Complimentary insured shipping across India

Notice v1 · Updated 11 August 2026

Privacy Notice

This notice explains how Sri ChintamaniVriti ("we") collects, uses, stores and protects your personal data. It is issued under the Digital Personal Data Protection Act, 2023 (DPDP Act) of India.

1. Who we are

Sri ChintamaniVriti is the Data Fiduciary responsible for your personal data. Registered address: Sri ChintamaniVriti, 4-79, Beside Mudra Flex, Hanuman Statue, Dharmapuri, Telangana, India - 505425. GSTIN 36JFIPK1653H1Z8.

Contact: support@srichintamanivriti.com · +91 81439 65901

2. What we collect and why

  • Account data (name, email, phone) — to create and secure your account.
  • Order data (shipping and billing address, items, payment reference) — to fulfil and deliver your order and to meet tax and accounting obligations.
  • Enquiry data (message, phone) — to answer your questions. Stored encrypted.
  • Usage data (device, pages viewed) — only with your consent, to improve the store.

We do not sell your personal data and we do not knowingly process the data of children under 18 without verifiable parental consent.

3. Lawful basis (consent and legitimate uses)

We process data on the basis of your consent, which is requested at the point of collection in clear language, and on the "certain legitimate uses" permitted by section 7 of the DPDP Act — for example, fulfilling an order you voluntarily placed and complying with legal obligations. Consent can be withdrawn at any time with the same ease with which it was given.

4. Your rights as a Data Principal

  • Right to access a summary of the data we process about you.
  • Right to correction, completion and updating of inaccurate data.
  • Right to erasure once the purpose is served and no law requires retention.
  • Right to withdraw consent at any time.
  • Right to nominate another person to exercise your rights.
  • Right to grievance redressal before approaching the Data Protection Board.

Exercise any of these through our data rights request form. We verify identity by email and respond within 30 days.

5. Security safeguards

  • All traffic is served over HTTPS with TLS 1.2+.
  • Data is encrypted at rest in our managed Postgres database and object storage.
  • Sensitive free-text fields (enquiry messages, phone numbers on enquiries, data-request details) are additionally encrypted with AES-256-GCM at the application layer; keys are held in the server secret store and never exposed to the browser.
  • Row-level security restricts every record to its owner; staff access is role-gated and least-privilege.
  • Passwords are never stored in plaintext and are checked against known breaches.
  • Backups are encrypted and access-controlled.

6. Retention

Order and invoice records are retained for eight years as required by Indian tax law. Enquiries are retained for 24 months. Consent logs are retained for the life of the account plus one year. Everything else is erased once its purpose is served.

7. Sharing and processors

We share the minimum data necessary with our payment gateway (Zoho Payments), logistics partners for delivery, and our cloud hosting and email providers. Each acts as a Data Processor under contract and may not use your data for their own purposes.

8. Cookies and consent

Essential cookies keep your bag and session working. Analytics and marketing cookies are set only after you accept them in the consent banner; your choice is logged with a timestamp and notice version, and you can change it any time by clearing site data or filing a withdrawal request.

9. Breach notification

In the event of a personal data breach we will notify affected Data Principals and the Data Protection Board of India without undue delay, in the manner prescribed under the DPDP Act and its rules.

10. Grievance redressal

Grievance Officer: Sri ChintamaniVriti, support@srichintamanivriti.com, +91 81439 65901. If your grievance is not resolved to your satisfaction, you may complain to the Data Protection Board of India.