Property Cart (mobile application and website)
| Data Fiduciary | MRK Engineering Services Private Limited |
| CIN | U71100RJ2025PTC101420 |
| Registered office | 17, Anjum Manzil, Gulzar Bag, Tonk, Rajasthan 304001 |
| Document version | 1.0 |
| Effective date | 17 September 2026 |
| Last updated | 17 September 2026 |
| Applies to | Property Cart app (Android, iOS) and property-cart.com |
| Contact | support@property-cart.com |
THE ONE THING TO KNOW BEFORE YOU LIST A PROPERTY: If you publish a listing, your name and phone number will be shown to any buyer who spends Coins to unlock it. That is the whole point of the Platform, and it is the main way your personal data is shared. If you are not comfortable with this, do not publish a listing.
This Privacy Policy is issued under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules made under it, the Information Technology Act, 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 ("IT Rules 2021"). It forms part of, and is incorporated into, the Property Cart Terms and Conditions of Use ("Terms"). Capitalised terms not defined here have the meaning given in the Terms.
1.1 We are the Data Fiduciary. MRK Engineering Services Private Limited is the Data Fiduciary in respect of the personal data described in this Policy. We determine the purpose and means of processing, and We are accountable for that processing under the DPDP Act.
1.2 Our service providers are Data Processors. Our hosting, analytics, communication, storage and payment vendors process personal data on Our behalf and on Our documented instructions as Data Processors under valid written contracts. We remain responsible to You for their processing.
1.3 Other Users are independent of Us. When a Buyer unlocks Contact Details and then contacts a Listing User, that Buyer becomes responsible for their own use of that personal data. We are not responsible for how another User uses personal data they obtain through the Platform, though We impose binding obligations on them under Clause 13.4 of the Terms and will act on complaints.
1.4 Not a Significant Data Fiduciary. We have not been notified as a Significant Data Fiduciary under Section 10 of the DPDP Act. If We are so notified, We will comply with the additional obligations that follow, including appointing a Data Protection Officer based in India, appointing an independent data auditor, and conducting Data Protection Impact Assessments, and We will update this Policy.
2.1 This Policy applies to the processing of digital personal data collected through the Platform, whether collected in digital form or digitised after collection in non-digital form.
2.2 It applies to processing within India, and to processing outside India where that processing is in connection with offering goods or services to Data Principals within India.
2.3 It does not apply to: (a) personal data You give directly to another User outside the Platform (for example over a phone call after an unlock); (b) third-party websites or apps You reach through a link on the Platform; or (c) data that is not personal data, including aggregated and de-identified statistics.
"Consent Manager" means a person registered with the Data Protection Board of India who enables a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform.
"Data Fiduciary" means any person who alone or with others determines the purpose and means of processing personal data - here, Us.
"Data Principal" means the individual to whom the personal data relates - here, You.
"Data Processor" means any person who processes personal data on behalf of a Data Fiduciary.
"Personal Data" means any data about an individual who is identifiable by or in relation to such data.
"Processing" means any wholly or partly automated operation on digital personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment, sharing, disclosure by transmission, dissemination, restriction, erasure or destruction.
"Board" means the Data Protection Board of India.
4.1 Itemised notice. In accordance with Section 5 of the DPDP Act, We give You, at or before the point of collection, a clear and plain-language notice that itemises:
(a) the personal data sought to be collected; (b) the specific purpose for which it will be processed; (c) how You may exercise Your rights under Sections 12 and 13 of the DPDP Act; (d) how You may withdraw Your consent, with the same ease with which it was given; and (e) how You may complain to the Board.
4.2 Languages. This Policy, and the notice at Clause 4.1, are available in English and in Hindi, Marathi, Gujarati, Punjabi, Bengali, Tamil, Telugu, Kannada and Malayalam (all specified in the Eighth Schedule to the Constitution of India), as well as a Hinglish (romanised Hindi) option, as published in-app. You may select Your preferred language in Settings. In the event of any inconsistency between versions, the English version prevails for legal interpretation, without prejudice to Your right to receive the notice in a language You understand.
