Privacy Policy
SAHAJE BY SAMADRITA
Privacy Policy
https://www.sahaje.shop | Effective: [DD Month YYYY] | Version 3.0
A short note from us
Hi. We're Sahaje by Samadrita, a small clothing label run out of India. We make garments and we ship them to people who love what we make. This page tells you, plainly, what we do with the small pieces of personal information we end up holding when you visit our website, place an order, write to us, or sign up for our updates.
We've tried to write this the way we'd cut a pattern — only what's needed, with clean lines. If anything here reads like fine print, write to us and we'll explain in plainer words. Our address is at the end of the document.
(A quick aside: we treat your data the way a good tailor treats a customer's measurements — kept private, used only for the fitting, not shared with the neighbour.)
1. Who we are
Brand: Sahaje by Samadrita
Website: https://www.sahaje.shop
Where we operate from: India. Our base of operations is in India, our team is in India, and the law that primarily governs how we handle your data is Indian law.
Address: [Registered / Operating Address in India — to be inserted]
Email for any privacy question: chakrabartisnil@gmail.com
Under the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), we are the “Data Fiduciary” for the personal data we collect through the website. For shoppers in the European Union or the United Kingdom, we are the “Data Controller” under the GDPR. For California shoppers, we are the “Business” under the CCPA/CPRA.
2. Where this Policy applies
Our shop is open to anyone with internet. Most of our customers are in India, and our prices show in Indian Rupees (INR). We also ship internationally on request and show prices in US Dollars (USD) for convenience. We do not run advertising campaigns aimed at any specific country outside India, and we do not monitor the behaviour of people who live in the EU, UK, or elsewhere outside India.
Even so, because the website is open to the world, we follow these laws where they apply:
-
India: the DPDP Act and the rules under it, the Information Technology Act, 2000 and the Sensitive Personal Data or Information Rules, 2011 (to the extent they still apply), and the Consumer Protection (E-Commerce) Rules, 2020.
-
EU / UK: the GDPR and the UK GDPR, where they apply to international visitors.
-
California (USA): the CCPA as amended by the CPRA.
-
Other shopper-protection laws where they apply (for example, CAN-SPAM in the US, CASL in Canada).
If you are reading this from outside India, please know that this page also serves as the “notice” your local law expects us to give you.
3. What we collect, and where it comes from
(Like a fitting: we ask only for measurements that matter.)
3.1 Things you give us yourself
-
Your name, billing and shipping address, email, and phone number.
-
Your account log-in (your username and a password that we store as a one-way hash; we never see your actual password).
-
Your order details (what you bought, what you paid, the currency, GST/invoice details, gift notes, sizing notes).
-
Anything you write to us — emails, contact-form messages, chat messages, social-media DMs, and attachments.
-
Your marketing choices (whether you've said yes to our emails, SMS, or WhatsApp updates).
-
Reviews you post, return or exchange requests, and answers to surveys.
3.2 Things we pick up automatically
-
Your device and browser details (IP address, browser type, OS, screen size, language, time-zone).
-
How you use the site (pages and products viewed, items added to cart, where you came from, your search terms on the site, time-stamps, session length).
-
Cookies and similar small files (see Section 7).
-
A rough idea of where you are (city or country, worked out from your IP address). We do not collect GPS-level location.
3.3 Things we hear from others
-
Razorpay: payment status, transaction ID, masked card BIN, masked UPI handle, refund status. We never see your full card number, CVV, or net-banking password. Those go straight to Razorpay on its secure (PCI-DSS) system.
-
Shiprocket and the couriers: the tracking (AWB) number, dispatch and delivery status, delivery exceptions, and return-to-origin updates.
-
Google and Meta (only if you've allowed our cookies): aggregate audience numbers and ad-conversion data from tools like Google Analytics, Google Ads, and the Meta Pixel.
-
Things you make public yourself on social media (tags, comments, DMs).
3.4 Do you have to give us this information?
For most of what we ask, yes — without it, we can't open your account, accept your order, deliver your parcel, refund a payment, or follow the law (for example, on tax invoices). If you'd rather not share it, we understand, but we won't be able to ship to you. Marketing sign-up, account-profile extras, and product reviews are always optional — saying no to those doesn't change anything else.
4. Why we use your data, and the law that lets us
(No hidden seams — here's the whole stitching.)
We use your information only for these reasons:
4.1 To run your order and your account
Open and keep your account, take your order, calculate tax and shipping, take payment through Razorpay, ship through Shiprocket and the couriers, handle returns/refunds, and answer your questions.
