The Privacy Policy should explain:
- What information is collected: name, phone number, email, delivery address, IP address, device information and order history.
- How information is collected through checkout, account registration, contact forms, cookies and analytics.
- Why the information is used: processing orders, delivering products, providing support, preventing fraud and sending marketing messages with consent.
- Which service providers receive necessary information, including payment gateways, delivery partners, hosting providers and analytics services.
- That complete card or UPI credentials are processed by the payment provider and are not stored directly by the website.
- Cookie categories and how customers can manage optional cookies.
- How long customer information is retained.
- Security measures used to protect personal information.
- Customer rights to access, correct, erase or withdraw consent.
- How customers can unsubscribe from promotional emails or messages.
- Whether information is processed outside India.
- Policy regarding information belonging to children.
- Name and contact details of the privacy or grievance contact.
- Effective date and procedure for policy updates.
Do not state that information is “never shared with third parties,” because order fulfilment normally requires sharing limited information with payment and courier providers. The policy should align with India’s Digital Personal Data Protection framework.
