Privacy Policy - Seventh Triangle
Seventh Triangle Consulting
- Version
- 2.0 (replaces the policy dated 01 March 2024)
- Effective date
- 21 August 2026
- Reviewed
- At least annually, and on any material change
- Governing law
- India
- Privacy contact
- privacy@seventhtriangle.com
1. Who we are, and what this covers
Seventh Triangle Consulting Private Limited, trading as Seventh Triangle Consulting and/or Seventh Triangle and/or STC (“we”, “us”), a private limited company, registered office Plot No. 15, Sector 142, Noida, Gautam Buddha Nagar, Uttar Pradesh 201305, with offices in Noida (Sector 142) and Bengaluru.
We are a digital agency. We run marketplace and advertising services (including on Amazon), performance marketing, SEO, retention, ecommerce development and analytics, and we publish applications on the Shopify App Store. We do not operate an online store and we do not sell products to consumers. An earlier version of this page said otherwise, because it was adapted from a store template.
This policy covers four situations, and which one you are in decides what applies:
| Who | Our role | |
|---|---|---|
| A | People who visit this website, enquire, or subscribe | Controller (Data Fiduciary under India’s DPDP Act, 2023) |
| B | Named contacts at our clients and prospective clients | Controller |
| C | Data inside a client’s Amazon or other marketplace account that we access to do our job | Processor, on the client’s instructions |
| D | Merchants who install our Shopify apps, and their customers | Processor, on the merchant’s instructions |
Under the DPDP Act, “controller” corresponds to Data Fiduciary, “processor” to Data Processor, and the individual the data relates to is the Data Principal.
In A and B we decide how data is used, and you can exercise your rights directly with us. In C and D the data belongs to our client or the merchant: they decide, and we act only on their instructions. If your data reaches us that way, contact the business you dealt with first; we will pass any request we receive straight to them and help them answer it.
2. Website visitors and enquirers (A)
What we collect. Your name, work email, phone, company and job title when you contact us or subscribe, plus whatever you write in the message. Automatically: IP address, browser and device type, pages viewed, referring URL, and approximate city-level location. We do not take payments on this site, and we ask you not to send us health, biometric or other sensitive personal data.
Why, and on what basis. To answer your enquiry and prepare proposals (you provided your details for that purpose); to run and secure the site; to measure how the site is used; and to send you marketing about our services. Under India’s DPDP Act we rely on your consent for analytics and marketing; section 7 of that Act lists permitted non-consent uses exhaustively and does not include them. Under GDPR and UK GDPR we rely on your consent, on steps taken at your request before a contract, and on our legitimate interest in running the business. We keep records where the law requires it.
You can unsubscribe from any marketing email using the link in it, or withdraw consent at any time by writing to privacy@seventhtriangle.com. Withdrawing is as easy as giving, and does not affect what we did before you withdrew. Where you gave consent through a registered Consent Manager under section 6(7) of the DPDP Act, you can give, manage, review and withdraw it through that Consent Manager.
Cookies. Strictly necessary cookies keep the site working and remember your cookie choice. Preference, analytics and advertising cookies are set only where you consent. Consent on this site is captured and stored by CompliEdge, our own DPDP consent management application, which records your choice with a timestamp so we can show what you agreed to and when. Change your choice at any time via Cookie preferences, or block cookies in your browser. The third-party tools currently on this site are Google Analytics 4 (site usage measurement), Microsoft Clarity (session and interaction analytics), HubSpot (enquiry and contact forms), Calendly (meeting booking) and Google reCAPTCHA (spam and abuse prevention on forms) each with its own privacy notice.
Where you consent to advertising cookies, data is disclosed to those advertising platforms for measurement and retargeting. Under California law that counts as “sharing” even though we are not paid for it, so we say so rather than relying on the technicality. We do not sell personal data for money. To stop the sharing, reject advertising cookies using the Cookie preferences control, or write to us at privacy@seventhtriangle.com. We honour Global Privacy Control signals.
