Privacy Policy
Last updated: 12 August 2026
Effective date: 10/08/2026 | Version: 1.0
This Privacy Policy explains how WIZCODER AI LABS PRIVATE LIMITED (“GoldJewellers”, “we”, “us”, “our”) collects, uses, shares, stores and protects your personal data when you use:
the website https://goldjewellers.in/ and any sub-domain we operate;
the [CONSUMER APP NAME] mobile application for shoppers, on Google Play and the Apple App Store;
the [PARTNER APP NAME] mobile application for jewellers and business partners, on Google Play and the Apple App Store; and
any related pages, APIs, e-mails, push notifications and support channels.
We call all of the above, together, the “Platform”. By using the Platform you confirm that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Platform.
This Policy should be read together with our Terms of Use and our Disclaimer.
1. What the Platform is, and who we are
GoldJewellers is an online directory and discovery platform for jewellery and diamond businesses. Shoppers use it to search for jewellers, showrooms, designs and product listings by city, locality, category, material, occasion and price band, and to contact a jeweller, request an appointment or leave a review. Jewellers use it to list their business, showrooms and products, and to receive and manage enquiries.
We are an intermediary. We do not manufacture, own, sell, deliver, certify, value, insure or take payment for any jewellery, gold, silver, diamond or gemstone shown on the Platform. Every transaction is a private matter between you and the jeweller. This distinction matters for privacy too: once you choose to contact a jeweller, that jeweller becomes an independent controller of the information you send them.
Data Fiduciary / Controller: WIZCODER AI LABS PRIVATE LIMITED, 205 Shivalik Western, L.P. Savani Road, Adajan, Surat, Gujarat, 395009, India.
Contact for privacy matters: support@goldjewellers.in
2. The three kinds of people we hold data about
Visitors — anyone browsing the website or an app without signing in.
Registered Users (Shoppers) — people who sign in to save favourites, send enquiries, book appointments or post reviews.
Jewellers / Partners — businesses (and the individuals who represent them) who list on the Platform. Business-verification data such as GST and PAN is collected only from this group.
Some sections below apply only to one group; where that is the case we say so.
3. Information we collect
3.1 Information you give us directly
Category | What it includes | Who provides it |
|---|---|---|
Account details | E-mail address, first and last name, mobile number, profile photo (optional), city and state (optional), preferred language | Shoppers and Jewellers |
Sign-in data | We use passwordless e-mail one-time passcode (OTP) sign-in, and optionally Sign in with Google. If you use Google, we receive your Google account e-mail, name, profile picture and a Google user identifier. We never receive or store your Google password. We do not store a password for shopper or jeweller accounts at all. | Shoppers and Jewellers |
Business & verification details | Business/trade name, year established, business logo, business address, GSTIN, PAN, business contact numbers, and any supporting documents you upload when you apply to become a jeweller or claim an existing listing (for example a shop licence, GST certificate, utility bill or authorisation letter) | Jewellers only |
Listing content | Showroom name, description, address, PIN code, locality, map co-ordinates, phone, WhatsApp number, business e-mail, website, opening hours, photographs and gallery images, categories, and product information such as design name, code, metal, purity, weight, stone details, making charges and indicative price range | Jewellers only |
Enquiries and appointments | Your name, phone number, e-mail, the store or product concerned, preferred date and time, and any message or notes you write | Shoppers |
Reviews and ratings | Star rating, written review, photographs you attach, and the display name shown against the review | Shoppers |
Wishlist / saved items | The stores and products you save | Shoppers |
Correspondence | Messages sent through the contact form, support e-mails, grievance submissions, and our replies | Everyone |
Subscription & billing references | Chosen plan, billing cycle, invoice details, GSTIN for invoicing, and a transaction or subscription reference identifier returned by our payment processor | Jewellers only |
We never store your full card number, CVV, UPI PIN, net-banking credentials or bank OTP. Where paid plans are offered, payment is captured by a regulated payment gateway or by the app store's own billing system, and we retain only the reference identifier and status needed to activate your plan and raise an invoice.