4.3 Where the notice appears. Just-in-time notices appear at: registration; listing creation; the first request for each device permission; Coin purchase; and the contact-unlock modal.
| Category | Data | When |
|---|---|---|
| Account | Full name, mobile number, email address, password (stored only as a salted hash), profile photograph (optional), city, user type (buyer / owner) | Registration |
| Verification | Documents You choose to upload to evidence identity or right to list; the last four digits of any identifier; email/phone verification status | Optional, when You choose to verify |
| Listing | Property address and locality, geo-coordinates, property type, area, price or rent, ownership type, floor, age, amenities, description, photographs, videos, floor plans, brochures, RERA registration numbers | Listing creation |
| Contact Details for disclosure | The name and phone number (and, if You choose, email) You nominate to receive buyer enquiries | Listing creation |
| Transaction | Coin purchase history, order IDs, invoice details, GSTIN (if You request a business invoice), refund requests | Coin purchase |
| Support | Content of Your messages, complaints, appeals, screenshots and call notes | When You contact Us |
| Preferences | Saved searches, shortlists, alerts, notification and marketing preferences, language | In use |
| Category | Data |
|---|---|
| Device | Device model, manufacturer, operating system and version, unique device identifier, app version, screen resolution, language and time-zone settings, network carrier, connection type |
| Log and technical | IP address, timestamps, referring URL, pages and screens viewed, session duration, crash logs, diagnostic and performance data |
| Usage | Searches run, filters applied, listings viewed and shortlisted, listings unlocked, Coins spent, features used, in-app clicks, notification interactions |
| Approximate location | Derived from IP address, and - only with Your permission - precise location from Your device, used to show nearby listings and to pin a property on a map |
| Cookies and identifiers | See Schedule 2 |
| Security | Failed login attempts, fraud and abuse signals, device fingerprint used solely to detect duplicate accounts, scraping and fraud |
We request the following, each optional, each revocable at any time in Your device settings. Refusing a permission disables only the related feature; it does not block use of the Platform.
| Permission | Why | If You refuse |
|---|---|---|
| Location | Show nearby listings; place a property pin | You enter the locality manually |
| Camera | Take listing photographs in-app | You upload from the gallery |
| Photos / storage | Upload listing images and documents | You cannot upload media |
| Notifications | Enquiry alerts, Coin expiry reminders, saved-search alerts | You get no alerts |
| Contacts | We do not request this permission. | - |
| Microphone / call logs / SMS | We do not request these permissions. | - |
Where You sign in with Google or another identity provider, We receive Your name, email address and profile picture from that provider in accordance with that provider's terms and Your settings with them. We receive payment success or failure status, and a masked instrument reference, from Our payment aggregator. We may receive fraud and abuse signals from security vendors.
We process personal data only for the following specified purposes. We do not process personal data for any purpose incompatible with these.
| # | Purpose | Data used |
|---|---|---|
| P1 | Create and administer Your account; authenticate You | Account, device, log |
| P2 | Publish, display, rank and search Listings | Listing, location |
| P3 | Disclose a Listing User's Contact Details to a Buyer who redeems Coins | Contact Details (see Clause 9) |
| P4 | Operate the Coin system: sell, credit, debit, expire and reconcile Coins | Transaction, account |
| P5 | Process payments, issue GST-compliant invoices, handle refunds and chargebacks | Transaction |
| P6 | Provide customer support, and handle grievances, appeals and takedowns | Support, account, listing |
| P7 | Detect, prevent and investigate fraud, fake listings, scraping, spam, impersonation, Coin-system circumvention and security incidents | Security, device, usage, log |
| P8 | Maintain, debug, secure and improve the Platform; measure performance and fix crashes | Log, device, usage |
| P9 | Send service communications: OTPs, enquiry alerts, Coin expiry reminders, invoices, policy changes | Account |
| P10 | Send marketing communications - only with Your separate optional consent | Account, preferences |
| P11 | Produce aggregated, de-identified analytics and market insights that do not identify any individual | De-identified usage |
| P12 | Comply with law: retention under Rule 3(1)(g) IT Rules 2021, responses to lawful orders, tax and accounting records, and the establishment, exercise or defence of legal claims | As required |
6.1 Purpose limitation. If We ever wish to process Your personal data for a new purpose not listed above, We will give You a fresh notice and, where consent is the basis, obtain fresh consent before doing so.
6.2 Data minimisation. We collect only what is necessary for the specified purpose. Fields marked optional in the app are genuinely optional.
