Privacy Policy
-
TRODUCTION AND WHO WE ARE
-
This Privacy Policy (“Policy”) is published by Mehrotra Consumer Products Private Limited, a company incorporated under the Companies Act 1956, bearing Corporate Identification Number: U15122UP2012PTC049728, having its registered office at 26G, Sector 31, Ecotech 1, Greater Noida - 201308, Uttar Pradesh, India (hereinafter referred to as “Company”, “we”, “us” or “our”). The Company owns and operates the brand “Organic Tattva” and the e-commerce website www.organictattva.com, including its mobile-optimised versions and associated ordering, communication and customer-engagement channels (collectively, the “Platform”), through which we sell organic and natural food products to consumers in India.
-
We respect your privacy and are committed to processing your personal data lawfully, fairly and transparently. For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), the Company is the “Data Fiduciary” i.e., the person who determines the purpose and means of processing your personal data and you, the natural person to whom the personal data relates, are the “Data Principal”.
-
This Policy: (a) describes the personal data we collect, the sources from which it is collected, the purposes for which it is processed, and the persons with whom it is shared; (b) constitutes, and forms part of, the notice given by the Company under Section 5 of the DPDP Act read with Rule 3 of the DPDP Rules; (c) explains your rights as a Data Principal and the manner in which you may exercise those rights, withdraw your consent, and make a complaint to the Data Protection Board of India (the “Board”); and (d) records our commitments on data security, retention, erasure and breach notification.
-
This Policy has been framed in accordance with: (a) the DPDP Act and the DPDP Rules; (b) the Information Technology Act, 2000 (“IT Act”) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), which continue to govern personal information during the phased commencement of the DPDP framework; (c) the Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020; and (d) other applicable laws, including the Telecom Commercial Communications Customer Preference Regulations, 2018 (“TCCCPR”) issued by the Telecom Regulatory Authority of India (“TRAI”) in respect of commercial communications. Where the DPDP framework prescribes a higher standard of protection than the law presently in force, we endeavour to apply the higher standard.
-
Please read this Policy carefully. This Policy is provided for transparency and information purposes only. It is not a consent instrument. Reading, accessing or acknowledging this Policy, or registering on or using the Platform, does not by itself constitute your consent to the processing of your personal data for any purpose. Where the law requires your consent for a particular processing activity, we will seek that consent separately through a clear affirmative action on your part, and this Policy will serve as the notice accompanying or preceding that request for consent.
-
Where we continue to process personal data for which you gave your consent before the commencement of the DPDP framework, this Policy also serves as the notice required to be given to you as soon as reasonably practicable under Section 5(2) of the DPDP Act, and you retain the right to withdraw that consent at any time in the manner set out in Section 7 of this Policy.
- As on the date of this Policy, the Company has not been notified by the Central Government as a Significant Data Fiduciary under Section 10 of the DPDP Act. If the Company is so notified in future, this Policy will be updated to reflect the additional obligations that apply.
-
DEFINITIONS AND INTERPRETATION
-
In this Policy, unless the context otherwise requires:
-
“Consent” means any free, specific, informed, unconditional and unambiguous indication of your wishes, by a clear affirmative action, signifying agreement to the processing of your personal data for a specified purpose, within the meaning of Section 6 of the DPDP Act;
-
“Consent Manager” means a person registered with the Board under the DPDP Act who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform;
-
“Data Fiduciary” means any person who, alone or in conjunction with other persons, determines the purpose and means of processing of personal data;
-
“Data Principal” means the individual to whom the personal data relates and, where such individual is a child, includes the parents or lawful guardian of such child, and where such individual is a person with disability, includes her lawful guardian acting on her behalf;
-
“Data Processor” means any person who processes personal data on behalf of a Data Fiduciary;
-
“Personal Data” means any data about an individual who is identifiable by or in relation to such data;
-
“Personal Data Breach” means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data;
-
“Processing”, in relation to personal data, means a wholly or partly automated operation or set of operations performed on digital personal data, and includes collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction;
-
“Child” means an individual who has not completed the age of eighteen years; and
-
“You” and “Your” refer to the Data Principal accessing or using the Platform or otherwise providing personal data to the Company.
-
Capitalised terms used but not defined in this Policy have the meanings assigned to them under the DPDP Act and the DPDP Rules. Headings are for convenience only and do not affect interpretation.
-
SCOPE AND APPLICABILITY
-
This Policy applies to digital personal data, that is, personal data collected by us in digital form, or collected in non-digital form and digitised subsequently, processed by or on behalf of the Company in connection with the Platform and the goods and services offered on it.
-
This Policy applies to all Data Principals who interact with the Platform, including registered account holders, guest purchasers, newsletter subscribers, visitors, persons who submit reviews or ratings, and persons who contact our customer support or submit enquiries or grievances.
-
This Policy does not apply to: (a) personal data processed by third parties acting as independent data fiduciaries in their own right (for example, your bank, card network or UPI application, or social media platforms you use to reach us); (b) aggregated or anonymised data that can no longer identify you; (c) personal data that you have voluntarily made publicly available, or that is made available by a person under a legal obligation, to which the DPDP Act does not apply; (d) personal data of our employees or job applicants, which is governed by separate internal notices; and (e) personal data processed by a third-party marketplace or quick-commerce platform (including Amazon, Flipkart, BigBasket, JioMart and Blinkit) through which our products may also be sold, each of which processes your personal data as an independent Data Fiduciary under its own privacy policy, and not under this Policy.
