This Privacy Policy explains what personal data the 1stNlast app collects, why we collect it, who we share it with, how long we keep it, and the choices and rights available to you. We publish it as required by Google Play and to meet our notice obligations as a Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”).
The 1stNlast app is operated by 1stNlast Scarcity Comm Private Limited (“1stNlast”, “we”, “us”), a private company limited by shares, incorporated in India under the Companies Act, 2013.
Our registered and corporate office is:
For the personal data described in this policy, we act as the Data Fiduciary. 1stNlast operates a scarcity-based commerce platform: only one unit of any given product variant is ever sold within a single PIN code. Understanding this matters for privacy, because your PIN code is central to how the service works.
This policy covers:
It does not cover our separate distributor and stockist portal or our internal admin console, which are governed by our agreements with those partners, nor any third-party website or app you reach through a link from our app.
We collect only what the service needs. The table below is an itemised description of the categories of personal data we process.
| Category | Specific data | How obtained |
|---|---|---|
| Account identity | Mobile number, full name, email address (optional), password (stored only as a one-way hash), account status and role | You provide it at registration |
| Location by PIN code | The 6-digit PIN code you enter as your home PIN, and the destination PIN code of each order | You type it; we never read GPS or precise device location |
| Verification data | One-time passwords (stored only as a hash), verification timestamps, delivery channel, number of attempts, and the IP address of the request | Generated when you verify your number or authorise a sensitive action |
| Order and transaction data | Products and variants ordered, destination PIN code, amounts, wallet amount applied, cashback earned, GST amount, order and payment status, invoice details including HSN/SAC and tax breakup, and product authenticity certificate records | Created when you place and pay for an order |
| Payment data | Payment gateway reference identifiers, transaction identifiers, amount and payment status | Returned to us by our payment gateway. See section 8. |
| Wallet and rewards data | Wallet balances, transaction type, amount, state and the related order | Generated by cashback, referrals and redemptions |
| Referral data | Your referral code, the code you signed up with, who referred whom, whether the PIN matched, and bonus state | Generated if you or someone else uses a referral code |
| Communication records | Recipient number, channel, message template used, message content, delivery status, provider message identifier and any failure reason | Generated when we send you a transactional message |
| Session and security data | Authentication tokens, an app-generated device identifier, session expiry and revocation state, failed login counts and account lock timestamps | Generated when you sign in |
| Technical and diagnostic data | IP address, app version, Android version, device model, crash reports and non-identifying usage events | Collected automatically. See section 7. |
Each purpose below is specific. We do not repurpose your data for unrelated uses.
| Purpose | Data used |
|---|---|
| Create and secure your account; sign you in | Account identity, session and security data |
| Verify that a mobile number belongs to you | Mobile number, verification data |
| Show you what is still claimable in your area and enforce One PIN One Piece | PIN code, order records |
| Take payment and confirm it | Order data, payment references |
| Route your order to the distributor serving your district and deliver it | Destination PIN code, order data, name and mobile number |
| Issue a GST-compliant invoice and an authenticity certificate | Name, address details where applicable, order and tax data |
| Operate wallet, cashback and referral programmes | Wallet, rewards and referral data |
| Send transactional messages such as OTPs, order and exchange updates | Mobile number, communication records |
| Send promotional messages, only if you opt in | Mobile number, opt-in record |
| Provide customer support and handle exchange requests | Order data, communication records |
| Detect and prevent fraud, abuse and automated attacks | IP address, verification attempts, failed login counts, device identifier |
| Fix crashes and improve the app | Technical and diagnostic data |
| Meet legal, tax and accounting obligations | Order, invoice and payment records |
We process your personal data on the basis of your consent, and for certain legitimate uses permitted by law, such as complying with a legal obligation or responding to a request you voluntarily make.
Consent you give us is:
If you withdraw consent, we stop the related processing. Some records must still be kept where the law requires it — for example tax invoices — and withdrawing consent for essential processing may mean we can no longer provide the service. Withdrawal does not affect processing already carried out lawfully.
Promotional messaging is separate from service messaging. Declining marketing never blocks you from buying, and you will still receive transactional messages such as OTPs and order updates because those are part of the service you asked for.
We request the minimum set of Android permissions. You can revoke any of them in Android Settings; the app will keep working with the corresponding feature disabled.
| Permission | Why we ask | If you decline |
|---|---|---|
| Internet / network state | Required to talk to our servers | The app cannot function offline |
| Notifications | Order status, drop reminders and exchange updates | You will not receive push alerts; in-app screens still work |
| Camera | Only when you choose to scan a product certificate or attach a photo to an exchange request | Pick an existing file instead; nothing else changes |
We do not request precise location, contacts, SMS reading, microphone or background location. If a future version needs a new permission, we will ask for it in context and update this policy first.
We share personal data only with the parties below, only for the purposes stated, and only to the extent needed. Each is bound by contract to protect your data and to use it solely for the service they provide to us.
| Recipient | What they receive | Why |
|---|---|---|
| Payment gateway | Order amount and reference; your payment credentials go directly to them, not to us | To process payments and refunds |
| District distributor or stockist fulfilling your order | Name, delivery address, mobile number, destination PIN code and order contents | To pack and dispatch your order |
| Logistics and courier partners | Name, delivery address, mobile number and package details | To deliver your order and let you track it |
| SMS and WhatsApp messaging providers | Mobile number and message content | To deliver OTPs and transactional messages through DLT-registered templates |
| Cloud hosting provider | All application data, as our infrastructure provider | To host the app backend, database and product images |
| Crash reporting and product analytics providers | Technical and diagnostic data, and pseudonymous usage events | To diagnose crashes and improve stability |
| Professional advisers and auditors | Only what a specific engagement requires | Accounting, tax and legal compliance |
| Government or judicial authorities | Only what a valid, lawful order requires | Legal obligation |
A current list naming the specific service providers we use, and the country in which each processes data, is available free of charge on request from the contact address in section 19.