Legal basis: This is needed for the contract between us — DPDP Act s. 7; GDPR Art. 6(1)(b); a business purpose under CCPA/CPRA.
4.2 To send you marketing — only if you've said yes
Newsletters, product launches, restock alerts, sale notices, by email, SMS, or WhatsApp where supported. We only send marketing after you say yes (no pre-ticked boxes, no buried check-boxes), and you can change your mind any time — it's just as easy to unsubscribe as to sign up.
Legal basis: Your consent — DPDP Act s. 6; GDPR Art. 6(1)(a); plus the ePrivacy rules in Europe and CAN-SPAM/CASL where they apply.
4.3 To stop fraud and abuse, and to cancel orders we believe are not genuine
We check transactions for fraud signs, watch for chargebacks and account take-overs, look out for abusive returns, and we may cancel orders that look fraudulent or mis-priced.
Legal basis: Our legitimate interest in protecting the shop and our customers — GDPR Art. 6(1)(f); a legitimate use under DPDP s.7 for preventing/detecting fraud; and our legal duties under Indian law.
4.4 To measure how we're doing as a shop
We work out internal scores like “return rate”, “lifetime value band”, “loyal customer”, “new customer”. We use these to give better service and to plan offers. These scores are reviewed by humans on our team. They do not, on their own, cause any legal or similarly serious effect on you. We don't use them for credit scoring, insurance, jobs, or housing.
Legal basis: Our legitimate interest in improving service quality — GDPR Art. 6(1)(f); legitimate use under DPDP s. 7. If we ever want to go further (a fully automated decision with a real impact on you), we'll ask for consent first.
4.5 To keep the website working and safe
Hosting, performance, debugging, security, fighting attacks, and understanding traffic. Non-essential analytics and advertising cookies are switched on only after you say yes.
Legal basis: Legitimate interests — GDPR Art. 6(1)(f); DPDP s. 7. For non-essential cookies, your consent.
4.6 To follow the law and defend ourselves if needed
GST, income-tax, customs, accounting, consumer-protection, and other laws; answering lawful requests from authorities; enforcing our Terms; defending legal claims.
Legal basis: Legal obligation — GDPR Art. 6(1)(c); DPDP s. 7(b); legitimate interests for legal claims.
4.7 To talk to you (transactional messages)
Order confirmations, dispatch and delivery updates, refund updates, password resets, security alerts, and replies to your questions.
Legal basis: This is part of running your order, so it goes out whether or not you've opted in to marketing.
4.8 Our balancing tests
Where we rely on our “legitimate interests”, we have considered your rights and freedoms first and use the data only where the use is necessary and proportionate. We keep a short internal record of this balancing test. We will share a high-level summary with a competent supervisory authority on lawful request; we will not, as standard practice, share our internal documents with members of the public.
5. Consent — and how to take it back
(You can take a yes off the rack as easily as you put it on.)
When we rely on your consent, we'll: ask in plain language, tell you what the consent is for, keep a record of it, and give you a simple way to withdraw.
To withdraw, click “unsubscribe” in any marketing email, change your cookie choices in the cookie panel on the website, update your account preferences, or simply email chakrabartisnil@gmail.com.
Taking back consent works from that moment onward — anything we already did with your data, lawfully, before you withdrew, stays lawful. Withdrawing marketing consent will not affect your right to shop with us.
When the DPDP Rules require integration with a registered Consent Manager, we will integrate with one within the timeline the Rules specify, and update this Policy.
6. Children's data
(We don't tailor anything for kids — no ads, no tracking, full stop.)
Our shop is not aimed at children. Under the DPDP Act, a “child” is anyone under 18 years of age in India. In other countries the age may be lower (for example 13 in the US under COPPA, or 13–16 in EU countries under the GDPR).
If we ever need to process a child's data, we will first take verifiable parental consent from a parent or lawful guardian, using a method recognised under the DPDP Rules in force at the time of processing.
We do not track children, monitor their behaviour, or run targeted advertising at children. This is a hard line under DPDP s. 9 and we apply it everywhere.
If you think a child has shared data with us by mistake, please write to chakrabartisnil@gmail.com and we'll delete it quickly.
7. Cookies and similar bits of code
(The good kind of cookies. Even so, we ask before we use the optional ones.)
Our site sits on Wix, so Wix sets a few cookies that the shop simply needs to work (your cart, log-in, security). On top of that, when you say yes in our cookie banner, we may switch on tools like Google Analytics, Google Ads, the Meta Pixel/Conversions API, and similar.
