Privacy Policy

Effective: 17 July 2026

EximJinn (“we”, “us”, “our”) is a software platform owned and operated by EximJinn Technology Private Limited that helps exporters, importers and consultants manage their Export-Import documentation and related workflows through a set of modules. This policy explains what we collect, how we use and protect it, and your rights. It applies to all current and future modules of the Service.

1. Information we collect

  • Account details you or your administrator provide: name, email, company name, phone, IEC and (where relevant) GSTIN.
  • Portal credentials (such as DGFT username and password) that you enter so a module can retrieve your data on your behalf. These are only collected where a module needs them.
  • Export-Import data and documents retrieved on your instruction — for example e-BRC certificates, shipping bills, EGM and duty/drawback details, amounts, dates, and generated PDF files.
  • Usage and activity logs such as job records, module lookups, timestamps and support tickets, used to run, secure and support the Service.
  • Technical data collected automatically when you use the Service — your IP address, browser and device type, and access timestamps — recorded in our server and security logs to keep the Service running, secure and auditable.

2. Cookies and similar technologies

We use only strictly necessary cookies — the ones required to keep you securely signed in and to protect your session (for example, our authentication/session cookie and security tokens). These are essential to operate the Service and cannot be switched off without breaking sign-in. We do not use advertising cookies, and we do not load third-party advertising or cross-site tracking on the Service.

On our public marketing pages (such as the home, pricing and knowledge-portal pages) we measure basic, anonymous and cookieless traffic — how many times a page is viewed and which website referred the visit. This is done first-party (on our own servers, not shared with any third-party analytics provider) and stores no cookie, no IP address and no visitor identifier, so it cannot identify you or track you across sites or sessions. It does not run inside the signed-in application. Because it sets no cookies and collects no personal data, it needs no cookie banner.

3. How we use your information

We use your information solely to provide and operate the Service for you: to retrieve your data from the relevant portals on your instruction, to store, organise, display and analyse it for you, to enable the modules assigned to your account, to provide support, and to keep the Service secure. We do not sell your data or use it for third-party advertising.

By signing up you consent to us contacting you by email and phone during business hours — to operate and support the Service, respond to your queries, and (if you opt in) share information about new modules. You can opt out of non-essential communications at any time by contacting us.

4. Legal basis and consent

We process your information to perform our agreement with you and to provide the modules you use, based on your instructions and consent. Where a module accesses a third-party portal, you authorise that access as described in our Terms of Service. You may withdraw consent by discontinuing use and contacting us, subject to legal retention requirements.

5. Your portal credentials

Any portal password you provide (for example, your DGFT login — and, in future, ICEGATE or the GST portal) is encrypted at restbefore it is stored, and is decrypted only on our server, only to log in to that portal to retrieve your own data on your behalf. It is never displayed back to you, never visible to our staff, and never shared with any third party. You can update or remove your credentials at any time. Some modules use public government enquiry services that require no login and therefore no credentials.

6. Who can see your data

Your Export-Import data — your e-BRCs, remittances, shipping bills and related records — is private to your account. It is isolated per account in our systems, and our staff and administrators cannot view it by default. Administrator accounts manage your subscription, modules and billing — not your business data.

If you ask us for help with a specific issue, you may grant our support team a time-limited, revocable window to view your account, which you control from your account settings. Any such access is read-only and recorded in our audit trail(who accessed what, and when), and it ends automatically when the window expires or you revoke it. We do not access your data without this consent, except where strictly required by law.

7. Confidentiality

We treat all of your account information and Export-Import data as strictly confidential. We use it only to provide the Service to you and for the purposes described in this policy. We do not sell, rent or trade your data, and we do not use it to build profiles for advertising. Access within our organisation is limited to the minimum personnel who need it to operate the Service, and — as set out in section 5 — our staff cannot view your business data without your explicit, time-limited, audited consent.

8. Data storage & security

Your data is stored on secure cloud servers operated by reputable infrastructure providers, and each account's data is logically isolated from others. We apply reasonable technical and organisational measures, including: HTTPS/TLS encryption in transit; encryption at rest for sensitive credentials and secrets; role-based access controls; audit logging of sensitive actions (including credential use and any support access); administrator two-factor authentication; rate limiting; and security response headers. Backups may be retained for resilience. While no system can be guaranteed perfectly secure, we work to protect your information and to detect and respond to incidents.

9. Data sharing

We access government or third-party portals on your behalf using the details you provide, and we use trusted infrastructure providers (such as our hosting and email providers) to operate the Service. We do not otherwise share your data with third parties, except where required by law or to protect our legal rights.

10. Where your data is processed

The Service is operated for a primarily Indian user base, and we aim to store and process your data on infrastructure located in or serving India. Some of the trusted providers we rely on (for example, email delivery) may process limited data — such as your email address and message content — on servers outside India. Where that happens, we take reasonable steps so your data continues to be protected in line with this policy and applicable law, including India's Digital Personal Data Protection Act, 2023.

11. Data retention

We retain your account and Export-Import data for as long as your account is active, so you can access your historical records, and thereafter only as long as needed for legitimate business purposes or as required by law. When you close your account, or on your written request, we delete or anonymise your personal data within a reasonable period — subject to any legal retention obligation and to routine backups, which are overwritten on their normal cycle. Your certificates also remain available directly on the relevant government portal.

12. Your rights

Subject to applicable law, including India's Digital Personal Data Protection Act, 2023, you may request access to, correction of, or erasure of your personal data, and may raise a grievance about how it is handled. To exercise these rights, contact us using the details below.

13. Eligibility

The Service is intended for businesses and professionals — exporters, importers and their consultants — and for use by adults (18 years or older) who are authorised to act for the account holder. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. By using the Service you confirm you are authorised to provide the information and credentials you enter and to bind the account holder to our Terms of Service.

14. Grievance / contact

For any privacy question or grievance, reach us at info@eximjinn.com or call +91 81691 90036 (Monday to Saturday, 10:30 AM – 6:30 PM). We will respond within a reasonable time. EximJinn Technology Private Limited is the data fiduciary responsible for your information.

This policy may be updated from time to time; the latest version will always be available on this page, and we may ask you to re-accept it when we make material changes.