal data: in the ordinary course we do not collect sensitive personal data as defined in the IT Rules 2011 (such as biometric data, health information, sexual orientation). Where any document uploaded by You contains sensitive personal data, You are solely responsible for the consequences of including such data, and Printster will treat the same with the higher level of protection set out in the IT Rules 2011 and the DPDP Act.

  3. Purposes for Which We Use Personal Data
    • To accept, process, produce and deliver Your Orders.
    • To create and manage Your account, authenticate You and prevent fraud.
    • To raise GST-compliant tax invoices and meet statutory accounting / tax obligations under the CGST Act 2017, the Income Tax Act 1961 and the Companies Act 2013.
    • To respond to Your queries, complaints, takedown notices and grievance escalations.
    • To improve the Site, perform analytics and product research, and personalise Your experience.
    • To send transactional communications about Your Orders (these are not "promotional" and cannot be opted out of without closing the account).
    • To send marketing communications where You have given specific, free, informed consent (and which You may withdraw at any time).
    • To comply with applicable law, court orders, regulatory directions, and to enforce our Terms.

  4. Lawful Basis Under the DPDP Act
    • Consent (Section 6 DPDP Act): for marketing communications, optional cookies and any feature where consent is the only suitable basis.
    • Legitimate uses (Section 7 DPDP Act): for fulfilment of Orders that You have voluntarily placed, for compliance with legal obligations, for protection from fraud and for safety of Customers.
    • Where consent is the basis, You may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

  5. Sharing and Disclosure of Personal Data
    • We do not sell Your personal data.
    • Service providers (Data Processors): payment gateways (e.g., Razorpay, Paytm, PayU), courier and logistics providers (e.g., DTDC, Delhivery, FedEx, Xpressbees), cloud and hosting providers, e-mail / SMS / WhatsApp dispatch tools, analytics providers, customer-support tools.
    • Production partners on a need-to-know basis where an Order is sub-contracted for fulfilment.
    • Auditors, advisors and professional services firms under confidentiality obligations.
    • Government authorities, regulators, courts and law-enforcement agencies where required by law.
    • Acquirers / successors in the event of a corporate restructuring, merger or acquisition, subject to confidentiality and continuity of this Privacy Policy.

  6. Data Retention
    • Customer Content (uploaded files): deleted from primary fulfilment systems within 30 days of delivery, except where retention is required for an open dispute, refund or legal obligation.
    • Order, invoice and tax records: retained for at least 8 years from the end of the relevant financial year as required under the Companies Act 2013 and CGST Act 2017.
    • Account data: retained for as long as the account is active and for up to 3 years thereafter for fraud prevention, audit and dispute resolution.
    • Marketing-consent records: retained for the duration of consent and for 12 months after withdrawal as proof of lawful basis.
    • Communications and grievance records: retained for at least 3 years from closure.

  7. Cross-Border Transfers
    • Where personal data is transferred outside India (for example, to a cloud or e-mail service provider whose servers are located abroad), the transfer is made only to jurisdictions that are not restricted by the Central Government under Section 16 of the DPDP Act and subject to appropriate contractual safeguards. Printster takes responsibility for any such transfers.

  8. Security
    • Data in transit: TLS 1.2+ encryption.
    • Data at rest: encryption of databases and file storage where technically feasible.
    • Access control: role-based access, multi-factor authentication for administrative consoles, periodic access reviews.
    • Vendor management: written agreements with all processors that include confidentiality and reasonable-security obligations.
    • Logging and monitoring of administrative actions on personal data; regular vulnerability assessment and patching of the Site and infrastructure.
    • Despite the above, no method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially reasonable means to protect Your personal data, we cannot guarantee absolute security.

  9. Cookies and Similar Technologies
    • Strictly necessary: required to operate the Site, log in, place an Order and process payments. These cannot be disabled.
    • Functional: remember Your preferences (e.g., language, last-used print settings).
    • Analytics: help us understand how Customers use the Site and improve performance (e.g., Google Analytics, with IP anonymisation where available).
    • Marketing: used to deliver targeted advertisements on third-party platforms; deployed only with consent.
    • On Your first visit and on the renewal date, the Site displays a cookie banner allowing You to accept all, reject non-essential, or manage preferences. You may also clear cookies through Your browser at any time.

  10. Your Rights as a Data Principal
    • Confirmation and access — to obtain confirmation of whether Your personal data is being processed and to access a summary of such data and the processing activities.
    • Correction and erasure — to have inaccurate or misleading data corrected, completed or updated and to seek erasure of personal data that is no longer necessary for the purpose for which it was collected.
    • Grievance redressal — to use a readily available grievance-redressal mechanism (see Grievance section below).
    • Nominate — to nominate any other individual who shall, in the event of Your death or incapacity, exercise the rights of the Data Principal under the DPDP Act.
    • Withdraw consent at any time, with effect prospectively (Section 6(4) DPDP Act).
    • To exercise any of the above, e-mail privacy@printster.in or write to the Grievance Officer. We will verify Your identity before responding. We respond within the timelines required by law and, in any case, within 30 days of receipt of a verifiable request.

  11. Grievance Redressal
    • If You have a complaint about how Your personal data is processed, please contact our Grievance Officer first at gaurav@printster.in. If You are not satisfied with the response, You may escalate the complaint to the Data Protection Board of India once it is established under the DPDP Act, or to any other regulator with jurisdiction.
    • Grievance Officer: Gaurav Singh, Tech Udyam Solutions Private Limited, S-548A, 1st Floor, School Block, Shakarpur, Laxmi Nagar, Delhi 110092. E-mail: gaurav@printster.in. Phone: +91-9643230482. Working Hours: Mon–Sat 11:00 to 18:00 IST. Acknowledgment within 48 hours; resolution within 30 days.

  12. Children's Data
    • Printster does not knowingly process personal data of children under the age of 18 without verifiable parental consent. We do not undertake tracking, behavioural monitoring of, or targeted advertising directed at, children. If You believe a child has provided personal data without consent, please write to gaurav@printster.in and we will delete the data after verification.

  13. Personal Data Breach Notification
    • In the event of a personal data breach as defined in the DPDP Act, we will (a) notify the Data Protection Board of India and (b) intimate affected Data Principals, in accordance with the form, manner and timelines prescribed under the DPDP Act and rules made thereunder, and the directions of CERT-In under Rule 12 of the IT (CERT-In) Rules, 2013.

  14. Third-Party Links
    • The Site may contain links to third-party websites. We are not responsible for the privacy practices of such third parties. Please review their policies before submitting personal data.

  15. Changes to This Privacy Policy
    • We may revise this Privacy Policy from time to time. The "Last Updated" date reflects the latest version. Where the changes are material, we will notify Customers by e-mail or by a prominent notice on the Site at least 7 days in advance of the effective date.

  16. How to Contact Us
    • For privacy questions or to exercise Your rights: privacy@printster.in.
    • For grievances: gaurav@printster.in.
    • Postal address: Tech Udyam Solutions Private Limited, S-548A, 1st Floor, School Block, Shakarpur, Laxmi Nagar, Delhi 110092, India.
    • Last Updated On: 01 Jan 2025.