Privacy Policy
How Trolly Ecommerce Pvt. Ltd. collects, uses, protects and shares personal data when you visit Webmins, buy products or use our ecommerce platform.
Applies to services purchased through kharedi.in
Responsible organization
Trolly Ecommerce Pvt. Ltd.
Operating Webmins from Goa, India.
Our approach
Purpose-based processing
We collect data needed to deliver, secure and support the services.
Coverage
India and global users
Local mandatory privacy rights apply based on your location.
Privacy should be understandable
This policy explains what Webmins collects, why it is needed, who may process it and what choices you have. We do not sell or rent personal data for money.
1. Scope, organization and privacy roles
Trolly Ecommerce Pvt. Ltd., trading as Webmins, is responsible for personal data collected for Webmins accounts, direct purchases, licensing, hosted-plan administration, website operations and customer support. Depending on applicable law, this role may be described as data fiduciary, controller or business.
When a merchant uses Webmins to process information about the merchant’s own customers, staff or suppliers, the merchant generally decides why that information is used. In that context, the merchant is the data fiduciary/controller and Webmins acts as its processor or service provider under the service agreement and merchant instructions.
This policy is designed for users in India and other countries. Applicable mandatory law—including India’s digital personal data framework and, where relevant, laws such as the EU or UK GDPR and applicable US state privacy laws—may provide additional rights.
2. Information we collect
Account and identity
Name, email, phone number, login identifiers, password hash, organization and account preferences.
Orders and billing
Products, plans, amounts, currency, billing address, tax details, invoices, payment status and gateway references.
Commerce and licensing
Store domain, subscriptions, licenses, activations, downloads, update entitlement and usage records.
Device and security
IP address, browser, device, timestamps, authentication events, cookies, audit logs and fraud signals.
Support and communications
Tickets, email, call or chat details, attachments, feedback and information you voluntarily provide.
AI feature content
Prompts, instructions, generated output and related content when you choose an AI-assisted feature.
We do not intentionally collect full card numbers, card security codes, UPI PINs, online-banking passwords or OTPs. Enter those only in the secure interface supplied by your bank or payment provider.
3. Sources of information
- directly from you when you browse, register, buy, configure a store, activate a license or contact support;
- automatically from your browser, device, cookies, server logs and security systems;
- from payment providers such as Razorpay or Paytm, which return payment status and transaction references;
- from an organization or merchant that creates or manages an account for you;
- from integration providers when you connect a service and authorize information exchange;
- from lawful public or fraud-prevention sources where needed to protect transactions and the platform.
4. How and why we use personal data
We use personal data only for identified business and legal purposes, including:
- creating and securing accounts;
- calculating, accepting, verifying and fulfilling orders;
- issuing invoices, licenses, downloads, updates and hosted subscriptions;
- validating domains and preventing conflicting or unauthorized activations;
- providing customer support and transactional communications;
- detecting fraud, abuse, security incidents and payment disputes;
- maintaining, debugging, measuring and improving the platform;
- meeting accounting, tax, corporate, regulatory and lawful-request obligations;
- establishing, exercising or defending legal claims.
Depending on applicable law and context, processing is based on your consent, steps requested before or performance of a contract, compliance with law, protection of users, or our legitimate interests in operating a secure and effective service. Where consent is required, you may withdraw it prospectively, although this does not invalidate earlier lawful processing.
5. Payments, Razorpay and Paytm
Checkout may use payment providers including Razorpay and Paytm Payment Gateway. These providers independently collect and process card, UPI, bank or wallet credentials under their own privacy notices and regulatory obligations.
- Webmins receives transaction identifiers, selected payment method, amount, currency, status and limited reconciliation information.
- We use payment information to confirm orders, issue invoices, detect duplicate or failed payments, process approved refunds and respond to disputes.
- Payment providers, banks, UPI systems and card networks may apply their own fraud checks and retain records independently.
- Never send card numbers, CVV, UPI PINs, bank passwords or OTPs through support tickets, email, WhatsApp or chat.
Refund information is handled under our Refund, Return and Cancellation Policy.
6. AI-assisted website builder features
When you choose an AI-assisted feature, the prompt, selected store context and relevant content may be transmitted to a configured AI technology provider to generate the requested response. Do not place payment credentials, passwords, private keys, health information, government identifiers or other unnecessary sensitive data in a prompt.
AI output may be incomplete or incorrect. Review generated text, code, images and recommendations before publishing or relying on them. The applicable provider may process request data under its contractual privacy and security terms. We use AI-feature data to provide the requested function, maintain safety, troubleshoot and improve the feature as permitted by law and our provider agreements.
