Section 1
Who we are and scope
Pupchu Tech Private Limited operates b2bsilvish and is responsible for the personal data described in this policy. This policy applies to the public marketplace, buyer area, supplier portal, administrator tools, generated manufacturer storefronts and related support, SMS, email and payment interactions.
It covers visitors, buyer representatives, supplier owners and team members, reviewers, support requesters and other people whose information is submitted to us. A manufacturer remains independently responsible for information it collects and uses after direct contact for its own quotation or transaction.
Section 2
Information we collect
- Identity and contact data: name, mobile number, OTP verification status, business email, company and role.
- Buyer requirement data: category, product, relevant specifications, quantity, unit, customisation, MOQ comparison, delivery location, attachments when enabled and manufacturer-sharing choice.
- Supplier data: legal name, GSTIN, PAN or other identifiers, address, factory information, contacts, team roles, catalogue, prices, MOQ, certifications, licences, verification evidence, plans and billing records.
- Interaction data: direct and related leads, contact disclosure, calls or WhatsApp button events, supplier response, lead outcome, reviews, disputes, support, abuse reports and feedback.
- Device and usage data: IP address, browser, device, pages, searches, clicks, session/security events, cookie choices, attribution and diagnostic information.
- Payment data: plan, amount, GST, invoice and payment status. Card, UPI and bank credentials are handled by the payment provider and are not stored by b2bsilvish.
Section 3
Where information comes from
We receive information directly from you; from authorised company colleagues; from activity on b2bsilvish; from manufacturers and buyers involved in a lead; from payment, authentication, communications, analytics and security providers; and from lawful public or government sources used to verify business claims.
If you submit another person’s data, you confirm that you are authorised to do so and have provided any required notice. Suppliers must not upload customer logos, employee information, certificates or references without the appropriate authority.
Section 4
Why we use information
- Create and secure accounts, send and verify OTPs and maintain the three-day trusted-device session.
- Create requirements and leads, calculate matching relevance, distribute consented requirements and disclose manufacturer contact after verification.
- Operate supplier catalogue, storefront, verification, moderation, subscriptions, entitlements and sponsored placement.
- Send essential lead alerts, security messages, invoices, verification reminders and support updates by SMS or email.
- Prevent traders from misrepresenting themselves, detect fraud and spam, investigate abuse and enforce platform rules.
- Provide analytics, improve taxonomy and matching, understand demand and measure lawful advertising and marketplace performance.
- Comply with tax, accounting, legal, regulatory, law-enforcement, dispute and audit obligations.
Section 5
Consent and other lawful processing
Where consent is required, we ask for a clear action—for example OTP submission, sharing a requirement with related manufacturers, optional marketing or non-essential analytics. You may withdraw consent using the relevant preference, account control or Help form. Withdrawal does not invalidate earlier lawful processing and may prevent the requested feature from continuing.
We may also process information where necessary to provide a service you requested, comply with law, protect users and the platform, resolve disputes or pursue legitimate business purposes permitted by applicable law. We do not use silence, inactivity or a pre-selected related-manufacturer option as consent.
Section 6
How requirement and contact sharing works
A direct enquiry is visible to the selected manufacturer. If the buyer chooses related matching, we may share the requirement and buyer contact with other eligible manufacturers whose category, capability and attributes are relevant, subject to the marketplace logic and plan rules.
We do not secretly broadcast a direct lead. The buyer’s verified phone may be disclosed to manufacturers receiving a lead, and the selected manufacturer’s phone and WhatsApp are disclosed to the buyer after verified submission. Marketplace requirements that have not created a manufacturer-specific connection do not qualify as a verified interaction for review.
Section 7
Public supplier information
Approved company names, business descriptions, general location, GST verification status or approved GSTIN display, products, MOQ, indicative prices, capabilities, certificates, reviews and public contact information may appear in search, listings and generated storefronts. Sensitive evidence such as PAN, personal identity documents and internal verification notes is not intended for public display.
Public content may be indexed by search engines and copied outside our control. A supplier should use the portal or Help form to request correction, pause or removal, subject to legal and audit retention.
Section 8
Who receives information
We do not sell personal data as a standalone data-broker product. We require service providers to use information for the contracted service and apply appropriate safeguards.
