Privacy Policy
Effective Date: January 1, 2026 | Last Updated: September 2026
Data Fiduciary: Peethmart Private Limited (CIN: U10619MH2022PTC384592), Nashik, Maharashtra, India.
📜 1. Scope & Commitment
Peethmart Private Limited ("PeethMart", "we", "us", "our") is dedicated to safeguarding your personal data and privacy. This Privacy Policy details how we collect, process, store, and protect digital personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
By accessing peethmart.in, creating an order, or utilizing our services, you acknowledge that you have reviewed and consented to the practices described in this policy.
📋 2. Personal Data We Collect
We strictly limit our data collection to what is necessary for fulfilling your orders, delivering wholesome packaged food products, and complying with statutory fiscal requirements under Indian Law:
| Identity & Contact | Full Name, Mobile Number, Email Address, Delivery / Billing Postal Address, Pin Code. |
|---|---|
| Transaction Details | Order contents, SKU numbers, quantities, delivery timestamps, and payment reference IDs. (Note: We never store raw Credit/Debit card numbers or CVV. Payments are securely tokenized via RBI-authorized payment aggregators). |
| B2B Verification Data | Legal Entity Name, Business Type, GSTIN, FSSAI License Number, Authorized Signatory Contact. |
| Device & Technical | IP address, browser type, operating system, and session tokens utilized solely for cart persistence and fraud prevention. |
🎯 3. Purpose of Processing Your Data
Your digital personal data is processed solely for lawful specified purposes:
- Order Fulfillment: Processing your food orders, packaging, shipping, and enabling real-time shipment tracking.
- Statutory Tax Invoicing: Generating mandatory GST Tax Invoices under Section 31 of the CGST Act, 2017.
- Transactional Communication: Sending essential order confirmations, dispatch notices, delivery alerts, and digital tax receipts via SMS, WhatsApp, and Email.
- Customer Support & Grievance: Addressing consumer queries, refunds, damaged package claims, or delivery coordination.
- Zero Data Brokering: We DO NOT sell, rent, lease, or trade your personal information to third-party data aggregators or advertising networks.
🤝 4. Disclosures & Data Processors
We share data exclusively with trusted Data Processors operating under strict confidentiality and security agreements:
- Logistics & Delivery Partners: Trusted Pan-India courier networks (e.g., Delhivery, BlueDart, DTDC) and local Nashik hyper-local fleet who receive your name, address, and contact number solely to deliver your parcel.
- RBI-Authorized Payment Gateways: Fully PCI-DSS Level 1 compliant payment gateways for seamless UPI, Net Banking, and Card processing.
- Statutory & Regulatory Authorities: When required by lawful process under Indian Law (e.g., GST audit, FSSAI inspection, or court directive).
⚖️ 5. Your Rights as a Data Principal
Under the Digital Personal Data Protection Act, 2023, you enjoy distinct rights:
- Right to Access: You can request a summary of the personal data processed by us and the processing activities undertaken.
- Right to Correction & Erasure: You have the right to request correction of inaccurate or misleading data, and completion of incomplete data. You may request erasure of personal data that is no longer necessary for the purpose it was collected, subject to statutory retention mandates (e.g., GST records).
- Right to Grievance Redressal: You have the right to readily register a grievance with our designated Grievance Officer.
- Right to Nominate: You have the right to nominate any individual who, in the event of death or incapacity, shall exercise your data rights.
🛡️ 6. Data Security & Storage within India
In accordance with Indian sovereignty and regulatory norms, all customer and transaction data is securely hosted on servers adhering to Indian data localization directives. We implement industry-standard 256-bit SSL encryption in transit, strict role-based internal access controls, and periodic security evaluations.
Data Retention: Personal data associated with transactions is retained for the statutory period mandated under the Central Goods and Services Tax Act, 2017 (typically up to 6–8 years for financial audit logs), after which it is securely anonymized or permanently purged.
👮 7. Grievance Redressal & Data Protection Desk
In compliance with Rule 5(9) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the DPDP Act, 2023, the details of our designated Grievance & Data Protection Cell are:
| Grievance Body | PeethMart Consumer Care & Data Protection Cell |
|---|---|
| Official Email | grievance@peethmart.in / care@peethmart.in |
| Operating City | Nashik, Maharashtra, India |
| Resolution Timeline | Acknowledgment within 48 hours; Redressal within 30 days. |