Skip to content
MapMyShops
How it worksFeatures
Solutions
  • Win local searchYour Google profile, run as marketing
  • Content at boutique scaleA month of on-brand posts
  • Reviews, answered in hoursEvery review, replied
  • WhatsApp campaignsThe right message, the right customer
  • Boss ModeApprove it all from WhatsApp
  • Competitive intelligenceKnow what your rival ships
What MMS doesSee all solutionsEverything MMS runs for your business, in one place.Explore
Verticals
  • Hospitality & StayHotels, resorts, homestays
  • Healthcare (Clinical)Dental & clinical specialties
  • Wellness & SpaSpas, wellness studios
  • Beauty & GroomingSalons, nail bars
  • Food & BeverageBakeries, cafés, fine-dine
  • Fitness & MovementGyms, yoga, studios
  • PetsPet care, grooming, boarding
  • Education & Early YearsPreschools & early years
  • Specialty RetailBoutiques, lifestyle, gifting
  • Lifestyle ServicesWeddings, photo, bridal
Built around your tradeNot sure where you fit?Thirty minutes on WhatsApp gets a straight answer.Explore
AboutBlog
Pricing
Plans & pricingTwo plans, one early-adopter offerFAQAnswers before you sign up
Early Adopter
Talk on WhatsAppWhatsApp
How it worksFeatures
Solutions
  • Win local search
  • Content at boutique scale
  • Reviews, answered in hours
  • WhatsApp campaigns
  • Boss Mode
  • Competitive intelligence
  • See all solutions
Verticals
  • Hospitality & Stay
  • Healthcare (Clinical)
  • Wellness & Spa
  • Beauty & Grooming
  • Food & Beverage
  • Fitness & Movement
  • Pets
  • Education & Early Years
  • Specialty Retail
  • Lifestyle Services
  • Not sure where you fit?
AboutBlog
Pricing
  • Plans & pricing
  • FAQ
Early Adopter
Talk on WhatsApp

DPDPA Compliance

DPDPA Compliance

The Digital Personal Data Protection Act, 2023 (DPDPA) is India's primary data-protection law. Many businesses are working out compliance for the first time. This page explains what we do under DPDPA and how it affects you. In short: MMS is DPDPA-compliant by architecture — consent, timestamps, erasure, and breach handling are built into how the system works, not bolted on as policy.

Our role

Data Fiduciary for the business data you give us directly (your name, business details, brand assets).

Data Processor for the customer data you upload via the Customer Data Gateway — you remain the Data Fiduciary for your customers.

Consent architecture

We require explicit, granular, informed consent at every collection point. We don't assume consent from continued use or pre-checked boxes. Section 5 notices are built into every consent flow, with the specific purpose, data categories, and retention period stated clearly.

Your customer data — your responsibility

When you upload customer contact data to the Customer Data Gateway, you confirm you have explicit consent from each customer for the specific use (marketing messages, birthday wishes, win-backs). MMS doesn't pre-validate that consent — under DPDPA, that's the Data Fiduciary's obligation.

Data Principal rights

Your customers exercise their rights through you (their Data Fiduciary). We propagate erasure requests across our systems within 72 hours of your relayed request.

Breach notification

If we detect a personal-data breach affecting your data, we notify you within 72 hours and follow our runbook to inform the Data Protection Board of India as required.

Cross-border transfers

Our infrastructure runs primarily in Indian data regions. Some third-party APIs (fal.ai, Google, Meta) may process data outside India per their own published policies — these are listed in our Privacy Policy.

Sub-processors (named for transparency)

For service delivery and DPDPA transparency, our processors include: Google Business Profile API, Meta (WhatsApp Business API), GoHighLevel, fal.ai, Razorpay, Google Analytics (only after cookie consent), Cloudflare, and our database systems. Named deliberately — DPDPA transparency requires disclosure.

The Empowerment Principle

No third-party passwords stored. Ever. We act through official APIs only — so your accounts, and your customers' trust, stay yours.

Data Processing Agreement

A DPA template is available on request for customers who need formal execution.

Grievance officer

Shiva Shankar R is the appointed Grievance Officer under the DPDPA.

For any question, concern, or complaint about how personal data is handled — yours or your customers' — write to grievance@itsinfraindia.com. Every grievance is acknowledged and handled within the timelines the Act and its rules prescribe.

Pending counsel (binding text)

Final DPDPA-binding language — Data Protection Board engagement and consent-withdrawal mechanics — to be drafted by counsel.

Company details

ITS Infra India · Partnership · GSTIN 33AALFI7872D1Z8
GST & billing (principal place of business): Building No. 155, SIPCOT Road, SIDCO Industrial Estate, Narasingapuram, Ranipet District, Tamil Nadu — 632403.
Office: #29, First Floor -1A, Nandi Tower, 2nd Cross, Manjunatha Layout, opposite Lumbini Kidzee, Bagalur Road, Kattigenahalli Bus Stop, Yelahanka, Bengaluru 560064, Karnataka.
(ITS Infra India is a partnership firm — no CIN.)
MapMyShops

Your shop’s superpower.

MapMyShopsis your WhatsApp-first marketing partner for India’s boutique businesses.

#29, First Floor -1A, Nandi Tower, 2nd Cross, Manjunatha Layout, opposite Lumbini Kidzee, Bagalur Road, Kattigenahalli Bus Stop, Yelahanka, Bengaluru 560064, Karnataka.

Product

  • How it works
  • Features
  • Solutions
  • Verticals
  • Pricing
  • Early Adopter

Company

  • About
  • Contact
  • Why consistency wins
  • Talk on WhatsApp

Resources

  • Blog
  • FAQ
  • Feature reference
  • Payment terms
  • Privacy
  • Terms
  • DPDPA
  • Cookie policy

Locations

  • Bangalore
  • Chennai
  • Hyderabad
  • Kochi
  • Coimbatore

© 2026 MapMyShops · A product of ITS Infra India (Partnership · GSTIN 33AALFI7872D1Z8) · GST & billing: Building No. 155, SIPCOT Road, SIDCO Industrial Estate, Narasingapuram, Ranipet District, Tamil Nadu 632403