Legal Document
Version 1.1

Privacy Policy

How we collect, use and protect information on the 3-GEE Distributor Portal

3-GEE Distributor Portal · B2B Customer Ordering Portal

Last updated

July 2026

Document version

1.1

Jump to a section

Operator

Marine Switchgear Private Limited

C-108, Sector 2, Bawana Industrial Area, Delhi – 110039

CIN: U51909DL2010PTC210020  ·  GSTIN: 07AAGCM8466K1ZV

Marine Switchgear Private Limited operates the 3-GEE Distributor Portal, including the website, Android application and iOS application through which authorised business customers may browse products, place and manage orders, receive dispatch updates, communicate with us and access related services.

In this Privacy Policy, “3-GEE”, “we”, “us” and “our” refer to Marine Switchgear Private Limited.

This Privacy Policy explains how we collect, use, store, disclose and protect personal data and commercially confidential business information relating to users of the 3-GEE Distributor Portal.

We process personal data in accordance with applicable Indian law, including the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025 as and when the relevant provisions become applicable, the Information Technology Act, 2000 and other applicable laws and regulations.

This Privacy Policy should be read together with the Terms & Conditions and Terms of Service made available through the Portal.

We do not sell personal data.

Personal data is used only for the purposes described in this Policy.


1. Scope and definitions

1.1 Who this Policy applies to

This Policy applies to:

  • distributors;
  • dealers;
  • wholesalers;
  • retailers;
  • other approved business customers;
  • proprietors, partners, directors, employees and representatives authorised to use a business customer’s account; and
  • persons who contact us regarding registration, orders, payments, support, warranty or other Portal-related matters.

Together, these persons are referred to as “you”, “your”, “Business Customer” or “Authorised User”, as the context requires.

1.2 Internal users

This customer-facing Privacy Policy does not govern the processing of personal data relating solely to our employees, workers, administrators, managers, packers, sales personnel, contractors or other internal operational users in their employment or engagement capacity. Such processing may be covered by separate internal privacy notices and policies.

1.3 Portal

“Portal” means the 3-GEE website, distributor ordering portal, mobile applications and related customer-facing digital services operated by us.

1.4 Personal data

“Personal data” means data about an individual who is identifiable by or in relation to such data.

1.5 Business information

“Business information” includes information concerning a business entity, such as its name, GSTIN, billing address, delivery address, pricing, order history, business terms and distributor status.

Business information that does not identify an individual may not constitute personal data. However, it is treated as commercially confidential information under our contractual terms and internal controls. Where business information also identifies an individual, we treat it as personal data under this Policy.


2. Information we collect

We collect only information reasonably necessary to operate the Portal, manage our business relationship, fulfil orders and comply with applicable law.

2.1 Account and identity information

We may collect:

  • name of the proprietor, partner, director, contact person or Authorised User;
  • business or trade name;
  • designation or role;
  • registered mobile number;
  • WhatsApp number;
  • email address;
  • account username;
  • authentication and account-verification information;
  • distributor, dealer or customer category;
  • distributor tier or account status; and
  • private marka or other business identification used for order processing.

2.2 Business and verification information

We may collect:

  • GSTIN;
  • GST registration certificate;
  • business address;
  • billing address;
  • delivery address;
  • place of supply;
  • business constitution;
  • authorised representative details; and
  • information required to verify the business or customer account.

We do not ordinarily request an Aadhaar card, biometric data, health information or a separate PAN document.

PAN-related information may nevertheless be processed where it forms part of a GST certificate, tax record, invoice, legally required verification document or other statutory business record.

2.3 Order and product information

We may collect:

  • products viewed or ordered;
  • quantities;
  • colours, models, modules and product variations;
  • cart contents;
  • saved drafts;
  • previous orders;
  • order remarks;
  • private marka instructions;
  • packaging instructions;
  • delivery instructions;
  • partial-dispatch instructions;
  • order amendments;
  • cancellation or return information; and
  • invoice and dispatch references.

2.4 Commercial, payment and account-management information

We may collect or generate:

  • customer-specific pricing;
  • applicable schemes, discounts and offers;
  • payment terms;
  • advance-payment requirements;
  • transaction references;
  • payment confirmations;
  • refund details;
  • bank-account details provided for a refund;
  • outstanding balances;
  • due dates;
  • payment history;
  • credit limits;
  • credit eligibility;
  • account holds;
  • order holds;
  • distributor qualification or status;
  • account approval or rejection records; and
  • internal commercial notes reasonably necessary to manage the customer relationship.

