Personal Information Collected
When it’s collected:
- At the time of purchase
- When users browse the site
- When users subscribe to marketing content
Types of data collected:
- Identifiers: Name, email, phone number, shipping address
- Technical data: IP address, browser type, operating system (collected automatically)
- Transaction data: Details about the purchase (excluding card information)
✅ Suggestion: You may expand to mention other optional data (like feedback, account preferences, saved items, etc.) if your site offers account creation or user profiles.
2. Consent
- Consent is explicit for marketing.
- For general use (like placing an order), implied consent is obtained through the action.
- Option to withdraw consent anytime by contacting the business via email.
✅ Best Practice: Offer a clear “unsubscribe” link in all marketing emails and a user dashboard (if applicable) to manage preferences.
3. Disclosure
Personal data may be disclosed:
- If required by law
- If there is a breach of Terms of Service
⚠️ Note: You might also mention other scenarios such as fraud prevention or enforcing legal rights.
4. Payment Security
- Uses secure third-party payment gateways
- Follows PCI-DSS compliance
- Does not store card information
✅ Suggestion: Mention the specific providers (e.g., Razorpay, PayPal, Stripe) and link to their privacy policies.
5. Third-Party Services
- Services like shipping, analytics, or customer service tools may access user data only as needed.
- Once users leave your site (e.g., redirected to PayPal), they’re subject to that site’s policies.
✅ Best Practice: List names of major third parties used (e.g., Google Analytics, Meta Pixel) and explain what data they handle.
6. Security Measures
- Uses reasonable precautions and industry best practices.
- Protects data from unauthorized access, misuse, or destruction.
🔐 Advanced Option: Mention whether data is encrypted in transit and at rest, if MFA is used for admin access, and how breaches are handled.
7. Cookies
- Cookies are used for session tracking.
- Do not personally identify users.
✅ Suggestion: Add a Cookie Banner for first-time visitors to comply with laws like GDPR and give an option to opt-out of non-essential cookies.
8. Age of Consent
- Users must be at least the age of majority in their region.
- Underage users need permission from a legal guardian.
✅ Suggestion: State what happens if the business discovers a user is underage without consent (e.g., delete data).
9. Policy Changes
- Users will be notified on the website for significant updates.
- If the business is sold or merged, data will be transferred to the new owners.
✅ Tip: It’s also good to state the date of the last revision at the top or bottom of the page.
📩 Contact Information
If users have questions or want to manage their personal information, they can contact:
✅ Extra Option: Add a mailing address or contact form if you receive requests for data deletion or access under laws like GDPR or CCPA.
✅ Final Recommendations
To ensure full compliance and build customer trust, consider:
Ensuring the policy is written in plain language for better accessibility.
Adding a Cookie Policy or a more detailed Cookie section.
Including a “Your Rights” section (especially for GDPR/CCPA compliance), outlining rights such as access, deletion, rectification, and objection to processing.
Stating the data retention period: how long you keep data and for what purposes.