1. Who is responsible
The operator of nearsubs.com is the Data Fiduciary for the personal data described here, within the meaning of the Digital Personal Data Protection Act 2023.
2. What we collect
If you are a customer
| What | Why |
|---|---|
| Email address | Signing in (a six-digit code), and sending you subscription and bill notices |
| Name, mobile number | So the vendor delivering to you knows who to look for and can call |
| Delivery address - house and street, area, city, pincode, landmark | Given to the vendor you subscribe to, so they can find you |
| Subscriptions, pauses, delivery history | Running the service and showing you what you have taken |
| Bill records and payment screenshots you choose to upload | So a vendor can match your payment to the right month. See what we do not hold |
If you are a vendor
Your business name and owner name, email, phone, category, city, delivery areas, address, website and social handles, plan and price details, photographs you upload, and your UPI ID and QR image. Most of this is deliberately public - it is your storefront.
If you join the waitlist
Email, and optionally name, phone, city and the services you want. We use it to decide which city to open next and to tell you when we arrive.
Technical
Our servers log the usual request information - IP address, browser user agent, the page requested, the time - for security and diagnostics. Sessions record the IP and user agent they were created from, so you can recognise a session that is not yours.
3. What we deliberately do not collect
- No card, bank or UPI credentials. There is no payment gateway on this platform. Customers pay vendors directly, and that money never passes through us. A vendor's UPI ID is stored because it is printed on their own storefront; a customer's payment credentials are never seen by us at all.
- No advertising or analytics trackers. No Google Analytics, no pixels, no third-party tags, no session recording. See cookies below.
- No location tracking. We know the address you typed. We do not follow a device.
- No profiling or automated decisions that produce legal or similarly significant effects.
4. Why we are allowed to hold it
Under the DPDP Act 2023 we rely on your consent, given when you create an account, place a subscription request or submit a form; and on certain legitimate uses, such as keeping records we are legally required to keep and preventing fraud or misuse. You may withdraw consent at any time - see your rights.
5. Who else sees it
- The vendor you subscribe to. They see your name, phone, delivery address, plan, delivery days, pauses and what you owe them. They have to: they are bringing it to your door. They see nothing about your subscriptions with any other vendor.
- Brevo (Sendinblue), our email provider, which delivers your sign-in codes and notices. It receives your email address and the content of those messages.
- Our hosting provider, on servers in India, which stores the database and uploaded images.
- Our own operators, for support and for keeping the marketplace honest. Customer contact details are masked by default in the operator console and can only be revealed by a senior operator through an action that is logged before the data is shown.
- Authorities, where we are required by law to disclose something.
We do not sell personal data, and we do not share it with advertisers.
6. Cookies
We set five cookies, and every one of them is strictly necessary - remove any and you cannot sign in or stay signed in:
| Name | What it does | Lasts |
|---|---|---|
ns_customer_sessionns_vendor_session | Keeps you signed in. Holds a random token, not your details, and is readable only by the server rather than by JavaScript. | 30 days |
ns_admin_session | The same for a NearSubs operator. Set only on our operator host, and never sent to nearsubs.com. | 12 hours |
ns_csrfns_admin_csrf | A random value the page echoes back with every change you make, so another site cannot make that change on your behalf while you are signed in. | Session |
There are no analytics or advertising cookies and no third-party tags, which is why you are not asked to consent to any. If that ever changes we will ask first, and this page will say so.
We also keep one item in your browser's own storage, nearsubs.city, holding the city you last browsed so the site does not ask again on every page. It is never sent to our servers, and clearing your browser data removes it.
Your browser can block or delete cookies under its privacy settings. Because ours hold your session, blocking them means you cannot sign in - everything you can do without an account still works.
7. How long we keep it
- Account and subscription records: while your account is open.
- Delivery and billing records: retained after a subscription ends, because they are the vendor's book of account and may be needed for tax and dispute purposes - ordinarily up to eight years.
- Payment screenshots: until the bill is settled, or until you remove them.
- Sign-in codes: ten minutes, and single-use.
- Waitlist entries: until we open your city, or until you ask us to remove you.
- Server logs: kept only while they are useful for security and debugging, and never used to build a profile of you.
8. How it is protected
- Everything is served over HTTPS.
- There are no customer or vendor passwords to steal - sign-in is a six-digit code, hashed before it is stored, valid for ten minutes, single-use, and rate limited.
- Session tokens are stored only as a hash, so a copy of our database cannot be replayed as a login.
- The operator console is on a separate host with its own host-only session, password plus an authenticator app, and every cross-account action writes an audit record naming the operator.
- Every query for your data is scoped to your own account on the server, not filtered in the browser.
No system is perfectly secure. If a breach affects you, we will inform you and the Data Protection Board as the DPDP Act requires.
9. Your rights
Under the DPDP Act 2023 you may ask us to:
- tell you what personal data we hold about you and who we have shared it with;
- correct anything inaccurate, or complete anything incomplete;
- erase it, where we are not required to keep it - note that a vendor's billing record of a delivery already made is generally something they must keep;
- withdraw a consent you previously gave;
- nominate someone to exercise these rights if you die or become incapacitated.
Much of this you can do yourself: your name, phone, addresses and subscriptions are all editable from your account. For anything else, write to us below.
10. Children
NearSubs is not for anyone under 18, and we do not knowingly collect data about children. If you believe we hold data about a child, tell us and we will delete it.
11. Changes
We will update this page when what we do changes, and change the date at the top. Where a change is significant we will tell registered users by email.
Contact and grievances
Write to support@nearsubs.com for anything about your account, your data or a vendor.
In line with the Consumer Protection (E-Commerce) Rules 2020 and the Information Technology (Intermediary Guidelines) Rules 2021, our Grievance Officer is:
We acknowledge a complaint within 48 hours and aim to resolve it within 30 days of receipt.