Privacy Policy

Applies to the 1stNlast Android application for customers and to services accessed through it.
Version 1.0 · Effective date: 1 September 2026 · Last updated: 9 August 2026

This Privacy Policy explains what personal data the 1stNlast app collects, why we collect it, who we share it with, how long we keep it, and the choices and rights available to you. We publish it as required by Google Play and to meet our notice obligations as a Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”).

Contents
  1. Who we are
  2. Scope of this policy
  3. Personal data we collect
  4. Why we process your data
  5. Consent and legal basis
  6. Device permissions
  7. Who we share data with
  8. Payments and financial data
  9. SMS, WhatsApp and notifications
  10. PIN codes and the One PIN One Piece model
  11. How long we keep data
  12. How we protect data
  13. Your rights
  14. Deleting your account and data
  15. Children
  16. Storage location and transfers
  17. Data breach notification
  18. Changes to this policy
  19. Contact and grievance redressal

1. Who we are

The 1stNlast app is operated by 1stNlast Scarcity Comm Private Limited (“1stNlast”, “we”, “us”), a private company limited by shares, incorporated in India under the Companies Act, 2013.

Our registered and corporate office is:

1stNlast Scarcity Comm Private Limited
Wave One, Silver Tower, 30B/01, 32nd Floor, Gate No. 3,
Sector 18, Noida, Gautam Buddha Nagar,
Uttar Pradesh – 201301, India
Phone: +91 95400 13003
Email: support@1stnlast.com

For the personal data described in this policy, we act as the Data Fiduciary. 1stNlast operates a scarcity-based commerce platform: only one unit of any given product variant is ever sold within a single PIN code. Understanding this matters for privacy, because your PIN code is central to how the service works.

2. Scope of this policy

This policy covers:

It does not cover our separate distributor and stockist portal or our internal admin console, which are governed by our agreements with those partners, nor any third-party website or app you reach through a link from our app.

3. Personal data we collect

We collect only what the service needs. The table below is an itemised description of the categories of personal data we process.

CategorySpecific dataHow obtained
Account identity Mobile number, full name, email address (optional), password (stored only as a one-way hash), account status and role You provide it at registration
Location by PIN code The 6-digit PIN code you enter as your home PIN, and the destination PIN code of each order You type it; we never read GPS or precise device location
Verification data One-time passwords (stored only as a hash), verification timestamps, delivery channel, number of attempts, and the IP address of the request Generated when you verify your number or authorise a sensitive action
Order and transaction data Products and variants ordered, destination PIN code, amounts, wallet amount applied, cashback earned, GST amount, order and payment status, invoice details including HSN/SAC and tax breakup, and product authenticity certificate records Created when you place and pay for an order
Payment data Payment gateway reference identifiers, transaction identifiers, amount and payment status Returned to us by our payment gateway. See section 8.
Wallet and rewards data Wallet balances, transaction type, amount, state and the related order Generated by cashback, referrals and redemptions
Referral data Your referral code, the code you signed up with, who referred whom, whether the PIN matched, and bonus state Generated if you or someone else uses a referral code
Communication records Recipient number, channel, message template used, message content, delivery status, provider message identifier and any failure reason Generated when we send you a transactional message
Session and security data Authentication tokens, an app-generated device identifier, session expiry and revocation state, failed login counts and account lock timestamps Generated when you sign in
Technical and diagnostic data IP address, app version, Android version, device model, crash reports and non-identifying usage events Collected automatically. See section 7.

What we do not collect

4. Why we process your data

Each purpose below is specific. We do not repurpose your data for unrelated uses.