Card, UPI, net-banking and similar payment credentials are processed by the relevant payment gateway or banking provider. We do not directly store full card numbers, CVV numbers or payment-account passwords.

2.5 Communications and customer support

We may collect communications made through:

  • the Portal;
  • WhatsApp;
  • SMS;
  • email;
  • telephone;
  • customer-support tickets;
  • warranty claims; and
  • other approved communication channels.

This may include:

  • messages;
  • queries;
  • complaints;
  • responses;
  • call-related records;
  • invoice references;
  • claim details;
  • voice notes;
  • product photographs;
  • dispatch photographs; and
  • proof-of-delivery or warranty-related information.

We do not record telephone calls unless you are specifically informed that a call is being recorded.

2.6 Voice notes and photographs

Where you choose to upload a voice note or photograph, we process it for purposes such as:

  • understanding an order instruction;
  • identifying a product or colour;
  • resolving an order issue;
  • processing a warranty or support claim;
  • verifying packing or dispatch; and
  • maintaining records relating to the relevant transaction.

You should not upload photographs, recordings or documents containing personal data of another person unless you are authorised to provide that information.

2.7 Information collected automatically

When you use the Portal, we may automatically collect:

Usage information

  • screens and pages visited;
  • features used;
  • searches performed;
  • products viewed;
  • cart and ordering activity;
  • timestamps;
  • session duration;
  • referral source;
  • application events; and
  • aggregated interaction statistics.

We do not use individual screen-session recordings unless this Policy is updated and appropriate notice or consent is provided.

Device and technical information

  • IP address;
  • device identifier;
  • application installation identifier;
  • notification token;
  • device model;
  • operating system and version;
  • browser type and version;
  • screen size;
  • language settings;
  • network operator; and
  • application version.

Security and diagnostic information

  • login attempts;
  • OTP events;
  • authentication events;
  • access logs;
  • administrative actions;
  • device-change events;
  • error logs;
  • crash reports;
  • suspected misuse; and
  • other security-related events.

2.8 Approximate location

We may derive an approximate city, state or region from an IP address for:

  • account security;
  • fraud detection;
  • unusual-login detection;
  • service analytics; and
  • investigation of misuse.

We do not collect precise GPS location through the Portal unless a future feature specifically requires it and you are separately informed and asked for permission.

2.9 Device permissions

The mobile application may request the following permissions:

  • Camera: when you choose to take and upload a photograph.
  • Photos or media: when you choose to upload an existing photograph or document.
  • Microphone: when you choose to record a voice note.
  • Notifications: to provide order, payment, dispatch, security and support updates.

Optional permissions may be disabled through your device settings. Disabling a permission may prevent the related feature from functioning.

2.10 Information received from third parties

We may receive information from:

  • payment gateways and banking providers;
  • WhatsApp Business service providers;
  • SMS and email service providers;
  • transporters and logistics providers;
  • company sales representatives;
  • your business organisation or authorised representative;
  • public or regulatory databases used for GSTIN or business verification; and
  • service providers assisting with hosting, security, analytics or technical support.

3. How we use information

We use personal data and business information for the following purposes.

3.1 Account creation and management

  • creating and approving customer accounts;
  • verifying registered contact details;
  • authenticating users;
  • maintaining profiles;
  • assigning customer categories or permissions;
  • managing authorised users; and
  • protecting accounts from unauthorised access.

3.2 Order processing

  • enabling product browsing and ordering;
  • maintaining carts and drafts;
  • reviewing and approving orders;
  • applying customer-specific prices and schemes;
  • checking stock;
  • preparing invoices;
  • packing products;
  • arranging dispatch;
  • managing partial dispatches;
  • processing cancellations, returns and refunds; and
  • maintaining order history.

3.3 Payment and commercial management

  • processing and verifying payments;
  • recording transaction status;
  • processing refunds;
  • managing outstanding balances;
  • applying agreed payment terms;
  • assessing credit eligibility;
  • determining credit limits;
  • placing or removing account or order holds; and
  • resolving payment disputes.

