Legal & Regulatory Disclosure

Privacy Policy

Data Fiduciary: SINDROX TECHNOLOGY PRIVATE LIMITED

CIN: U62090DL2025PTC457455 | GSTIN: 07ABRCS7108N1ZL

Governing Laws: Digital Personal Data Protection Act 2023 (DPDP Act), IT Act 2000 & IT Rules 2011

Grievance Officer: Madan Gopal (hello@sindrox.shop)

1. Data Fiduciary Identity

The data fiduciary responsible for all personal data collected on sindrox.shop is SINDROX TECHNOLOGY PRIVATE LIMITED, having its registered office at:

55, 2nd Floor, Lane-2, Westend Marg, Saidulajab, Near Saket Metro Station, Gadaipur, South West Delhi, New Delhi, Delhi, India, 110030

2. Personal Data We Collect

CategoryInformation CollectedPurpose & Storage Method
Account InformationFull Name, Email Address, Salted Hashed Password, Phone Number, Saved Delivery Addresses.Account management & order processing. Passwords encrypted with one-way hashing & unique salt.
Order & Transaction DataBilling/Shipping Name, Address, Phone, Items Purchased, Quantities, Prices, Discount Codes, Payment Method Type.Order fulfilment, GST compliance, invoice generation. Full card/CVV details are never stored by us.
Technical & Device DataIP Address, Browser Type, Operating System, Referring URL, Page View Duration, Clickstream Paths.System diagnostics, security logging, aggregate performance analytics.
Cookies & Local StorageSession Tokens, Cart State, Analytics Cookies (anonymised).Maintain active sessions, retain cart items. Users can manage cookies via browser settings.

3. Purposes of Data Processing

We process your personal data exclusively to:

  1. Process, pack, ship, and deliver your orders.
  2. Send transactional notifications (order confirmation, tax invoice, shipping tracking, return receipts).
  3. Send promotional updates, product launches, and sale alerts via Email/WhatsApp/SMS (only with explicit opt-in consent).
  4. Prevent fraudulent transactions, security breaches, and platform abuse.
  5. Comply with statutory tax and accounting mandates (e.g., GST invoice retention).
  6. Resolve consumer complaints under the Consumer Protection (E-Commerce) Rules 2020.

4. Lawful Basis for Processing (DPDP Act 2023)

  • Performance of Contract: Necessary to deliver ordered products and service your account.
  • Consent: Required for marketing communications and non-essential analytics (consent can be withdrawn at any time).
  • Legitimate Uses & Compliance: Statutory obligations under the Companies Act 2013, GST laws, IT Act 2000, and fraud prevention.

5. Third-Party Data Sharing & Processors

We do not sell your personal data to third parties. Data is shared strictly on a need-to-know basis with authorised service providers:

  • Payment Gateway (Razorpay): Transaction amounts and reference tokens for payment processing. All payments handled on PCI-DSS Level 1 certified infrastructure.
  • Logistics Partners (Delhivery, Bluedart, India Post): Name, delivery address, PIN code, and phone number for shipping execution only.
  • Statutory Authorities: Disclosed only when mandated by court orders, law enforcement, or statutory tax audits under Indian law.

6. Data Retention Schedule

  • Order Records & Invoices: Retained for 7 years to satisfy GST and statutory corporate audit requirements.
  • Account Profiles: Retained while the account is active. Upon account deletion request, marketing data is purged within 30 days.
  • Marketing Consent: Retained until opt-out; communications cease within 5 business days of unsubscription.

7. Your Statutory Rights under DPDP Act 2023

You hold the following rights regarding your personal data:

  • Right to Access: Obtain a summary of personal data held and processing activities.
  • Right to Correction & Erasure: Correct inaccurate data or request deletion (subject to statutory retention obligations).
  • Right to Withdraw Consent: Opt out of marketing communications at any time.
  • Right of Grievance Redressal: Submit data complaints to our Grievance Officer.
  • Right to Nominate: Designate an individual to exercise data rights in the event of incapacity.

8. Security Measures & Encryption

Enforced TLS 1.2+ / HTTPS encryption across all web pages and API endpoints. Sensitive database fields are encrypted with AES-256 encryption. In the event of a personal data breach, notification will be sent to affected users and the Data Protection Board of India.

9. Cookies Policy

Sindrox uses cookies and local storage for essential cart functionality, active sessions, and anonymised performance analytics. Non-essential cookies can be managed via your browser settings.

10. Grievance Officer Contact Details

Grievance Officer: Madan Gopal

Designation: Director & Grievance Officer

Email: hello@sindrox.shop

Phone: +91 11 4000 7382

Address: 55, 2nd Floor, Lane-2, Westend Marg, Saidulajab, Near Saket Metro Station, Gadaipur, South West Delhi, New Delhi, Delhi, India, 110030

*Grievances are acknowledged within 48 hours and resolved within 30 days under Rule 5(9) of IT Rules 2011 and Section 10 of DPDP Act 2023.*