Privacy Policy
Your privacy matters to us. Learn how we protect and handle your personal information.
Table of Contents
At DateBox, accessible from https://datebox.in, we are committed to protecting your privacy and ensuring that your personal data is handled responsibly and transparently. This Privacy Policy outlines how we collect, use, store, share, and protect the personal information you provide when you use our website or interact with our brand.
1. Who We Are
DateBox is an Indian-based brand that curates intimate experience boxes and sensual products for couples. Our goal is to enhance romantic relationships through carefully selected items that encourage connection and playful intimacy.
Registered Office
India (Full address available upon request)
Data Controller
DateBox Team - support@datebox.in
2. What Information We Collect
We collect both personal and non-personal information when you interact with us through our website or related services.
a. Personal Information
When you place an order, register on our site, fill out a form, or communicate with us, we may collect personal details such as:
Legal Basis: We process this information based on contract performance, legitimate interests, and your consent where required.
b. Payment Information
We use trusted third-party payment gateways (such as Razorpay) to handle transactions. While you may enter card or UPI details at checkout, we do not store or access your complete payment credentials.
- Transaction IDs
- Payment status
- Last 4 digits of card (masked)
- Complete card numbers
- CVV codes
- Banking passwords
c. Technical and Usage Data
When you browse our website, certain data is automatically collected through cookies and tracking technologies:
Analytics Tools: We may use Google Analytics, Hotjar, or similar tools to understand user behavior and improve our services. You can opt out of these through your browser settings or our cookie preferences.
d. Communication and Support Data
When you contact us through various channels, we collect:
3. How We Use Your Information
The information we collect helps us provide you with a seamless, safe, and personalized shopping experience. We process your data for the following purposes:
Primary Business Operations
Business Improvement & Marketing
Our Commitment: We only use your information for legitimate business purposes and with appropriate legal basis. You can withdraw consent for marketing communications at any time.
4. Sharing and Disclosure of Information
π Your Trust Matters
We value your trust and never sell your personal data. We only share information with trusted partners for specific business purposes:
Payment Processing Partners
Razorpay, PayPal, and other PCI-compliant payment providers for secure transaction processing.
Transaction details, billing information
PCI DSS compliance, encryption, contractual obligations
Logistics and Shipping Partners
Shiprocket, Blue Dart, and courier services for order delivery and tracking.
Name, address, phone number, order details
Data processing agreements, limited access, purpose limitation
Technology Service Providers
Cloud hosting, analytics, customer support, and security services.
Technical data, usage analytics, support interactions
Data protection agreements, anonymization where possible
Legal and Regulatory Authorities
Government agencies when required by law or to protect our rights and safety.
Information relevant to legal proceedings or compliance
Limited to legal requirements, judicial oversight
Protection Guarantee: All third parties are contractually bound to protect your data and use it only for agreed purposes. We regularly audit our partners' compliance.
6. Data Retention
We retain your data only as long as necessary for the purposes outlined in this policy or as required by law.
Account Data
Duration: Active account + 3 years after closure
Reason: Customer service, legal compliance
Order Records
Duration: 7 years from purchase
Reason: Tax compliance, warranty support
Payment Data
Duration: As per payment provider policies
Reason: Fraud prevention, chargebacks
Marketing Data
Duration: Until consent withdrawal
Reason: Marketing communications
Analytics Data
Duration: 26 months maximum
Reason: Business insights, anonymized
Support Tickets
Duration: 3 years from resolution
Reason: Quality improvement, patterns
Automated Deletion: We have automated systems in place to delete data when retention periods expire, unless legal obligations require longer retention.
7. How We Protect Your Data
We implement comprehensive security measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction.
Technical Safeguards
- β’ SSL/TLS encryption for data transmission
- β’ AES-256 encryption for data at rest
- β’ Regular security audits and penetration testing
- β’ Secure cloud infrastructure with AWS/Google Cloud
- β’ Multi-factor authentication for admin access
- β’ Automated backup and disaster recovery
Organizational Measures
- β’ Privacy training for all staff members
- β’ Access controls and need-to-know basis
- β’ Regular policy updates and compliance reviews
- β’ Incident response and breach notification procedures
- β’ Third-party security assessments
- β’ Data protection impact assessments
Important: While we implement industry-standard security measures, no system is 100% secure. Please keep your login credentials confidential and report any suspicious activity immediately.
