AttesarServicesSell

Identity-verified sellers

Government ID + selfie before anyone can list

Payment protected

Held by our payment partner until you confirm delivery

Fair disputes

Evidence reviewed by Trust & Safety, usually within 48h

Attesar

The verified marketplace for premium digital products. Templates, source code, UI kits, graphics, fonts and business templates from creators who prove who they are — with every payment protected until you confirm delivery.

CardsUPINet-bankingWallets

Payments processed by licensed partners. We never accept cryptocurrency.

Code & Software

  • Website Templates & Themes
  • Source Code & Scripts
  • Mobile App Templates
  • APIs & Backend Services
  • HTML Email Templates
  • Landing Page Templates
  • Admin & Dashboard Templates

Developer Tools

  • No-code App Templates
  • Workflow & AI Automations
  • BI & Analytics Templates

Knowledge & Business

  • Productivity Templates
  • Business Plan Templates
  • Financial Models
  • Invoicing & Accounting
  • Project Management Templates
  • CRM & Sales Templates

Company

  • How it works
  • Fees & pricing
  • Rankings
  • Affiliate programme
  • Pricing guide
  • Find a professional
  • List your practice
  • Sell on Attesar
  • Marketplace rules
  • FAQ
  • Blog
  • Community
  • About
  • Contact support

Legal

  • Terms of Service
  • Privacy Policy
  • Refunds & Delivery
  • Seller Agreement
  • Prohibited Items
  • IP & Takedown Policy
  • Verification & AML
  • Cookie Policy
  • Grievance Officer
Attesar

© 2026 Attesar. All rights reserved. Attesar is a marketplace; sellers are the suppliers of record for the products they list.

Verified sellers · Reviewed listings · Protected payments

    Privacy Policy

    Updated 10 September 2026. Version 2026-09-107 min read14 sections

    On this page

    • 01Data We Collect
    • 02Why We Use It and Our Legal Bases
    • 03Identity Documents
    • 04Location Data and the Services Directory
    • 05Automated Screening
    • 06Who We Share Data With
    • 07International Transfers
    • 08Retention
    • 09Your Rights
    • 10Cookies
    • 11Security
    • 12Children
    • 13Changes
    • 14Contact

    This policy explains how Attesar (operating entity to be confirmed) ("we") collects, uses, shares and protects personal data when you use Attesar. It is written to satisfy India's Digital Personal Data Protection Act 2023 (DPDP), the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) and similar laws. We are the data fiduciary / controller for the data described here.

    01Data We Collect#

    • Directory data (if you list a practice): the particulars you submit for publication — name, qualifications, registration number, practice areas, place of work and any contact details — plus verification evidence, which is never published.
    • Enquiry data (if you contact a professional): your name, email, any phone number and your message.
    • Approximate location: a city you choose, a position your browser shares with your permission, or an estimate from your connection. See Section 4.
    • Account data: name, username, email, password (hashed), avatar, language, country.
    • Identity verification data (sellers): legal name, date of birth, document type and number, images of the document and a selfie, proof of address, verification result. Where a third-party verifier is used, they process this data on our behalf.
    • Legal and payout data (sellers): business name, tax identifiers, address, bank account, UPI ID or PayPal email. We never collect card numbers.
    • Transaction data: listings, orders, payments (references and amounts, not card details), downloads, invoices, disputes and their evidence.
    • Communications: order chat messages, support tickets, forum posts, notifications, consent records with timestamp and version.
    • Technical data: IP address, device and browser information, approximate location from IP, cookies and similar identifiers, security logs.

    02Why We Use It and Our Legal Bases#

    • To provide the marketplace, process orders and payouts, deliver products and issue invoices (performance of a contract).
    • To verify sellers, prevent fraud and money laundering, screen sanctions, moderate content and resolve disputes (legal obligation and legitimate interest in a safe marketplace).
    • To comply with tax, accounting, consumer-protection and law-enforcement obligations (legal obligation).
    • To send service messages about your account and orders (contract), and marketing emails only if you opted in (consent, withdrawable at any time).
    • To improve the Platform using analytics, only with your cookie consent (consent).

    03Identity Documents#

    Verification documents are stored outside the public web root in access-controlled storage, are viewed only by trained Trust & Safety staff, and every access is logged. They are used only to verify identity and age, match payout accounts to the verified name, and meet legal duties. They are deleted when no longer required for those purposes, subject to retention obligations in Section 7.

    04Location Data and the Services Directory#

    We use an approximate location to sort directory results by distance. There are three sources and you can always override or clear the result.