Under the DPDP Act, personal data may be processed only for a lawful purpose, either (a) with Your consent, or (b) for a "legitimate use" under Section 7.
| Basis | Applies to |
|---|---|
| Consent (Section 6) | P2 (publishing Your Listing), P3 (disclosure of Contact Details), P10 (marketing), precise location, optional document uploads |
| Legitimate use - voluntarily provided for a purpose you sought (Section 7(a)) | P1, P4, P5, P6, P9 - data You give Us for a service You asked for, and for which You have not indicated You do not consent |
| Legitimate use - compliance with law / judgment / order (Sections 7(b), 7(f), 7(g)) | P12, and disclosures under Clause 10.3 |
| Legitimate use - responding to a medical emergency, epidemic, disaster or breakdown of public order (Sections 7(c)-(e)) | Only if such a situation arises |
7.1 Security and service integrity. Processing under P7 and P8 is necessary to provide the service You asked for and to comply with Our due diligence obligations under Rule 3 of the IT Rules 2021, and is undertaken on the bases indicated above. We keep this processing to the minimum necessary.
7.2 We do not use "legitimate interest" as a general-purpose basis. The DPDP Act does not contain an open-ended legitimate-interest ground of the kind found in some foreign laws, and We do not rely on one.
8.1 Our consent standard. Every consent We seek is free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and is limited to the personal data necessary for the specified purpose.
8.2 Practically, this means:
(a) no pre-ticked boxes anywhere in the app; (b) separate, granular consents - consent to publish a Listing is separate from consent to marketing, which is separate from consent to precise location; (c) no bundling - We will never make access to the Platform conditional on a consent that is not necessary for it. You can use the entire Platform without ever consenting to marketing or precise location; (d) a record kept of every consent: what You consented to, the version of the notice shown, the timestamp, and the device; and (e) withdrawal made as easy as giving - one tap, in Settings > Privacy.
8.3 Withdrawal of consent. You may withdraw any consent at any time, without giving reasons, in Settings > Privacy, or by writing to support@property-cart.com.
8.4 Effect of withdrawal.
(a) Withdrawal takes effect prospectively. It does not make lawful past processing unlawful. (b) On withdrawal, We will cease the relevant processing within a reasonable time and will cause Our Data Processors to do the same. (c) Withdrawing consent to display Your Contact Details will unpublish Your Listing, because the Listing cannot function without it. It cannot recall Contact Details already disclosed to a Buyer who has already spent Coins - that disclosure has already happened, and the Coins are already consumed. This is why Clause 9 asks You to read carefully before publishing. (d) Withdrawal does not affect processing on a legitimate-use basis, or processing We are legally required to continue (for example the 180-day retention under Rule 3(1)(g), or tax records).
8.5 Consent Managers. Where Consent Managers are registered with the Board and We integrate with them, You will be able to give, manage, review and withdraw Your consent through a Consent Manager of Your choice. We will notify You in-app when this becomes available.
This is the single most important disclosure in this Policy.
9.1 What happens. If You publish a Listing, and a Buyer spends Coins to unlock it, We show that Buyer the name and telephone number (and email, if You provided one) that You nominated. They will then be able to contact You directly, off the Platform.
9.2 This is the core purpose. This disclosure is not incidental. It is the purpose for which the Contact Details are collected, and it is the service the Buyer has paid for. You consent to it expressly, by a separate unticked checkbox, at the time You publish the Listing (Schedule C.6 of the Terms).
9.3 Who can see it. Only Users who have spent Coins on that specific Listing. Contact Details are not shown on the public listing page, are not indexed by search engines, and are not sold or made available in bulk.
9.4 Disclosure is irreversible. Once a Buyer has seen Your Contact Details, We cannot take that back. We can stop further disclosures - by unpublishing the Listing, or by Your withdrawing consent - but We cannot erase what a person has already seen or written down.
9.5 Controls You have.
(a) Choose what to expose. You may nominate a secondary or business number rather than Your personal one. Email is optional. (b) Unpublish at any time, immediately, from the Listing screen. No further unlocks will occur. (c) Withdraw consent in Settings > Privacy (see Clause 8.4(c)). (d) Report misuse. If a Buyer spams You, markets to You, or passes Your number on, report it via the in-app "Report" button or to the Grievance Officer. We will investigate and may permanently ban that Buyer under Clause 13.4 of the Terms. (e) DND. Register with Your telecom provider's Do Not Disturb service to reduce unsolicited commercial calls, and report violations under the Telecom Commercial Communications Customer Preference Regulations, 2018.
9.6 What We cannot control. Once contact moves off the Platform, We have no visibility of, control over, or record of the conversation. We do not monitor, record or retain calls, SMS or messaging-app conversations between Users.
