PRIVACY POLICY
Salt and Grey
Effective Date: [Insert Date]
Last Updated: [Insert Date]
1. INTRODUCTION AND APPLICABILITY
Salt and Grey (“we”, “us”, “our”) is committed to protecting your privacy and personal information in accordance with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”).
This Privacy Policy applies to personal and sensitive personal data collected through our website, mobile platforms, physical stores, customer support channels, and other interactions. By using our services, you consent to the collection, use, processing, storage, disclosure, and transfer of your information as described herein. We collect data lawfully, for defined purposes, and do not use it beyond those purposes without consent.
2. INFORMATION WE COLLECT
a) Information You Provide
We collect personal information such as name, email, phone number, billing and shipping address, booking or order details, payment information, feedback, reviews, preferences, photographs, and communications you share with us.
Sensitive personal data (such as payment details) is collected only with explicit consent and processed securely in accordance with the SPDI Rules and applicable industry standards.
b) Information Collected Automatically
We automatically collect information including IP address, browser type, device details, operating system, pages visited, timestamps, clickstream data, and approximate location through cookies and similar technologies. Cookies help improve functionality, analyse usage, and personalise content. You may disable cookies via browser settings, though some features may be affected.
c) Information from Third Parties
We may receive information from social media platforms (if linked), payment processors, logistics partners, analytics providers, and publicly available sources, in a lawful manner and for defined purposes.
3. PURPOSES OF PROCESSING
We process personal information for the following purposes:
Service Delivery & Fulfilment: Order processing, bookings, delivery coordination, logistics, and customer notifications.
Customer Support: Responding to queries, complaints, and service requests.
Marketing & Promotions: Sending promotional communications where consent is provided; you may opt out anytime.
Website Improvement & Analytics: Enhancing user experience, personalisation, research, and analytics.
Legal & Compliance: Meeting legal obligations, enforcing agreements, preventing fraud, and protecting rights.
Payment Processing: Secure transaction processing via compliant payment gateways with explicit consent.
4. DISCLOSURE OF INFORMATION
We do not sell or trade personal data. Information may be shared only as necessary with:
Service Providers & Partners: Hosting, payment processing, logistics, analytics, CRM, marketing, and IT services, under contractual confidentiality and security obligations.
Legal & Regulatory Authorities: Where required by law or legal process.
Business Transfers: In case of merger, acquisition, or restructuring, subject to equivalent data protection safeguards.
Third-Party Integrations: As chosen by you, governed by their respective privacy policies.
Sensitive personal data is shared only with explicit consent and appropriate safeguards.
5. DATA RETENTION
We retain personal information only as long as necessary:
Transaction Data: Up to 7 years for legal, tax, and audit purposes.
Account Data: While the account is active or as legally required after deletion.
Marketing Data: Until consent is withdrawn.
Cookie & Log Data: Typically 12–24 months.
Legal Records: As required by applicable laws.
Data is securely deleted, destroyed, or anonymised upon expiry of retention periods.
6. DATA SECURITY
We implement appropriate technical, organisational, and physical safeguards to protect personal data, including encryption, SSL/TLS, access controls, firewalls, employee training, confidentiality obligations, audits, and incident response procedures. While we strive for strong security, no system is entirely risk-free.
Data Breach Notification: In case of a data breach, we will investigate, mitigate risks, and notify affected users and authorities as required by law.
7. YOUR RIGHTS
You have the right to:
Access your personal information
Correct or update inaccurate data
Request deletion (subject to legal obligations)
Withdraw consent
Opt out of marketing communications
Request data portability
Object to or restrict processing
Raise grievances under the SPDI Rules
Requests can be made using the contact details below. We typically respond within 30 days after identity verification.
8. GRIEVANCE REDRESSAL
In compliance with the IT Act and SPDI Rules, we have appointed a
Grievance Officer. [Insert Name]
Designation: [Insert Designation]
Company: Salt and Grey
Address: [Insert Address]
Email: [Insert Email]
Phone: [Insert Phone]Working Hours: Mon–Fri, 10:00 AM – 6:00 PM ISTComplaints will be acknowledged within 48 hours and resolved within 30 days. Unresolved issues may be escalated to appropriate authorities.
9. CHANGES TO THIS POLICY
We may update this Privacy Policy periodically. Changes will be posted on our website with a revised “Last Updated” date. Continued use of our services constitutes acceptance of the updated policy.
10. GOVERNING LAW
This Privacy Policy is governed by the laws of India. Courts in New Delhi shall have exclusive jurisdiction.
11. ACKNOWLEDGMENT
By using our website or services, you confirm that you have read, understood, and consent to this Privacy Policy. If you do not agree, please discontinue use of our services.
Contact Us:
Email: [Insert Email Address]
Phone: [Insert Telephone Number]
Address: [Insert Complete Postal Address]