Privacy Policy
Effective date: 9 September 2026 | Last updated: 9 September 2026
This policy applies to https://akinfotools.com/, the AKINFO Tools mobile application, and our WhatsApp Business service on +91 88516 30600.
IN SHORT
We collect your phone number, email address and delivery details so that we can sell you mobile repair tools and parts, deliver them to you, and let you sign in securely. We send login codes and order updates over WhatsApp, which means your phone number is processed by Meta, who operate the WhatsApp Business Platform. We do not sell your personal data, and we do not send marketing on WhatsApp unless you have asked us to. You can opt out of WhatsApp messages, and you can ask us to delete your account, at any time.
1. WHO WE ARE
Akinfo Tools Private Limited ("AK Info Tools", "we", "us") sells mobile phone spare parts, repair tools and related equipment through https://akinfotools.com/ and the AKINFO Tools mobile application.
For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act") we are a Data Fiduciary and you are a Data Principal. Where the EU or UK General Data Protection Regulation applies, we act as a data controller.
2. INFORMATION WE COLLECT
2.1 Information you give us
- Identity and contact details – your name, mobile number and email address, used to create your account, sign you in and communicate about your orders.
- Delivery details – shipping and billing address, city, state, PIN code, country and company name where supplied, used to deliver your order and raise an invoice.
- Order records – the items you ordered, amounts, order status, invoices and returns, used for fulfilment, support and statutory record-keeping.
- Communication preferences – whether you have opted in to newsletters or promotional messages.
- Support correspondence – messages you send us by chat, email or WhatsApp.
2.2 Information collected through WhatsApp
When you receive a message from us on WhatsApp, or message our business number, we collect and store:
- your WhatsApp phone number and the WhatsApp identifier associated with it;
- message metadata – the unique message identifier, timestamps, and the delivery status reported back to us (sent, delivered, read or failed);
- error information where a message could not be delivered, so that we can diagnose the problem; and
- the content of any message you choose to send us for support.
We record delivery receipts. When we send you a login code, WhatsApp tells us whether it was delivered and whether it was read. We keep this so that we can tell whether a code reached you when you report a sign-in problem. We do not read the content of the codes we send, and we cannot read your other WhatsApp conversations.
2.3 Information collected automatically
- Technical data such as your IP address, browser type, device information and the pages you visit, recorded in our server logs.
- Cookies and similar technologies, used to keep you signed in, remember your cart and understand how the site is used.
2.4 Payment information
Card and banking details are collected and processed directly by our payment gateway. We do not receive, store or have access to your full card number, CVV or banking credentials. We receive only a transaction reference, the amount, and whether the payment succeeded.
3. HOW WE USE YOUR INFORMATION
We use personal data only for the purposes set out below.
- Authentication – sending one-time passcodes so that you can sign in securely, and verifying the code you enter.
- Order fulfilment – processing your order, arranging delivery, issuing invoices and handling returns and refunds.
- Service messages – order confirmations, packing and dispatch updates and delivery notifications.
- Customer support – responding to your questions and resolving complaints.
- Security and fraud prevention – detecting abuse, limiting repeated sign-in attempts and protecting accounts.
- Legal compliance – meeting our tax, accounting and consumer-protection obligations.
- Marketing – only where you have separately opted in, and you may withdraw that consent at any time.
What we do not do: we do not sell your personal data; we do not rent or trade contact lists; we do not use WhatsApp to send marketing without your consent; and we do not use your data to make automated decisions that produce legal effects for you.
4. OUR LEGAL BASIS
Under the DPDP Act we process personal data on the basis of your consent, given when you create an account or place an order, and for certain legitimate uses permitted by the Act such as complying with a legal obligation.
Where the GDPR applies, our legal bases are:
- performance of a contract – processing your order and delivering goods;
- legitimate interests – securing accounts, preventing fraud and improving our service;
- legal obligation – retaining tax and transaction records; and
- consent – marketing communications and non-essential cookies.
5. HOW WE SHARE INFORMATION
We do not sell your personal data to anyone, for any purpose.
We share data only with service providers who help us operate, and only to the extent needed for them to perform their function. Each is bound to protect it and may not use it for their own purposes.
- Meta Platforms (WhatsApp Business Platform) – your phone number and the content of the messages we send you, so that login codes and service messages can be delivered.
- Payment gateway – the order amount, order reference and the contact details needed to process your payment securely.
- Logistics partners – your name, delivery address and phone number, so that your order can be delivered and the courier can contact you.
- SMS provider – your mobile number and the message text, so that login codes can be sent by SMS.
- Support tools – information you provide in a chat or support ticket, so that we can handle your request.
- Authorities – only what is legally required, where we are compelled by law or a court order, or where necessary to protect rights and safety.
If our business is transferred or merged, personal data may transfer with it. We will notify you, and the receiving party will remain bound by this policy or an equivalent one.
6. WHATSAPP MESSAGING
We use the WhatsApp Business Cloud API, operated by Meta, to send you authentication codes and service messages from +91 88516 30600.
6.1 What we send
- Authentication codes – one-time passcodes for signing in. These expire after 10 minutes and can be used only once.
