Legal
Privacy Policy
What we collect, why we collect it, who else sees it, and how to make us delete it.
Last updated 16 September 2026
1.The short version
We collect the minimum needed to take your money legally, get a box to your door, and answer you when you write in. We do not sell your data, we do not run advertising trackers, and we never see your card details.
2.Who is responsible for your data
The Dronacharya is the Data Fiduciary for the personal data described here, within the meaning of the Digital Personal Data Protection Act, 2023. You are the Data Principal. Contact details are at the bottom of this page.
3.What we collect
When you place an order
- Your name, mobile number and email address.
- The delivery address you enter, including PIN code, city and state.
- What you ordered, what you paid, and when.
- Delivery notes you choose to write.
- A payment reference from Razorpay. We never receive your card number, CVV, UPI PIN or net-banking credentials — those go directly to the gateway.
When you create an account
- Your mobile number (for OTP sign-in), or the email address and name from your Google or Apple account if you use those.
- Saved delivery addresses, if you choose to save any.
- A push-notification token per device, if you allow notifications in the app. It identifies the device, not you.
When you write to us
- Your name, email, optional phone number, and whatever you put in the message.
Automatically
- Standard server logs from our hosting provider — IP address, timestamp, page requested, user agent — kept for security and abuse prevention.
- Aggregate analytics about which pages are visited. We do not build advertising profiles and we do not share this with ad networks.
We do not collect location data, contacts, photos, or anything from your device beyond what is listed here.
4.Why we collect it, and on what basis
Under the DPDP Act we process your data on the basis of the consent you give when you place an order or write to us, and — for record-keeping — because the law requires it.
- To fulfil your order. Name, address and phone go to the courier. Email gets you the confirmation, the invoice and the tracking link.
- To take payment. Your name, email, phone and order amount go to Razorpay so the payment can be processed and reconciled.
- To support you. So that when you write in about an order, we can find it.
- To meet legal obligations. Invoice and transaction records must be retained under tax law — see retention, below.
- To keep the site working. Abuse prevention, rate limiting and fraud checks.
5.Who else sees it
We share data only with the processors needed to run the business:
- Google Firebase (Google Cloud India, Mumbai region) — hosting, database, authentication and push notifications. Your order data is stored here, in India.
- Razorpay Software Private Limited — payment processing. They receive your name, email, phone and amount, and they hold the card data we never see.
- Resend — transactional email delivery. Receives your email address and the contents of order emails.
- Our courier partners — receive your name, full delivery address and phone number so they can deliver and call you.
We do not sell, rent or trade your personal data. We do not share it with advertisers or data brokers. We will disclose data if we are legally compelled to by a court or a competent authority, and only to the extent required.
6.Where it is stored
Our database, files and functions run in Google Cloud's asia-south1 region in Mumbai. Your order data does not leave India in the normal course of business. Email delivery and payment processing involve providers who may process data outside India under their own terms.
7.How long we keep it
- Order and invoice records: 8 years. Rule 56 of the CGST Rules, 2017 requires a seller to retain books of account and invoices for 72 months from the due date of the annual return, and the Income-tax Act adds its own retention expectations. This is why we cannot delete your orders on request — see below.
- Account profile and saved addresses: until you delete your account.
- Push notification tokens: until you uninstall the app, turn notifications off, or delete your account.
- Contact messages: 24 months, then deleted.
- Server logs: typically 30–90 days, per our hosting provider's defaults.
8.Your rights
Under the DPDP Act, 2023 you may:
- Ask what personal data we hold about you and get a copy of it.
- Ask us to correct anything that is wrong or out of date.
- Ask us to delete your data, subject to the retention obligations above.
- Withdraw consent for anything we do that relies on it. Withdrawing consent for order processing means we cannot fulfil outstanding orders.
- Nominate someone to exercise these rights on your behalf if you die or become incapacitated.
- Complain to the Data Protection Board of India if you believe we have mishandled your data.
Write to thedronacharyaaa@gmail.com and we will respond within 30 days.
9.Getting your data deleted
There are no accounts on this site — you order over WhatsApp, and nothing is stored about you unless you place an order. To have your data removed, message us on WhatsApp or email thedronacharyaaa@gmail.com. We action deletion requests within 7 days and confirm when it is done.
What is deleted: your WhatsApp conversation with us, your email correspondence, and any delivery address we hold outside an invoice.
What is retained, and why: your past orders and their invoices. We cannot lawfully delete them — a seller is required to keep invoice records for 72 months from the due date of the annual return. What we do instead is sever them from your account: the order is disconnected from your identity and nobody can sign in to reach it. The invoice keeps the name, address and amount that tax law requires an invoice to carry, and nothing more.
10.Security
- Everything is served over HTTPS.
- Database access is governed by security rules that deny by default. Order records cannot be written by any browser or app — only by our server-side functions.
- Payment pages are hosted by Razorpay; card data never reaches our infrastructure.
- Our checkout endpoints are protected by Firebase App Check and are rate limited.
- Administrative access requires a separate, explicitly granted privilege on a specific account.
No system is perfectly secure. If we ever suffer a personal-data breach, we will notify the Data Protection Board and every affected person, as the DPDP Act requires.
11.Cookies and similar technology
We do not use advertising or cross-site tracking cookies. What we do store in your browser is:
- Your cart, in local storage, so it survives a page refresh. It never leaves your device unless you sign in.
- A half-finished checkout form, in session storage, so you do not lose it if you navigate away. It is cleared when you complete an order.
- A sign-in token, if you have an account.
- Cookies set by Firebase App Check and reCAPTCHA to verify that requests come from a real browser rather than a script.
12.Children
This site is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us data, write to us and we will delete it.
13.Changes
If this policy changes materially we will update the date at the top and, where the change affects how we use data you have already given us, tell you by email.
Who you are contracting with
The DronacharyaMumbai, Maharashtra, Indiathedronacharyaaa@gmail.comNot currently registered under GST. All listed prices are final and no tax is charged separately.