Privacy Policy
This Privacy Policy describes how Purrcolate Coffee LLP collects, stores, processes, shares, and protects your personal data when you visit, create an account on, or make a purchase from https://purrcolatecoffeeco.in (the "Platform").
We operate as a Data Fiduciary under the Digital Personal Data Protection (DPDP) Act, 2023, and are committed to safeguarding your privacy in compliance with Indian laws, including the Information Technology Act, 2000, the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Consumer Protection (E-Commerce) Rules, 2020.
By visiting our Platform, creating an account, or placing an order, you acknowledge that you have read and understood this Privacy Policy and explicitly consent to our collection and lawful processing of your personal data as outlined herein.
1. OUR STRICT COMMITMENT TO YOUR PRIVACY
-
No Sale or Commercial Renting: We do never sell, rent, lease, or trade your personal data (including your name, phone number, physical address, email address, or transaction history) to third-party data brokers, marketing agencies, or advertisers for commercial gain.
-
Strict Purpose Limitation: Your data is collected solely for specified, explicit, and legitimate commercial purposes—primarily to process payments, pack and deliver your orders, provide customer service, and comply with Indian statutory obligations.
2. CATEGORIES OF PERSONAL DATA WE COLLECT
We collect only the minimum personal data necessary to operate our e-commerce store and fulfill our services:
-
Contact & Identification Data: Includes your full name, shipping address, billing address, mobile phone number, and email address. We collect this directly from you when you create an account, place an order, or complete checkout.
-
Account Credentials: Includes your username, encrypted/hashed password, and saved address book details provided directly by you during registration.
-
Order & Transaction Data: Includes records of products purchased, order values, delivery preferences, tax invoice details, and customer return or refund requests generated through your interactions with the Platform.
-
Payment & Financial Data: Includes your selected payment mode (e.g., UPI, Card, Net Banking), transaction reference IDs, and bank settlement tokens. Note: We never collect or store full credit/debit card numbers, CVVs, net banking passwords, or UPI PINs on our servers. All payments are processed securely via RBI-authorized payment aggregators.
-
Technical & Device Data: Includes your IP address, browser type, operating system, device identifiers, and pages visited, collected automatically via standard session cookies to ensure site functionality.
-
Customer Support Communications: Includes queries, messages, and feedback submitted directly through email, web forms, WhatsApp Business messaging, or customer support phone lines.
3. PURPOSE AND LEGAL BASIS FOR DATA PROCESSING
Under Section 4 and Section 6 of the DPDP Act, 2023, we process your personal data under the lawful bases of Consent and Contractual Necessity / Legitimate Uses:
-
Order Processing & Fulfillment (Contractual Necessity): Validating orders, generating tax invoices, packing merchandise, and coordinating doorstep courier dispatch and delivery.
-
Transaction Communication (Legitimate Use): Sending transactional order confirmations, dispatch alerts, live shipment tracking links, and digital GST invoices via SMS, WhatsApp, or Email.
-
Payment Reconciliation & Fraud Prevention (Legitimate Use): Preventing duplicate orders, unauthorized transactions, identity theft, and resolving payment gateway chargebacks.
-
Statutory Tax & Regulatory Compliance (Legal Obligation): Maintaining sales logs, GST registers, and accounting books as required by the Central Goods and Services Tax (CGST) Act, 2017 and Income Tax Act, 1961.
-
Marketing Communications (Explicit Consent): Sending newsletters, promotional discounts, or product launch notifications—only if you have provided separate, opt-in consent. You can withdraw this consent at any time.
4. DISCLOSURE AND SHARING OF DATA WITH THIRD PARTIES
We do not share your private data except with verified third-party service providers (Data Processors) strictly required to perform our business operations under formal Data Processing Agreements:
-
Logistics & Delivery Partners: Sharing your name, delivery address, and contact number with contracted courier companies (e.g., Shiprocket, Delhivery, Blue Dart, India Post) strictly for route delivery and OTP verification at doorstep drop-off.