3.4 Communications

We may send:

  • OTP and login messages;
  • order confirmations;
  • order approval or rejection notices;
  • payment reminders;
  • invoice information;
  • dispatch alerts;
  • transporter or delivery information;
  • refund confirmations;
  • warranty and support updates;
  • security alerts; and
  • important changes affecting the Portal.

These communications may be sent through WhatsApp, SMS, email, telephone, push notification or an in-app notice.

3.5 Customer support and warranty

We use information to:

  • respond to enquiries;
  • investigate complaints;
  • resolve order discrepancies;
  • process warranty claims;
  • review photographs and voice notes;
  • verify invoices;
  • handle returns or replacements; and
  • maintain dispute records.

3.6 Security and fraud prevention

We use information to:

  • verify identities;
  • detect suspicious activity;
  • investigate unauthorised access;
  • prevent account misuse;
  • identify abnormal ordering or payment behaviour;
  • maintain audit logs;
  • protect our systems; and
  • establish, exercise or defend legal claims.

3.7 Service administration and improvement

We may use usage, diagnostic and aggregated information to:

  • understand how the Portal is used;
  • identify errors;
  • resolve technical problems;
  • measure application performance;
  • improve navigation and usability;
  • develop new features;
  • improve ordering workflows; and
  • conduct internal reporting.

3.8 Legal and regulatory compliance

We may process information for:

  • GST invoicing;
  • accounting;
  • tax filings;
  • statutory audits;
  • maintenance of books and records;
  • regulatory inspections;
  • responding to lawful requests;
  • complying with court or governmental orders; and
  • meeting other applicable legal obligations.

3.9 Marketing

We send promotional information about products, schemes, offers, launches and reorder opportunities only where:

  • you have separately opted in;
  • the communication is otherwise permitted under applicable law; or
  • the message is sent to a business contact in a manner permitted by law.

Marketing consent is separate from acceptance of the Terms or use of the core ordering service.


4. When we process personal data

We process personal data only for lawful purposes.

Depending on the nature of the processing, we may process personal data:

  • with your consent;
  • where you voluntarily provide personal data for a specified purpose and have not indicated that you do not consent to its use for that purpose;
  • to provide a service or respond to a request initiated by you;
  • to maintain records required under applicable law;
  • to comply with a judgment, decree, order or legal obligation;
  • to protect our systems, users and business against fraud or misuse;
  • to establish, exercise or defend legal claims; or
  • under another use expressly permitted by applicable law.

Where processing is based on consent, you may withdraw that consent through the methods stated in this Policy.

Withdrawal of consent will not affect processing lawfully completed before withdrawal. It may, however, prevent us from continuing an optional feature or service that reasonably requires the relevant information.

Withdrawal of marketing consent will not affect transactional or service-related communications.


5. Automated processing and human review

The Portal may automatically perform routine operational activities, including:

  • calculating order values;
  • calculating outstanding periods;
  • checking order thresholds;
  • applying pricing or scheme rules;
  • identifying incomplete orders;
  • generating reminders;
  • detecting unusual login activity; and
  • generating risk or account-management indicators.

We do not intend to make a material decision concerning account approval, customer status, credit terms, credit limits or order holds solely through automated processing.

Material decisions in these areas are subject to review or approval by authorised personnel.


6. How we share information

We disclose information only where reasonably necessary for the purposes stated in this Policy.

6.1 Authorised personnel

Personal data and business information may be accessed by authorised:

  • customer-support personnel;
  • sales personnel;
  • account managers;
  • administrators;
  • billing and accounts personnel;
  • order-processing personnel;
  • managers;
  • packers;
  • dispatch personnel; and
  • technical or security personnel.

Access is provided according to role and business need.

6.2 Payment gateways and banking providers

We share necessary payment and transaction information to:

  • process payments;
  • confirm payment status;
  • investigate payment failures;
  • process refunds; and
  • prevent fraudulent transactions.

6.3 Transporters, couriers and logistics providers

We may share limited information such as:

  • business or customer name;
  • contact-person name;
  • mobile number;
  • delivery address;
  • invoice or dispatch reference;
  • number of packages;
  • delivery instructions; and
  • shipment information.