-
The Platform may contain links to third-party websites, applications and services. Those third parties process personal data under their own privacy policies, and we encourage you to review them (see Section 21).
-
PERSONAL DATA WE COLLECT
-
We follow the principle of data minimisation: we collect only such personal data as is necessary for the specified purposes described in this Policy. The categories of personal data we collect, itemised as required under Rule 3 of the DPDP Rules, are set out in Table 1 below.
Table 1 – Itemised description of personal data collected
|
Category |
Personal data (itemised) |
Collected at / through |
|
A. Identity and Contact Data |
Full name; email address; mobile / telephone number. |
Account registration; checkout; newsletter subscription; Contact Us forms; customer support. |
|
B. Address Data |
Shipping address; billing address; saved addresses in your account address book (including PIN code, city, state and landmark details). |
Checkout; account settings. |
|
C. Account Data |
Login credentials (your password is stored only in encrypted / hashed form by our platform provider); account settings and preferences; wishlist items. |
Account registration and use of the Platform. |
|
D. Order and Transaction Data |
Order history and details of products purchased; order value; invoices and credit notes; payment mode and payment status; refund, replacement and cancellation details; delivery status; order reference numbers. We do not collect or store your full card numbers, CVV, UPI PIN or net-banking credentials as these are provided by you directly to our payment partners on their secure payment pages. |
Order placement and checkout; payment confirmation received from our payment partners. |
|
E. Communications and Support Data |
Contents of Contact Us forms (name, email, phone number, order ID and message); emails and chat messages exchanged with us; call recordings (you are informed at the start of the call that it is being recorded) or call notes of support interactions; details of complaints and grievances. |
Contact Us forms; customer support interactions; grievance correspondence. |
|
F. Reviews and Ratings Data |
Review text, star ratings, the display name you choose, and any other information you voluntarily include in a review. |
Product review and rating features. |
|
G. Marketing and Preference Data |
Newsletter subscription status; channel wise marketing opt-ins and opt-outs; communication preferences; records of the consents you have given or withdrawn. |
Newsletter sign-up; checkout opt-ins; preference centre; unsubscribe actions. |
|
H. Technical and Usage Data |
IP address and approximate location derived from it; device and browser type; operating system; unique cookie, device and advertising identifiers; pages viewed, session duration, click stream and search terms; referral source; cart contents, including abandoned cart data. |
Automatically, through cookies and similar technologies described in Section 9, when you use the Platform. |
-
We do not require your date of birth or marital status to sell you our products, and we do not knowingly collect government issued identity documents (except where required by law for a specific transaction), financial account credentials, or any data revealing your health, biometrics, caste, religion or similar characteristics.
-
If you provide us with the personal data of another person, for example, the name, phone number and address of a recipient for a gift delivery, you confirm that you are authorised to do so and that you have informed that person of this Policy. We will process such data solely to fulfil the relevant order.
-
HOW WE COLLECT YOUR PERSONAL DATA
-
Directly from you: when you register an account, place an order, complete checkout, subscribe to our newsletter, submit a Contact Us form, write to or call customer support, post a review or rating, or otherwise correspond with us.
-
Automatically: through cookies, pixels, tags, software development kits and server logs when you browse or use the Platform, as described in Section 9.
-
From third parties: limited data received in the course of serving you, such as payment confirmation and transaction status from our payment aggregator, delivery and tracking status from our logistics partners, and aggregated or pseudonymised campaign-measurement signals from advertising and analytics platforms.
-
We do not purchase personal data about you from data brokers, and we do not collect personal data from publicly available sources for marketing purposes.
-
PURPOSES OF PROCESSING AND LAWFUL BASIS
-
Table 2 sets out, on an itemised basis, each purpose for which we process your personal data, the categories of personal data used for that purpose (by reference to Table 1), and the lawful basis on which we rely under the DPDP Act.