Where prospect details come from. Some business contact details reach us from sources other than you: public professional profiles and company websites, business data providers, events and directories, and referrals. Where the law requires, we tell you within a month of obtaining them, or in our first message to you; every outbound email links to this page. Object or ask us to erase at any time and we will.
3. Client contacts (B)
We hold business contact details, correspondence, meeting records, contract and billing information, and a record of which of our people worked on your account. We use it to deliver the engagement, manage the relationship, invoice, meet legal record-keeping duties, and, where permitted, tell you about relevant services.
We do not disclose your confidential information or your data to another client, and we do not use your data to build benchmarks, indices, datasets or models. General skills and methodology our people develop remain ours and are applied across our practice; that never involves reusing or revealing your data.
4. Marketplace data we handle for clients (C)
This section covers data inside a client’s account on Amazon Seller Central, Vendor Central, Amazon Advertising and the Selling Partner API, and equivalently on other marketplaces we are engaged to run.
4.1 How we get in, and what we take
We obtain access only through the platform’s own delegated-access mechanisms: permissions granted by the account holder, or an authorised application flow. We do not request, accept, store or use a client’s marketplace username and password. If a client sends credentials we decline them, delete them, and ask them to grant access properly.
We request the minimum permissions the contracted service needs. If a role would give us data the service does not require, we ask for a narrower one or decline it.
We work with advertising performance data, business and traffic reports, catalogue and listing data, inventory data, Brand Analytics where the client is brand registered, and financial data where contracted. We do not need buyer personal information for advertising optimisation or marketplace growth work, and do not access it for those services. Where an engagement genuinely requires it, access goes to named individuals for the duration of that task only.
4.2 What we will never do
Whatever we are instructed or offered, we will not: use a client’s data for anything other than that client’s contracted service; commingle one client’s data with another’s or with our own; use it to build or train any product, model, benchmark, index or dataset, including any artificial intelligence or machine learning system; sell, licence, rent or otherwise disclose it to anyone outside our approved processors, the client’s written instruction, or a legal requirement; use buyer data to contact buyers for anything but fulfilling that transaction, and never for marketing; contact buyers outside permitted platform channels; publish any client-identifying detail, screenshot or metric without the client’s written consent, and never any buyer personal information; store any of it on personal devices, personal email, personal cloud accounts, or any system not on our approved systems register; or attempt to re-identify data that has been aggregated or de-identified.
4.3 What we commit to Amazon
These are documented procedures, approved by our leadership on 21 August 2026 and reviewed at least annually. The underlying documents (our Information Security Policy, Security Incident Response Plan, Risk Assessment and Management Procedure, and Organizational Change Notification Policy) are available to Amazon and to clients on request.
- Security incidents. Where an incident involves, or may involve, information obtained through Amazon, we notify Amazon within twenty-four (24) hours of detection, through the channel Amazon designates, and keep reporting until it is resolved, with a written root-cause analysis and remediation plan at the end.
- Organizational changes. We notify Amazon in writing within thirty (30) days of any organizational change or event that alters our need for, or use of, that information: change of control, merger or acquisition, insolvency, a change of legal entity name or registered address, a change in the categories of information we access or why we access it, a change of security or privacy contact, or a change in the roles, permissions or API scopes we require. Where a change reduces what we need, we give the access back rather than keep it.
- Risk assessment and incident response. We maintain a documented risk assessment process and a documented incident response plan covering monitoring, detection and response. A full assessment runs at least annually and on defined triggers; risks sit in a register with owners and dates, reviewed by leadership at least quarterly; the response plan is tested at least annually.
- Retention. Where we hold buyer personal information at all, it is deleted as soon as the task is done and never kept beyond thirty (30) days from the date we obtained it, unless the law requires longer, in which case it sits in a separate encrypted archive for the minimum statutory period and is then destroyed. We do not write buyer personal information to our logs.
- Deletion on request. On written request from a client or from Amazon we delete the information and certify the deletion in writing within thirty (30) days.