9. International data processing
Webmins is operated from India, while service providers or customers may be located elsewhere. Personal data may therefore be processed in India and other countries where privacy rules differ. Where required, we use contractual, organizational or other legally recognized safeguards for cross-border transfers and comply with applicable transfer restrictions.
10. Retention and deletion
We retain personal data only as long as reasonably required for the purpose collected, including:
- account information while the account or service relationship remains active;
- orders, payments, refunds, invoices and tax records for applicable statutory and audit periods;
- license, activation, download and update records for entitlement, anti-piracy, security and contractual enforcement;
- support records while needed to resolve issues and maintain service history;
- security and technical logs for limited periods based on risk and operational needs;
- consent and privacy-request records as evidence of compliance.
When data is no longer required, we delete, anonymize or securely isolate it. A deletion request may not remove information that must be retained for tax, payment reconciliation, fraud prevention, disputes, security, backups or legal obligations. Backup copies are removed through normal retention cycles.
11. Security and incident response
We use measures appropriate to the nature and risk of the information, including encrypted transport, password hashing, access controls, restricted administrative privileges, private file storage, audit logging, token expiration, backups and security monitoring. Payment credentials are handled by dedicated payment providers.
No internet service can guarantee absolute security. Protect your password and OTPs, keep devices updated and report suspected misuse promptly. If a personal-data breach occurs, we will investigate, contain and notify affected people or authorities when applicable law requires it.
12. Privacy rights and grievance handling in India
Subject to applicable Indian law, verification and lawful exceptions, you may request information about personal data processed and relevant sharing, correction or completion of inaccurate data, erasure of data no longer needed, withdrawal of consent, and grievance redressal. Where applicable, you may nominate another individual to exercise rights in the event of death or incapacity.
You are expected to provide authentic information, avoid impersonation or false grievances, and furnish information reasonably required to verify and fulfil a request. Withdrawal of consent may prevent features that depend on that data, but does not affect lawful processing already completed.
Email support@webmins.com with the subject “Privacy Request”. Include your account email, country, requested action and enough information to identify the relevant records. Do not attach identity documents unless we specifically request a secure verification method.
13. Additional rights for global users
Depending on where you live, you may have some or all of the following rights:
- access to or confirmation of personal data;
- correction of inaccurate information;
- deletion or erasure, subject to exceptions;
- restriction of or objection to certain processing;
- data portability for qualifying information;
- withdrawal of consent;
- opt-out of qualifying targeted advertising, sale or sharing where applicable;
- review of certain significant automated decisions where provided by law;
- complaint to a competent privacy or data-protection authority;
- non-discrimination for exercising a protected privacy right.
We may verify identity and authority before responding. Authorized agents must provide legally sufficient authorization. Rights vary and are subject to exemptions; we will explain if a request cannot be completed. Webmins does not intentionally make decisions producing legal or similarly significant effects solely through automated processing without safeguards required by applicable law.
14. Data processed for Webmins merchants
Merchants using the Webmins ecommerce platform are responsible for telling their shoppers, staff and suppliers how they collect and use personal data, selecting lawful settings, responding to rights requests and complying with applicable ecommerce, marketing, cookie and privacy requirements.
When Webmins processes that data on a merchant’s instructions, requests should normally be directed to the merchant first. We assist merchants as required by contract and law. We may independently process limited account, security, billing and service-usage data for our own legitimate operational and compliance purposes.
15. Children’s privacy
Webmins business accounts and purchasing services are not directed to children under 18. We do not knowingly permit a child to enter into a purchase or business-service agreement. If you believe a child submitted personal data without appropriate authorization, contact us so we can investigate and take suitable action. Merchants must configure their stores and notices appropriately for their own audience.
16. Transactional and marketing communications
We send service messages needed for accounts, security, orders, payments, invoices, licenses, downloads, subscriptions, updates and support. These are not marketing opt-ins and may be necessary to provide the service.
Where we send promotional communication, we use consent or another lawful basis required in the recipient’s location and provide an unsubscribe method. Opting out of marketing does not stop essential transactional or security messages.
17. Policy changes and contact
We may update this policy when services, providers or laws change. The revised version applies prospectively from its published effective date. We will provide additional notice where a material change requires it.
Avantinagar, Tisk Usgao, Ponda, Goa, India
For general customer support, visit the Contact Us page. These privacy terms should be read with our Terms and Conditions.