This information is shared for dispatch, delivery, shipment tracking, proof of delivery and resolution of delivery-related issues.

6.4 Communication service providers

We may use WhatsApp Business, SMS, email, cloud-telephony and push-notification providers to send:

  • OTPs;
  • transaction messages;
  • order updates;
  • support messages; and
  • marketing communications where permitted.

6.5 Hosting, cloud and technology providers

We may use service providers for:

  • application hosting;
  • databases;
  • file storage;
  • backups;
  • authentication;
  • cybersecurity;
  • error reporting;
  • application maintenance; and
  • technical support.

6.6 Analytics providers

Analytics providers may process usage events, device information and pseudonymous identifiers on our behalf.

We use such services for application measurement, security and improvement and not for the sale of customer personal data.

6.7 Professional advisers

Information may be disclosed to legal, tax, accounting, insurance, audit and other professional advisers on a need-to-know basis and subject to appropriate confidentiality obligations.

6.8 Government authorities and legal disclosures

We may disclose information where required by:

  • applicable law;
  • tax or regulatory requirements;
  • a lawful governmental request;
  • a court order;
  • an investigation;
  • legal proceedings; or
  • enforcement or defence of legal rights.

6.9 Corporate restructuring

Information may be transferred as part of a merger, acquisition, restructuring, financing, transfer of business or sale of assets.

Where reasonably practicable, affected users will be informed of a material change in the organisation responsible for their personal data.

6.10 Service-provider obligations

Where a service provider processes personal data on our behalf, we seek to require the provider to:

  • process information only for authorised purposes;
  • maintain confidentiality;
  • apply reasonable security safeguards;
  • limit access;
  • notify us of relevant security incidents; and
  • delete or return information when no longer required, subject to legal obligations.

We currently do not share personal data with a group company or affiliate because we do not have any such group company or affiliate. This Policy will be updated if that position changes.


7. Data retention

We retain personal data only for as long as reasonably necessary for the relevant purpose, contractual relationship, security requirement, dispute or legal obligation.

Indicative retention periods are set out below.

Account profile and contact information

Retained while the account remains active and ordinarily for up to three years after account closure or the last business transaction, where required for account history, support, disputes, fraud prevention or legal claims. Information will be deleted earlier where appropriate and legally permissible.

Login credentials

Active credentials and authentication tokens are disabled or invalidated following account closure. Security and authentication logs may be retained separately for the period stated below.

GST and business-verification records

Retained for the duration of the business relationship and thereafter for the period required for tax, corporate, audit, dispute-resolution and other legal purposes.

Orders, invoices, payments and refunds

Retained for up to eight financial years or for a longer period where required in connection with GST, taxation, corporate records, accounting, audit, investigation, litigation, recovery proceedings, or another legal requirement.

Credit and commercial account records

Retained during the customer relationship and ordinarily for up to eight financial years after the relevant transaction, payment or account closure where required for accounting, recovery, audit, disputes or legal claims.

Support tickets, complaints and warranty claims

Retained for three years after resolution or for the applicable warranty period plus three years, whichever is later, unless longer retention is required for a dispute or legal proceeding.

Voice notes, photographs and uploaded files

Retained for the period applicable to the related order, support request, warranty claim or dispute. Files that are no longer reasonably required may be deleted earlier.

Marketing consent and preferences

Marketing preferences are retained until you opt out or the relevant account is closed. A minimal suppression record may be retained after opt-out to ensure that marketing communications are not restarted unintentionally.

Security, access and diagnostic logs

Ordinarily retained for twelve months, unless a longer period is reasonably necessary to investigate misuse, a security incident or a legal claim.

Consent and privacy-request records

Records of consent, withdrawal, notices and privacy-rights requests may be retained for as long as reasonably necessary to demonstrate compliance and resolve disputes.

Backups

Rolling backups may be retained for up to ninety days. Deletion from active systems may therefore not immediately remove information from an existing backup. Backup copies are protected and are deleted or overwritten according to the backup cycle.

After the relevant retention period, information is securely deleted, anonymised or de-identified, unless further retention is required under applicable law.


8. Your rights

Subject to applicable law and relevant exemptions, you may request the following.

8.1 Access

You may request:

  • confirmation of whether we process your personal data;
  • a summary of the personal data being processed;
  • a summary of the processing activities undertaken; and
  • information about other entities with whom the personal data has been shared, where required by applicable law.