-
Payment Gateways & Aggregators: Redirecting payment sessions to RBI-licensed payment processors (e.g., Razorpay, Cashfree, PayU, Stripe). All card processing complies strictly with PCI-DSS Level 1 standards and RBI Tokenization Guidelines.
-
Communication Infrastructure Providers: Sharing contact information with transactional SMS gateways and WhatsApp Business API partners to deliver automated delivery updates.
-
Legal & Statutory Authorities: We will disclose personal information without prior notice only if required by a valid warrant, court order, subpoena, or mandatory statutory notice issued by an authorized government or law enforcement agency in India under the IT Act, 2000.
5. DATA SECURITY & REASONABLE SECURITY PRACTICES
In compliance with Section 8(5) of the DPDP Act, 2023, and Rule 5 of the IT SPDI Rules, 2011:
-
We deploy 256-bit SSL/TLS end-to-end encryption across our entire Platform.
-
All access to backend order management systems is restricted to authorized personnel using role-based access control and multi-factor authentication (MFA).
-
Customer passwords are stored in one-way encrypted cryptographic hashes and are inaccessible even to our internal team.
-
In the unlikely event of a personal data security breach, we will notify the affected Data Principals and the Data Protection Board of India (DPBI) in accordance with statutory timelines and procedures.
6. DATA RETENTION & DELETION TIMELINES
-
Account & Profile Data: Retained for as long as your account remains active. If an account remains completely inactive for three (3) consecutive years, personal profile data will be scheduled for permanent deletion or anonymization, preceded by a prior notice.
-
Statutory Transaction Records: Transaction invoices, tax receipts, and payment logs will be retained for a mandatory minimum period of 7 to 8 years to comply with Indian tax (GST and Income Tax) statutes, after which they are securely purged.
-
Marketing Consent Logs: Retained until you withdraw consent or for up to 3 years following consent withdrawal.
7. YOUR RIGHTS AS A DATA PRINCIPAL
Under the Digital Personal Data Protection Act, 2023, you have enforceable legal rights regarding your personal information:
-
Right to Access & Information: You have the right to request a summary of the personal data we hold about you and the identities of third-party processors with whom it was shared.
-
Right to Correction & Updating: You have the right to correct, update, or complete inaccurate or outdated personal details stored in your account profile.
-
Right to Erasure (Account Deletion): You may request the permanent deletion of your account and personal data, except where retention is legally mandated by Indian tax or fraud prevention laws.
-
Right to Withdraw Consent: You can withdraw consent for promotional communications or cookie tracking at any time without affecting the lawfulness of processing carried out prior to withdrawal.
-
Right to Nominate: You have the right to nominate another individual who, in the event of your death or incapacity, can exercise your data privacy rights under the DPDP Act.
8. PROTECTION OF CHILDREN'S DATA
Our Platform is designed for general audiences and does not intentionally collect personal data from individuals under the age of 18 without verifiable parental/guardian consent. We do not engage in targeted behavioral advertising, tracking, or profiling directed at minors in compliance with Section 9 of the DPDP Act, 2023.
9. LIMITATION OF LIABILITY & FORCE MAJEURE
While we implement reasonable physical, managerial, and electronic security safeguards, no internet transmission can be guaranteed to be 100% immune from sophisticated cyberattacks. Purrcolate Coffee LLP shall not be held liable for unauthorized access, data loss, or system breaches caused by factors outside our reasonable control, including third-party internet service interruptions, distributed denial of service (DDoS) attacks, unauthorized device access due to user negligence, or events classified as Force Majeure under Indian law.
10. AMENDMENTS & REVISIONS
We reserve the right to revise this Privacy Policy periodically to reflect updates in legal statutes, regulatory guidelines, or technical practices. Continued use of our Platform after updates are published constitutes acceptance of the revised terms.