Complimentary Express Shipping on orders above ₹999 · Easy 15–30 Day Returns
Shinacart.

Privacy Policy

Last Updated: August 2026 · Official Policy Document

Document Type: Legal & Regulatory Disclosure

Brand & Website: Shinacart (shinacart.shop)

Data Fiduciary: Shinacart Ecommerce & Tech Private Limited (CIN: U47912UW2026PTC250123)

Governing Laws: Digital Personal Data Protection Act 2023 (DPDP Act), Information Technology Act 2000 & IT Sensitive Personal Data Rules 2011

Grievance Contact: shinecartecommerceandtech@gmail.com

1. Data Fiduciary Identity

The data fiduciary responsible for all personal data collected on shinacart.shop is Shinacart Ecommerce & Tech Private Limited, having its registered office at:

A 67, Sector 2, Noida, Gautam Buddha Nagar, Uttar Pradesh — 201301, India.

2. Personal Data We Collect

CategoryInformation CollectedPurpose & Storage Method
Account InformationFull Name, Email Address, Salted Hashed Password, Phone Number, Saved Delivery Addresses.Account management & order processing. Passwords encrypted with one-way hashing & salt.
Order & Transaction DataBilling/Shipping Name, Address, Phone, Items Purchased, Variant/Shade, Prices, Discount Codes, Payment Method Type.Order fulfilment, GST compliance, invoice generation. Full card/CVV details are never stored by us.
Technical & Device DataIP Address, Browser Type, Operating System, Referring URL, Page View Duration, Clickstream Paths.System diagnostics, security logging, aggregate performance analytics.
Cookies & Local StorageSession Tokens, Cart State, Analytics Cookies (anonymised).Keep sessions active, retain cart items. Users can manage cookies in browser settings.

3. Purposes of Data Processing

We process your personal data exclusively to:

  1. Process, pack, ship, and deliver your orders.
  2. Send transactional notifications (order confirmation, tax invoice, shipping tracking, return receipts).
  3. Send promotional updates, sale alerts, or product recommendations via Email/SMS (only if explicit opt-in consent is given).
  4. Prevent fraudulent transactions, security breaches, and platform abuse.
  5. Comply with statutory tax and accounting mandates (e.g., GST invoice retention).
  6. Resolve consumer complaints under the Consumer Protection (E-Commerce) Rules 2020.

4. Lawful Basis for Processing (DPDP Act 2023)

  • Performance of Contract: Necessary to deliver ordered goods and service your account.
  • Consent: Required for marketing communications and non-essential analytics (consent can be withdrawn at any time).
  • Legitimate Uses & Compliance: Statutory obligations under Companies Act 2013, GST laws, IT Act 2000, and fraud prevention.

5. Third-Party Data Sharing & Processors

We do not sell your personal data to third parties. Data is shared strictly on a need-to-know basis with authorised service providers:

  • Payment Gateway (Razorpay): Transaction amounts and reference tokens. Payments are processed on PCI-DSS Level 1 certified infrastructure.
  • Logistics Partners (Delhivery, Bluedart, India Post): Name, delivery address, PIN code, and phone number for shipping execution.
  • Statutory Authorities: Disclosed only when mandated by court orders, law enforcement, or statutory tax audits under Indian law.

6. Data Retention Schedule

  • Order Records & Invoices: Retained for 7 years to satisfy GST and statutory corporate audit requirements.
  • Account Profiles: Retained while active. Upon account deletion request, marketing data is purged within 30 days.
  • Marketing Consent: Retained until opt-out; communications cease within 5 business days of unsubscription.

7. Your Statutory Rights under DPDP Act 2023

You hold the following rights regarding your personal data:

  • Right to Access: Obtain a summary of personal data held and processing activities.
  • Right to Correction & Erasure: Correct inaccurate data or request deletion (subject to statutory retention laws).
  • Right to Withdraw Consent: Opt-out of marketing communications at any time.
  • Right of Grievance Redressal: Submit data complaints to our Grievance contact.
  • Right to Nominate: Designate an individual to exercise data rights in event of incapacity.

To exercise these rights, email shinecartecommerceandtech@gmail.com.

8. Security Measures & Encryption

  • Data in Transit: Enforced TLS 1.2+ / HTTPS encryption across all web pages.
  • Data at Rest: Sensitive database fields encrypted with AES-256 encryption.
  • Breach Notification: In the event of a personal data breach impacting your rights, notification will be sent to impacted users and the Data Protection Board of India in accordance with DPDP regulations.

9. Grievance Contact Details

In compliance with Rule 5(9) of the IT Rules 2011 and Section 10 of the DPDP Act 2023, queries or complaints regarding data privacy may be directed to:

Email: shinecartecommerceandtech@gmail.com

Response Address: Shinacart Ecommerce & Tech Private Limited, A 67, Sector 2, Noida, Gautam Buddha Nagar, Uttar Pradesh — 201301, India

Grievances are acknowledged within 48 hours and resolved within 30 days.

Corporate Entity & Operator Details

Company Name: Shinacart Ecommerce & Tech Private Limited

Brand Name: Shinacart

Corporate Identification No (CIN): U47912UW2026PTC250123

GSTIN: To be updated

Registered Office Address: A 67, Sector 2, Noida, Gautam Buddha Nagar, Uttar Pradesh — 201301

Customer Support Email: shinecartecommerceandtech@gmail.com