3.2 Information collected automatically
Device and connection data — IP address, browser or app version, operating system, device model, screen size, language and time zone.
Identifiers — a randomly generated visitor identifier and session identifier stored on your device, plus your account identifier if you are signed in.
Usage data — pages and screens viewed, stores and products viewed, search terms you type, filters you apply, number of results returned, taps on “call”, “WhatsApp”, “directions” and “enquire” buttons, referring URL, and the date and time of each event.
Diagnostics — crash reports, error logs and performance timings.
We use this data to run and secure the Platform, to produce aggregate statistics, and to give each jeweller a count of how many people viewed and contacted their listing. Jewellers see aggregated and de-identified figures — they do not see your IP address, your identifier, or your activity on other listings.
3.3 Permissions the mobile apps may ask for
Every permission below is optional. You can decline it, or withdraw it later in your device settings, and continue to use the app - only the specific feature stops working.
Permission | Why we ask | If you decline |
|---|---|---|
Location (approximate or precise, while the app is in use) | To detect your city automatically, sort jewellers by distance, power “near me” search, and let a jeweller pin the exact map location of a showroom | You simply choose your city from a list. We do not collect location in the background and do not build a location history. |
Camera | To take a photo for a review, a product listing, a store gallery or a verification document | You can still upload an existing image from your gallery |
Photos / media / files | To select and upload images and documents | Image upload is unavailable |
Notifications | To alert you about the status of an enquiry, an appointment confirmation, a listing approval, or an account or security event. We register a push token with Google Firebase Cloud Messaging along with your device's user-agent string. | You receive the same information by e-mail and inside the app |
We do not request access to your contacts, call logs, SMS, microphone, health data, calendar or installed-app list, and we do not read your clipboard.
3.4 Information from other sources
Publicly available business information. To make the directory useful from day one, some jeweller listings are compiled from publicly accessible business directories and map services. These contain business contact details (shop name, address, phone, opening hours, public photographs, public ratings) — not private personal data. Such listings are marked as unclaimed until the owner claims and verifies them. If you are a business owner and want your listing corrected or removed, see section 12.
Google, if you choose Sign in with Google (see 3.1).
Our payment processor, for the status of a subscription payment.
Cloudflare Turnstile, which returns a pass/fail signal telling us whether a form submission is likely to be automated.
3.5 Sensitive personal data
We do not knowingly collect biometric data, financial account credentials, health data, sexual orientation, caste, religion, political affiliation, genetic data or government identity numbers other than the GSTIN and PAN of a business, which are collected from jewellers only, for tax-invoice and business-verification purposes. Please do not enter sensitive information in free-text fields such as enquiry notes or reviews.
4. Why we use your data, and our lawful basis
Under India's Digital Personal Data Protection Act, 2023 we process personal data either with your consent or for a permitted legitimate use. Where the EU/UK GDPR applies to a visitor, the equivalent basis is shown in brackets.
Purpose | Data used | Basis |
|---|---|---|
Create and secure your account; send and verify sign-in OTPs | Account details, sign-in data, device data | Performance of our Terms (contract) |
Show the directory, run search, filters and “near me” results | Usage data, optional location | Contract; consent for location |
Deliver your enquiry or appointment request to the jeweller you chose | Name, phone, e-mail, message, store/product | Contract — this is the service you asked for |
Publish your review and update the store's rating | Review text, rating, images, display name | Consent, withdrawable by deleting the review |
Verify a jeweller, approve or reject a listing, process a listing claim | Business and verification details, uploaded documents | Contract; legal obligation; legitimate interest in a trustworthy directory |
Send transactional notifications and e-mails | E-mail, push token | Contract |
Send offers, newsletters and promotional messages | E-mail, push token | Consent — opt out at any time |
Measure traffic, improve ranking and features, produce aggregate insights for jewellers | Usage and device data, identifiers | Legitimate use / legitimate interest |
Detect fraud, fake listings, fake reviews, scraping and abuse; enforce our Terms | Device data, IP, usage patterns, captcha signal | Legitimate use / legitimate interest |
Raise invoices, manage subscriptions, comply with tax and accounting law | Billing references, GSTIN, business details | Legal obligation |
Respond to grievances, legal notices, court orders and regulator requests | Whatever is relevant | Legal obligation |
We do not sell your personal data. We do not share your personal data with data brokers, and we do not use your personal data to train third-party advertising profiles.