Table 2 – Purposes of processing, data used and lawful basis
|
Purpose |
Data categories used |
Lawful basis (DPDP Act) |
|
Creating and administering your customer account, including saved addresses and Wishlist. |
A, B, C |
Consent (Section 6); voluntary provision of data for a specified purpose (Section 7(a)). |
|
Processing and fulfilling your orders, including invoicing, dispatch, delivery, returns, replacements, cancellations and refunds. |
A, B, D |
Consent given at checkout; voluntary provision for the specified purpose (Section 7(a)). |
|
Payment collection through your chosen method (card, UPI, net banking or wallet including Paytm, Amazon Pay), verification, settlement and refund processing, and prevention of payment fraud and abuse. |
A, D, and limited H |
Consent (Section 6); records retained where required by law, as authorised under Section 6(6) read with Section 8(7). |
|
Delivery and logistics, including sharing your delivery details with courier partners and resolving delivery failures. |
A, B, D |
Consent; processing necessary to complete the purchase you have requested, as a voluntary provision of data for a specified purpose under Section 7(a) of the DPDP Act. |
|
Customer support, responding to enquiries, and grievance redressal. |
A, D, E |
Voluntary provision of data for a specified purpose (Section 7(a)); Maintenance of the grievance redressal mechanism required under Section 8(10) of the DPDP Act and Rule 4 of the Consumer Protection (E-Commerce) Rules, 2020. |
|
Sending transactional and service communications: order confirmations, payment receipts, shipping and delivery updates, delivery OTPs and service notices. These are not marketing messages. |
A, D |
Necessary incident of the specified purpose for which you provided your data, as a voluntary provision of data for a specified purpose under Section 7(a) of the DPDP Act. |
|
Sending marketing and promotional communications by email, SMS, WhatsApp or RCS. |
A, G |
Your separate, specific, opt-in consent only under Section 6 DPDP Act; withdrawable at any time under Section 6(4) of DPDP Act, as further described in Section 10 of this Policy. |
|
Sending our newsletter. |
A (email), G |
Consent given at subscription under Section 6 of the DPDP Act; withdrawable at any time under Section 6(4), as further described in Section 10 of this Policy. |
|
Publishing product reviews and ratings you choose to post. |
F |
(Section 6 of the DPDP Act), signified by your choosing to submit and publish the review. |
|
Website analytics, performance measurement, and improvement of the Platform, our products and services. |
H |
Consent given through your cookie preferences, in accordance with Section 6 of the DPDP Act; withdrawable at any time under Section 6(4). |
|
Advertising measurement, conversion tracking, remarketing and audience building through Google and Meta services. |
H; hashed contact identifiers where enabled via the Meta Conversions API described in Section 9.2 of the Policy. |
Consent given through your cookie / marketing preferences, in accordance with Section 6 of the DPDP Act; withdrawable at any time under Section 6(4). |
|
Maintaining the security of the Platform, detecting and investigating fraud, abuse and security incidents, and maintaining logs. |
D, H |
Compliance with our security obligations under Section 8(5) of the DPDP Act and the IT Act. |
|
Complying with applicable law, responding to lawful requests of governmental, regulatory or judicial authorities, and maintaining statutory records. |
As relevant |
Fulfilment of obligations under law to disclose information to the State or its instrumentalities (Section 7(d) of the DPDP Act); compliance with judgments, decrees and orders (Section 7(e)); retention of records as permitted under Section 8(7). |
|
Establishing, exercising or defending legal claims. |
As relevant |
Processing necessary for enforcing legal rights or claims, exempt to that extent under Section 17(1)(a) of the DPDP Act. |
|
Corporate transactions such as a merger, amalgamation, acquisition or asset transfer, subject to confidentiality safeguards. |
As relevant |
Where undertaken pursuant to a scheme of compromise, arrangement, merger, amalgamation or transfer of undertaking approved by a court, tribunal or other competent authority, exempt under Section 17(1)(e) of the DPDP Act; in other cases, with notice to you and, where required, your consent. |
-
If we propose to process your personal data for a purpose not described in this Policy, we will give you a fresh notice and, where required, obtain your consent before doing so.
-
We do not carry out automated decision-making that produces legal effects concerning you without human involvement. Profiling is limited to the analytics and marketing personalisation described above and is subject to your consent.
-
CONSENT: STANDARD, MANAGEMENT AND WITHDRAWAL
-
Standard of consent. Wherever we rely on your consent, it will be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and will signify agreement to the processing of only such personal data as is necessary for the specified purpose (Section 6(1), DPDP Act).
-
Notice. Every request for consent will be accompanied or preceded by a notice i.e., this Policy, or a shorter purpose specific notice linking to it presented in clear and plain language and understandable on its own, as required under Rule 3 of the DPDP Rules. You may access the request and the notice in English or in any of the twenty-two languages specified in the Eighth Schedule to the Constitution of India, as provided in Section 5(3) of the DPDP Act.
-
No bundling. We will not make the sale of our products conditional on your consent to processing that is not necessary for that sale. For example, you can purchase from the Platform without opting in to marketing communications, and declining marketing will never affect your order.
-
Withdrawal of consent. You may withdraw your consent at any time, with the same ease with which you gave it: (a) for marketing: use the unsubscribe link, reply as indicated for SMS/WhatsApp, or use your account preference settings; (b) for cookies: use the cookie preference controls described in Section 9; and (c) for any other consent: write to the Grievance Officer (Section 24). Upon withdrawal, we will, within a reasonable time, cease (and cause our Data Processors to cease) the processing to which the withdrawal relates, unless continued processing or retention is required by law. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. The consequences of withdrawal are borne by you for example, if you withdraw a consent necessary for an order in progress, we may be unable to complete that order. Where we no longer need your personal data for the purpose for which it was collected, or where you withdraw your consent, we will erase it and cause our data processors to do the same, unless retention is required under applicable law.
-
Consent Managers. Once Consent Managers registered with the Board are operational, you will be able to give, manage, review and withdraw your consent through such a Consent Manager, and we will honour requests received through that channel as required by law.
-
Records. We maintain records of the notices given and the consents given, managed and withdrawn, so that we can demonstrate compliance and honour your choices.