Important for visitors in the EU/UK and other consent-first places: we do not set any non-essential cookies, pixels, or tags on your device until you give consent on the banner. You can change your mind any time from the “Cookie Preferences” link in the footer.
7.1 The kinds of cookies we use
-
Necessary: for the cart, checkout, log-in, and security. These are always on.
-
Preference: remember your language and region.
-
Analytics: so we can see what's working — Google Analytics, Wix Analytics. Only on with your consent.
-
Advertising: for ad campaigns on Google and Meta. Only on with your consent.
7.2 Browser “Do not sell” / Global Privacy Control
Where it applies (for example, California), we honour the Global Privacy Control (GPC) signal your browser sends as a valid “do not sell or share” request. We also respect choices you register through the IAB Europe Transparency and Consent Framework.
8. Who we share your data with
(Off the rack, never sold.)
We do not sell your data. We share it only with the people and tools we need to run the shop, and only what they need to do their part.
8.1 Our service providers
-
Wix.com Ltd. — our website and storefront: hosts the site, stores order and account data, and runs the shop's backend. Wix may store data in the United States, Israel, the EEA, and other places where its sub-providers (major cloud companies) operate.
-
Razorpay Software Private Limited — payments: takes your payment. Razorpay collects your card / UPI / banking details directly on its own secure (PCI-DSS) systems. Razorpay acts on its own under its own privacy policy for that part, and as our processor for payment-status updates.
-
Shiprocket / Kart Rocket Pvt. Ltd. — shipping: works out the courier, prints labels, and shares tracking with us. We share your name, shipping address, phone, email, and the order details with Shiprocket and the chosen courier.
-
Analytics and ads (with your cookie consent only): Google LLC (Analytics, Ads), Meta Platforms, Inc. (Pixel, Conversions API), and similar.
-
Communication tools: email providers, DLT-registered SMS/WhatsApp gateways for the Indian market, and helpdesk tools.
-
Advisors: our auditors, accountants, and lawyers, who are under confidentiality duties.
8.2 Sub-processors
Our service providers use their own sub-providers. We require them, by contract, to keep the same standard of protection. We do not publish a real-time sub-processor list, because that list is maintained by our providers and changes from time to time. You can ask for the categories of sub-processors currently engaged by writing to chakrabartisnil@gmail.com; we will respond within 30 days, up to once in any 12-month period per requestor.
8.3 When the law asks us to share
If a court, the police, a regulator, or another lawful authority asks for data and the request is valid, we will share what we have to share.
8.4 If the business changes hands
If we merge, sell, restructure, or close, your data may move to the new owner — but they will be bound by this Policy, or one at least as protective.
8.5 “Sale” or “sharing” under CCPA/CPRA
We don't sell personal information for money. If the use of an advertising cookie (Meta Pixel, Google Ads) counts as “sharing” for cross-context behavioural advertising under California law, that sharing is on only when you consent. California shoppers can switch it off in the cookie panel, through the GPC signal, or by emailing chakrabartisnil@gmail.com with the subject “Do Not Sell or Share My Personal Information”.
9. CCPA notice at collection — quick table
Here is a one-page summary for California shoppers, covering the last 12 months.
Category of personal information
Where it comes from
Why we use it
Who it goes to
Identifiers (name, email, phone, address, IP)
You; cookies/logs; processors
Account, orders, communication, security
Wix; Razorpay; Shiprocket; couriers; analytics/ads (with consent)
Commercial information (orders, returns, choices)
You; processors
Fulfilment, customer service, analysis
Wix; Razorpay; Shiprocket; advisors
Internet/network activity (browsing, clicks)
Cookies; server logs
Site operation, security, analytics
Wix; Google Analytics; Meta (with consent)
Approximate location (city/country from IP)
Cookies; server logs
Tax and shipping rules, fraud check
Wix; Razorpay; analytics
Inferences (loyalty score, service-tier flags)
Worked out from the above
Better service, prioritisation of support
Internal only
Sensitive PI (account log-in)
You
Logging you in
Only the providers that run the log-in
We do not use Sensitive Personal Information beyond what California law allows, and you have the right to limit such use.
10. Sending data outside India (and outside the EU/UK)
Because we use global tools (Wix, Razorpay, Shiprocket, Google, Meta), your data may sit in countries other than yours — including India, the United States, the EEA, the United Kingdom, Israel, and other places where our providers operate.
Sending data from the EEA or UK to a country without an adequacy decision: we (or our providers) use the European Commission's 2021 Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum/IDTA, plus extra technical measures (encryption, access controls, contractual limits on government access). For US-based providers, we also rely on the EU-US Data Privacy Framework (and the UK extension and Swiss-US DPF) where they are self-certified.