- Precedence. Where anything here conflicts with an Amazon policy that applies to us (the Amazon Data Protection Policy, the Acceptable Use Policy, the Services Business Solutions Agreement, or any solution provider or developer terms), the Amazon policy wins and we follow the stricter obligation.
We apply the same commitments to other platforms whose policies impose equivalent duties.
5. Our Shopify applications (D)
We publish applications exclusively through the Shopify App Store. Installation, billing and uninstallation are handled by Shopify.
What they access. Each application requests specific API scopes, which Shopify shows the merchant before installation. Depending on the app this can include shop configuration, product and catalogue data, order data, and, where the app’s function needs it, protected customer data such as customer names, addresses, emails and phone numbers. We request the narrowest scopes the functionality requires, and where an app can work without protected customer fields, it does not ask for them. Where an app does need them, we request that access and declare our data protection practices through the Shopify Partner Dashboard and use the data only once Shopify approves.
How we handle it. We meet Shopify’s protected customer data requirements at Level 1 and, for apps touching customer name, address, email or phone, at Level 2. In practice: we process only the minimum needed; we tell merchants what we process and why and stay within those purposes; we respect customer consent and opt-out decisions, and where any automated decision-making is used we let customers opt out; we enter data protection agreements with merchants; we apply retention limits; we encrypt data in transit, at rest and in backups; we keep test and production data separate and never use production personal data in development; we run a data loss prevention strategy; we limit staff access, require strong authentication and keep an access log; and we operate a documented incident response policy.
What we don’t do. We do not sell app data, use it for our own advertising, or use it to train models, and we never use one merchant’s data to benefit another. Merchant data from an application is not made available to our agency engagements, and client data from an agency engagement is not made available to our applications, unless the same client instructs it in writing.
6. Who else sees data
Processors we appoint: Google Workspace (email, documents and file storage), Zoho Projects (project management and delivery records), HubSpot (CRM and marketing), and Shopify (this website, and the platform our applications run on). They act on our instructions, are bound by written terms no less protective than this policy, are assessed before we engage them and at least annually after, and we remain responsible to you for what they do. A current list is available from privacy@seventhtriangle.com. Where a client’s contract requires prior notice or approval of a sub-processor, we obtain it before engaging them.
Independent parties we are not responsible for: Amazon and Shopify (platform operators running their own terms), the advertising and analytics platforms named above, our professional advisers, and regulators or courts where the law compels disclosure. These decide their own purposes; they are not our sub-processors and this policy does not bind them.
One qualification: for the advertising and analytics platforms, we and the platform are joint controllers for data collected by their tags on our own website (we chose to place them), and they are independent controllers for what they do with it afterwards. You can exercise your rights against either of us; write to privacy@seventhtriangle.com and we will help.
7. Security, retention and transfers
Security. A named individual, Mr. Manas (manas@seventhtriangle.com), owns information security here. We encrypt data in transit (TLS 1.2+) and at rest (AES-256 or equivalent), enforce multi-factor authentication on every account that can reach client or personal data, allow no shared logins, keep credentials in an approved secrets manager and rotate them at least every 90 days, grant access on a least-privilege basis and review it quarterly, and log and monitor access to systems holding personal data. Our full Information Security Policy is available on request. No system is perfectly secure, but these are the controls we operate and we will tell you promptly if something goes wrong.
If something goes wrong. We notify affected clients without undue delay after becoming aware and in any event within 72 hours, or sooner if their contract says so. We notify Amazon within 24 hours of detection where Amazon-obtained information is involved, and Shopify without undue delay where app merchant or customer data is involved. Under India’s DPDP Act we intimate the Data Protection Board and every affected individual; other regulators are notified where their law requires, on their deadlines, including CERT-In, whose directions require certain cyber incidents to be reported within six hours of being noticed.
Personal data contained in incident evidence and security logs sits in a segregated, encrypted store used only for incident investigation, even after closure or longer under a legal hold. Where buyer personal information appears incidentally in incident evidence it is minimised or redacted when collected, kept only as long as the law or a legal hold requires, and that period is recorded in the incident record.
At the end of a period we delete or irreversibly anonymise the data, including in backups as they cycle.