-
MANDATORY INFORMATION AND CONSEQUENCES OF NOT PROVIDING IT
-
Certain information is necessary for us to serve you: your name, contact details are required to register an account; and your name, contact details, shipping address and completion of payment are required to process and deliver an order (whether placed through your account or as a guest). If you choose not to provide this information, we will not be able to process your purchase.
-
All other processing is optional: newsletter subscription, marketing communications, reviews, wishlist and non-essential cookies are entirely your choice, and declining them does not affect your ability to purchase from the Platform.
-
COOKIES AND TRACKING TECHNOLOGIES
-
Cookies are small text files placed on your device; pixels, tags and similar technologies serve comparable functions. We use them as described in Table 3. Some cookies last only for your browsing session, while others persist on your device until they expire or you delete them; the lifetime of each is set by us or, for third-party cookies, by the provider concerned
Table 3 – Cookies and similar technologies used on the Platform
|
Category |
Providers / examples |
Purpose |
Consent Required |
|
Strictly necessary |
Shopify platform cookies (session, cart, checkout, security). |
Enabling core functions: shopping cart, session continuity, secure checkout, load balancing and fraud prevention. These cannot be switched off through the banner; you may block them in your browser, but the Platform may not function. |
No since it is necessary for the Service requested |
|
Analytics / performance |
Google Analytics 4; Shopify Analytics. |
Understanding how visitors use the Platform, measuring traffic and performance, and improving our services. |
Yes, it is taken through the Cookie Consent Notice |
|
Advertising / marketing |
Google Ads conversion tracking; Meta Pixel and Meta Conversions API; remarketing tags. |
Measuring advertising campaigns, attributing conversions, showing you relevant advertisements and building advertising audiences. |
Yes, it is taken through the Cookie Consent Notice |
|
Functionality / preference |
Platform preference cookies. |
Remembering your choices, such as region and display preferences. |
Yes, it is taken through the Cookie Consent Notice |
|
Tag management |
Google Tag Manager. |
A container tool used to deploy and manage the tags above; it does not itself collect personal data beyond what is operationally necessary. |
Yes, it is taken through the Cookie Consent Notice |
-
Server-side events. Where the Meta Conversions API is enabled, certain event data (which may include hashed contact identifiers) is transmitted from our systems to Meta server-to-server. We treat such transmission as marketing processing subject to the same consent as the corresponding cookies.
-
Managing your preferences. When you first visit the Platform, a consent banner allows you to accept or decline non-essential cookies and to make granular, category-level choices. You may change your choices at any time through the Cookie Settings link in the footer of the Platform, and analytics and advertising tags will operate only in accordance with the preferences you set. You may also control cookies through your browser settings, and manage advertising preferences through the controls offered by Google (Google Ads Settings) and Meta (Ad Preferences). Disabling certain cookies may limit Platform functionality.
-
No third-party social embeds. Video content on the Platform is hosted by us on our platform provider's content delivery network and is not embedded from any third-party video service. Our social media icons are ordinary hyperlinks and do not load third-party content or set third-party cookies unless and until you click them.
-
Do Not Track. There is no uniform industry standard for browser “Do Not Track” signals; we honour the choices you make through our consent banner and preference controls.
-
MARKETING AND COMMERCIAL COMMUNICATIONS
-
We may send you marketing and promotional communications through email, SMS, WhatsApp and web push notifications(where you have enabled them in your browser or device).
-
Opt-in only. Marketing communications are sent only where you have opted in by subscribing to our newsletter, or by selecting the marketing opt-in during checkout or account creation. Opt-in boxes are not pre-ticked, and we keep a record of the source, date and scope of each opt-in. Reminders relating to items left in your shopping cart or saved to your wishlist are treated as marketing communications for the purposes of this Section and are sent only where you have opted in to receive marketing communications; entering your contact details at checkout without completing a purchase does not, by itself, authorise such reminders.
-
SMS and WhatsApp communications. Promotional communications by SMS are sent in accordance with the Telecom Commercial Communications Customer Preference Regulations, 2018 (TCCCPR), using headers and content templates registered on the Distributed Ledger Technology (DLT) platform of the telecom access providers, and only against consent recorded in the DLT consent framework. Where you have given us that consent, promotional messages may reach you even if your number is registered on the national customer preference register, because your specific consent to hear from us takes precedence over your general preference; where you have not given consent, or have withdrawn it, we do not send you promotional messages at all. You may change this at any time through our own opt-out channels, by revoking your consent on the DLT platform, or by registering or updating your preferences with your telecom operator, including through 1909. Communications by WhatsApp are not governed by the TCCCPR; we send these only through providers authorised by the platform, only where you have opted in, and you may opt out by replying as indicated in the message.
-
Service and transactional messages. Messages relating to your orders and account such as order confirmations, payment receipts, dispatch and delivery updates, delivery one-time passwords and service notices, are service or transactional communications arising from our existing relationship with you and necessary to fulfil the purchase you have asked us to complete. They are not promotional and continue even if you opt out of marketing. We do not include promotional content in these messages: under the TCCCPR a message combining service and promotional content is treated in its entirety as promotional, and we therefore keep the two strictly separate. Our ability to send service messages on this basis subsists only for the duration of our relationship with you. To help you identify what you are receiving, SMS headers carry a category suffix applied automatically by the telecom operator for example "-P" for promotional, "-S" for service and "-T" for transactional messages.
