Privacy notice
How personal data is handled here under the Digital Personal Data Protection Act 2023 — what is already true of the system, and what still has to be written.
The full privacy notice is not published yet
The itemised notice required by the DPDP Act has not been drafted or versioned. This page sets out its structure and states what is already true of how the software works. Where a section is still a gap, it says so and names the provision that requires it — rather than filling the space with a paragraph nobody has approved.
1. Who holds your data
The Data Fiduciary — the entity that decides why and how your personal data is processed — is the entity that sells on this site.
- Registered name
- Not yet supplied — the legal name of the entity that sells on this site. Required by Consumer Protection (E-Commerce) Rules 2020, rule 4(3).
- Registered address
- Not yet supplied — the principal geographic address of the headquarters, and of every branch and warehouse. Required by Consumer Protection (E-Commerce) Rules 2020, rule 4(3).
- GSTIN
- Not yet supplied — the GST registration number — compulsory for an e-commerce supplier from the first sale, at any turnover. Required by Central Goods and Services Tax Act 2017, s.24; CGST Rules 2017, rule 46.
- FSSAI licence
- Not yet supplied — the FSSAI licence number held by this business as a seller of packaged pet food. Required by Food Safety and Standards Act 2006 — licensing of a food e-commerce business.
The rows marked above are open business dependencies, tracked in the project’s licence register. Nothing is filled in with a placeholder value: a plausible-looking registration number on a public listing is an offence, not a stand-in.
2. Who to ask about it
- Data protection contact
- Not yet supplied — the name of the person able to answer a Data Principal’s questions about the processing of their personal data. Required by Digital Personal Data Protection Act 2023, s.8(9).
- Not yet supplied — an e-mail address that reaches that person. Required by Digital Personal Data Protection Act 2023, s.8(9).
The rows marked above are open business dependencies, tracked in the project’s licence register. Nothing is filled in with a placeholder value: a plausible-looking registration number on a public listing is an offence, not a stand-in.
The Act requires a published contact who can answer a Data Principal’s questions about the processing of their personal data. Until one is named, questions go to consumer care on the contact page.
3. What is collected, and why
To be supplied by the business
The itemised description required by rule 3 of the DPDP Rules 2025: each category of personal data collected, paired with the specific purpose it is processed for. It must be written so that a reader can tell, item by item, what is held about them and why — a general description of “account and order information” does not meet it.
Required by Digital Personal Data Protection Act 2023, s.5; DPDP Rules 2025, rule 3
One design decision is settled and shapes the rest: consent here is asked for per purpose. There is no single “I agree to everything” box anywhere in this product, and there never will be — a bundled consent is not valid consent under the Act. The purposes are separate, and each is separately grantable and separately withdrawable.
- Order and account messages
- Order confirmations, dispatch and delivery updates, refund notices, and anything else about an order you actually placed. This is not marketing and it is asked for separately.
- Marketing by email
- Offers, new products and reminders by email.
- Marketing by SMS
- Offers, new products and reminders by text message.
- Marketing on WhatsApp
- Offers, basket reminders and new products on WhatsApp.
- Marketing by app notification
- Offers and reminders as notifications in the Pawgress app.
- Usage analytics
- Measuring how the store is used, so the shelves and the search can be made better.
4. Consent, and taking it back
This much is the law, not our policy
Withdrawing consent must be as easy as giving it was, and no purpose may be bundled with another. Marketing consent is never a condition of buying anything.
Digital Personal Data Protection Act 2023, s.6(3), s.6(6)
Each choice is recorded with the purpose, whether it was granted or withdrawn, when, and the version of this notice in force at the time. Withdrawal is written as a new record rather than by editing the old one, so the history of what you agreed to and when stays intact. The Privacy Centre is where each purpose is turned on or off.
To be supplied by the business
The notice version identifier and its effective date. This is not decoration: the version string is stored against every consent record, so a notice that is not versioned cannot produce usable evidence that anyone consented to it.
Required by Digital Personal Data Protection Act 2023, s.5; DPDP Rules 2025, rule 3
5. Your rights
The Act gives a Data Principal the right to a summary of the personal data held and how it is processed, the right to have it corrected or completed, the right to have it erased, the right to a grievance route that works, and the right to nominate someone to exercise those rights on their behalf.
Access, export and erasure are built as real endpoints in this system rather than as a support e-mail address, and the Privacy Centre is where they are exercised. That page explains exactly what is and is not available today.
To be supplied by the business
The period within which a data-principal request or a privacy grievance will be answered, and the escalation route if it is not. The Data Fiduciary is required to publish this period, and it is a service commitment the business has to set.
Required by Digital Personal Data Protection Act 2023, ss.11–14
6. How long data is kept, and what erasure does not delete
This much is the law, not our policy
Personal data is erased when consent is withdrawn, except where another law requires it to be retained. Tax law is that other law: invoices and order financial records must be kept for the statutory period, so an erasure minimises the personal data in them rather than destroying the record.
Digital Personal Data Protection Act 2023, s.8(7)
To be supplied by the business
The retention schedule: how long each class of data is kept — account, addresses, pet profiles, order history, support tickets, marketing engagement, analytics — and what happens to each at the end of that period.
Required by Digital Personal Data Protection Act 2023, s.5; DPDP Rules 2025, rule 3
7. Who else processes your data
Running a store means other companies touch some of this data — a payment gateway, a courier, a messaging provider, an e-mail provider. Each is a Data Processor acting on our instructions, and each has to be named.
To be supplied by the business
The list of processors, and for each one the categories of personal data it receives and what it does with them. None of these vendor relationships is in place yet, so naming a specific gateway or courier here would describe an arrangement that does not exist.
Required by Digital Personal Data Protection Act 2023, s.5; DPDP Rules 2025, rule 3
8. Children
The Act treats anyone under eighteen as a child and prohibits tracking, behavioural monitoring and targeted advertising directed at children.
To be supplied by the business
How this business verifies that an account holder is not a child, and how verifiable parental consent would be obtained if a child’s data were ever processed. There is no age check in the sign-up flow today, so no claim is made that one exists.
Required by Digital Personal Data Protection Act 2023, s.9
9. Keeping it safe
One safeguard is absolute and worth stating on its own: there is no card number, CVV or expiry column in our database. Not encrypted, not nullable — absent. Card credentials are held by the payment gateway, so a breach of our systems cannot expose a card.
To be supplied by the business
The statement of reasonable security safeguards required by s.8(5) — encryption, access control, logging, retention of logs, and the measures taken against a personal-data breach — written against the infrastructure as it is actually deployed rather than as intended.
Required by Digital Personal Data Protection Act 2023, s.8(5)
10. If there is a breach
This much is the law, not our policy
A personal-data breach has to be intimated to every affected Data Principal and to the Data Protection Board of India without delay, with a detailed report to the Board following within seventy-two hours. That duty exists whether or not it is written on a page like this one.
Digital Personal Data Protection Act 2023, s.8(6); DPDP Rules 2025, rule 7
11. Complaining
A privacy complaint goes first to the data-protection contact above. If it is not resolved, a Data Principal may complain to the Data Protection Board of India. The consumer-complaint route, which is a separate one, is on the contact page.
12. Changes to this notice
When the notice changes it gets a new version identifier, and that identifier is what gets recorded against any consent given afterwards. Where a change alters what a purpose covers, consent for that purpose has to be asked for again rather than assumed.