Privacy Policy

Prakriti's Garden

Last updated: [10/08/2026]
Effective date: [10/08/2026]


1. Introduction

This Privacy Policy explains how [Legal Entity Name], a [proprietorship / partnership firm / private limited company] registered under the laws of India, having its registered office at [Full Registered Address, City, State, PIN] (trading as "Prakriti's Garden", "we", "us", "our"), collects, uses, stores, shares and protects your personal data when you visit [www.prakritisgarden.com] (the "Website"), place an order, or otherwise interact with us.

We act as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act") in respect of the personal data described in this Policy. We also comply with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

This Policy forms part of our Terms of Service. By using the Website, you acknowledge that you have read and understood this Policy.

This is an electronic record under the Information Technology Act, 2000 and does not require a physical or digital signature.


2. Definitions

  • "Personal Data" means any data about an individual who is identifiable by or in relation to such data.
  • "Data Principal" means you — the individual to whom the Personal Data relates.
  • "Data Fiduciary" means Prakriti's Garden, which determines the purpose and means of processing your Personal Data.
  • "Data Processor" means a third party that processes Personal Data on our behalf, such as our hosting, payment or logistics partners.
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, sharing, retention and erasure.

3. Personal Data We Collect

3.1 Data you provide directly

Category Examples When collected
Identity data Name, date of birth (if voluntarily shared) Account creation, checkout
Contact data Billing address, shipping address, email, mobile number Checkout, account, enquiries
Account data Username, password (stored in hashed form), preferences, wishlist Registration
Order data Products purchased, order value, order history, gift messages, delivery instructions Purchase
Payment data Payment method type, transaction ID, partial card identifiers Checkout
Communication data Emails, WhatsApp and chat messages, call records, support tickets Customer support
User content Product reviews, ratings, photographs, comments, survey responses Voluntary submission
Recipient data Name, address and phone number of a gift recipient Gift orders

3.2 Data collected automatically

  • IP address, approximate location derived from IP, and PIN code for serviceability checks
  • Device type, operating system, browser type and version, screen resolution
  • Pages viewed, products browsed, time on page, referring URL, exit pages
  • Cart activity, including abandoned carts
  • Cookie identifiers and similar tracking technologies (see Section 6)

3.3 Data from third parties

  • Order, fulfilment and delivery status from our courier and logistics partners
  • Transaction confirmations and fraud signals from payment gateways
  • Aggregated campaign and audience data from advertising and analytics platforms
  • Public profile information where you choose to log in or interact via a social media account

3.4 What we do not collect

We do not collect or store your complete debit or credit card number, CVV, card PIN, UPI PIN, net-banking password or any equivalent credential. These are captured directly by our PCI-DSS compliant payment gateway partners.

We do not knowingly collect sensitive personal data such as health, biometric, caste, religious or sexual-orientation data, and request that you do not share such data with us.


4. Why We Process Your Personal Data

We process Personal Data for the following purposes:

(a) To fulfil your order — processing payment, packing, dispatch, delivery, tracking, returns, replacements and refunds.

(b) To provide customer service — responding to queries, complaints, plant-care questions and grievance redressal.

(c) To operate and maintain your account — authentication, order history, saved addresses, wishlists.

(d) To improve our Website and catalogue — analysing browsing and purchase patterns, identifying popular collections, fixing errors, testing features.

(e) To personalise your experience — recommending plants, planters or care products relevant to your interests and location.

(f) To communicate with you — order confirmations, dispatch and delivery updates, care reminders, and (with your consent) newsletters, seasonal offers and promotional messages.

(g) To prevent fraud and secure our systems — detecting fraudulent orders, payment misuse, coupon abuse and unauthorised access.

(h) To meet legal obligations — GST invoicing, tax records, statutory reporting, and responding to lawful requests from courts, regulators or law-enforcement agencies.

4.1 Basis of processing

We process Personal Data on the basis of:

  • Your consent, freely given, specific, informed and unambiguous, which you may withdraw at any time; and
  • Certain legitimate uses permitted under Section 7 of the DPDP Act, including where you voluntarily provide data for a specified purpose, and for compliance with law or judgments.

We will not use your Personal Data for any purpose materially different from those stated above without giving you notice and, where required, obtaining fresh consent.


5. Marketing Communications

5.1 Transactional messages relating to your order — confirmation, dispatch, delivery, refund and service alerts — are sent as part of performing the contract and are not marketing.

5.2 Promotional emails, SMS and WhatsApp messages are sent only where you have opted in. You may opt out at any time by clicking "unsubscribe" in any email, replying STOP to a WhatsApp or SMS message, or writing to [privacy@prakritisgarden.com].

5.3 Opting out of marketing does not stop transactional messages relating to an active order.

5.4 Our telephonic and SMS communications are subject to TRAI's Telecom Commercial Communications Customer Preference Regulations.


6. Cookies and Tracking Technologies

6.1 We use cookies and similar technologies to operate the Website and understand how it is used.

Type Purpose Can you disable?
Strictly necessary Cart function, checkout, login sessions, security No — the Website will not function
Functional Language, currency, saved preferences Yes
Analytics Traffic, page performance, conversion measurement Yes
Advertising Retargeting and measuring ad campaigns on Meta, Google and similar platforms Yes

6.2 The Website is built on Shopify, which sets certain cookies necessary for cart and checkout operation.

6.3 You can manage cookies through our cookie banner (where displayed) or through your browser settings. Blocking cookies may impair checkout and other features.