9.7 Buyer's obligations. A Buyer who unlocks Contact Details is bound by Clause 13.4 of the Terms: they may use them only to discuss that specific Listing in good faith, and must not market to You, add You to a database, or transfer Your details to anyone. Breach can result in a permanent ban, and may itself be a contravention of the DPDP Act for which that Buyer is answerable.
We do not sell personal data. We do not rent, trade, or share personal data.
10.2 Payment aggregators. Payment data is collected directly by an RBI-authorised payment aggregator. We never receive or store Your full card number, CVV, PIN, UPI PIN or net-banking credentials. We receive only the transaction outcome and a masked instrument reference. The aggregator processes that data as an independent controller under its own policy and RBI regulations.
10.3 Legal and regulatory disclosure. We may disclose personal data where necessary to:
(a) comply with an order of a court or tribunal, or a lawful written order or notice of a Government agency authorised under Rule 3(1)(j) of the IT Rules 2021 or any other law; (b) respond to a lawful request from law enforcement, the Enforcement Directorate, the Financial Intelligence Unit - India, the Income-tax Department, or the Data Protection Board of India; (c) enforce the Terms, investigate suspected fraud, protect the security of the Platform, or protect the rights, property or safety of Us, Our Users or the public; or (d) establish, exercise or defend a legal claim.
We assess each request for lawfulness, require it in writing from an identified authorised officer, disclose only the minimum data responsive to it, and keep a record of it. Where We are permitted to do so by law, We will notify You of such a disclosure. We will not notify You where notification is prohibited, or would prejudice an investigation.
10.4 Corporate transactions. In a merger, amalgamation, restructuring, acquisition or sale of business, personal data may transfer to the successor entity, subject to this Policy and the DPDP Act. We will notify You of any such transfer and of any change in the identity of the Data Fiduciary.
10.5 Aggregated and de-identified data. We may publish or share statistics, price trends and market insights that are aggregated and de-identified, and from which no individual can be identified. This is not personal data.
10.6 Other Users. As described in Clause 9, and: Your Listing content (excluding Contact Details) is publicly visible; Your first name and city may appear on the Listing.
11.1 Where data is stored. Our primary data storage and processing is in data centres located in India, operated by Our hosting provider, Hostinger.
11.2 Transfers outside India. Some Data Processors - for example analytics, crash reporting, email and messaging providers - may process limited personal data on servers outside India. Section 16 of the DPDP Act permits transfer of personal data outside India except to countries or territories restricted by notification of the Central Government.
11.3 Our commitment. We will not transfer personal data to any country or territory that the Central Government has notified as restricted. Where We transfer data outside India, We do so under written contracts imposing standards of protection equivalent to those in this Policy, and We limit the data transferred to what is necessary.
11.4 Sectoral restrictions. Where any sectoral law or regulator imposes a stricter data-localisation requirement on any category of data, that stricter requirement prevails and We will comply with it.
11.5 Current list. The categories of Processor and their processing locations are at Schedule 3, which We keep current.
12.1 Principle. We retain personal data only for as long as necessary for the purpose for which it was collected, unless a longer period is required by law. When the purpose is served and no legal requirement applies, We erase the personal data, and cause Our Data Processors to do the same, in accordance with Section 8(7) of the DPDP Act.
12.2 Retention schedule.
| Data | Retention period | Reason |
|---|---|---|
| Account data (active account) | For the life of the account | Provide the service |
| Account data after You delete Your account | 180 days, then erased | Rule 3(1)(g), IT Rules 2021 |
| Listing content after deletion | 180 days in backups, then erased | Rule 3(1)(g); dispute defence |
| Contact Details after a Listing is unpublished | Erased on account deletion, subject to the 180-day period | No continuing purpose |
| Record of which Buyer unlocked which Listing | three (3) years | Refund disputes, fraud investigation, defence of claims |
| Coin ledger, invoices, payment records | 8 years from the end of the relevant financial year | Section 128, Companies Act 2013; GST and Income-tax record-keeping |
| Grievance and complaint records | three (3) years from disposal | Regulatory audit; compliance reporting |
| Consent records | Life of the account + three (3) years | Evidence of lawful basis |
| Server, security and access logs | 180 days | Security, fraud investigation, Rule 3(1)(g) |
| Marketing preference / opt-out record | Indefinitely, as a suppression record | So We do not contact You again by mistake |
| Data under legal hold | Until the proceeding, investigation or order concludes | Legal obligation |
12.3 Inactivity. If You do not access Your account for twenty-four (24) continuous months, We will notify You at Your registered email and mobile, and if You do not respond within thirty (30) days, We will close the account and erase the personal data, subject to the retention schedule above.