- Service messages – order confirmations, packing and dispatch updates relating to an order you have placed.
We do not send promotional or marketing content on WhatsApp unless you have separately opted in.
6.2 Meta's role
Meta processes your phone number and message content in order to deliver our messages, and reports the delivery status back to us. Meta's own handling of that data is governed by the WhatsApp Privacy Policy, which we recommend you review as it covers matters outside our control.
6.3 Message metadata we retain
For each message we send we retain the message identifier, the recipient number, timestamps, the delivery status and any error reported. We use this solely to confirm whether a message reached you and to diagnose delivery problems.
6.4 Opting out
You may reply STOP to any WhatsApp message from us, or block our number, and we will stop sending you WhatsApp messages. You may also contact us using the details in section 13.
Please note: authentication codes are a security function rather than marketing. If you opt out of WhatsApp we will send your login codes by SMS or email instead. If you opt out of every channel we may be unable to verify your identity, and you may not be able to sign in.
7. HOW LONG WE KEEP DATA
- Account details – while your account is active, and for a reasonable period afterwards.
- Order and invoice records – as required by applicable tax and accounting law.
- One-time passcodes – these expire after 10 minutes and are cleared once used.
- WhatsApp delivery metadata – retained for troubleshooting, then deleted on a rolling basis.
- Server and security logs – for a limited period, for security and diagnostics.
- Support correspondence – for as long as needed to resolve the matter and evidence how it was handled.
When data is no longer required we delete it or irreversibly anonymise it.
8. YOUR RIGHTS AND CHOICES
Subject to applicable law, you have the right to:
- access a summary of the personal data we hold about you and how we process it;
- correct or complete data that is inaccurate or out of date;
- erase your personal data where it is no longer needed for the purpose it was collected;
- withdraw your consent at any time, without affecting processing already carried out;
- raise a grievance with us and receive a response; and
- nominate another individual to exercise your rights in the event of death or incapacity, as provided under the DPDP Act.
Where the GDPR applies you additionally have rights to data portability, to restrict or object to processing, and to lodge a complaint with your supervisory authority.
8.1 How to exercise them
Email us at akinfowebwork@gmail.com, or use the contact details in section 13, stating what you would like us to do. We may need to verify your identity before acting, which protects you against someone else making a request in your name. We respond within 30 days, and if we cannot act on a request we will tell you why.
8.2 Deleting your account
You may request deletion of your account at any time using the contact details below, or through the account deletion page or the account deletion option in the AKINFO Tools mobile application. We will delete your personal data except where we are legally required to retain certain records, for example invoices for completed orders which tax law obliges us to keep.
9. DATA SECURITY
We maintain technical and organisational safeguards appropriate to the sensitivity of the data we hold:
- Encryption in transit – the website, mobile application and all payment flows are served over HTTPS/TLS.
- Passwordless authentication – sign-in uses one-time passcodes rather than stored passwords, and codes expire after 10 minutes.
- Abuse controls – limits on how often codes may be requested and on the number of incorrect attempts, protecting accounts against brute-force attacks.
- Credential separation – integration secrets are stored outside the public web directory with restricted file permissions, and are never written to logs.
- Access control – staff access is limited to those who need it for their role, and administrative accounts can be revoked immediately.
- Payment isolation – card data never reaches our servers; it is handled entirely by the payment gateway.
- Monitoring – server, application and delivery logs are reviewed to detect faults and suspicious activity.
No system can be guaranteed completely secure. If a personal data breach occurs that is likely to affect you, we will notify you and the relevant authority as required by law, including the reporting obligations under the DPDP Act.
10. INTERNATIONAL TRANSFERS
Some of our service providers, including Meta, operate infrastructure outside India. Where personal data is transferred internationally we rely on the transfer mechanisms those providers put in place, such as standard contractual clauses, and we take reasonable steps to ensure the data continues to be protected to the standard described in this policy.
11. CHILDREN
Our services are intended for business and trade customers and are not directed at children. We do not knowingly collect personal data from anyone under 18 years of age. If we become aware that we have done so we will delete it. If you believe a child has provided us with personal data, please contact us.
12. CHANGES TO THIS POLICY
We may update this policy to reflect changes in our services or the law. The "Last updated" date at the top of this page will always show the current version. Where changes are significant we will give you notice through the website, the application, or by contacting you directly.
13. GRIEVANCE OFFICER AND CONTACT
In accordance with the DPDP Act and the Information Technology Act, 2000, we have designated a Grievance Officer to address questions and complaints about how we handle personal data.
- Entity: Akinfo Tools Private Limited
- Grievance Officer: MD Adnan Ansari, Website Administrator
- Email: akinfowebwork@gmail.com
- Phone: +91 96400 57000
- WhatsApp: +91 88516 30600
- Principal place of business: AKINFO TOOLS PRIVATE LIMITED, S/o Late Mr. K. L. Kapoor, 625/626/2, Double Storey, New Rajendra Nagar, Delhi, Central Delhi, Delhi – 110060, India
- Response time: we acknowledge grievances within 48 hours and aim to resolve them within 30 days
If you are not satisfied with our response you may escalate to the Data Protection Board of India. Individuals in the EU or UK may complain to their local supervisory authority.