5. Who we share data with
5.1 The jeweller you contact
When you submit an enquiry, request an appointment, or claim an offer, we pass your name, phone number, e-mail address and your message to that specific jeweller so they can respond. This is the whole point of the enquiry, and it cannot be switched off while still sending the enquiry. From that moment the jeweller is independently responsible for how they use your details, and their own privacy practices apply. We require jewellers to use enquiry data only to answer you, but we are not responsible for a jeweller's independent conduct. If a jeweller misuses your details, please report it to us at support@goldjewellers.in.
5.2 Service providers who process data on our instructions
Provider | What it does | Where processing happens |
|---|---|---|
Cloud hosting & database provider | Runs our servers and stores the database | [HOSTING REGION] |
Object storage (S3-compatible) | Stores uploaded images and documents | [STORAGE REGION] |
Google Firebase Cloud Messaging | Delivers push notifications | Global |
Google (Sign in with Google) | Optional sign-in | Global |
Transactional e-mail provider | Sends OTPs, alerts and notifications | [EMAIL PROVIDER REGION] |
Cloudflare Turnstile | Blocks automated form abuse | Global |
Map and geocoding provider | Converts addresses to map co-ordinates and renders maps | Global |
Search infrastructure | Powers fast on-site search | [HOSTING REGION] |
Payment gateway / app-store billing | Collects subscription payments from jewellers | India / global |
Each provider is bound by contract to process data only for the purpose we specify, to keep it confidential, and to apply appropriate security. An up-to-date list of providers is available on request from support@goldjewellers.in.
5.3 Other disclosures
Legal and regulatory — where disclosure is required by law, by a court or by a government agency lawfully authorised to demand it, or to establish, exercise or defend legal claims.
Safety and enforcement — to prevent or investigate fraud, impersonation, counterfeit listings, threats to life or property, or breaches of our Terms.
Corporate transaction — if we are involved in a merger, acquisition, restructuring or sale of assets, your data may transfer to the successor, who will remain bound by this Policy. We will notify you before your data becomes subject to a materially different policy.
Public content — anything you deliberately publish (a review, a public profile name, a store listing) is visible to everyone, may appear in search-engine results, and may be quoted or cached by third parties beyond our control.
6. Cookies and similar technologies
On the website we use:
Strictly necessary cookies — a secure, HTTP-only session cookie that keeps you signed in, plus cookies for security and load balancing. The site cannot function without these.
Preference storage — your chosen city, language and recently viewed items, kept in your browser's local storage.
Analytics identifiers — a first-party visitor identifier used to count unique visits and understand which searches succeed.
You can clear or block cookies through your browser settings; blocking strictly necessary cookies will sign you out and break parts of the site. The mobile apps use equivalent local storage rather than browser cookies. We do not run third-party advertising cookies or cross-site tracking pixels, and we do not participate in cross-app tracking. On iOS we therefore do not present an App Tracking Transparency prompt, because we do not track you across apps and websites owned by other companies.
7. How long we keep data
Data | Retention |
|---|---|
Account profile | Until you delete your account, then removed or irreversibly anonymised within 30 days (see section 9) |
Behavioural analytics events (page views, searches, clicks) | 90 days, after which the raw rows are deleted automatically; only aggregate counts survive |
Enquiries and appointment records | 3 years from creation, so that both sides have a record of the conversation, unless you ask us to delete sooner |
Reviews | Until you delete the review or your account; we may retain an anonymised rating so store averages stay accurate |
Store and product listings | For as long as the listing is active, plus 90 days after removal to allow restoration |
Jeweller verification documents (GST, PAN, proofs) | Duration of the business relationship plus the period required by tax and company law, currently up to 8 years |
Invoices, billing and tax records | As required by Indian tax law, currently up to 8 financial years |
Security, access and audit logs | Up to 180 days, or longer where preserved for an ongoing investigation |
Grievance and support correspondence | 3 years from resolution |
Where we are required to preserve data under the Information Technology Act, 2000 or rules made under it, we retain it for the mandated period even after account deletion, and only for that purpose.