-
Opt-out. You may opt out at any time: every marketing email contains an unsubscribe link; SMS and WhatsApp messages indicate the manner of opting out; and you may in any case write to the Grievance Officer or customer support. We will give effect to your opt-out across all our channels promptly, and in any event within 72 (seventy-two) hours. Once you have opted out, we will not approach you again to seek fresh marketing consent for a period of at least 90 (ninety) days, though you remain free to opt back in at any time. Opting out of marketing does not stop transactional and service communications necessary for your orders and account.
-
We do not sell your personal data, and we do not share your personal data with unrelated third parties for their own marketing.
-
DISCLOSURE AND SHARING OF PERSONAL DATA
-
We share personal data strictly on a need-to-know basis. Where a recipient processes personal data on our behalf as a Data Processor, we engage it under a valid contract that imposes purpose limitation, confidentiality and security obligations consistent with Section 8(2) of the DPDP Act and Rule 6 of the DPDP Rules, and the processor acts only on our documented instructions.
Table 4 – Recipients of personal data
|
Recipient and role |
What is shared |
Purpose |
|
Shopify Inc. and its affiliates E-commerce platform and hosting provider. Shopify acts as a Data Processor in respect of the store, hosting, checkout and platform analytics services it provides on our instructions. |
Account, order, address and transaction data; technical and usage data generated on the Platform. |
Operating, hosting and securing the online store, checkout and platform-native analytics. |
|
Razorpay Software Private Limited RBI-authorised payment aggregator; a regulated entity processing payment data under RBI directions. Razorpay acts as an independent Data Fiduciary in respect of the payment services it provides, determining its own purposes and means in accordance with directions of the Reserve Bank of India and its own terms. |
Name, contact details, order amount and order reference. Your card, UPI, wallet and net-banking details are entered by you directly on Razorpay's secure payment page and are not stored by us. |
Processing payments made by card, UPI, net banking or wallet (including Paytm and Amazon Pay), together with verification, settlement, refunds and fraud checks. |
|
Google (Google LLC / Google India) Analytics and advertising services: Google Analytics 4, Google Tag Manager and Google Ads. Google acts as a Data Processor in respect of the analytics and tag-management services it provides on our instructions, and as an independent Data Fiduciary in respect of its advertising services, which it provides under its own terms and for its own purposes. |
Online identifiers (including cookie, device and advertising identifiers), device and usage data, and conversion events. Shared only in accordance with the cookie and marketing preferences you have set. |
Measuring how the Platform is used and how our advertising performs, attributing conversions and delivering remarketing. Google additionally uses the data it receives through its advertising services for its own purposes under its own terms. |
|
Meta Platforms, Inc. Advertising services: Meta Pixel and Meta Conversions API. Meta acts as an independent Data Fiduciary in respect of the advertising services it provides under its own terms and for its own purposes. |
Online identifiers and event data recording your activity on the Platform, together with hashed contact identifiers where these are transmitted through the Conversions API. Shared only in accordance with the cookie and marketing preferences you have set. |
Measuring advertising performance, attributing conversions and building advertising audiences. Meta additionally uses the data it receives for its own purposes under its own terms. |
|
Email / SMS / WhatsApp marketing platform- Mailchimp, Trustsignal, Bitespeed Data Processor. |
Name, email address, phone number, order metadata and engagement data of opted-in recipients. Email campaigns are sent through Mailchimp, Trustsignal and Bitespeed; SMS campaigns through Trustsignal and Bitespeed; and WhatsApp communications through Bitespeed. |
Sending the newsletter and marketing communications you have opted in to receive. |
|
Logistics and courier partners - Logistics aggregators Shiprocket, NimbusPost and Eshopbox, and courier partners including Delhivery, Xpressbees, Shadowfax, Blue Dart, DTDC, Ekart and, from time to time, Amazon Transportation Services[ Delivery service providers. They act as independent Data Fiduciaries in respect of the delivery services they provide under their own terms. |
Recipient name, phone number, delivery address, order reference and, for cash-on-delivery orders, the collectible amount. |
Shipping, delivery, returns and delivery-failure resolution. |
|
Integrated third party applications Applications installed on our Shopify store for product reviews, customer engagement, support, marketing and store functionality. Where such an application processes personal data solely on our instructions, it acts as a Data Processor and is engaged on the contractual terms described in clause 11.1. Where it determines its own purposes and means, it acts as an independent Data Fiduciary and processes personal data under its own terms. |
Only the data functionally required by the relevant application for the service it provides. |
Product reviews, customer engagement, support and store functionality. |
|
Professional advisers Legal, accounting, tax and audit advisers, under duties of confidence. Each acts as an independent Data Fiduciary in its own right, subject to professional duties of confidentiality and to its own regulatory obligations. |
As strictly necessary. |
Professional advice, audits and compliance. |
|
Governmental, regulatory and judicial authorities Recipients acting under statutory or judicial authority. They are not our Data Processors and process personal data in exercise of their own powers under applicable law. |
As required by law or lawful direction. |
Compliance with applicable law, orders and lawful requests. |
|
Successors in a corporate transaction Prospective or actual acquirers, and their advisers, under confidentiality obligations. An acquirer acts as an independent Data Fiduciary in respect of personal data it receives, whether for the purpose of evaluating the transaction or, on completion, in succession to us. |
As necessary for due diligence and completion. |
Merger, amalgamation, acquisition, reconstruction or asset transfer, with notice to you where required by law. |
-
We do not presently share customer personal data with group or affiliate companies for their independent use. If this changes, we will update this Policy, identify the relevant entities and purposes, and, where required, seek your consent.