PurposeData used
Create and secure your account; sign you inAccount identity, session and security data
Verify that a mobile number belongs to youMobile number, verification data
Show you what is still claimable in your area and enforce One PIN One PiecePIN code, order records
Take payment and confirm itOrder data, payment references
Route your order to the distributor serving your district and deliver itDestination PIN code, order data, name and mobile number
Issue a GST-compliant invoice and an authenticity certificateName, address details where applicable, order and tax data
Operate wallet, cashback and referral programmesWallet, rewards and referral data
Send transactional messages such as OTPs, order and exchange updatesMobile number, communication records
Send promotional messages, only if you opt inMobile number, opt-in record
Provide customer support and handle exchange requestsOrder data, communication records
Detect and prevent fraud, abuse and automated attacksIP address, verification attempts, failed login counts, device identifier
Fix crashes and improve the appTechnical and diagnostic data
Meet legal, tax and accounting obligationsOrder, invoice and payment records

We process your personal data on the basis of your consent, and for certain legitimate uses permitted by law, such as complying with a legal obligation or responding to a request you voluntarily make.

Consent you give us is:

If you withdraw consent, we stop the related processing. Some records must still be kept where the law requires it — for example tax invoices — and withdrawing consent for essential processing may mean we can no longer provide the service. Withdrawal does not affect processing already carried out lawfully.

Promotional messaging is separate from service messaging. Declining marketing never blocks you from buying, and you will still receive transactional messages such as OTPs and order updates because those are part of the service you asked for.

6. Device permissions

We request the minimum set of Android permissions. You can revoke any of them in Android Settings; the app will keep working with the corresponding feature disabled.

PermissionWhy we askIf you decline
Internet / network state Required to talk to our servers The app cannot function offline
Notifications Order status, drop reminders and exchange updates You will not receive push alerts; in-app screens still work
Camera Only when you choose to scan a product certificate or attach a photo to an exchange request Pick an existing file instead; nothing else changes

We do not request precise location, contacts, SMS reading, microphone or background location. If a future version needs a new permission, we will ask for it in context and update this policy first.

7. Who we share data with

We share personal data only with the parties below, only for the purposes stated, and only to the extent needed. Each is bound by contract to protect your data and to use it solely for the service they provide to us.

RecipientWhat they receiveWhy
Payment gateway Order amount and reference; your payment credentials go directly to them, not to us To process payments and refunds
District distributor or stockist fulfilling your order Name, delivery address, mobile number, destination PIN code and order contents To pack and dispatch your order
Logistics and courier partners Name, delivery address, mobile number and package details To deliver your order and let you track it
SMS and WhatsApp messaging providers Mobile number and message content To deliver OTPs and transactional messages through DLT-registered templates
Cloud hosting provider All application data, as our infrastructure provider To host the app backend, database and product images
Crash reporting and product analytics providers Technical and diagnostic data, and pseudonymous usage events To diagnose crashes and improve stability
Professional advisers and auditors Only what a specific engagement requires Accounting, tax and legal compliance
Government or judicial authorities Only what a valid, lawful order requires Legal obligation

A current list naming the specific service providers we use, and the country in which each processes data, is available free of charge on request from the contact address in section 19.

We may also transfer data as part of a merger, acquisition or restructuring, in which case we will notify you and the acquirer will remain bound by this policy or a policy at least as protective.

8. Payments and financial data

Payments are processed by a PCI-DSS compliant payment gateway. Your card number, CVV, UPI PIN and net-banking credentials are entered on the gateway’s interface and are never transmitted to or stored on our servers. We retain only the gateway’s reference identifiers, the amount, and the payment status, which we need for reconciliation, refunds and dispute resolution.

Wallet balances are an account credit on our platform, not a bank deposit and not a prepaid payment instrument. Redemptions may require OTP verification, so keep access to your registered mobile number.

9. SMS, WhatsApp and notifications

Transactional SMS in India is sent through operator-approved DLT-registered templates using our registered entity and sender identifiers. We keep a log of messages sent to you, including the recipient number, template, content, delivery status and any failure reason, so that we can prove delivery and investigate complaints such as an OTP that never arrived.

We never ask for your OTP, password, card details or UPI PIN by phone, SMS, email or WhatsApp. Anyone who does is attempting fraud. Report it to us immediately using the contact details in section 19.

10. PIN codes and the One PIN One Piece model

Our platform sells only one unit of any product variant per PIN code, permanently. To make that work, we must record that a specific variant has been claimed in a specific PIN code.

