Privacy Policy
Version 2026-09-v9 · RYSAG INDIA PRIVATE LIMITED · published 27 Sept 2026
RYSAG INDIA PRIVATE LIMITED ("RYSAG", "we", "us") operates rysag.com, the RYSAG and RYSAG Sellers mobile applications, and vendor storefronts at *{seller}*.rysag.com — together, the "Platform". RYSAG is a business-to-business marketplace for licensed agricultural input dealers.
This policy explains what personal data we process, why, for how long, and what you can do about it. It is issued under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 and rules made under it.
Flat No. 502, 5th Floor, C Block, Srikara Heights, Pedda Amberpet, K.V. Rangareddy, Rangareddy, Telangana 501505 · CIN U47912TS2026PTC222008 · GSTIN 36AAQCR2665B1Z9
1. Who is responsible
RYSAG is the Data Fiduciary for the personal data described here. Where a vendor processes your data for its own purposes — for example, its own customer records after a sale — that vendor is a separate Data Fiduciary and its own policy applies to that processing.
2. What we process, and why
Identity and contact. Your name, mobile number and email address — the email is required for a seller, because approval sends the sign-in details to it and a verification code proves it first; optional for a dealer, who is sent sign-in details only at an address they have confirmed the same way. Used to create and operate your account, to send one-time login codes, and to reach you about orders, deliveries, refunds and support. Your mobile number is your account identifier.
Business identity. Legal name, trade name, constitution, GSTIN, PAN, and registered and delivery addresses. Required because a tax invoice must carry the buyer's and seller's particulars under the CGST Act, 2017, and because marketplace onboarding requires verification of the business.
Regulatory licences and KYC documents. Pesticide (PL), fertilizer (FL) and seed (SL) licences, GST certificates, PAN cards, bank proof, premises photographs and any document you upload for verification. Required because the Insecticides Act, 1968, the Fertilizer (Control) Order, 1985 and the Seeds Act, 1966 restrict who may buy and sell these goods; we cannot lawfully let you transact without checking them.
Commerce records. Carts, quotes, orders, payments, refunds, invoices, shipments, lorry receipts and e-Way Bill references. Used to perform the contract you entered into and to meet statutory record-keeping obligations.
Automatic verification of a dealer. When a dealer registers, we look up the GSTIN they give on the GST register, which returns the business's legal name, trade name, registration status and principal address; we compare the name the dealer entered with it, and use the register's address as the registered address. We then check the GST certificate and each licence uploaded: that the file is a genuine PDF or image and opens, and — where a PDF carries text — that the GSTIN appears on the certificate and the licence number on the licence. We compare the licence holder's name with the GST register and check the licence's expiry date. We keep the result of each check with the application, and RYSAG staff review a sample of approved dealers, including every document these checks could not read. Used to confirm that a dealer holds the registration and licences the law requires before they can buy restricted agri inputs.
Bank account details. For selling organisations, the settlement account and settlement history; for dealers, the account refunds are paid to. That is the account number, IFSC and account holder name. We check an account by a penny drop through our verification provider, which tells us the name the bank holds for it; that name is kept with the account so a reviewer can compare it. Bank details are stored encrypted (AES-256-GCM) and only the last four digits are ever displayed back to anyone, including our own staff.
Support and grievance records. Cases you raise, messages, attachments and the actions our team took. Used to resolve your issue and to evidence compliance with grievance timelines.
Technical and security data. IP address, device and browser characteristics, session identifiers, timestamps and audit entries for sensitive actions. Used to keep accounts secure, detect fraud and abuse, and investigate incidents. Sensitive administrative actions are written to an append-only audit log.
Notification preferences and consent records. What channels you agreed to, when, and which version of which policy you accepted. Kept as evidence of consent under the DPDP Act.
3. How we obtain it
Directly from you (registration, KYC upload, checkout, support), automatically from your use of the Platform (technical and security data), and from our service providers — for example, the payment gateway confirms a payment, the e-Way Bill provider returns a bill number, the verification provider returns the name your bank holds for your account, and the GST register returns the registration details held against your GSTIN.
