Privacy Policy

Home | Privacy Policy

Version 1.0

MSME LEAP Privacy Policy & Data Protection Framework

Effective Date: January 1, 2026 | Last Revised: September 2026 | DPDP Act (2023) Compliant


At MSME LEAP (referred to as "Platform", "MSME Leap", "We", "Us", or "Our"), accessible from msmeleap.com, we respect the privacy of our verified business members, suppliers, buyers, and visitors. This Privacy Policy details how we collect, handle, safeguard, and process corporate and personal data in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000.

Section 01

Introduction & Scope of Policy

This Privacy Policy outlines how MSME LEAP collects, uses, protects, and discloses information gathered through your use of our digital B2B marketplace portal, mobile-responsive interfaces, APIs, and member communication channels.

By registering on the platform, claiming an enterprise profile, posting buy requirements, submitting supplier catalogs, or communicating with counterparties, you acknowledge the practices described in this document.

Scope of B2B Commercial Engagement

MSME LEAP is a business-to-business (B2B) network. The majority of information collected pertains to legal entities, corporate enterprises, manufacturing facilities, product inventories, and authorized business representatives operating in commercial capacities.

Section 02

Information We Collect

We collect information to facilitate transparent B2B trade discoveries and verify member legitimacy. The information categories include:

A. Enterprise & Representative Profile Data
  • Legal Business Details: Legal entity name, trade name, year of establishment, business constitution (Proprietorship, Partnership, LLP, Private Limited, Public Limited).
  • Statutory Verification Identifiers: Goods and Services Tax Identification Number (GSTIN), Permanent Account Number (PAN), Udyam Registration Certificate number, and related municipal trade licenses.
  • Authorized Contact Information: Name of representative, designation, registered office address, factory/warehouse addresses, corporate email, and verified mobile numbers.
B. Marketplace Listings, Inquiries & RFQs
  • Catalog & Specification Data: Product titles, categories, technical specifications, HS Codes, pricing indicators, Minimum Order Quantities (MOQ), and product media/brochures.
  • Procurement Requirements: Buy lead titles, required quantities, target destination pin codes, delivery timelines, and technical purchase descriptions.
  • Inquiries & Quotations: RFQ responses, negotiated price quotations, and direct buyer-seller messages initiated via the platform.
C. Technical & Diagnostic Logs
  • Device & Network Data: Internet Protocol (IP) address, browser user-agent string, operating system, network provider, and referring URL parameters.
  • Platform Interaction Logs: Timestamps of logins, search queries entered, product page views, OTP request attempts, and session durations.
Section 03

Purpose of Data Collection & Processing

We process collected data under lawful bases recognized under Indian data protection regulations, exclusively for legitimate B2B marketplace objectives:

  • Account Setup & Authentication: Creating secure enterprise accounts, validating identities via mobile/email OTPs, and maintaining secure login sessions.
  • Trust Verification & Badging: Authenticating GSTIN and PAN information against official public registers to assign verified supplier trust badges.
  • Algorithmic Requirement Matching: Connecting buyer procurement requirements with relevant verified MSME manufacturers and suppliers across Indian states.
  • Transactional Communications: Sending critical transactional SMS/email notifications regarding buyer leads, RFQ alerts, quotation updates, and account security notices.
  • Fraud Prevention & Abuse Control: Detecting bot activity, preventing unauthorized data harvesting, mitigating fraudulent listings, and ensuring marketplace integrity.
Section 04

Direct B2B Information Sharing (No Middlemen)

Our core operating philosophy is "No Middlemen". To enable direct bilateral commercial trade, information is shared under strict protocols:

Transparent Trade Disclosure

When a buyer posts an RFQ or contacts a supplier, relevant enterprise contact details (company name, authorized contact, verified phone, city, and requirement specifications) are disclosed directly to the matching verified member to facilitate direct commercial quotation.

