Privacy · India and global

Privacy Policy

How Trolly Ecommerce Pvt. Ltd. collects, uses, protects and shares personal data when you visit Webmins, buy products or use our ecommerce platform.

Applies to services purchased through kharedi.in

Responsible organization

Trolly Ecommerce Pvt. Ltd.

Operating Webmins from Goa, India.

Our approach

Purpose-based processing

We collect data needed to deliver, secure and support the services.

Coverage

India and global users

Local mandatory privacy rights apply based on your location.

Privacy should be understandable

This policy explains what Webmins collects, why it is needed, who may process it and what choices you have. We do not sell or rent personal data for money.

Payment credentialsHandled by the selected gateway or bank—not requested by Webmins support.
Privacy requestssupport@webmins.com
Who this policy applies to. It covers visitors, account holders, customers, trial users, license holders, hosted-store subscribers and people who contact support through kharedi.in. A merchant using Webmins must publish its own privacy notice for shoppers and employees whose data it controls.

1. Scope, organization and privacy roles

Trolly Ecommerce Pvt. Ltd., trading as Webmins, is responsible for personal data collected for Webmins accounts, direct purchases, licensing, hosted-plan administration, website operations and customer support. Depending on applicable law, this role may be described as data fiduciary, controller or business.

When a merchant uses Webmins to process information about the merchant’s own customers, staff or suppliers, the merchant generally decides why that information is used. In that context, the merchant is the data fiduciary/controller and Webmins acts as its processor or service provider under the service agreement and merchant instructions.

This policy is designed for users in India and other countries. Applicable mandatory law—including India’s digital personal data framework and, where relevant, laws such as the EU or UK GDPR and applicable US state privacy laws—may provide additional rights.

2. Information we collect

Account and identity

Name, email, phone number, login identifiers, password hash, organization and account preferences.

Orders and billing

Products, plans, amounts, currency, billing address, tax details, invoices, payment status and gateway references.

Commerce and licensing

Store domain, subscriptions, licenses, activations, downloads, update entitlement and usage records.

Device and security

IP address, browser, device, timestamps, authentication events, cookies, audit logs and fraud signals.

Support and communications

Tickets, email, call or chat details, attachments, feedback and information you voluntarily provide.

AI feature content

Prompts, instructions, generated output and related content when you choose an AI-assisted feature.

We do not intentionally collect full card numbers, card security codes, UPI PINs, online-banking passwords or OTPs. Enter those only in the secure interface supplied by your bank or payment provider.

3. Sources of information

  • directly from you when you browse, register, buy, configure a store, activate a license or contact support;
  • automatically from your browser, device, cookies, server logs and security systems;
  • from payment providers such as Razorpay or Paytm, which return payment status and transaction references;
  • from an organization or merchant that creates or manages an account for you;
  • from integration providers when you connect a service and authorize information exchange;
  • from lawful public or fraud-prevention sources where needed to protect transactions and the platform.

4. How and why we use personal data

We use personal data only for identified business and legal purposes, including:

  • creating and securing accounts;
  • calculating, accepting, verifying and fulfilling orders;
  • issuing invoices, licenses, downloads, updates and hosted subscriptions;
  • validating domains and preventing conflicting or unauthorized activations;
  • providing customer support and transactional communications;
  • detecting fraud, abuse, security incidents and payment disputes;
  • maintaining, debugging, measuring and improving the platform;
  • meeting accounting, tax, corporate, regulatory and lawful-request obligations;
  • establishing, exercising or defending legal claims.

Depending on applicable law and context, processing is based on your consent, steps requested before or performance of a contract, compliance with law, protection of users, or our legitimate interests in operating a secure and effective service. Where consent is required, you may withdraw it prospectively, although this does not invalidate earlier lawful processing.

5. Payments, Razorpay and Paytm

Checkout may use payment providers including Razorpay and Paytm Payment Gateway. These providers independently collect and process card, UPI, bank or wallet credentials under their own privacy notices and regulatory obligations.

  • Webmins receives transaction identifiers, selected payment method, amount, currency, status and limited reconciliation information.
  • We use payment information to confirm orders, issue invoices, detect duplicate or failed payments, process approved refunds and respond to disputes.
  • Payment providers, banks, UPI systems and card networks may apply their own fraud checks and retain records independently.
  • Never send card numbers, CVV, UPI PINs, bank passwords or OTPs through support tickets, email, WhatsApp or chat.

Refund information is handled under our Refund, Return and Cancellation Policy.

6. AI-assisted website builder features

When you choose an AI-assisted feature, the prompt, selected store context and relevant content may be transmitted to a configured AI technology provider to generate the requested response. Do not place payment credentials, passwords, private keys, health information, government identifiers or other unnecessary sensitive data in a prompt.

AI output may be incomplete or incorrect. Review generated text, code, images and recommendations before publishing or relying on them. The applicable provider may process request data under its contractual privacy and security terms. We use AI-feature data to provide the requested function, maintain safety, troubleshoot and improve the feature as permitted by law and our provider agreements.

7. Cookies, local storage and analytics

We use cookies or similar browser storage for secure sessions, authentication, checkout continuity, currency and preference selection, fraud prevention and core site operation. These are necessary for requested services and may not work if blocked.

If analytics, advertising or other non-essential technologies are enabled, we will use them subject to applicable notice and consent requirements. Browser settings can delete or block cookies, but doing so may interrupt account, dashboard or checkout features. Because browser “Do Not Track” signals are not interpreted consistently, we respond to legally required preference signals where technically supported and applicable.