- Selected and eligible manufacturers as described in the buyer’s requirement choice.
- Authorised supplier team members and authorised Pupchu Tech staff according to role-based permissions.
- Hosting, database, authentication, SMS, email, storage, payment, analytics, error-monitoring, security and customer-support providers acting for us.
- Professional advisers, auditors, insurers and corporate transaction participants under appropriate confidentiality.
- Courts, regulators, law-enforcement agencies or affected parties when legally required or reasonably necessary to protect rights, safety and platform integrity.
Section 9
Service-provider categories
The planned stack includes Supabase for data and authentication, MSG91 for SMS delivery, Resend for email, Razorpay for supplier subscription payments, Vercel for hosting, Cloudflare for traffic security, Google Analytics and Tag Manager for measurement, Microsoft Clarity for experience analytics and Sentry for error monitoring. A provider is active only after it is connected and configured.
Provider locations and subprocessors may change. Where information is processed outside India, we use contractual and technical protections and comply with applicable transfer restrictions.
Section 10
How long we retain information
When retention is no longer necessary, data is deleted, de-identified or securely isolated. Backups expire according to the backup schedule and are not used for ordinary processing.
- Account and profile data: while the account is active, then for the period needed for restoration, disputes, fraud prevention or law.
- Requirements, leads, contact disclosures and outcomes: normally up to three years after the last relevant activity, unless a longer legal or dispute hold applies.
- OTP, security, access and system logs: for the period needed for authentication, incident investigation and applicable cyber-security requirements; relevant logs may be retained for at least 180 days where required.
- Subscription, invoice and tax records: for the statutory accounting and tax retention period.
- Verification and moderation evidence: while the claim is active and afterwards as needed to prevent misrepresentation and respond to disputes.
- Support, grievance and review records: normally up to three years after closure, or longer if required for a continuing matter.
Section 11
Security
We use role-based access, row-level database restrictions, signed webhooks, server-held secrets, OTP controls, audit history, soft deletion, storage policies, rate limits, encryption in transit, backups and monitoring appropriate to the service. Access is limited according to job responsibility.
No system is completely secure. Never share an OTP, password, payment credential or confidential design through an untrusted channel. Report suspected compromise promptly through the Help form.
Section 12
Your rights and choices
We may verify identity and authority before acting. Some records cannot be removed immediately where they are required for tax, security, fraud prevention, legal claims or audit integrity. We will explain a refusal where permitted.
- Request a summary of personal data and processing, subject to applicable law.
- Correct inaccurate or incomplete account, profile or requirement information.
- Request erasure where retention is not legally or operationally required.
- Withdraw consent and manage optional communication or cookie preferences.
- Raise a grievance and, where applicable, nominate another person to exercise rights in specified circumstances.
- Object to or report inaccurate public supplier information, a listing, review or misuse of contact data.
Section 13
Children
b2bsilvish is a business service intended for people aged 18 or older. We do not knowingly create accounts for children or intentionally collect their personal data. If you believe a child’s data was submitted, report it for review and removal.
Section 15
Matching and automated assistance
The platform may score a requirement against manufacturer taxonomy, attributes, capabilities, MOQ, location, verification, responsiveness and other relevance signals. This score helps rank possible matches; it does not make a binding purchasing, credit or legal decision.
Administrators can review matching, correct taxonomy and override distribution. Buyers and suppliers may report irrelevant matches or inaccurate attributes.
Section 16
Breaches, policy changes and grievances
If a personal-data breach is likely to affect you, we will investigate, contain and notify affected people and authorities as required. Keep your contact details current so important notices can reach you.
We may update this policy for law, vendors, security or product changes. Material updates will be notified as required and the effective date revised. Privacy and grievance requests should include the relevant mobile number or account, the request, affected URL or lead and enough information to verify authority.
Questions, notices or grievances
Contact Pupchu Tech Private Limited, the operator of b2bsilvish. Choose the relevant topic so the request is recorded and routed to the appropriate team.
- Phone
- +91 88606 88607
- Registered office
- Delhi, India — complete verified address to be published before launch
These pages describe the intended platform rules. They must be reviewed against the final company details, provider contracts and launch operations by qualified Indian counsel before public launch.