-
Participants in the payment chain, including your bank, card network and UPI application, receive your payment data directly in the course of completing the transaction you initiate, and are not recipients to whom we disclose your personal data; they process that data as independent regulated entities under their own terms and privacy policies.
-
Some of the recipients identified in Table 4 determine their own purposes and means of processing and therefore act as independent Data Fiduciaries in their own right, rather than as our Data Processors; the role of each recipient is stated against it in Table 4. Where a recipient acts as an independent Data Fiduciary, it processes your personal data under its own privacy policy and its own legal and regulatory obligations, which are not within our control, and we encourage you to review those policies. We share personal data with such recipients only on the lawful basis identified for the relevant purpose in Table 2: in some cases your consent, and in others because the sharing is necessary to provide the service you have requested or is required under applicable law.
-
CROSS-BORDER TRANSFER OF PERSONAL DATA
-
The Platform is hosted on Shopify's global cloud infrastructure, and certain of our service providers, including Google and Meta, process personal data on servers located outside India. Your personal data may therefore be transferred to, and stored and processed in, jurisdictions outside India. Payment data is subject to a separate regime: our payment aggregator is regulated by the Reserve Bank of India and is required, under the Reserve Bank's directions on storage of payment system data, to store the data relating to the payment systems it operates only in India. Where a payment is processed outside India, that data must be deleted from systems abroad and returned to India for storage within one business day or twenty-four hours of processing, whichever is earlier.
-
Under Section 16 of the DPDP Act, personal data may be transferred outside India except to countries or territories restricted by notification of the Central Government. We do not transfer personal data to any restricted country or territory, and we will comply with any conditions the Central Government specifies for cross-border processing, including any requirements relating to making personal data available to a foreign State or its agencies.
-
During the currency of the SPDI Rules, we additionally ensure that any transferee provides the same level of data protection as required under those rules, and that transfers occur only where necessary for the performance of our lawful contract with you or with your consent.
-
Wherever your personal data is processed, the contractual, technical and organisational safeguards described in this Policy travel with it.
-
DATA RETENTION
-
We retain your personal data only for as long as reasonably necessary for the purpose for which it was collected, or for as long as a longer period is required to comply with applicable law, whichever is later, consistent with Section 8(7) of the DPDP Act. Once neither condition is met, we will erase, or anonymise or aggregate, the personal data concerned.
-
Depending on the category of personal data concerned, we apply the following retention periods:
-
Account data (Category C). Retained while your account remains active and thereafter for such period as is reasonably necessary for legitimate legal, security, fraud-prevention and dispute-resolution purposes, subject to applicable law and our records-retention policy.
-
Address data (Category B). Retained while linked to an active account or an outstanding order, and thereafter only for such period as is necessary for applicable legal, tax, accounting, dispute-resolution or other legitimate purposes.
-
Order and transaction data (Category D), including payment metadata. Retained for the period required under applicable accounting, taxation, audit and other legal requirements, or for such longer period as may be necessary to establish, exercise or defend legal claims.
-
Communications, support and grievance records (Category E). Retained for such period as is reasonably necessary for quality assurance, dispute resolution, legal compliance, and the establishment, exercise or defence of legal claims. Call recordings, however, are retained for 90 (ninety) days from the date of the call.
-
Reviews and ratings (Category F). Retained for as long as the review remains published on the Platform, or until you request its removal, whichever is earlier, subject to applicable legal requirements.
-
Marketing and preference data (Category G), including consent/opt-out records. Marketing preferences and consent status are retained while relevant to your marketing relationship. Where you withdraw consent, marketing communications will cease and relevant consent/withdrawal records may be retained for a limited period thereafter solely to evidence and honour your withdrawal and for compliance purposes.
-
Technical, security and access logs (part of Category H). Retained for one year from creation, or for such longer period where required by applicable law or necessary for investigation, remediation or prevention of security incidents.
-
Cart, browsing and analytics data (part of Category H). Retained only for the period necessary for the relevant purpose and in accordance with the applicable cookie/analytics retention period set out in Table 3, following which the data will be deleted, aggregated or anonymised as appropriate.
-
Consent Records. Retained for such period as is reasonably necessary to demonstrate the existence, scope and withdrawal of consent and to meet applicable legal and compliance requirements.
-
Backup data. Retained for up to 90 (ninety) days from backup creation for business-continuity and disaster-recovery purposes, following which backups will be overwritten or deleted in accordance with the applicable backup cycle.
-
Where Personal Data has been genuinely anonymised, such that a User can no longer reasonably be re-identified from it, whether alone or in combination with other information reasonably available, it ceases to be Personal Data for the purposes of this Policy and the DPDP Act, and may be retained and used for lawful purposes such as research, service improvement, and security monitoring.