8.2 Correction and updating

You may request correction of inaccurate or misleading personal data and completion or updating of incomplete or outdated personal data.

Certain profile information may also be updated directly through the Portal.

8.3 Erasure

You may request erasure of personal data that is no longer required for the purpose for which it was processed.

We may retain information where necessary for:

  • GST or tax compliance;
  • accounting or audit requirements;
  • corporate record-keeping;
  • outstanding payments;
  • fraud prevention;
  • legal claims;
  • investigations;
  • court proceedings; or
  • another lawful purpose.

Where information cannot be erased, we will explain the reason where required.

8.4 Withdrawal of consent

You may withdraw consent for processing that is based on consent.

Withdrawal will not affect processing already completed before the withdrawal.

8.5 Marketing opt-out

You may opt out of marketing communications by:

  • changing marketing preferences in the Portal;
  • using the unsubscribe option provided in a message;
  • replying “STOP” where that facility is supported; or
  • contacting us using the details in Section 16.

8.6 Grievance redressal

You may raise a grievance concerning:

  • use of your personal data;
  • failure to respond to a request;
  • unauthorised access;
  • inaccurate information;
  • marketing preferences; or
  • another privacy concern.

8.7 Nomination

Where provided under applicable law, you may nominate another individual to exercise your rights in the event of your death or incapacity.

8.8 Complaint to the Data Protection Board

After using our grievance process, you may approach the Data Protection Board of India through the procedure made available under applicable law, when such procedure is applicable and available.


9. How to exercise your rights

You may submit a request:

Your request should include:

  • your name;
  • registered mobile number;
  • business name;
  • account or customer reference, where available;
  • the right you wish to exercise; and
  • sufficient details to identify the relevant information.

Identity verification

To protect customer accounts, we may verify a request through:

  • an OTP sent to the registered mobile number;
  • confirmation through the registered email address;
  • account authentication; or
  • another proportionate method.

We will not ordinarily request a government identity document. Where additional verification is reasonably necessary, unnecessary information may be redacted and the verification copy will not be retained longer than required.

Response timeline

We aim to:

  • acknowledge a privacy request or grievance within forty-eight hours; and
  • provide a substantive response or reasoned update within thirty days.

A complex request may take longer where permitted by law. In such a case, we will provide an update.


10. Cookies and similar technologies

10.1 Cookies

Cookies are small text files stored on a device when a website is used.

Similar technologies may include:

  • local storage;
  • session storage;
  • pixels;
  • application installation identifiers;
  • notification tokens; and
  • mobile application identifiers.

10.2 Categories used

Strictly necessary

Used for login, authentication, session security, fraud prevention, cart persistence and core Portal functions.

Indicative duration: session-based or up to thirty days.

Functional

Used to remember language, display mode, sidebar state, customer preferences and draft-related settings.

Indicative duration: up to one year.

Analytics

Used to understand feature usage, application performance, errors, aggregated navigation patterns and service improvement.

Indicative duration: up to two years, subject to the configuration of the relevant provider.

Marketing

Used only where enabled and permitted for measuring campaigns, managing marketing preferences and understanding responses to scheme or product communications.

Indicative duration: up to one year.

10.3 Cookie choices

When you first access the web Portal, you may be offered the following choices:

  • Accept all
  • Reject non-essential
  • Manage preferences

Strictly necessary technologies remain active because they are required for login, security and ordering.

Analytics and marketing technologies remain disabled unless the relevant permission has been provided, where consent is required.

10.4 Changing preferences

Cookie choices may be changed through the Cookie Preferences link available in the Portal.

Comparable application controls may be provided through mobile-app settings.

Blocking strictly necessary technologies may prevent login, cart or ordering functions from operating. Refusing analytics or marketing technologies will not prevent use of the core ordering service.


11. Communications

11.1 Transactional communications

Transactional and service communications may include:

  • OTP messages;
  • order updates;
  • dispatch alerts;
  • payment reminders;
  • refund information;
  • invoice information;
  • security alerts;
  • warranty updates; and
  • customer-support responses.

These communications are necessary to operate an active account and fulfil orders. You may not be able to opt out of them while the relevant account, transaction, payment or support request remains active.