8. Your rights
8.1 If you are in India (DPDP Act, 2023)
Right to access a summary of the personal data we process about you, and the identities of those we have shared it with.
Right to correction and completion of inaccurate or incomplete data, and updating of outdated data.
Right to erasure of your personal data where it is no longer needed for the purpose it was collected for and no law requires us to keep it.
Right to withdraw consent at any time, as easily as you gave it. Withdrawal does not affect processing already carried out.
Right to nominate another individual to exercise your rights in the event of your death or incapacity.
Right of grievance redressal — you may complain to our Grievance Officer (section 13) and, if unsatisfied, to the Data Protection Board of India.
The Act also places duties on you: please provide accurate information, do not impersonate anyone, and do not file false or frivolous grievances.
8.2 If the GDPR or UK GDPR applies to you
You additionally have the rights to restrict or object to processing, to data portability in a machine-readable format, not to be subject to solely automated decision-making with legal effect (we do not carry out such decision-making), and to lodge a complaint with your local supervisory authority.
8.3 If you are a California resident
You may request to know the categories and specific pieces of personal information collected, to delete it, and to correct it, and you will not be discriminated against for exercising those rights. We do not sell or share personal information for cross-context behavioural advertising as those terms are defined by the CCPA/CPRA.
8.4 How to exercise a right
Use the in-app controls where available, or write to support@goldjewellers.in from the e-mail address registered on your account. We respond within 30 days. We may ask you to verify your identity before acting, and we may decline a request where the law permits — in which case we will tell you why.
9. Deleting your account and your data
You can delete your account at any time. There are three routes, and all three lead to the same outcome:
In either mobile app: Profile → Account Settings → Delete Account, then confirm.
On the website: sign in and go to Profile → Delete Account, or visit https://goldjewellers.in//account/delete.
By e-mail: write to support@goldjewellers.in from your registered address with the subject “Delete my account”.
What is deleted: your profile, name, e-mail, phone number, profile photo, wishlist, saved searches, push tokens, session records and behavioural analytics tied to your account.
What is retained, and why: reviews may be kept in de-identified form so that store ratings remain accurate; enquiry and appointment records already delivered to a jeweller remain with that jeweller and in our records for the retention period in section 7; invoices, tax records and jeweller verification documents are retained where tax, company or IT law obliges us; and records preserved for an ongoing investigation or legal claim are retained until it concludes. Backups are rotated on a [BACKUP RETENTION] cycle, so residual copies disappear within that window.
Deletion completes within 30 days of a verified request. A jeweller account with an active paid subscription must cancel the subscription first; deletion does not by itself trigger a refund.
If you would rather not delete everything, you can instead ask us to deactivate your listings, unsubscribe from marketing, or remove specific reviews or images.
10. Security
We apply reasonable security practices and procedures in line with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011:
All traffic between your device and our servers is encrypted with TLS.
Sign-in uses one-time passcodes with a short expiry and HMAC verification; shopper and jeweller accounts have no stored password to steal. Administrator passwords are stored only as salted hashes.
Session tokens are issued as signed JWTs and, on the web, held in secure, HTTP-only cookies that JavaScript cannot read.
Rate limiting, account lockout after repeated failed attempts, and CAPTCHA protection on public forms.
Role-based access control, with staff access limited to what their role requires and access logged.
Encryption at rest for the database and uploaded files, and regular patching and backups.