4. Legal basis
We process your data for the lawful purposes for which you have given consent, and where processing is necessary for us to perform the contract between us, to comply with a legal obligation (tax, e-commerce, agri-input licensing), and for the legitimate uses permitted by section 7 of the DPDP Act. Marketing messages are sent only on separate, specific, opt-in consent, recorded apart from your account consent, and you may withdraw that consent at any time without affecting your account.
5. Who we share it with, and who we do not
We do not sell personal data. We do not share it for third-party advertising.
We share the minimum necessary with:
- The vendor you buy from — your business name, GSTIN, delivery address and contact person, because they raise the tax invoice and dispatch the goods to you.
- The dealer a vendor sells to — for sellers, the corresponding details, for the same reason.
- Payment aggregator. Payments are collected by an RBI-authorised payment aggregator. RYSAG never receives or stores your card number, CVV, UPI PIN or net-banking credentials.
- Bank verification provider, to run the penny drop on a bank account. It receives only what that check needs.
- GST verification provider, to look up a GSTIN on the GST register. It receives only the GSTIN.
- Logistics and e-Way Bill providers, to move goods and generate statutory transport documents.
- Communication providers, to deliver one-time codes and transactional messages.
- Cloud infrastructure and storage providers, who host the Platform under contract.
- Professional advisers, auditors, and regulators or law-enforcement agencies where the law requires disclosure or where it is necessary to establish, exercise or defend a legal claim.
Every processor is bound by contract to process data only on our instructions and to protect it.
6. Storage and transfers
Platform data is stored in India. If any provider processes data outside India, it will be a country not restricted by the Central Government under section 16 of the DPDP Act, and the transfer will be under contractual safeguards.
7. Security
Access tokens are short-lived and refresh tokens are single-use and device-bound. Bank details are encrypted at rest. Documents you upload are stored in private object storage and served only through short-lived, access-checked links; image metadata (including any GPS coordinates in a photograph) is stripped on upload. Payments are confirmed only by a signature-verified webhook from the payment provider — never by a browser or app telling us a payment succeeded. Administrative access is role-based and audited.
No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and affected users as the DPDP Act requires.
8. Retention
We keep personal data only as long as needed for the purpose, and then delete or anonymise it:
- One-time codes: deleted within an hour of expiry.
- Revoked sessions: 90 days, for security forensics.
- Notifications: 180 days.
- Support cases: 3 years from closure.
- Orders, invoices and ledger entries: retained for the period required by the CGST Act and the Companies Act, 2013 — these survive account deletion in anonymised form, because tax law does not permit their erasure.
- KYC and licence documents: for the life of the account and 8 years after, to evidence that a regulated sale was lawful when it happened.
9. Your rights
From Account → Privacy & data on the web, or Account → Privacy in the apps, you can:
- See and download everything we hold about you, in a machine-readable file.
- Correct inaccurate or incomplete data.
- Erase data that we are not required to keep. Erasure anonymises your identity; statutory commercial records remain in anonymised form as described above.
- Nominate another person to exercise your rights in the event of your death or incapacity.
- Withdraw consent for anything you consented to, including marketing.
- Complain — see the Grievance Redressal Policy.
We respond within 30 days. If we cannot do what you asked, we tell you why.
10. Children
The Platform is for licensed businesses and is not directed at children. We do not knowingly process the personal data of anyone under 18. If you believe a child's data has reached us, contact the Grievance Officer and we will delete it.
11. Cookies and device storage
We use only strictly necessary browser storage. See the Cookie Policy.
12. Changes
Material changes are published here with a new version number, and where the law requires it we will ask for consent again. The version you accepted is recorded against your account.
13. Contact
Grievance Officer and Data Protection contact details are published at rysag.com/support and returned by the Platform at all times.
Security vulnerability reports: security@rysag.com — see /.well-known/security.txt.