-
Deletion of your account or personal data may not immediately remove every backup copy; we apply deletion, de-identification or retention controls to backups in the ordinary course of our backup cycle.
-
Notwithstanding the foregoing, we may retain personal data beyond the periods above where necessary: (a) to comply with an order of a court or tribunal, or a demand of a government agency or law-enforcement authority acting under authority of law; (b) to establish, exercise or defend a legal claim; (c) for the purposes set out in Section 17 of the DPDP Act, including legal claims, judicial or regulatory processing, offence prevention or investigation, corporate restructuring approved by a competent authority, and research, archiving or statistical processing; or (d) where you have given us explicit instructions to the contrary that we are able to honour consistently with applicable law.
-
DATA SECURITY
-
We implement reasonable security safeguards to prevent personal data breach, as required under Section 8(5) of the DPDP Act read with Rule 6 of the DPDP Rules and Section 43A of the IT Act read with the SPDI Rules. These include, at a minimum:
-
encryption of personal data in transit (TLS/HTTPS across the Platform) and security measures, including encryption and obfuscation, applied to data at rest by our hosting and platform providers;
-
tokenisation of card data in accordance with the Reserve Bank of India’s card-on-file tokenisation framework; we never store your card credentials;
-
role-based access controls and least privilege access to systems containing personal data;
-
monitoring, logging and alerting for the detection, investigation and remediation of unauthorised access, with logs retained for at least one year;
-
appropriate backup and recovery measures to maintain continued availability of personal data;
-
contractual security obligations on every Data Processor, and due diligence of vendors before onboarding;
-
confidentiality obligations on our personnel and access on a need-to-know basis; and
-
periodic review of our technical and organisational measures.
-
Payment processing on the Platform is handled by Payment Card Industry Data Security Standard (PCI-DSS) compliant providers.
-
Your role. Please keep your account password confidential and unique, log out on shared devices, and notify us immediately at the contact details in Section 24 of this policy if you suspect unauthorised access to your account. Beware of phishing: we will never ask you for your password, OTP or card credentials over a call, SMS or email.
-
PERSONAL DATA BREACH
-
In the event of a personal data breach affecting you, we will, on becoming aware of the breach, intimate you without delay, in a concise, clear and plain manner, through your registered mode of communication, describing: (a) the nature, extent and timing of the breach; (b) its likely consequences for you; (c) the measures we have taken or are taking to mitigate risk; (d) the safety measures you may take to protect your interests; and (e) the contact details of a person able to respond to your queries.
-
We will also report the breach to the Data Protection Board of India within the timelines prescribed under Rule 7 of the DPDP Rules, an initial intimation without delay on becoming aware of the breach, followed by a detailed report within 72 (seventy-two) hours or such further period as the Board permits.
-
Where an incident is also of a category notifiable to the Indian Computer Emergency Response Team (CERT-In) under the IT Act and the directions issued thereunder, we will report it to CERT-In within the prescribed timelines (currently 6 (six) hours from noticing the incident).
-
We maintain an incident-response process, coordinated with our platform and payment providers, to identify, contain, assess and remediate incidents.
-
YOUR RIGHTS AS A DATA PRINCIPAL
-
Right to access information (Section 11 DPDP Act). Where processing is based on your consent (including personal data you provided voluntarily for a specified purpose, as referred to in Section 7(a) of the DPDP Act), you may request: (a) a summary of the personal data being processed and the processing activities undertaken; (b) the identities of all other Data Fiduciaries and Data Processors with whom your personal data has been shared, along with a description of the personal data so shared; and (c) any other prescribed information. This does not extend to sharing made with lawfully authorised agencies for the prevention, detection or investigation of offences or cyber incidents.
-
Right to correction, completion, updating and erasure (Section 12 DPDP Act). You may require us to correct inaccurate or misleading personal data, complete incomplete data, update your data, and erase personal data that is no longer necessary for the specified purpose, unless retention is required under applicable law.
-
Right of grievance redressal (Section 13 DPDP Act). You have the right to readily available means of grievance redressal in respect of any act or omission of the Company concerning your personal data or your rights (see Sections 16, 17 and 24 of this policy).
-
Right to nominate (Section 14 DPDP Act). You may nominate one or more individuals who may exercise your rights in the event of your death or incapacity. To record a nomination, write to the Grievance Officer with your details and the nominee’s name and contact information.
-
Right to withdraw consent (Section 6(4) DPDP Act). As described in Section 7.4 of this Policy.
-
Your rights may be exercised by you, by the parent or lawful guardian of a child, by the lawful guardian of a person with disability acting on her behalf, and, once operational, through a registered Consent Manager in respect of consent.
-
EXERCISING YOUR RIGHTS: PROCEDURE AND TIMELINES
-
How to make a request. You may: (a) view and update your profile and saved addresses directly through your account dashboard; and (b) for all other requests like access, correction, erasure, nomination or consent withdrawal write to the Grievance Officer at the contact details in Section 24, stating your full name, the email address and/or mobile number registered with us, the nature of your request, and, where relevant, the order ID.
-
Verification. To protect you against fraudulent requests, we will verify your identity against your registered email address or mobile number (for example, through a one-time password or verification email) before acting on a request, and may seek reasonable additional information where necessary to confirm identity or locate your data. No fee is charged for exercising your rights.