This scarcity record is retained on a long-term basis because the rule is lifelong: the platform must be able to say, indefinitely, that a variant is no longer available in that PIN code. Where a scarcity record must outlive your account, we retain it in a form that does not identify you personally — we keep the product variant and the PIN code, and sever the link to your identity.

We use only the PIN code you type in. We do not read GPS, Wi-Fi positioning or cell-tower location to infer where you are.

11. How long we keep data

DataRetention
Account identity and profileWhile your account is active, then deleted or anonymised within 30 days of a verified deletion request
OTP recordsCodes expire within minutes; records are purged within 90 days
Session and authentication tokensUntil expiry, sign-out or revocation, and in any case not beyond 90 days after expiry
Orders, invoices, payments and tax records8 years from the end of the relevant financial year, as required by Indian tax and company law
Wallet and referral ledgersWhile balances or obligations exist, then per the 8-year financial-records period above
Communication logs24 months, for dispute resolution and regulatory proof of delivery
Scarcity recordsLong-term, in de-identified form once no longer linked to an active account. See section 10.
Crash and diagnostic data90 days
Security logs such as IP addresses and failed login counts180 days

When a retention period ends, we delete the data or irreversibly anonymise it so that it can no longer be linked to you.

12. How we protect data

No system is perfectly secure. Please use a strong, unique password, never share your OTP, and sign out on shared devices.

13. Your rights

As a Data Principal under the DPDP Act, you have the right to:

How to exercise a right

Use the in-app option under Profile → Privacy & data, email support@1stnlast.com from your registered address, or write to our Grievance Officer at the address in section 19. We may verify your identity, typically by OTP to your registered mobile number, before we act — this protects you from someone else making requests in your name. We acknowledge requests within 3 working days and respond within 30 days.

There is no charge for exercising your rights.

14. Deleting your account and data

You can request deletion in either of these ways:

  1. In the app, open Profile → Privacy & data → Delete my account; or
  2. email support@1stnlast.com with the subject “Account deletion” from your registered email address, or send the request from your registered mobile number.

When we process a deletion request:

Deletion is completed within 30 days of verification. Note that uninstalling the app does not delete your account.

15. Children

The app is not intended for anyone under 18, and you must be 18 or older to buy from us. We do not knowingly collect personal data from children. Where the law requires it, processing a child’s personal data needs verifiable consent from a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has given us personal data, contact us and we will delete it promptly.

16. Storage location and transfers

Our application servers, database and product images are hosted with a cloud infrastructure provider, and some of our service providers process data outside India. This means your personal data may be transferred outside India. Where that happens we rely on contractual safeguards with every recipient, restrict them to processing on our instructions only, and comply with applicable Indian law and any restrictions notified by the Central Government on transfers to particular territories. You can ask us at any time which countries your data is processed in, using the contact details in section 19.

17. Data breach notification

If a personal data breach affects you, we will notify you and the Data Protection Board of India as required by law, describing the nature and extent of the breach, its likely consequences, the measures we have taken, and what you should do to protect yourself.

18. Changes to this policy

We may update this policy as the service, our providers or the law change. The version number and “last updated” date at the top will always reflect the current version. If a change materially affects how we use your personal data, we will give you prominent notice in the app or by message before it takes effect and, where required, seek your fresh consent. Continuing to use the app after a change takes effect means you accept the updated policy.

19. Contact and grievance redressal

For any question, request or complaint about your personal data, contact us:

Data Fiduciary1stNlast Scarcity Comm Private Limited
Grievance OfficerMr Manas Kumar Sahoo, Director
Registered & corporate office Wave One, Silver Tower, 30B/01, 32nd Floor, Gate No. 3,
Sector 18, Noida, Gautam Buddha Nagar,
Uttar Pradesh – 201301, India
Phone+91 95400 13003 — Monday to Saturday, 9 AM to 8 PM IST
Emailsupport@1stnlast.com
Response timeAcknowledged within 3 working days; resolved within 30 days

If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India in the manner prescribed under the DPDP Act and the rules made under it.