8. When we disclose personal data

We disclose only information reasonably needed for a defined purpose to:

  • cloud hosting, database, storage, security and content-delivery providers;
  • payment gateways, banks, UPI systems, card networks, invoicing and fraud-prevention partners;
  • email, support desk, messaging, analytics and AI technology providers;
  • professional advisers, auditors, insurers and corporate service providers;
  • a buyer, investor or successor during a genuine corporate transaction, subject to safeguards;
  • courts, regulators, law enforcement or other parties where disclosure is required or legally justified;
  • a merchant organization that administers your account or store.

Service providers are expected to process data for contracted purposes and apply appropriate safeguards. We do not sell or rent personal data for money. If a jurisdiction treats certain advertising or analytics disclosures as a “sale” or “sharing,” any required notice and opt-out will be provided when those activities apply.

9. International data processing

Webmins is operated from India, while service providers or customers may be located elsewhere. Personal data may therefore be processed in India and other countries where privacy rules differ. Where required, we use contractual, organizational or other legally recognized safeguards for cross-border transfers and comply with applicable transfer restrictions.

10. Retention and deletion

We retain personal data only as long as reasonably required for the purpose collected, including:

  • account information while the account or service relationship remains active;
  • orders, payments, refunds, invoices and tax records for applicable statutory and audit periods;
  • license, activation, download and update records for entitlement, anti-piracy, security and contractual enforcement;
  • support records while needed to resolve issues and maintain service history;
  • security and technical logs for limited periods based on risk and operational needs;
  • consent and privacy-request records as evidence of compliance.

When data is no longer required, we delete, anonymize or securely isolate it. A deletion request may not remove information that must be retained for tax, payment reconciliation, fraud prevention, disputes, security, backups or legal obligations. Backup copies are removed through normal retention cycles.

11. Security and incident response

We use measures appropriate to the nature and risk of the information, including encrypted transport, password hashing, access controls, restricted administrative privileges, private file storage, audit logging, token expiration, backups and security monitoring. Payment credentials are handled by dedicated payment providers.

No internet service can guarantee absolute security. Protect your password and OTPs, keep devices updated and report suspected misuse promptly. If a personal-data breach occurs, we will investigate, contain and notify affected people or authorities when applicable law requires it.

12. Privacy rights and grievance handling in India

Subject to applicable Indian law, verification and lawful exceptions, you may request information about personal data processed and relevant sharing, correction or completion of inaccurate data, erasure of data no longer needed, withdrawal of consent, and grievance redressal. Where applicable, you may nominate another individual to exercise rights in the event of death or incapacity.

You are expected to provide authentic information, avoid impersonation or false grievances, and furnish information reasonably required to verify and fulfil a request. Withdrawal of consent may prevent features that depend on that data, but does not affect lawful processing already completed.

Grievance and privacy contact

Email support@webmins.com with the subject “Privacy Request”. Include your account email, country, requested action and enough information to identify the relevant records. Do not attach identity documents unless we specifically request a secure verification method.

13. Additional rights for global users

Depending on where you live, you may have some or all of the following rights:

  • access to or confirmation of personal data;
  • correction of inaccurate information;
  • deletion or erasure, subject to exceptions;
  • restriction of or objection to certain processing;
  • data portability for qualifying information;
  • withdrawal of consent;
  • opt-out of qualifying targeted advertising, sale or sharing where applicable;
  • review of certain significant automated decisions where provided by law;
  • complaint to a competent privacy or data-protection authority;
  • non-discrimination for exercising a protected privacy right.

We may verify identity and authority before responding. Authorized agents must provide legally sufficient authorization. Rights vary and are subject to exemptions; we will explain if a request cannot be completed. Webmins does not intentionally make decisions producing legal or similarly significant effects solely through automated processing without safeguards required by applicable law.

14. Data processed for Webmins merchants

Merchants using the Webmins ecommerce platform are responsible for telling their shoppers, staff and suppliers how they collect and use personal data, selecting lawful settings, responding to rights requests and complying with applicable ecommerce, marketing, cookie and privacy requirements.

When Webmins processes that data on a merchant’s instructions, requests should normally be directed to the merchant first. We assist merchants as required by contract and law. We may independently process limited account, security, billing and service-usage data for our own legitimate operational and compliance purposes.

15. Children’s privacy

Webmins business accounts and purchasing services are not directed to children under 18. We do not knowingly permit a child to enter into a purchase or business-service agreement. If you believe a child submitted personal data without appropriate authorization, contact us so we can investigate and take suitable action. Merchants must configure their stores and notices appropriately for their own audience.

16. Transactional and marketing communications

We send service messages needed for accounts, security, orders, payments, invoices, licenses, downloads, subscriptions, updates and support. These are not marketing opt-ins and may be necessary to provide the service.

Where we send promotional communication, we use consent or another lawful basis required in the recipient’s location and provide an unsubscribe method. Opting out of marketing does not stop essential transactional or security messages.

17. Policy changes and contact

We may update this policy when services, providers or laws change. The revised version applies prospectively from its published effective date. We will provide additional notice where a material change requires it.

Privacy and grievance contactsupport@webmins.com+91 9921881388
Postal addressTrolly Ecommerce Pvt. Ltd.
Avantinagar, Tisk Usgao, Ponda, Goa, India

For general customer support, visit the Contact Us page. These privacy terms should be read with our Terms and Conditions.

Effective and last updated: 20 September 2026Applies to India and global users
Submit a privacy requestContact our privacy and grievance channel.Terms and ConditionsRules governing accounts, payments and services.Contact WebminsBusiness details and customer support channels.