8. Your Rights and Choices
Under applicable data protection laws, you have the following rights regarding your personal information:
Right to Access
Request a copy of all personal data we hold about you
Response time: Within 30 days
Right to Rectification
Correct or update inaccurate or incomplete information
Response time: Immediately upon request
Right to Erasure
Request deletion of your data (subject to legal exceptions)
Response time: Within 30 days
Right to Restrict Processing
Limit how we process your data in certain circumstances
Response time: Immediately upon valid request
Right to Data Portability
Receive your data in a structured, machine-readable format
Response time: Within 30 days
Right to Object
Object to processing based on legitimate interests or for marketing
Response time: Immediately for marketing
Rights Related to Automated Decision-Making
Object to purely automated processing that affects you
Response time: Upon request
Right to Withdraw Consent
Withdraw consent for marketing or optional data processing
Response time: Immediate effect
How to Exercise Your Rights: Contact us at privacy@datebox.in with your request. We may need to verify your identity before processing requests.
9. Third-Party Services and Links
Our website may contain links to third-party websites, plugins, or services. We also integrate with various external services to provide you with better functionality.
Integrated Services
Payment Gateways
Razorpay, PayPal
Their privacy policies apply to payment data
Analytics
Google Analytics
Subject to Google's privacy policy
Customer Support
Chatbot, Help desk
Conversation data processed by third parties
Social Media
Instagram, Facebook widgets
Subject to respective platform policies
External Links
Our website may contain links to:
- Partner websites and affiliate links
- Social media profiles and content
- Review platforms and testimonials
- Educational resources and blog posts
- Third-party tools and applications
We are not responsible for the privacy practices of external websites. Please review their privacy policies before sharing personal information.
Important: When you click on external links or use third-party services, you are subject to their terms and privacy policies. We encourage you to read them carefully.
10. Children's Privacy
Age Restriction Policy
DateBox is exclusively intended for adults aged 21 and above. We do not knowingly collect, use, or share personal information from individuals under 21 years of age.
- Age verification during registration
- Immediate deletion of underage user data
- Monitoring and content filtering
- Contact us if you suspect underage use
- We'll investigate and remove accounts
- Consider parental control software
Report Underage Users: If you believe someone under 21 has created an account or provided personal data, please contact us immediately at privacy@datebox.in.
11. International Data Transfers
While DateBox is based in India, some of our service providers may store or process your data in other countries. We ensure appropriate safeguards are in place for any international transfers.
Countries Where Data May Be Processed
- β’ India (Primary location)
- β’ United States (Cloud services)
- β’ European Union (Analytics services)
- β’ Singapore (Payment processing)
Transfer Safeguards
- β’ Standard Contractual Clauses
- β’ Adequacy decisions recognition
- β’ Certification schemes compliance
- β’ Approved codes of conduct
Your Rights: You have the right to request information about the safeguards we have in place for international transfers and to object to transfers in certain circumstances.
12. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or business operations.
How We Notify You
- β’ Email notification for significant changes
- β’ Website banner for 30 days
- β’ In-app notifications
- β’ Social media announcements
Types of Changes
- β’ New data collection practices
- β’ Changes in data sharing
- β’ Updated legal requirements
- β’ Modified retention periods
Version Control: This policy is version 2.1, last updated January 8, 2025. Previous versions are archived and available upon request. Continued use after changes indicates acceptance.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us through any of the following channels:
Privacy Officer
privacy@datebox.inCustomer Support
support@datebox.inWebsite
datebox.inResponse Time
Within 48 hours
Data Protection Authority
If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction. In India, you may contact the appropriate authorities under the Digital Personal Data Protection Act.
Your Privacy is Protected
SSL Encrypted
All data transmission secured with industry-standard encryption
Secure Storage
Personal information stored in protected, compliant databases
Your Rights
Complete control over your data with easy access and deletion
Global Standards
Compliance with international privacy laws and best practices