12.4 Erasure requests. See Clause 15.3 and Schedule 4.
12.5 Backups. Data in encrypted backups is erased on the ordinary backup rotation cycle, which does not exceed ninety (90) days beyond the primary erasure. Backups are not used to restore erased data into production.
13.1 Our obligation. Section 8(5) of the DPDP Act requires Us to protect personal data in Our possession or control by taking reasonable security safeguards to prevent a personal data breach. This is an obligation of implementation, not merely of contract, and We take the following measures:
13.2 Technical measures.
(a) Encryption in transit - TLS 1.2 or higher on all connections; (b) Encryption at rest - AES-256 for databases, object storage and backups; (c) Credential protection - passwords stored only as salted hashes using a modern adaptive algorithm (bcrypt/Argon2); We never store passwords, OTPs, card numbers, CVVs, PINs or UPI PINs in readable form; (d) Access control - role-based access on a need-to-know basis, unique named accounts, mandatory multi-factor authentication for all administrative access, and no shared credentials; (e) Segregation - production data is not used in development or test environments; where test data is derived from production, it is masked or synthesised; (f) Logging and monitoring - access to personal data is logged, logs are tamper-evident, and anomalies are alerted; (g) Backups - encrypted, access-controlled, and restore-tested periodically; (h) Secure development - code review, dependency scanning, and periodic vulnerability assessment and penetration testing by an independent party.
13.3 Organisational measures.
(a) written information security and data protection policies; (b) confidentiality obligations in every employment and vendor contract; (c) periodic staff training on data protection and phishing; (d) a documented incident response plan, tested periodically; (e) vendor due diligence before onboarding any Data Processor, and contractual flow-down of these obligations; (f) prompt revocation of access on exit or role change; and (g) a periodic review of this Policy and of Our processing activities.
13.4 Your part. Use a strong, unique password, do not share Your OTP with anyone (We will never ask You for Your OTP or password), keep Your device secured and updated, and log out on shared devices. Be alert to impersonation: We will never call You asking for payment towards a property, and We will never ask You to install a screen-sharing or remote-access application.
13.5 No absolute guarantee. No method of transmission or storage is completely secure. While We take the measures above, We cannot guarantee absolute security, and any transmission is at Your own risk to that extent. This does not limit Our statutory obligations under the DPDP Act.
14.1 Notification. In the event of a personal data breach, and in accordance with Section 8(6) of the DPDP Act and the rules made under it, We will:
(a) intimate each affected Data Principal, without delay, in a concise, clear and plain-language description of the breach - its nature, extent and timing, the likely consequences, the measures We have taken to mitigate risk, and the safety measures You should take; and (b) intimate the Data Protection Board of India without delay of the fact of the breach, and furnish detailed particulars - including the events and circumstances leading to it, the mitigation measures taken, the findings on the person who caused it, remedial measures to prevent recurrence, and a report on the intimations given to Data Principals - within seventy-two (72) hours, or such longer period as the Board allows on request.
14.2 Records. We maintain a breach register and, where a breach involves an offence, We will report it to law enforcement and to CERT-In in accordance with the applicable directions.
14.3 No suppression. We will not delay, minimise or suppress notification of a breach to reduce reputational impact.
You have the following rights under the DPDP Act. All are free of charge, and We will respond within thirty (30) days. How to exercise them is at Schedule 4.
15.1 Right to access information (Section 11). You may obtain: (a) a summary of the personal data of Yours being processed and the processing activities undertaken; (b) the identities of all Data Fiduciaries and Data Processors with whom Your personal data has been shared, and a description of the data shared; and (c) any other prescribed information. In-app, this is available immediately as Settings > Privacy > Download my data.
15.2 Right to correction, completion and updating (Section 12). You may correct inaccurate or misleading personal data, complete incomplete data, and update data. Most fields are directly editable in Settings > Profile. We will correct on request and, where the data has been shared, take reasonable steps to inform recipients.
15.3 Right to erasure (Section 12). You may request erasure of Your personal data. We will erase it unless retention is necessary for the specified purpose or for compliance with law - in which case We will tell You which data We are retaining, for how long, and under which provision. Account deletion is available in-app at Settings > Delete my account.