We may also transfer data as part of a merger, acquisition or restructuring, in which case we will notify you and the acquirer will remain bound by this policy or a policy at least as protective.
Payments are processed by a PCI-DSS compliant payment gateway. Your card number, CVV, UPI PIN and net-banking credentials are entered on the gateway’s interface and are never transmitted to or stored on our servers. We retain only the gateway’s reference identifiers, the amount, and the payment status, which we need for reconciliation, refunds and dispute resolution.
Wallet balances are an account credit on our platform, not a bank deposit and not a prepaid payment instrument. Redemptions may require OTP verification, so keep access to your registered mobile number.
Transactional SMS in India is sent through operator-approved DLT-registered templates using our registered entity and sender identifiers. We keep a log of messages sent to you, including the recipient number, template, content, delivery status and any failure reason, so that we can prove delivery and investigate complaints such as an OTP that never arrived.
We never ask for your OTP, password, card details or UPI PIN by phone, SMS, email or WhatsApp. Anyone who does is attempting fraud. Report it to us immediately using the contact details in section 19.
Our platform sells only one unit of any product variant per PIN code, permanently. To make that work, we must record that a specific variant has been claimed in a specific PIN code.
This scarcity record is retained on a long-term basis because the rule is lifelong: the platform must be able to say, indefinitely, that a variant is no longer available in that PIN code. Where a scarcity record must outlive your account, we retain it in a form that does not identify you personally — we keep the product variant and the PIN code, and sever the link to your identity.
We use only the PIN code you type in. We do not read GPS, Wi-Fi positioning or cell-tower location to infer where you are.
| Data | Retention |
|---|---|
| Account identity and profile | While your account is active, then deleted or anonymised within 30 days of a verified deletion request |
| OTP records | Codes expire within minutes; records are purged within 90 days |
| Session and authentication tokens | Until expiry, sign-out or revocation, and in any case not beyond 90 days after expiry |
| Orders, invoices, payments and tax records | 8 years from the end of the relevant financial year, as required by Indian tax and company law |
| Wallet and referral ledgers | While balances or obligations exist, then per the 8-year financial-records period above |
| Communication logs | 24 months, for dispute resolution and regulatory proof of delivery |
| Scarcity records | Long-term, in de-identified form once no longer linked to an active account. See section 10. |
| Crash and diagnostic data | 90 days |
| Security logs such as IP addresses and failed login counts | 180 days |
When a retention period ends, we delete the data or irreversibly anonymise it so that it can no longer be linked to you.
No system is perfectly secure. Please use a strong, unique password, never share your OTP, and sign out on shared devices.
As a Data Principal under the DPDP Act, you have the right to:
Use the in-app option under Profile → Privacy & data, email support@1stnlast.com from your registered address, or write to our Grievance Officer at the address in section 19. We may verify your identity, typically by OTP to your registered mobile number, before we act — this protects you from someone else making requests in your name. We acknowledge requests within 3 working days and respond within 30 days.
There is no charge for exercising your rights.
You can request deletion in either of these ways:
When we process a deletion request:
Deletion is completed within 30 days of verification. Note that uninstalling the app does not delete your account.
The app is not intended for anyone under 18, and you must be 18 or older to buy from us. We do not knowingly collect personal data from children. Where the law requires it, processing a child’s personal data needs verifiable consent from a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has given us personal data, contact us and we will delete it promptly.
Our application servers, database and product images are hosted with a cloud infrastructure provider, and some of our service providers process data outside India. This means your personal data may be transferred outside India. Where that happens we rely on contractual safeguards with every recipient, restrict them to processing on our instructions only, and comply with applicable Indian law and any restrictions notified by the Central Government on transfers to particular territories. You can ask us at any time which countries your data is processed in, using the contact details in section 19.
If a personal data breach affects you, we will notify you and the Data Protection Board of India as required by law, describing the nature and extent of the breach, its likely consequences, the measures we have taken, and what you should do to protect yourself.
We may update this policy as the service, our providers or the law change. The version number and “last updated” date at the top will always reflect the current version. If a change materially affects how we use your personal data, we will give you prominent notice in the app or by message before it takes effect and, where required, seek your fresh consent. Continuing to use the app after a change takes effect means you accept the updated policy.
For any question, request or complaint about your personal data, contact us:
| Data Fiduciary | 1stNlast Scarcity Comm Private Limited |
|---|---|
| Grievance Officer | Mr Manas Kumar Sahoo, Director |
| Registered & corporate office |
Wave One, Silver Tower, 30B/01, 32nd Floor, Gate No. 3, Sector 18, Noida, Gautam Buddha Nagar, Uttar Pradesh – 201301, India |
| Phone | +91 95400 13003 — Monday to Saturday, 9 AM to 8 PM IST |
| support@1stnlast.com | |
| Response time | Acknowledged within 3 working days; resolved within 30 days |
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India in the manner prescribed under the DPDP Act and the rules made under it.