No system is perfectly secure. If we become aware of a personal data breach that is likely to affect you, we will notify you and the Data Protection Board of India (and CERT-In where applicable) without undue delay and in the manner the law requires. Please help us by never sharing your OTP with anyone — no one from GoldJewellers will ever ask you for it.
To report a security vulnerability, write to support@goldjewellers.in. We will not pursue good-faith researchers who report responsibly and do not access or destroy other users' data.
11. Children
The Platform is intended for users aged 18 and over. We do not knowingly collect personal data from children (under Indian law, anyone under 18), and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. Our apps are not listed in any children's or family category on Google Play or the App Store. If we learn that we have collected data from a child without verifiable parental consent, we will delete it promptly. A parent or guardian who believes their child has provided us data should contact support@goldjewellers.in.
12. Business listings, including unclaimed ones
Listings compiled from publicly available sources contain business contact information rather than private personal data, and are shown so that shoppers can find jewellers in their area. If you own or represent a business and wish to claim, correct, unpublish or remove a listing, you can claim it through the Platform after verification, or write to support@goldjewellers.in with the listing URL and proof of your association with the business. We act on verified requests within 15 days.
13. Cross-border transfers
Our primary infrastructure is located in [HOSTING REGION]. Some service providers listed in section 5.2 — notably push notification, e-mail, map and bot-protection services — process limited data outside India. Where personal data leaves India we transfer it only to countries not restricted by the Central Government under the DPDP Act, and we put contractual safeguards in place. For transfers out of the EEA or UK we rely on Standard Contractual Clauses or an equivalent approved mechanism.
14. Marketing and notifications
Transactional messages — OTPs, enquiry updates, appointment confirmations, listing approvals, security alerts and billing notices — are part of the service and cannot be turned off while your account is active.
Promotional messages — offers, new-jeweller announcements and newsletters — are sent only with your consent. Withdraw it at any time using the unsubscribe link in any e-mail, the notification settings in the app, or by writing to support@goldjewellers.in. We honour Indian TRAI/DND preferences for commercial SMS and calls.
15. Third-party links and jeweller premises
The Platform links to jeweller websites, social media profiles, WhatsApp, map applications and dialler apps. Once you follow a link or place a call, you leave our Platform, and the third party's own privacy policy governs. We are not responsible for their content or practices. Anything you do at a physical showroom — including CCTV recording or KYC collected by the jeweller — is entirely between you and that business.
16. Changes to this Policy
We may update this Policy as the Platform, the law or our providers change. The version number and effective date at the top always reflect the current version. For material changes we will give notice at least 7 days in advance by e-mail, in-app notice or a banner on the website. Continuing to use the Platform after the effective date means you accept the updated Policy; if you do not accept it, please delete your account. Previous versions are available on request.
17. Grievance Officer and how to complain
In accordance with the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Consumer Protection (E-Commerce) Rules, 2020 and the Digital Personal Data Protection Act, 2023, the details of our Grievance Officer are:
Grievance Officer | Bhargav Patel |
|---|---|
Designation | Grievance Officer & Data Protection Contact |
Company | WIZCODER AI LABS PRIVATE LIMITED |
Address | 205 Shivalik Western, L.P. Savani Road, Adajan, Surat, Gujarat, 395009, India |
Phone | |
Working hours | Monday to Friday, 10:00 to 18:00 IST (excluding public holidays) |
We acknowledge every complaint within 24 hours and resolve it within 15 days of receipt. Complaints about unlawful content that violates a person's privacy or dignity are actioned within 72 hours. Please include your registered e-mail, a clear description of the issue, the relevant URL or screenshot, and what outcome you are seeking.
If you are not satisfied with our response, you may escalate to the Data Protection Board of India, or to the appropriate consumer forum or supervisory authority in your jurisdiction.
18. How to reach us
WIZCODER AI LABS PRIVATE LIMITED
205 Shivalik Western, L.P. Savani Road, Adajan, Surat, Gujarat, 395009, India
General support: support@goldjewellers.in
Privacy matters: support@goldjewellers.in
Grievances: support@goldjewellers.in