Transfers. We operate from India and work with clients in India, the UK, the US, Australia and elsewhere, so data may be stored in or accessed from other countries. Where a UK or EEA client instructs us to process data on their behalf, they are the exporter and we sign the Standard Contractual Clauses (with the UK Addendum where relevant) as importer. Transfers outside India follow the DPDP Act and any restrictions notified under it. Where we transfer data onward to our own processors we put the appropriate onward-transfer terms in place first and assess the destination’s legal environment as part of our vendor assessment. A copy of the relevant safeguard is available on request. The same controls in this section apply wherever the data sits.
8. Your rights
Wherever you are, you can ask us what personal data we hold about you, ask us to correct or delete it, object to or restrict how we use it, ask for a copy in a portable format, and withdraw consent where consent is what we rely on. Depending on where you live you may have further rights. Tell us what you want and we will honour whatever your local law gives you rather than making you cite it.
In India, under the Digital Personal Data Protection Act, 2023, you also have the right to nominate someone to exercise your rights if you die or become incapacitated, and the right to a grievance mechanism. Our Grievance Officer is Mr. Manas, Co-Founder, at manas@seventhtriangle.com. If we do not resolve your complaint you can go to the Data Protection Board of India.
Where we hold your data as a processor (Sections 4 and 5), contact the business whose data it is, and we will forward your request to them promptly and help.
To exercise a right, write to privacy@seventhtriangle.com. We acknowledge within 10 business days and respond within 30 days, extending only where the law allows and telling you if we do. We may need to verify who you are first.
Other than as described in Section 5 for our applications, we do not make decisions with legal or similarly significant effects about people by purely automated means. We do use automated tools (bid and budget management, audience segmentation, campaign optimisation) to deliver advertising services; these run on campaign and aggregate performance data under human supervision and defined targets, not on individual profiles we build.
Our services are for businesses and are not directed at anyone under 18, and we do not knowingly collect children’s data. Where a client’s or merchant’s own customer data reaches us as a processor, responsibility for age-related obligations rests with that client or merchant.
9. Changes, and how to reach us
We review this policy at least annually and update it when our processing, systems or the law change. The effective date above shows the current version, and we will tell you about material changes by email or a notice on this page.
- Privacy
- privacy@seventhtriangle.com
- Grievance Officer (India)
- Mr. Manas, manas@seventhtriangle.com
- Security incidents
- privacy@seventhtriangle.com
- General
- partner@seventhtriangle.com
- Post
- Seventh Triangle Consulting Private Limited, Plot No. 15, Sector 142, Noida, Gautam Buddha Nagar, Uttar Pradesh 201305
Incorporated by reference into our Terms and Conditions. Amazon, Seller Central, Vendor Central and Amazon Advertising are trademarks of Amazon.com, Inc. or its affiliates; Shopify is a trademark of Shopify Inc. We are an independent service provider, not endorsed by or affiliated with them except where we state a current partner status.
Featured In
We attend to all your business's needs - from setting up your online
Seventh Triangle & ZEPIC Host Retail Roundtable in Mumbai
A leadership roundtable exploring shifting purchase journeys, omnichannel execution, and how AI is transforming how consumers move across platforms before making decisions.
“The journey now jumps from reels to reviews to marketplaces to stores, making consistency, data, and real value critical for growth.”
Featured in Outlook India: Promising Founders to Watch in Q1 2026
A curated list of emerging founders reshaping industries across D2C, technology, and modern business ecosystems, highlighting leaders driving innovation and long-term growth.
“Seventh Triangle operates with 150+ experts and powers 300+ brands globally, reflecting its scale and credibility in the Shopify ecosystem.”
Seventh Triangle & ZEPIC Host Roundtable on Omnichannel Growth
An exclusive leadership roundtable focused on evolving consumer behaviour, omnichannel realities, and the growing role of AI in shaping modern retail and customer journeys.
“Discussions centred on brand infidelity, AI-led transformation, and how consumer journeys are becoming increasingly non-linear across channels.”