6.4 We honour browser-level opt-out signals where technically supported.


7. Who We Share Your Personal Data With

We do not sell, rent or trade your Personal Data. We share it only as follows:

Recipient category Data shared Purpose
E-commerce platform (Shopify) Account, order and browsing data Hosting, storefront and checkout
Payment gateways Transaction amount, contact details, transaction ID Payment processing, fraud checks
Courier and logistics partners Recipient name, address, phone, order contents Delivery and returns
Communication providers Email, mobile number Order and marketing communications
Analytics and advertising platforms Pseudonymised or aggregated usage and conversion data Measurement and campaign optimisation
Professional advisers As relevant Accounting, audit, tax and legal advice
Regulatory and law-enforcement bodies As legally required Compliance with law, court orders, lawful requests
Successor entity Relevant customer records Merger, acquisition or business transfer, subject to this Policy

Every processor is engaged under a written contract requiring them to process Personal Data only on our instructions, maintain reasonable security safeguards, and not retain data longer than necessary.


8. Third-Party Services and Links

8.1 The Website may link to third-party websites, plugins and social media platforms. These operate under their own privacy policies, which we do not control.

8.2 We encourage you to review the privacy policy of any third-party service — including our payment gateway and courier partners — before sharing data with them.


9. Cross-Border Transfers

9.1 Some of our service providers — including hosting, analytics and communication platforms — may store or process data on servers located outside India.

9.2 Where such transfer occurs, it is made in accordance with Section 16 of the DPDP Act and is not made to any country restricted by the Central Government.

9.3 We require such providers to maintain security standards at least equivalent to those we apply in India.


10. Data Retention

10.1 We retain Personal Data only for as long as necessary for the purpose for which it was collected, or as required by law.

Data Retention period
Order, invoice and GST records [8] years, as required under tax and companies legislation
Account data Until you request deletion, or [3] years of continuous inactivity
Marketing consent records Until withdrawal, plus [1] year as proof of consent
Support and grievance records [3] years from resolution
Website analytics data [26] months, or as configured in the relevant platform

10.2 On expiry of the applicable period, we erase Personal Data or irreversibly anonymise it, except where retention is required to comply with law or to establish, exercise or defend legal claims.


11. Security Safeguards

11.1 We implement reasonable security practices and procedures proportionate to the nature of the data, including:

  • HTTPS/TLS encryption in transit across the Website and checkout
  • Passwords stored in salted, hashed form
  • Role-based access controls limiting staff access to a need-to-know basis
  • PCI-DSS compliant payment processing handled entirely by our gateway partners
  • Periodic review of access rights, platform permissions and third-party integrations

11.2 No method of transmission or storage over the internet is completely secure. While we take reasonable measures, we cannot guarantee absolute security.

11.3 You are responsible for keeping your account credentials confidential and for notifying us promptly of any suspected unauthorised access.


12. Personal Data Breach

In the event of a personal data breach, we will notify the Data Protection Board of India and each affected Data Principal in the form and manner prescribed under the DPDP Act and its rules, without undue delay.


13. Your Rights as a Data Principal

Under the DPDP Act, you have the right to:

(a) Access — obtain a summary of the Personal Data we process about you, the processing activities undertaken, and the identities of Data Fiduciaries and Processors with whom it has been shared.

(b) Correction and erasure — have inaccurate or misleading data corrected, incomplete data completed, data updated, and data erased where it is no longer necessary for the purpose for which it was collected, unless retention is required by law.

(c) Grievance redressal — a readily available means of raising a grievance with us, as set out in Section 15.

(d) Nomination — nominate another individual to exercise your rights in the event of your death or incapacity.

(e) Withdraw consent — withdraw consent at any time, with the same ease with which it was given. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and may limit our ability to provide certain services.

13.1 How to exercise your rights

Write to [privacy@prakritisgarden.com] from your registered email address, stating the right you wish to exercise. We may seek reasonable information to verify your identity before acting. We will respond within [30] days of receipt.

13.2 Your duties

Under Section 15 of the DPDP Act, you must not impersonate another person, suppress material information, register a false or frivolous grievance, or furnish false particulars when exercising your rights.


14. Children's Data

14.1 The Website is not directed at children. We do not knowingly collect Personal Data of any person below 18 years of age without the verifiable consent of a parent or lawful guardian.

14.2 We do not undertake tracking, behavioural monitoring or targeted advertising directed at children.

14.3 If you believe a child has provided us Personal Data without such consent, write to [privacy@prakritisgarden.com] and we will delete it promptly.


15. Grievance Officer

For any question, request or complaint relating to this Policy or your Personal Data, contact:

Name [Full Name]
Designation Grievance Officer / Data Protection Contact
Email [grievance@prakritisgarden.com]
Phone [+91 XXXXXXXXXX]
Address [Full Registered Address, City, State, PIN]
Working hours [Monday–Saturday, 10:00 AM – 6:00 PM IST]

We will acknowledge every complaint within 48 hours and endeavour to resolve it within [30] days, and in any event within one month of receipt.

If you are not satisfied with our response, you may approach the Data Protection Board of India in accordance with the DPDP Act.


16. Changes to this Policy

16.1 We may update this Policy to reflect changes in our practices, technology or the law. The revised version will be posted on this page with an updated "Last updated" date.

16.2 Where a change is material, we will notify you by email or a prominent notice on the Website before it takes effect.

16.3 Your continued use of the Website after the effective date constitutes acceptance of the revised Policy.


17. Contact Us

[Legal Entity Name] (trading as Prakriti's Garden) [Full Registered Address, City, State, PIN] Email: [privacy@prakritisgarden.com] Phone: [+91 XXXXXXXXXX] GSTIN: [XXXXXXXXXXXXXXX]