15.4 Right of grievance redressal (Section 13). You may complain to Our Grievance Officer about any act or omission of Ours regarding Your rights or Our obligations. See Clause 20. You must exhaust this remedy before approaching the Board.
15.5 Right to nominate (Section 14). You may nominate any individual to exercise Your rights under the DPDP Act on Your behalf in the event of Your death or of Your incapacity by reason of unsoundness of mind or infirmity of body. Nominate in Settings > Privacy > Nominee.
15.6 Right to withdraw consent (Section 6(4)). See Clause 8.3.
15.7 Additional controls We give You voluntarily.
(a) opt out of marketing at any time, with one tap, and in every marketing message; (b) unpublish any Listing immediately; (c) revoke any device permission at any time in Your device settings; (d) export Your listings and account data in a machine-readable format; and (e) object to any automated decision by asking for human review (Clause 18).
15.8 Verification. To protect You, We will verify Your identity before acting on a request - normally by an OTP to Your registered mobile or email. We will not ask for a new identity document merely to process a rights request.
15.9 If We refuse. If We refuse or partly refuse a request, We will tell You in writing, with reasons and with the statutory provision relied on, within the same 30-day period, and inform You of Your right to complain to the Grievance Officer and then to the Board.
Section 15 of the DPDP Act imposes duties on You. You must:
(a) comply with all applicable laws while exercising Your rights; (b) not impersonate another person when providing personal data for a specified purpose; (c) not suppress any material information while providing personal data for any document, unique identifier, proof of identity or proof of address issued by the State; (d) not register a false or frivolous grievance or complaint with Us or with the Board; and (e) furnish only such information as is verifiably authentic when exercising the right to correction or erasure.
Breach of these duties is punishable with a penalty of up to Rs. 10,000 under the Schedule to the DPDP Act. It is also a breach of the Terms and may result in suspension of Your account.
17.1 18+ only. The Platform is not intended for, and may not be used by, anyone under the age of 18. We do not knowingly collect personal data of children.
17.2 Age declaration. Every User declares at registration that they are 18 or older (Schedule C.1 of the Terms). We do not process the personal data of children and therefore do not undertake the tracking, behavioural monitoring or targeted advertising directed at children that Section 9(3) of the DPDP Act prohibits.
17.3 If We discover a minor. If We learn that a User is under 18, We will immediately suspend the account, cease processing, and erase the personal data within seven (7) days, subject only to any retention We are legally compelled to make. If You believe a child has provided personal data to Us, write immediately to support@property-cart.com and We will act.
17.4 Persons with disability. Where a User is a person with disability who has a lawfully appointed guardian, We will process personal data only on the basis of the guardian's verifiable consent, in accordance with Section 9 of the DPDP Act. Write to support@property-cart.com to arrange this.
18.1 What is automated. We use automated systems to: rank and order search results; recommend listings similar to those You viewed; detect duplicate, fake or fraudulent listings; detect scraping, bot traffic and Coin-system circumvention; and flag accounts for review.
18.2 What these systems do not do. They do not verify property title, ownership or legality (Clause 3.7 and 16.2(b) of the Terms), and they do not make any decision about Your creditworthiness, employment or access to any service outside the Platform.
18.3 Human review. Where an automated system results in a decision that materially affects You - such as suspension of Your account or removal of Your Listing - You may ask for human review by writing to the Grievance Officer. A person not involved in the original decision will review it and respond within fifteen (15) days.
18.4 No sale of profiles. We do not build or sell advertising profiles about You, and We do not share Your personal data with third-party advertising networks for their own targeting.
For clarity, We do not collect, ask for, or want:
(a) Aadhaar numbers or Aadhaar documents. Do not upload them (Clause 8.4 of the Terms). If received, We delete them; (b) card numbers, CVVs, PINs, UPI PINs, net-banking passwords, or any authentication credential - these go directly to Our RBI-authorised payment aggregator; (c) your phone's contact list, SMS messages, or call logs - We do not request these permissions; (d) biometric data, including fingerprints and facial recognition templates; (e) data revealing caste, religion, political opinions, trade union membership, sexual orientation, or health - and any Listing seeking to state a preference on such grounds is prohibited under Schedule A of the Terms; (f) bank account numbers of Users, except where necessary to process a refund to a source that no longer exists, in which case We collect the minimum necessary and delete it after the refund; and (g) personal data of any person other than You, unless You are lawfully authorised to provide it and have their consent - if You upload a photograph showing an identifiable person, You warrant that You have their consent.