Our Zero-Spam & Non-Selling Commitment:
  • We NEVER sell your data: MSME LEAP does not rent, sell, monetize, or trade your corporate or personal contact lists to third-party telemarketers or external advertisers.
  • Public vs. Protected Data: Public catalog items, company names, product brochures, and general business cities are indexed for search visibility. Specific personal identification numbers (e.g. raw PAN cards) are kept strictly confidential and never displayed publicly.
  • Statutory Disclosures: We may share information with law enforcement agencies or judicial authorities only when explicitly required by a valid legal subpoena, court order, or applicable statutory mandate.
Section 05

Data Security & Infrastructure Safeguards

We deploy multi-layered organizational and technical safeguards to preserve the confidentiality and integrity of your corporate data:

  • Encryption in Transit: All data transmitted between your browser and our servers is secured using 256-bit TLS/HTTPS cryptographic encryption protocols.
  • Credential Hashing: User account passwords are encrypted using state-of-the-art one-way salted hashing algorithms (bcrypt/Argon2) and are never stored in plain text.
  • Role-Based Access Controls (RBAC): Administrative backend access is strictly partitioned and restricted to authorized personnel with multi-factor authentication.
  • Database Isolation & Firewalls: Databases and server infrastructure are protected behind Web Application Firewalls (WAF) with real-time DDoS mitigation and automated vulnerability monitoring.
Section 06

Cookies & Session Management

MSME LEAP utilizes standard browser cookies and local storage tokens to deliver a smooth and secure user experience:

  • Essential Authentication Cookies: Necessary for maintaining your authenticated user session, verifying CSRF tokens, and securing account dashboards.
  • Functional & Preference Cookies: Remember your interface preferences (e.g. selected state filters, category views, or catalog display modes).
  • Aggregated Analytical Cookies: Help us measure anonymous platform traffic volumes, page load speeds, and error rates to optimize server performance.

You can configure your web browser to decline non-essential cookies. However, disabling essential session cookies may prevent you from logging into your account or submitting buy requirements.

Section 07

Data Retention & Statutory Archival

We retain your business records and transaction history only for as long as necessary to fulfill the objectives set forth in this Privacy Policy:

  • Active Accounts: Business profile listings, active catalogs, and member preferences are retained as long as your account remains in active status.
  • Audit & Legal Compliance: In accordance with statutory Indian taxation (GST) guidelines and commercial trade laws, transaction logs, invoices, and verification audit trails are archived for a mandatory period of up to eight (8) years.
  • Deactivated Accounts: Upon approved account deletion, public catalog listings are purged from public indices within thirty (30) days, except for non-identifiable aggregated statistics or statutory audit records.
Section 08

Data Principal Rights & Controls

In accordance with the Digital Personal Data Protection Act, 2023, you and your authorized enterprise representatives possess the following rights regarding processed data:

  • Right of Access & Summary: You may request a summary of the personal and enterprise data actively processed by MSME LEAP.
  • Right to Rectification: You may update inaccurate, obsolete, or incomplete corporate information directly through your Member Dashboard (myaccount/index.php) or by contacting our support desk.
  • Right to Erasure & Account Deactivation: You may request the deactivation and deletion of your profile, subject to statutory tax and commercial retention requirements.
  • Right to Grievance Redressal: You have the right to accessible and timely grievance redressal through our designated Grievance Officer.
Section 09

Data Storage & Localisation (India)

All core customer data, supplier catalogs, GST verification records, and database backups are hosted and stored on secure cloud server facilities located physically within the territory of the Republic of India, ensuring strict adherence to national data sovereignty and regulatory compliance standards.

Section 10

Third-Party Integrations & External Links

MSME LEAP may include links to third-party payment gateways (e.g. UPI, NetBanking), trade associations, industry bodies, or supplier websites. We are not responsible for the privacy practices, cookie policies, or content of such external websites. We encourage you to review their respective privacy policies before providing sensitive information.

Section 11

B2B Commercial Exclusivity

MSME LEAP is exclusively dedicated to business-to-business commercial enterprises and adult professionals. We do not knowingly solicit, collect, or process information from individuals under 18 years of age. If we identify that a minor has provided information, we will immediately take steps to purge such data from our systems.

Section 12

Policy Revisions & Version History

We may update this Privacy Policy periodically to reflect evolving legal frameworks, technical upgrades, or marketplace enhancements. The "Last Revised" date and "Version" tag at the top of this document will always indicate the most current version. We encourage members to review this page periodically.

Section 13

Grievance Officer & Privacy Contact Desk

In accordance with the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, and rules made thereunder, you may direct all privacy queries, data requests, or grievances to our designated Data Protection & Grievance Desk:

Data Protection & Grievance Officer
Direct Legal & Privacy Desk
Privacy & Grievance Email privacy@msmeleap.com
General Support Email support@msmeleap.com
Phone & Business Hours
Customer Helpline
Direct Helpline +91 97947 13405
Operational Timings
Mon – Sat: 09:30 AM to 06:30 PM IST
MSME LEAP Network Operations Office

Registered Office: Lucknow, Uttar Pradesh, India • Support Portal: www.msmeleap.com

DPDP Compliant Platform