PrivacyPolicy
đź”’ Privacy Policy for SMOOTH
Brand Name: SMOOTH (the “Data Fiduciary,” “we,” “us,” or “our”)
SMOOTH is committed to safeguarding your privacy. As a Data Fiduciary operating in India, we comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) and all applicable rules.
1. Contact Information & Grievance Redressal (DPDP Mandate)
If you have questions or wish to exercise your rights under the DPDP Act, contact our designated Grievance Contact Person:
| Contact Method | Details |
|---|---|
| Grievance Contact Person | [Insert Name] |
| Grievance Email | 8loopstudios@gmail.com |
| Mailing Address | [Insert Business/Legal Address] |
We address all grievances within the timelines mandated by law.
2. Personal Data We Collect
We only collect data necessary for specified, lawful purposes. You will receive a notice describing the data and purpose before giving consent.
A. Information You Provide Directly
Collected when you interact with our Site, place an order for SMOOTH Nasal Strips, or contact us:
-
Identity & Contact Data: Name, billing/shipping address, email, optional phone number.
-
Order & Transaction Data: Product details, payment confirmation.
Note: We do not store full card numbers; payments are handled by secure third-party gateways. -
Account Data: Username, password, purchase history.
-
Communication Data: Information provided via email or support messages.
B. Device & Usage Data (Automatic Collection)
-
Usage patterns (page views, clicks, scrolls).
-
Device data (IP, browser type, time zone).
-
Cookies (defined in Section 5).
C. Third-Party Data
We may receive information from service providers such as payment gateways, logistics partners, and platforms supporting our operations.
3. Lawful Processing & Purpose (DPDP-Compliant Consent)
We process your Personal Data only for Lawful Purposes, based on Consent or Legitimate Uses permitted under the DPDP Act.
| Purpose | Personal Data Used | Legal Basis |
|---|---|---|
| Order Fulfillment | Identity, Contact, Transaction Data | Consent |
| Customer Support | Identity, Contact, Communication Data | Legitimate Use |
| Marketing (Optional) | Identity, Contact, Usage Data | Consent (Opt-in) |
| Security & Fraud Control | Device, Transaction, Contact Data | Legitimate Use |
| Legal Compliance | Any required data | Legitimate Use |
You may withdraw consent at any time.
4. Data Principal Rights (DPDP Act, 2023)
You may exercise the following rights by emailing 8loopstudios@gmail.com:
| Your Rights | What It Means |
|---|---|
| Access | Know what data we process and with whom it's shared. |
| Correction | Fix inaccurate or incomplete data. |
| Erasure | Request deletion when the data is no longer needed or consent is withdrawn. |
| Grievance Redressal | Use our grievance channel for issues. |
| Nominate | Appoint someone to act on your behalf if you cannot. |
| Withdraw Consent | Stop us from processing data based on consent. |
Your Duties (DPDP Requirement)
You must not:
-
Provide false information
-
File frivolous grievances
-
Submit unauthentic data for corrections
5. Sharing & Disclosure of Data
We share data strictly on a “need-to-know” basis:
A. Data Processors
Third-party service providers (e.g., payment processors, logistics partners, hosting services) that process data under written contracts ensuring privacy safeguards.
B. Legal Requirement
We may disclose your data when required by law, court orders, or government agencies.
6. Data Retention (Storage Limitation)
We retain data only as long as necessary for the original purpose or as required by Indian law.
We will delete or anonymize your data when:
-
The purpose is fulfilled
-
You withdraw consent
-
Retention is no longer legally required
7. Security & Safeguards
We implement reasonable security safeguards to protect your data from unauthorized access, breach, or misuse.
In case of a data breach, we will notify the Data Protection Board of India (DPBI) and all affected users as required under the DPDP Act.
8. International Data Transfers
We may transfer your data outside India (e.g., for cloud hosting).
Transfers occur only if the destination is not restricted by the Central Government.
9. Children's Data (Minors Under 18)
Our products and services are not intended for minors.
We do not knowingly process data of children under 18 without verifiable parental consent.
We do not perform targeted advertising or behavioral tracking of children.
10. Changes to This Privacy Policy
We may update this policy periodically.
The updated version will be posted on our Site with a revised “Last Updated” date.
Legal Disclaimer
This Privacy Policy aligns with the Digital Personal Data Protection Act, 2023.
We recommend consulting qualified legal counsel to ensure full compliance with all applicable laws and regulations relevant to your operations.
Â