At Xpert, your privacy is fundamental to how we operate. This Privacy Policy explains how we collect, use, protect, and share information when you use our buyer intelligence platform — and the rights you and your customers have over that data.
Xpert is a business-to-business platform. We work with brands and retailers across India to help them reach verified buyers through privacy-compliant audience targeting. We take our obligations to both our business clients and their end customers seriously.
This policy applies to all businesses and individuals who access or use Xpert's platform, website, or services — including brands, retailers, and marketing teams using Xpert's audience targeting, retail intelligence, and buyer analytics products.
Xpert's data privacy protocols adhere to the provisions of the Indian Digital Personal Data Protection (DPDP) Bill 2023, ensuring that our platform aligns with the stipulated guidelines for processing digital personal data within India. The bill requires the collection of data either online or offline, followed by digitization for its applicability.
The consent of individuals is crucial for the lawful processing of personal data, with specific exemptions outlined for legitimate uses, including medical emergencies and government-provided benefits or services. Xpert's audience targeting solution is designed to facilitate compliance with these applicable privacy laws.
Xpert is currently available to businesses operating in India. Our privacy practices are designed specifically to comply with Indian privacy law and apply to all data processed through our platform.
Xpert operates on purchase transaction data — information about what real buyers have purchased, where they are located, and what categories they buy in. This is not behavioural or interest-based data. It is verified purchase data sourced from 1,000+ consumer brands across 90+ categories in India.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the date at the top of this page. We encourage you to review this policy periodically.
For the full rules governing use of the Xpert platform, please also read our Terms & Conditions.
Xpert collects two categories of information: platform usage data from our business clients, and anonymised purchase transaction data that powers our buyer intelligence network.
We use the information we collect exclusively to deliver Xpert's services. Specifically:
We do not sell your data or your customers' data to third parties. We do not use your data for advertising unrelated to Xpert's own services.
Our website and dashboard use cookies to maintain your session, remember your preferences, and understand how the platform is being used. By continuing to use Xpert, you agree to our use of cookies in accordance with this policy.
Most cookies we use are either essential (required for the platform to function) or analytical (used to improve our product). We do not use advertising cookies on the Xpert platform itself. Some third-party integrations may set their own cookies subject to their own privacy policies.
We retain your business account data for as long as your account is active, and for a reasonable period thereafter in case you return. Customer data you share with us for audience generation is retained only as long as necessary to fulfil that purpose.
When you delete a customer record or close your account, your customer data is removed from our active systems. Residual copies in backups are deleted within 30 days.
When you generate an audience list on Xpert, your customer data is hashed before being transmitted to any marketing platform. Hashing is a one-way cryptographic process — it converts personal information into an irreversible string that cannot be decoded back into the original data.
The marketing platform (Meta, Google) then matches its own hashed user records against your hashed audience list. At no point does any identifiable customer information leave your environment in readable form.
Your customer data is hashed at the point of audience generation. Xpert and our marketing platform partners never receive or store your customers' raw personal information.
No other business using Xpert can identify which brands are part of our network. It is not possible for any business to create an audience list using another business's customer base. Each brand's customer data is isolated and inaccessible to other platform users.
We also take measures to ensure that no single audience list can be reverse-engineered to reconstruct your original customer list. Our audience generation methodology is designed with this protection built in.
Xpert employs industry-standard security practices to protect all data processed through our platform. This includes encryption in transit and at rest, access controls limiting which team members can access sensitive data, and regular security reviews of our systems and processes.
While we take all reasonable steps to safeguard your data, no method of electronic transmission or storage is completely secure. We encourage you to take appropriate steps to protect your Xpert login credentials.
Xpert integrates with third-party marketing platforms (Meta, Google) to deliver audiences. These platforms operate under their own privacy policies, which we encourage you to review. When your hashed audience list is transmitted to these platforms, it is subject to their data handling practices in addition to ours.
We do not share your data with any third parties beyond what is necessary to deliver Xpert's services.
Your participation in Xpert's audience targeting network is entirely voluntary. You choose to share customer data with Xpert by integrating your store or manually uploading a CSV file. You can stop sharing data and deactivate your account at any time.
In accordance with the Indian DPDP Bill 2023, your customers have the right to know how and with whom their personal information is being shared. If a customer contacts you to ask about data sharing, you are required to provide them with this information. Xpert can provide documentation to support your disclosure obligations upon request.
In accordance with relevant Indian privacy laws, you must provide customers with the option to opt out of the sharing of their personal information for targeted advertising. Xpert gives you the tools to manage these opt-outs manually within the platform.
Manually excluded customers will no longer have their data shared for future audience lists. Please note that previously created audience lists are not retroactively updated when a customer is excluded.
To exclude a customer from data sharing:
From your Xpert dashboard, go to Settings > Account.
Click Customer opt-out.
Enter the customer's email address in the Customer email field.
Click Submit. The customer will be excluded from all future audience lists.
When you delete a customer's personal information from Xpert — such as in response to a customer opt-out request — that record is removed from our active audience targeting network. Residual copies in system backups are deleted within 30 days.
To delete your own Xpert account and all associated data, go to Settings > Account and select Delete my account. After deletion, you will lose access to all insights and audiences, and your customer data will be fully removed from our systems within 30 days.
You have the right to request access to the personal information Xpert holds about you as a business account holder, and to request corrections if any information is inaccurate. To make such a request, please contact us using the details below.
If you have questions about this Privacy Policy, want to exercise your data rights, or need support with a customer opt-out, reach out to our team directly.
We typically respond within 2–3 business days. For urgent data erasure requests, please mention "Data Request" in your message.