Sending data from India: we send data only to countries that the Central Government has not restricted under the DPDP Act. If the Government issues a restriction notification, we'll update our setup to match.
If you would like to know which transfer mechanism applies to data about you, write to chakrabartisnil@gmail.com. Where law requires, we will share the relevant clauses with commercial terms redacted, within 30 days, up to once in any 12-month period per requestor.
11. How long we keep your data
(Like clothes you no longer wear — we don't keep what we don't need.)
We keep your data only for as long as we need it. After that, we either delete it or anonymise it so it can't be traced back to you.
What
How long
Account profile and contact details
For as long as your account is active. After you close it, up to 90 days for clean-up — unless one of the rows below applies.
Order, invoice, GST, customs, and tax records
8 financial years from the end of the relevant financial year, or longer if the Income-Tax Act, GST law, or Companies Act says so.
Payment metadata (from Razorpay)
As long as RBI rules and PCI-DSS require — usually 7 years for chargeback and reconciliation.
Shipping and courier records (Shiprocket)
Up to 3 years, for delivery disputes.
Customer support messages
Up to 3 years from the last message, then deleted or anonymised.
Marketing consent record
For as long as we rely on the consent, plus 3 years after withdrawal for audit.
Marketing suppression list
For as long as we run marketing, so we do not re-contact you after an opt-out.
Analytics cookies
Up to 14 months.
Advertising cookies
Up to 13 months.
Server, security, and access logs
Up to 18 months.
Records of consent (other than marketing)
For the time we rely on the consent, plus 3 years for audit and defence of claims.
Records of your rights requests
Up to 3 years from closing the request, for audit and regulator checks.
Reviews / public posts you made on our site
Stays online while published. On deletion request, we remove the review or anonymise the author shown.
12. Your rights — and how to use them
(Fits you, not us.)
12.1 Rights under the DPDP Act (India)
-
Right to a summary of the personal data we process about you and how (s. 11).
-
Right to correct, complete, update, or erase your personal data (s. 12).
-
Right to grievance redressal — i.e., to complain to our Grievance Officer (s. 13).
-
Right to nominate someone else to use your rights if something happens to you (s. 14).
-
Right to withdraw consent at any time, as easily as you gave it (s. 6(4)).
12.2 Rights under the GDPR / UK GDPR
-
Access (Art. 15), correction (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20).
-
Objection to processing based on our legitimate interests, including profiling, and an absolute right to object to direct marketing (Art. 21).
-
The right not to be subject to fully automated decisions with legal or similarly serious effects (Art. 22). We don't do that — see Section 13.
-
The right to complain to your local supervisory authority (the data-protection regulator in your country, the UK's ICO, or the Irish DPC where relevant).
12.3 Rights under the CCPA/CPRA (California) and similar US state laws
-
Right to know, right to delete, right to correct.
-
Right to opt out of “sale” or “sharing” for cross-context behavioural advertising (including by GPC).
-
Right to limit use and disclosure of Sensitive Personal Information.
-
Right not to be discriminated against for using these rights.
-
Right to send your request through an authorised agent.
12.4 How to ask, and how we'll respond
Write to chakrabartisnil@gmail.com with the subject “Privacy Rights Request” and tell us what you'd like.
Checking it's really you: we will ask you to log in (if you have an account) or to confirm the email and order details we already hold for guest orders. For broader requests (full data export, deletion), we will ask for one additional piece of verification, such as a recent order number or a short identity check. We will not share data with anyone we cannot verify is you.
How long we take: we acknowledge every privacy request within 7 working days. We close it within 30 days under the DPDP Act and the GDPR/UK GDPR. We may extend that by up to 60 days where a request is complex or where we have several requests from you, and we will tell you within the first 30 days if we need the extension. For CCPA/CPRA requests, we close within 45 days, extendable by 45 days where allowed.
Authorised agents: you can send someone else; we will ask for written proof they are allowed to act for you, plus your verification as above.
No fee, unless a request is manifestly unfounded or excessive (for example, repeated requests about the same data), in which case we may charge a small administrative fee or refuse, as GDPR Art. 12(5) and the DPDP Rules allow.
13. Automated decisions and profiling
We do not use a fully automated system to make decisions about you that have a legal or similarly serious effect — no robo-decisions on credit, insurance, jobs, or housing here. The scores we use (see Section 4.4) are inputs that our team uses to decide things like service priority, not the final word.
If we ever build something that would cross that line, we'll get your consent first, explain in plain language how it works, and give you the right to ask a human to review it.