    • What we use. If you pick a city, or allow your browser to share your position, we use that. Otherwise we read the approximate country and city our content-delivery network derives from your connection, which requires no external lookup and sends nothing to a third party. If neither is available and an administrator has switched it on, we may send your IP address to a third-party geolocation service to obtain an approximate city; this is disabled by default and named in the cookie notice when it is in use.
    • Accuracy. Location derived from an IP address is an estimate, not a fact — VPNs, mobile networks and corporate connections routinely place people in the wrong city. We always show you which location we are using and how it was determined, and let you change it.
    • How it is stored. Your location is kept in a cookie in your browser so results stay sorted between pages. It is not stored against your account, is not used to profile you or target advertising, and is not shared. Clearing it in the location control, or clearing your cookies, removes it.
    • Legal basis. Legitimate interests in showing you relevant nearby results, and your consent where you actively share your device location or where an IP lookup is used.

    Professionals listed in the directory. If you publish a profile, the particulars you submit — including your name, qualifications, registration number, practice areas, place of work and any contact details you provide — are published on a public page, indexed by search engines and available to anyone. This is on the basis of your request and our contract with you. Verification evidence you send us is held privately and is never published. You can withdraw your listing at any time, which removes the public page; search engines may retain a cached copy for a period we do not control.

    Enquiries. When you send an enquiry through the directory, we pass your name, email, any phone number and your message to the professional you chose, with your explicit consent, so that they can reply. From that point they decide how to use it and are an independent controller of it; their own privacy practices and professional confidentiality obligations apply. We keep a copy so we can investigate misuse and answer complaints. Do not include sensitive details in an enquiry that you would not put in an ordinary email.

    05Automated Screening#

    New listings and messages are screened automatically, including by AI models, for prohibited items, fraud patterns and off-platform payment requests. Automated results never remove a listing or close an account by themselves: a person reviews before any decision with legal or significant effect. You can contest any decision through the Grievance Officer.

    06Who We Share Data With#

    We never sell personal data and never share it for third-party advertising.

    • A professional you send a directory enquiry to receives your name, contact details and message, and decides independently how to use them from that point.
    • Payment providers (Stripe, Razorpay) to process payments and payouts, under their own privacy terms.
    • Identity-verification providers, when enabled, to perform document and liveness checks.
    • Service providers for hosting, email delivery, error monitoring and AI moderation and support, bound by contracts that limit use to our instructions and apply data minimisation.
    • The other party to your order: buyers see a seller's username, verified status and business details on invoices; sellers see a buyer's username and, on invoices, their name and country.
    • Authorities, courts and regulators where required by law, and rights-holders where necessary to respond to an infringement notice.
    • A successor in the event of a merger or acquisition, under the same protections.

    07International Transfers#

    Our servers and providers may be located outside your country, including in India, the European Union, the United Kingdom and the United States. Transfers are protected by appropriate safeguards such as standard contractual clauses and, for DPDP purposes, are limited to countries not restricted by the Indian Government.

    08Retention#

    Account data is kept while your account is open. Transaction, invoice and tax records are kept for the period required by tax and accounting law (up to 8 years). Identity-verification records are kept for as long as anti-fraud and anti-money-laundering rules require after account closure, then deleted. Dispute evidence is kept until the limitation period for claims expires. Backups are purged on a rolling schedule.

    • Directory listings are kept while published and for 3 years after withdrawal, so we can evidence what was published and when it was verified. Enquiries are kept for 2 years to investigate misuse and answer complaints. Verification evidence is kept for 5 years or as your regulator requires, whichever is longer.

    09Your Rights#

    Depending on where you live, you have the right to access, correct, update or delete your data; to receive a copy in a portable format; to restrict or object to processing; to withdraw consent; to nominate a person to exercise your rights (DPDP); to opt out of the sale or sharing of personal data (CCPA — we do not sell); and not to be discriminated against for exercising your rights. Use Settings → Privacy & data to submit a request, or email privacy@attesar.com. We respond within 30 days. You may also complain to the Data Protection Board of India, your EU or UK supervisory authority, or your local regulator.

    10Cookies#

    We use strictly necessary cookies for sign-in, security and your theme, and analytics cookies only after you accept them in the cookie banner. See the Cookie Policy.

    11Security#

    Passwords are hashed, sessions are token-versioned, staff accounts require two-factor authentication, documents are encrypted at rest and in transit, and money movements are recorded in an immutable audit log. No system is perfectly secure; report vulnerabilities to security@attesar.com.

    12Children#

    The Platform is for adults. We do not knowingly collect data from anyone under 18; if you believe we have, contact us and we will delete it.

    13Changes#

    We will post updates here and, for material changes, notify you on the Platform or by email.

    14Contact#

    Data protection contact: Data Protection Officer (to be appointed), privacy@attesar.com. Grievance Officer: Grievance Officer (to be appointed), grievance@attesar.com. Postal address: Attesar (operating entity to be confirmed), registered office address to be published.