-
Timelines. We will acknowledge your request or grievance within 48 (forty-eight) hours and endeavor to resolve it as expeditiously as possible. In any event, we will respond to your grievance within 90 (ninety) days of its receipt, in accordance with Rule 14 of the Digital Personal Data Protection Rules 2025.
-
We may decline a request that cannot be verified, is contrary to law, or would infringe the rights of another person, and will communicate our reasons to you.
-
GRIEVANCE REDRESSAL AND THE DATA PROTECTION BOARD OF INDIA
-
If you have any grievance regarding the processing of your personal data or the exercise of your rights under the DPDP Act, please contact our Grievance Officer (Section 24). We will respond to such grievances in accordance with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.
-
If you have a consumer complaint relating to the Platform, our Grievance Officer will acknowledge your complaint within 48 (forty-eight) hours and redress it within 1 (one) month from the date of receipt, in accordance with Rule 4(5) of the Consumer Protection (E-Commerce) Rules, 2020.
-
If you are not satisfied with our response after exhausting this grievance-redressal opportunity, you have the right to make a complaint to the Data Protection Board of India in the manner prescribed under the DPDP Act and the DPDP Rules, through the channels published by the Board.
-
Nothing in this Policy limits any right or remedy available to you under the Consumer Protection Act, 2019 or any other applicable law.
-
CHILDREN’S PERSONAL DATA
-
The Platform is intended for use by persons who are 18 (eighteen) years of age or older. We do not knowingly process the personal data of children.
-
We do not undertake tracking or behavioural monitoring of children, or targeted advertising directed at children, and we do not process children’s personal data in a manner likely to cause any detrimental effect on a child’s well-being.
-
If it comes to our attention that we have collected personal data of a child without the verifiable consent of the child’s parent or lawful guardian, we will delete that data or obtain such verifiable consent in the manner prescribed under the DPDP Rules. If you are a parent or lawful guardian and believe that a child has provided personal data to us, please contact the Grievance Officer.
-
Where a person with disability has a lawful guardian, we honour the framework for the guardian’s verifiable consent on her behalf as prescribed.
-
DUTIES OF DATA PRINCIPALS
-
Under Section 15 of the DPDP Act, while exercising your rights you must: (a) comply with applicable law; (b) not impersonate another person while providing personal data for a specified purpose; (c) not suppress any material information while providing personal data for any document, unique identifier, proof of identity or proof of address issued by the State; (d) not register a false or frivolous grievance or complaint; and (e) furnish only such information as is verifiably authentic while exercising the right to correction or erasure. A breach of these duties may attract penalties under the DPDP Act.
-
THIRD-PARTY WEBSITES, APPS AND SERVICES
-
The Platform contains hyperlinks to our pages on Facebook, Instagram, YouTube and LinkedIn, and our blog articles offer sharing links to social media platforms. Clicking any of these links takes you to the relevant third-party platform, which will then process your personal data as an independent data fiduciary under its own privacy policy. Checkout likewise redirects you to the secure pages of our payment partners. We do not control these third parties and encourage you to review their privacy policies.
-
LANGUAGE AND ACCESSIBILITY OF THIS POLICY
-
This Policy is published in English and is accessible from the footer of every page of the Platform as a standalone document in clear and plain language. You may request access to this Policy, and to any request for consent, in any of the languages listed in the Eighth Schedule to the Constitution of India by writing to the Grievance Officer; translated versions, when published, will be linked here.
-
CHANGES TO THIS POLICY
-
We may update this Policy from time to time to reflect changes in law, technology or our processing activities. The revised Policy will be published on the Platform with an updated “Last Updated” date. Where a change is material, we will notify you through your registered email address or a prominent notice on the Platform, and where a change involves a new purpose requiring consent, we will seek your fresh consent before processing for that purpose. Archived versions are available on request.
-
GRIEVANCE OFFICER AND CONTACT DETAILS
-
The following officer is designated as: (a) the person authorised to answer, on behalf of the Company, questions about the processing of your personal data, whose contact particulars are published under Section 8(9) of the DPDP Act read with Rule 9 of the DPDP Rules; (b) the Grievance Officer under Rule 5(9) of the SPDI Rules; and (c) the Grievance Officer under Rule 4 of the Consumer Protection (E-Commerce) Rules, 2020:
|
Particulars |
Details |
|
Name |
Mohit Sachan |
|
Designation |
IT Department |
|
Address |
Mehrotra Consumer Products Private Limited, 26G, Sector 31, Ecotech 1, Greater Noida - 201308, Uttar Pradesh, India (mark: “Attn.: Grievance Officer -Data Protection”) |
|
|
customercare@organictattva.com |
|
Phone |
+91 120 4260545 |
|
Working hours |
10:00am – 7pm |
-
For general customer support, you may also reach us at customercare@organictattva.com or +91 120 4260545.
-
GOVERNING LAW
-
This Policy is governed by the laws of India. Subject to Section 18 of this Policy and without prejudice to your rights before the Data Protection Board of India or any consumer commission or other forum having jurisdiction under applicable law, disputes arising out of or in connection with this Policy are subject to the jurisdiction of the competent courts in India.
