BuildWrightFor Builders
ServicesPricingResourcesPartners

BuildWright Consultants

Your virtual compliance team for early-stage businesses across India: incorporation, licenses, documentation, and dispute resolution.

Services

  • Incorporation
  • Licenses & registrations
  • Documentation
  • Dispute resolution
  • Monthly plans

Company

  • Blog
  • Resources
  • Tools
  • Partners
  • For Advisers
  • For Freelancers
  • Privacy Policy
  • Terms of Use

Get in touch

  • Free consultation
  • WhatsApp
  • Client login

BuildWright Consultants is a virtual compliance team. We do not provide advocacy or litigation representation.

Your data is encrypted in transit and at rest on Google Cloud infrastructure. We never sell it. See our privacy policy.

© 2026 BuildWright Consultants. All rights reserved.

HomeDocumentationWebsite Terms, Privacy & Refund Policy Drafting

Documentation

Website Terms, Privacy & Refund Policy Drafting

We take your product details: what you collect, how you use it, and whether you sell to consumers or businesses. Then we produce a customized Terms of Use, DPDP-compliant Privacy Policy, and Refund Policy set, reviewed against the Consumer Protection (E-Commerce) Rules 2020 where applicable.

A live Indian website needs Terms of Use, a DPDP-compliant Privacy Policy, and a Refund Policy if it takes payment, three different documents answering three different questions. We draft all three from your actual product details, checked against the Consumer Protection (E-Commerce) Rules 2020 where they apply.

Terms of Use, a Privacy Policy, and a Refund Policy each answer a different question: what a user can do on your site, what data you collect and why, and what happens if a customer wants their money back. A template built for one rarely answers the others correctly.

If you sell to individual consumers, the Consumer Protection (E-Commerce) Rules 2020 add disclosure and grievance-redressal obligations on top. If you sell purely to other businesses for their business use, those Rules generally don't apply to that transaction, and we confirm which situation you're in before drafting.

Scope

What's included

  • Terms of Use set for India, with governing law and liability-limit clauses matched to your product rather than a generic download.

  • The Privacy Policy is drafted against the DPDP Act's notice requirements and cross-referenced with our DPDP Compliance Checklist tool, giving you a way to keep assessing your compliance well after delivery.

  • Where your intake flags third-party vendors touching personal data, we note where a separate Data Processing Agreement is needed with that vendor. Drafting the DPA itself sits outside this service today.

Specifics

The details

Three documents, three different jobs

DocumentAnswers
Terms of UseWhat a user is allowed to do on your site, and what you're not liable for
Privacy PolicyWhat personal data you collect, why, and what rights a user has over it
Refund PolicyWhat qualifies for a refund, the timeline, and how a customer requests one

We keep the Privacy Policy standalone rather than folded into the Terms of Use. A data-protection notice buried inside a general terms document is one of the more common reasons a consent flow doesn't hold up as proper notice under the DPDP Act.

The B2B question we ask before drafting anything

The Consumer Protection (E-Commerce) Rules 2020 apply based on the Consumer Protection Act's definition of consumer, which excludes purchases for commercial use. A platform selling purely to other businesses generally sits outside these Rules for that transaction. We confirm whether you sell to consumers, businesses, or both before drafting, since it changes what the documents need to say.

What this service doesn't cover

This service drafts your own public-facing documents. It doesn't draft the Data Processing Agreement between you and a vendor who touches your users' data on your behalf, that's a separate document we flag as needed but don't bundle in here today. It also isn't a substitute for a qualified data-protection review before you rely on any DPDP exemption.

Process

How it works

Step 1 of 4

Tell us about your product

What it does, what personal data you collect, and who you sell to.

Tell us about your product

What it does, what personal data you collect, and who you sell to.

Common mistakes founders make

  • Folding the Privacy Policy into the Terms of Use instead of keeping it standalone, which weakens it as proper DPDP notice.
  • Assuming a B2B product doesn't need a Privacy Policy at all, when the DPDP Act's notice requirements apply to any personal data collected, regardless of whether the sale itself is B2B or consumer.
  • Applying the Consumer Protection (E-Commerce) Rules 2020 to purely B2B transactions where the commercial-use exclusion actually applies.
  • Publishing a Refund Policy that doesn't match what the payment gateway or App Store/Play Store policies actually require.
  • Assuming this service also covers a Data Processing Agreement with vendors, when that's a separate, unbundled document.

Clarifications

Frequently asked questions

Yes. The DPDP Act's notice and consent requirements apply to personal data you collect from anyone, including individual users at a business customer, whether or not the product itself is consumer-facing.

Usually not, if you sell purely to other businesses for their business use. It applies the moment you sell to an individual, including someone buying for self-employment. We confirm which applies to you before drafting.

Not as part of this service today. We flag where a DPA is needed based on the vendors you list at intake, which you can then take to a dedicated drafting conversation with us.

Yes. Taking payment is what triggers the requirement, regardless of the product type.

Related

Learn more

Learn the details

Guides that walk through every step.

Guide

buildwright.co.in

What Your Website Legally Needs in India: Terms, Privacy, Refunds, and the E-Commerce Rules

A live Indian website needs Terms of Use, a DPDP-compliant Privacy Policy, and a Refund Policy if it takes payment. Selling to consumers pulls in the Consumer Protection (E-Commerce) Rules 2020, with a B2B exclusion most founders get wrong.

Prefer to skip the paperwork?

BuildWright can take this off your plate — done properly, the first time.

Ready to get started?

Tell us about your partners and business and we'll take it from there.

Get a Quote

Skip the hassle — have us do it for you. We do it best.

  • The journey
  • What's included
  • The details
  • How it works
  • FAQ
  • Learn more
  • Pricing

Key terms

Terms of Use
The contract between you and anyone using your site or product: what they can do, what you're not liable for, and how the relationship ends.
Data Fiduciary
The DPDP Act term for whoever determines the purpose and means of processing personal data, generally you, for data your own product collects.
Data Processing Agreement (DPA)
A separate contract with a vendor or processor who touches your users' personal data, making your security, breach-notification, and erasure obligations binding on them too.
Commercial-use exclusion
The Consumer Protection Act 2019 test that keeps purchases made for business use outside the Consumer Protection (E-Commerce) Rules 2020, evaluated per transaction.