20.1 Grievance Officer. Appointed under Section 13 of the DPDP Act, Rule 3(2) of the IT Rules 2021, and Rule 4(5) of the Consumer Protection (E-Commerce) Rules 2020:
| Field | Detail |
|---|---|
| Name | Inayatullah Khan |
| Designation | Grievance Officer |
| Company | MRK Engineering Services Private Limited |
| Address | 17, Anjum Manzil, Gulzar Bag, Tonk, Rajasthan 304001 |
| support@property-cart.com | |
| Privacy-specific email | support@property-cart.com |
| Telephone | +91 88491 68539 |
| Hours | 10:00 - 18:00 IST, Monday to Saturday, excluding public holidays |
20.2 Timelines. We acknowledge every grievance within 24 hours and dispose of it within 15 days. Requests to exercise DPDP rights are answered within 30 days.
20.3 Escalation ladder.
21.1 We may update this Policy. The current version, with its version number and effective date, is always available in-app and at property-cart.com/privacy.
21.2 Material changes. For any material change - a new purpose, a new category of data, a new category of recipient, a new cross-border destination, or a longer retention period - We will give at least fifteen (15) days' prior notice by in-app notification and email, and, where the change requires it, We will seek fresh consent. We will not apply a materially different purpose to previously collected data without a fresh lawful basis.
21.3 Annual notification. In compliance with Rule 3(1)(c) of the IT Rules 2021, We notify all Users of this Policy at least once every year.
21.4 Previous versions are archived and available on request from the Grievance Officer.
MRK Engineering Services Private Limited 17, Anjum Manzil, Gulzar Bag, Tonk, Rajasthan 304001 CIN: U71100RJ2025PTC101420
| Purpose | Contact |
|---|---|
| Privacy and data protection | support@property-cart.com |
| Grievances (all types) | support@property-cart.com |
| General support | support@property-cart.com |
| Security vulnerability reports | support@property-cart.com |
| Accessibility assistance | support@property-cart.com |
(All routed today through the single monitored inbox above; We intend to split these into dedicated addresses as the team grows.)
| Data category | Collected? | Purpose (ref. Clause 6) | Basis | Shared with | Retention |
|---|---|---|---|---|---|
| Name, mobile, email | Yes | P1, P3, P9 | S.7(a) / Consent for P3 | Buyers on unlock; comms processors | Account life + 180 days |
| Password | Hash only | P1 | S.7(a) | No one | Account life + 180 days |
| Profile photo | Optional | P1 | Consent | Other Users (if shown) | Account life + 180 days |
| Listing content and photos | Yes | P2 | Consent | Publicly visible | Account life + 180 days |
| Property location | Yes | P2 | Consent | Publicly visible | Account life + 180 days |
| Precise device location | Optional | P2 | Consent | Map provider | Session only |
| Identity documents | Optional | P7 | Consent | Reviewed in-house; not shared with any processor | Twelve (12) months from upload |
| Coin ledger, invoices | Yes | P4, P5, P12 | S.7(a), S.7(b) | Payment aggregator; auditors | 8 financial years |
| Payment credentials | No | - | - | Aggregator only, directly | Not held by Us |
| Unlock records (who unlocked what) | Yes | P4, P6, P7 | S.7(a) | No one | Three (3) years |
| Device and log data | Yes | P7, P8 | S.7(a) | No one | 180 days |
| Usage and search history | Yes | P8, P11 | S.7(a) | No one | 180 days, then aggregated |
| Support correspondence | Yes | P6 | S.7(a) | No one | Three (3) years |
| Marketing preferences | Yes | P10 | Consent | Comms processor | Suppression record kept indefinitely |
| Consent records | Yes | P12 | S.7(b) | Auditors | Account life + three (3) years |
| Aadhaar / biometrics / contacts / SMS | No | - | - | - | - |
2.1 What we use. On the website We use cookies and similar technologies. In the mobile app We use device identifiers and local storage, which serve the same functions.