14. Marketing
(We'd love to drop you a note. Only if you'd like one.)
We send marketing only after you opt in. You can unsubscribe at any time via the link in any email, by replying STOP to an SMS or WhatsApp message where supported, by changing your account preferences, or by emailing chakrabartisnil@gmail.com.
Indian rules we follow: our SMS marketing goes through DLT-registered providers and follows TRAI's TCCCPR rules. Our WhatsApp marketing follows the WhatsApp Business and Meta Business policies. We do not make marketing phone calls without proper consent.
Custom audiences: if we upload hashed contact lists to Meta, Google, or similar, to build custom or look-alike audiences, we do it only with your consent (where consent is required) and under the platforms' data-processing terms.
Transactional emails and SMS — order confirmations, dispatch and delivery updates, refunds, security alerts — keep going either way; they're part of your order.
15. Keeping data safe — and what we'll do if something goes wrong
(Buttoned-up. But no system is bulletproof.)
We protect your data with sensible technical and organisational steps: HTTPS/TLS encryption in transit, least-privilege access for our team on the Wix dashboard, strong passwords plus multi-factor authentication where available, PCI-DSS payments via Razorpay, written data-protection terms with our service providers, and an incident-response plan.
We meet the “reasonable security practices and procedures” standard expected under the Information Technology Act, 2000 and the SPDI Rules, 2011.
Even so, no system is unbreakable. Please keep your account password safe, and let us know at chakrabartisnil@gmail.com if you ever think someone else has used your account.
If a breach does happen, we will: tell the Data Protection Board of India within 72 hours of becoming aware of the breach (or such other timeline as the DPDP Rules then in force may prescribe), and tell affected Data Principals as soon as we reasonably can; tell the relevant EU/UK supervisory authority within 72 hours if Article 33 GDPR applies (unless the risk to people is unlikely); tell affected data subjects without undue delay if Article 34 GDPR applies (high risk); and follow US state breach laws (such as California Civ. Code § 1798.82) where they apply.
16. Other websites we link to
We sometimes link to other websites — Instagram, Facebook, Pinterest, payment partners, courier tracking pages, and so on. Once you click through, you're in their hands, not ours, and they have their own privacy policies. Have a look at those if you're curious.
17. How often we review this Policy
We review this Policy when our shop's data practices change in a material way, when Indian law (or the laws of countries we reach) changes in a way that affects this Policy, and otherwise from time to time. If we add a new processing activity that is likely to be high risk for your rights, we will carry out a Data Protection Impact Assessment before we start.
18. Changes to this Policy
If we update this Policy, we will post the new version on the website with a fresh Effective Date. If the change is material (it changes what we collect, how we use it, who we share it with, or your rights), we will tell you — by email or with a clear notice on the website — at least 7 days before it takes effect, except where the law requires an immediate change. We keep older versions of this Policy for 3 years and can share them on reasonable request.
19. Plain language and accessibility
(Tailored to read, not to confuse.)
We've written this Policy in simple English on purpose. If you'd like it in large print or an audio version, write to chakrabartisnil@gmail.com and we will share a reformatted version within 30 days. If you'd like a translation into a language listed in the Eighth Schedule to the Constitution of India, write to us and we will share the substantive contents in that language within 45 days, subject to translation feasibility for technical terms.
20. How to reach us — and our Grievance Officer
For any privacy question, request, withdrawal of consent, exercise of rights, or grievance, please contact us using the details below.
Sahaje by Samadrita
Grievance Officer (under the DPDP Act and the Consumer Protection (E-Commerce) Rules, 2020): [Name — to be inserted]
Designation: [Designation — e.g., Founder / Proprietor]
Email: chakrabartisnil@gmail.com
Postal address: [Postal Address — to be inserted]
We will acknowledge your message within 7 working days and respond within 30 days (extendable as set out in Section 12.4). If we have not sorted it out to your satisfaction, you can take it further with: the Data Protection Board of India (once it is operational); your local data-protection authority in the EEA or UK; the California Privacy Protection Agency (cppa.ca.gov); or another competent authority.
21. Governing law and courts
This Policy is governed by the laws of India. The courts at [City, India] will have jurisdiction, except where local consumer-protection or data-protection law gives you a right to sue at home that we cannot take away.
22. Thanks for reading
By using the website, opening an account, placing an order, or otherwise sharing personal data with us, you confirm you've read this Policy. Where the law requires it, we will ask for your separate, clear consent.
And thank you. We know privacy policies are not anyone's favourite reading. We've tried to make this one feel a little less like fine print.
(Wear it well.)
— End of Privacy Policy —