11.2 Marketing communications

Marketing communications may include:

  • product launches;
  • promotional schemes;
  • offers;
  • reorder reminders;
  • account re-engagement messages; and
  • sales campaigns.

You may opt out of marketing without affecting transactional communications or your ability to place orders.

SMS communications are sent through applicable registered channels where required under telecommunications regulations.


12. Data security

We use reasonable technical and organisational safeguards designed to protect personal data against:

  • unauthorised access;
  • unauthorised disclosure;
  • alteration;
  • loss;
  • misuse;
  • destruction; and
  • personal-data breaches.

Safeguards may include:

  • HTTPS and encryption for information transmitted through the Portal;
  • secure one-way password hashing where passwords are used;
  • protected authentication tokens;
  • OTP-based account verification;
  • stronger authentication controls for privileged accounts;
  • role-based access controls;
  • need-to-know access;
  • session expiry;
  • logging of important administrative and security events;
  • access removal when personnel no longer require access;
  • restrictions on data exports;
  • protected backups;
  • monitoring of suspected unauthorised access;
  • security updates;
  • vendor-security requirements; and
  • use of payment providers that maintain applicable payment-security standards.

No electronic system is completely secure. You are responsible for:

  • keeping your registered phone and account credentials secure;
  • not sharing OTPs or passwords;
  • restricting account use to authorised persons;
  • informing us promptly of a lost device or unauthorised access; and
  • ensuring that account information remains accurate.

Personal-data breaches

Where a personal-data breach occurs, we will take reasonable steps to:

  • contain and investigate the incident;
  • reduce potential harm;
  • restore security;
  • maintain relevant records; and
  • notify affected individuals and the appropriate authority where required under applicable law.

13. Children’s data

The Portal is intended exclusively for business users who are at least eighteen years old.

We do not knowingly create accounts for or collect personal data directly from children.

If we become aware that personal data of a child has been collected through the Portal without appropriate authorisation, we will take reasonable steps to delete it unless retention is required by law.

A parent, guardian or other person who believes that a child’s personal data has been provided should contact us using the details in Section 16.


14. International and cross-border processing

Our primary operational systems may be hosted in India.

Some service providers, including cloud, communication, analytics, authentication, application-distribution or technical-support providers, may process or store information outside India.

Where cross-border processing occurs, we seek to apply appropriate contractual, organisational and technical safeguards and comply with restrictions, conditions or requirements imposed under applicable Indian law.

The exact location of processing may depend on the infrastructure used by the relevant service provider.


15. Your responsibilities

You should:

  • provide accurate and authentic information;
  • keep account and business information updated;
  • use the Portal only for lawful business purposes;
  • avoid impersonating another person;
  • avoid submitting false or misleading complaints or requests;
  • avoid uploading another person’s personal data without authority;
  • protect OTPs, passwords and devices; and
  • notify us promptly of suspected unauthorised use.

You are responsible for ensuring that persons using your business account are properly authorised.


16. Privacy and grievance contact

For privacy requests, grievances and Portal-related privacy queries, use the contacts below.

Authorised Grievance Officer

Pranshul Agrawal

Authorised Grievance Officer · Marine Switchgear Private Limited

Phone

08068863181

Address

C-108, Sector 2, Bawana Industrial Area, Delhi – 110039

General privacy or Portal-related queries

We aim to acknowledge grievances within forty-eight hours and provide a substantive response or reasoned update within thirty days.


17. Changes to this Privacy Policy

We may update this Privacy Policy to reflect:

  • changes to the Portal;
  • new features;
  • changes in service providers;
  • changes in data practices;
  • changes in security controls; or
  • changes in applicable law.

The updated Policy will be published through the Portal with a revised version number and date.

Where a change materially affects the categories of personal data collected, purposes of processing, information sharing, retention periods or user rights, we may provide advance notice through:

  • an in-app notice;
  • WhatsApp;
  • SMS; or
  • email.

Where required, we will request fresh consent before beginning materially different consent-based processing.


18. Language

This Privacy Policy is issued in English.

A Hindi or other translated version may be provided for accessibility or reference. Where legally permissible and where there is an inconsistency between translations, the English version will prevail.

Consent notices and important privacy information may be provided in additional languages where required under applicable law or supported by the Portal.