2.2 Categories.
| Category | Purpose | Consent needed? | Typical lifespan |
|---|---|---|---|
| Strictly necessary | Session management, login state, load balancing, CSRF protection, fraud prevention, remembering Your cookie choice | No - the site cannot work without them | Session to 12 months |
| Functional | Language, city, saved filters, recently viewed, display preferences | Yes | Up to 12 months |
| Analytics / performance | Aggregated measurement of page views, journeys, crashes, load times, so We can fix and improve | Yes | Up to 14 months |
| Advertising / retargeting | We do not currently use advertising or third-party retargeting cookies. If We introduce them, We will update this Notice and obtain Your consent first. | Yes (if introduced) | - |
2.3 Your control.
(a) In-app / on-site: a consent banner appears on first visit with "Accept all", "Reject all" (equally prominent) and "Manage preferences". You can change Your choice at any time in Settings > Privacy > Cookie preferences. Rejecting non-essential cookies does not restrict access to the Platform. (b) Browser: You may block or delete cookies in Your browser settings. Blocking strictly necessary cookies will break login. (c) Mobile: reset or limit Your advertising identifier in your device settings (Android: Settings > Privacy > Ads; iOS: Settings > Privacy & Security > Tracking). (d) Do Not Track: browser DNT signals are not yet standardised; We honour Global Privacy Control (GPC) signals where Our platform receives them.
2.4 Third-party cookies. Embedded maps and video players may set their own cookies under their own policies. See Schedule 3.
We keep this list current, and it names only vendors We actually use — We do not list a vendor We do not use. Contact support@property-cart.com for the version in force on any date.
| Category | Provider | Data processed | Location | Role |
|---|---|---|---|---|
| Cloud hosting and storage | Hostinger | All Platform data | India | Processor |
| Payment aggregation | Razorpay | Payment instrument data, transaction status | India | Independent controller (RBI-regulated) |
| SMS and OTP | MSG91 | Mobile number, message content | India | Processor |
| Brevo | Email address, message content, open/click events | Outside India | Processor | |
| WhatsApp messaging | Meta (WhatsApp Business) | Mobile number, message content | Global | Processor |
| Push notifications | Expo Push Notification Service (built on Google FCM / Apple APNs) | Device push token, message content | Global | Processor |
| Sign-in | Google Sign-In | Name, email address, profile picture | Global | Processor |
| Maps, place search and geocoding | Google Maps Platform; Photon (Komoot); OpenStreetMap Overpass API | Approximate or precise location, address strings | Global | Processor / independent |
Vendors We do not use (kept here so this list stays honest as the Platform grows, rather than silently going stale): We do not currently use a CDN, third-party product analytics, crash/performance monitoring, a third-party customer-support desk tool, third-party fraud/bot-detection services, a third-party identity-verification service (KYC review is done in-house by Our own team), or an external accounting/invoicing service. If We start using any of these, We will add it here and give notice under Clause 21.2 before doing so.
Every Processor above is engaged under a written contract requiring: processing only on Our documented instructions; confidentiality; the security measures at Clause 13; no onward sub-processing without Our consent; assistance with Data Principal requests; breach notification to Us without undue delay; and deletion or return of data on termination.
| I want to... | Fastest route | Alternative | We respond in |
|---|---|---|---|
| See what data you hold on me | Settings > Privacy > Download my data | Email support@property-cart.com | Immediate / 30 days |
| Know who you shared it with | Settings > Privacy > Sharing summary | Email support@property-cart.com | 30 days |
| Correct or update my details | Settings > Profile | Email support@property-cart.com | Immediate / 30 days |
| Delete my account and data | Settings > Delete my account | Email support@property-cart.com | 30 days (see Clause 12.2) |
| Stop showing my number to buyers | Listing screen > Unpublish, or Settings > Privacy > withdraw consent | Email support@property-cart.com | Immediate |
| Stop marketing messages | Settings > Notifications, or the unsubscribe link in any message | Reply STOP to any SMS | Immediate |
| Turn off location | Your device Settings > Apps > Property Cart > Permissions | - | Immediate |
| Appoint a nominee | Settings > Privacy > Nominee | Email support@property-cart.com | Immediate |
| Ask a human to review an automated decision | Email support@property-cart.com | In-app Help | 15 days |
| Report misuse of my number by a buyer | In-app Report button | Email support@property-cart.com | Ack 24 hrs / 15 days |
| Raise a privacy grievance | Email support@property-cart.com | Post to the address in Clause 20.1 | Ack 24 hrs / 15 days |
Before You contact the Data Protection Board of India, You must first raise the matter with Our Grievance Officer (Section 13(3), DPDP Act).
END OF PRIVACY POLICY
Document version 1.0 | Effective 17 September 2026 | (c) MRK Engineering Services Private Limited. All rights reserved. English version prevails.