Applicable law: IT Act 2000 IT Rules 2011 DPDP Act 2023
1. What We Collect
We collect information that you provide directly, information collected automatically, and information from third parties, including but not limited to:
- Identity Data: Full name, username, date of birth, gender.
- Contact Data: Email address, phone number, shipping and billing address.
- Transaction Data: Purchase history, order details, payment instrument type (we do not store full card numbers — payments are processed by PCI-DSS compliant gateways).
- Technical Data: IP address, browser type and version, time zone, operating system, device identifiers, and cookie data.
- Usage Data: Pages visited, search queries on site, referral URLs, click paths, time spent on pages.
- Marketing & Communications Data: Preferences for receiving marketing from us, communication preferences.
- UGC (User-Generated Content): Reviews, ratings, photos, and any other content you voluntarily submit.
We collect this data through account registration, order placement, newsletter sign-ups, cookie tracking, and any written communication you send us.
2. How We Use It
We process your personal data only where we have a lawful basis to do so under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000. We use your data to:
- Process and fulfil your orders, manage returns, and send order-related notifications.
- Create and manage your D.PRA account.
- Send transactional emails (order confirmations, shipping updates, invoices).
- Send promotional communications, offers, and newsletters — only with your explicit consent; you may opt-out at any time.
- Improve our website, products, and services based on aggregate analytics and feedback.
- Detect and prevent fraud, unauthorised access, and other illegal activity.
- Comply with legal obligations, including tax records, under applicable Indian law.
- Respond to customer service requests and grievances.
- Enforce our Terms of Use and other applicable policies.
3. Data Sharing
We share your data only in the following limited circumstances:
- Logistics & Delivery Partners: Your name, address, and contact number are shared with our logistics partners solely to fulfil deliveries.
- Payment Processors: We share transaction details with regulated payment gateways (e.g., Razorpay, PayU). These processors adhere to PCI-DSS standards and applicable RBI guidelines.
- Technology Service Providers: Cloud hosting, email delivery, analytics, and customer support tools — bound by data processing agreements.
- Legal & Regulatory Authorities: Where required by law, court order, or governmental authority under Indian law, including requests under Section 69 of the IT Act, 2000.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to equivalent privacy protections.
All third-party processors are contractually required to maintain confidentiality and implement appropriate security measures consistent with the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
4. Cookies
We use cookies and similar tracking technologies to enhance your browsing experience, remember your preferences, and analyse site traffic. The types of cookies we use include:
- Essential Cookies: Necessary for the website to function (e.g., session management, cart persistence). Cannot be disabled.
- Preference Cookies: Store your choices such as language, currency, and login state.
- Analytics Cookies: Help us understand how visitors interact with the site (e.g., Google Analytics). Data is aggregated and anonymised.
- Marketing Cookies: Used to deliver relevant advertisements and track the effectiveness of our marketing campaigns.
You can control cookie settings through your browser. Disabling certain cookies may affect site functionality. Most browsers allow you to refuse cookies or alert you when a cookie is being sent.
We do not use cookies to collect Sensitive Personal Data or Information (SPDI) as defined under the IT Rules, 2011.
5. Data Security
We implement and maintain reasonable security practices as mandated by the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, including:
- SSL/TLS encryption for data in transit across our website.
- Encrypted storage of sensitive data at rest.
- Access controls limiting data access to authorised personnel only.
- Regular security assessments and vulnerability checks.
- Two-factor authentication options for account access.
In the event of a data breach affecting your personal data, we will notify you and the relevant authorities in accordance with our obligations under the DPDP Act, 2023 and applicable rules as notified by the Government of India.
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security.
6. Your Rights
Under the Digital Personal Data Protection Act, 2023, you have the following rights as a "Data Principal":
- Right to Access: Request a summary of personal data we process about you and the processing activities.
- Right to Correction: Request correction of inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of your personal data where it is no longer necessary for the purpose it was collected, subject to legal retention requirements.
- Right to Withdraw Consent: Withdraw consent for processing at any time, without affecting the lawfulness of prior processing based on consent.
- Right to Grievance Redressal: Lodge a complaint with our Grievance Officer (details in Section 10).
- Right to Nominate: Nominate another person to exercise your rights in the event of your death or incapacity.
To exercise any of these rights, please contact us at care@dpra.in. We will respond within 30 days of receiving your request. We may ask you to verify your identity before processing your request.
7. Third-Party Links
Our Site may contain links to third-party websites, social media platforms, and services not operated by D.PRA (e.g., Instagram, Facebook, YouTube). We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites.
We encourage you to review the privacy policy of every website you visit. A link from our Site does not constitute an endorsement of, or responsibility for, any third-party website or its privacy practices.
8. Children's Privacy
Our products and services are intended for individuals who are 18 years of age or older, or minors with the consent of a parent or legal guardian, consistent with the eligibility criteria set out in our Terms of Use.
We do not knowingly collect personal data from children under the age of 18 without verifiable parental consent. In accordance with the DPDP Act, 2023, processing of children's data requires explicit consent from a parent or lawful guardian, and we do not engage in tracking or behavioural monitoring of children.
If you believe that we have inadvertently collected personal data from a child without appropriate consent, please contact us immediately at care@dpra.in so we can delete it promptly.
9. Changes to Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page.
- Display a prominent notice on our Site or send you an email notification (where required by applicable law).
- Where required under the DPDP Act, 2023, seek fresh consent from you for new or changed purposes of processing.
Your continued use of the Site following the posting of changes constitutes your acceptance of the revised Privacy Policy. We encourage you to review this page periodically.
10. Contact DPO / Grievance Officer
In accordance with the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the DPDP Act, 2023, a Grievance Officer has been designated to address your concerns:
Grievance Officer
K-355 KESAVPURAM AV NO.1, KALYANPUR,
Kanpur Nagar, Uttar Pradesh – 208017, India
CIN: U14101UP2026PTC246813