- We collect only what we need to value your gold, close your loan, pay you and meet KYC and tax laws.
- We never sell your data. We share it only with your lender, banks, verification agencies, service providers and authorities, as needed.
- KYC and transaction records are kept for at least five years because the law requires it. Other data is deleted when no longer needed.
- You can access, correct or erase your data, withdraw consent and nominate someone, by contacting our Grievance Officer.
This summary helps you read the document. The full text below is what applies.
01Who we are
Tracemetal Private Limited (CIN U32111KA2024PTC187918) (“Tracemetal”, “we”, “us”) is the Data Fiduciary for the personal data described in this policy under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the rules made under it.
This policy also meets our obligations under the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. It applies to our website, valuation requests, branches, phone and WhatsApp conversations, and every gold release and purchase transaction.
02Personal data we collect
| Category | Examples | When |
|---|---|---|
| Contact details | Name, mobile number, email, city | Valuation request, calls, messages |
| Identity and KYC | PAN, Aadhaar (masked, or verified through authorised methods), other officially valid documents, photograph, signature | Before a transaction |
| Financial details | Bank account number and IFSC, cancelled cheque or passbook, gold loan account, pledge receipt, outstanding dues | Before a transaction |
| Transaction details | Description, weight and purity of gold, valuation report, amounts paid, invoices, signed agreements | During a transaction |
| Audio and video | CCTV footage at branches and recordings of gold testing | At branches and during testing |
| Technical data | IP address, browser and device type, pages visited, essential cookies | When you use the website |
Financial information such as bank account details is sensitive personal data under the 2011 Rules and is handled with additional safeguards. We do not collect biometric information. We collect only what is necessary for the purposes below.
03How and why we use your data
We process personal data on the basis of your consent, or for legitimate uses permitted by the DPDP Act, to:
- respond to your valuation request and give you an estimate;
- verify your identity and ownership of the gold, and carry out KYC;
- close your gold loan with your lender and complete the purchase of your gold;
- make payments to your lender and to your verified bank account;
- comply with laws, including the Prevention of Money-Laundering Act, 2002, the Income-tax Act, 1961 and the GST laws, and respond to lawful requests from authorities;
- prevent fraud, detect spurious or stolen gold, and protect the safety of customers, staff and property;
- resolve disputes and grievances, and establish or defend legal claims; and
- send you service messages and, only with your consent, information about our services.
We do not sell your personal data, and we do not use it for any purpose that is incompatible with the above.
04Consent and withdrawal
Where we rely on consent, we will ask for it through a clear notice in English and, on request, in any language listed in the Eighth Schedule to the Constitution of India. You may withdraw consent at any time by contacting our Grievance Officer. Withdrawal is as easy as giving consent. It does not affect processing already carried out, or data we must retain by law. If you withdraw consent needed for a transaction in progress, we may be unable to continue that transaction.
06Where your data is stored
We store personal data on servers located in India wherever reasonably possible. If any data is processed outside India by a service provider, we will do so only as permitted under section 16 of the DPDP Act, and never to a country restricted by the Central Government, with equivalent protection in place.
07How long we keep data
We keep personal data only as long as necessary for the purpose, or as required by law:
- KYC and transaction records: at least five years after the transaction, as required under the Prevention of Money-Laundering Act, 2002 and its rules, and longer where tax laws require;
- Accounting and tax records: for the periods required under the Companies Act, 2013, the Income-tax Act, 1961 and the GST laws;
- CCTV and testing recordings: up to 90 days, unless needed for an investigation, dispute or legal claim;
- Valuation requests that do not lead to a transaction: up to 12 months, or earlier if you ask us to delete them.
After these periods, we securely delete or anonymise the data.
08How we protect your data
We follow reasonable security practices consistent with the 2011 Rules and recognised standards such as IS/ISO/IEC 27001. These include encryption in transit, role-based access controls, audit logs, secure storage of physical documents, staff confidentiality obligations and regular reviews. If a personal data breach occurs, we will inform the Data Protection Board of India and affected persons as required under the DPDP Act and its rules, and take steps to contain it.
09Your rights
Under the DPDP Act, you have the right to:
- obtain a summary of your personal data we process and the processing activities;
- know the identities of other Data Fiduciaries and Data Processors with whom your data was shared;
- correct, complete or update inaccurate or incomplete data;
- request erasure of data that is no longer needed, subject to retention required by law;
- withdraw consent;
- nominate another person to exercise your rights in the event of your death or incapacity; and
- have your grievances redressed.
To exercise these rights, contact our Grievance Officer. We may ask you to verify your identity before acting on the request. You also have duties under section 15 of the DPDP Act, including not providing false information or impersonating another person.
10Children
Our services are only for persons aged 18 and above. We do not knowingly collect personal data of children. If we learn that we have collected a child's data without verifiable consent of a parent or lawful guardian, we will delete it.
12Calls and messages
When you submit a request, we contact you by phone, SMS, WhatsApp or email about it. We send promotional messages only with your consent and in line with the Telecom Commercial Communications Customer Preference Regulations. You can opt out of promotional messages at any time by replying STOP or by contacting us.
13Grievance Officer
For any question, complaint or request about your personal data or this policy, contact our Grievance Officer:
- Phone
- +91 99864 74446
- Hours
- Monday to Saturday, 9:30 am – 7:00 pm (except public holidays)
- Post
- Grievance Officer, Tracemetal Private Limited, at our registered office
- Timelines
- Acknowledgement within 48 hours. Resolution within 30 days of receipt.
We will acknowledge your complaint within 48 hours and resolve it within 30 days. If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India under the DPDP Act, after first using our grievance process.
14Changes to this policy
We may update this policy from time to time. The updated version will be posted on this page with a new “last updated” date. Where changes are significant, we will notify you through the website or by message and, where required, seek fresh consent.