Privacy Policy
Last Updated: August 2026 · Official Policy Document
Document Type: Legal & Regulatory Disclosure
Brand & Website: Shinacart (shinacart.shop)
Data Fiduciary: Shinacart Ecommerce & Tech Private Limited (CIN: U47912UW2026PTC250123)
Governing Laws: Digital Personal Data Protection Act 2023 (DPDP Act), Information Technology Act 2000 & IT Sensitive Personal Data Rules 2011
Grievance Contact: shinecartecommerceandtech@gmail.com
1. Data Fiduciary Identity
The data fiduciary responsible for all personal data collected on shinacart.shop is Shinacart Ecommerce & Tech Private Limited, having its registered office at:
A 67, Sector 2, Noida, Gautam Buddha Nagar, Uttar Pradesh — 201301, India.
2. Personal Data We Collect
| Category | Information Collected | Purpose & Storage Method |
|---|---|---|
| Account Information | Full Name, Email Address, Salted Hashed Password, Phone Number, Saved Delivery Addresses. | Account management & order processing. Passwords encrypted with one-way hashing & salt. |
| Order & Transaction Data | Billing/Shipping Name, Address, Phone, Items Purchased, Variant/Shade, Prices, Discount Codes, Payment Method Type. | Order fulfilment, GST compliance, invoice generation. Full card/CVV details are never stored by us. |
| Technical & Device Data | IP Address, Browser Type, Operating System, Referring URL, Page View Duration, Clickstream Paths. | System diagnostics, security logging, aggregate performance analytics. |
| Cookies & Local Storage | Session Tokens, Cart State, Analytics Cookies (anonymised). | Keep sessions active, retain cart items. Users can manage cookies in browser settings. |
3. Purposes of Data Processing
We process your personal data exclusively to:
- Process, pack, ship, and deliver your orders.
- Send transactional notifications (order confirmation, tax invoice, shipping tracking, return receipts).
- Send promotional updates, sale alerts, or product recommendations via Email/SMS (only if explicit opt-in consent is given).
- Prevent fraudulent transactions, security breaches, and platform abuse.
- Comply with statutory tax and accounting mandates (e.g., GST invoice retention).
- Resolve consumer complaints under the Consumer Protection (E-Commerce) Rules 2020.
4. Lawful Basis for Processing (DPDP Act 2023)
- Performance of Contract: Necessary to deliver ordered goods and service your account.
- Consent: Required for marketing communications and non-essential analytics (consent can be withdrawn at any time).
- Legitimate Uses & Compliance: Statutory obligations under Companies Act 2013, GST laws, IT Act 2000, and fraud prevention.
5. Third-Party Data Sharing & Processors
We do not sell your personal data to third parties. Data is shared strictly on a need-to-know basis with authorised service providers:
- Payment Gateway (Razorpay): Transaction amounts and reference tokens. Payments are processed on PCI-DSS Level 1 certified infrastructure.
- Logistics Partners (Delhivery, Bluedart, India Post): Name, delivery address, PIN code, and phone number for shipping execution.
- Statutory Authorities: Disclosed only when mandated by court orders, law enforcement, or statutory tax audits under Indian law.
6. Data Retention Schedule
- Order Records & Invoices: Retained for 7 years to satisfy GST and statutory corporate audit requirements.
- Account Profiles: Retained while active. Upon account deletion request, marketing data is purged within 30 days.
- Marketing Consent: Retained until opt-out; communications cease within 5 business days of unsubscription.
7. Your Statutory Rights under DPDP Act 2023
You hold the following rights regarding your personal data:
- Right to Access: Obtain a summary of personal data held and processing activities.
- Right to Correction & Erasure: Correct inaccurate data or request deletion (subject to statutory retention laws).
- Right to Withdraw Consent: Opt-out of marketing communications at any time.
- Right of Grievance Redressal: Submit data complaints to our Grievance contact.
- Right to Nominate: Designate an individual to exercise data rights in event of incapacity.
To exercise these rights, email shinecartecommerceandtech@gmail.com.
8. Security Measures & Encryption
- Data in Transit: Enforced TLS 1.2+ / HTTPS encryption across all web pages.
- Data at Rest: Sensitive database fields encrypted with AES-256 encryption.
- Breach Notification: In the event of a personal data breach impacting your rights, notification will be sent to impacted users and the Data Protection Board of India in accordance with DPDP regulations.
9. Grievance Contact Details
In compliance with Rule 5(9) of the IT Rules 2011 and Section 10 of the DPDP Act 2023, queries or complaints regarding data privacy may be directed to:
Email: shinecartecommerceandtech@gmail.com
Response Address: Shinacart Ecommerce & Tech Private Limited, A 67, Sector 2, Noida, Gautam Buddha Nagar, Uttar Pradesh — 201301, India
Grievances are acknowledged within 48 hours and resolved within 30 days.
Corporate Entity & Operator Details
Company Name: Shinacart Ecommerce & Tech Private Limited
Brand Name: Shinacart
Corporate Identification No (CIN): U47912UW2026PTC250123
GSTIN: To be updated
Registered Office Address: A 67, Sector 2, Noida, Gautam Buddha Nagar, Uttar Pradesh — 201301
Customer Support Email: shinecartecommerceandtech@gmail.com