Privacy Policy

Your privacy matters to us. Learn how we protect and handle your personal information.

Last Updated: January 8, 2025

At DateBox, accessible from https://datebox.in, we are committed to protecting your privacy and ensuring that your personal data is handled responsibly and transparently. This Privacy Policy outlines how we collect, use, store, share, and protect the personal information you provide when you use our website or interact with our brand.

This policy is compliant with applicable Indian data protection laws and international best practices.

1. Who We Are

DateBox is an Indian-based brand that curates intimate experience boxes and sensual products for couples. Our goal is to enhance romantic relationships through carefully selected items that encourage connection and playful intimacy.

Registered Office

India (Full address available upon request)

Data Controller

DateBox Team - support@datebox.in

2. What Information We Collect

We collect both personal and non-personal information when you interact with us through our website or related services.

a. Personal Information

When you place an order, register on our site, fill out a form, or communicate with us, we may collect personal details such as:

Full name and contact details
Email address and phone number
Shipping and billing addresses
Order history and preferences
Account credentials (encrypted)
Communication preferences and consent records

Legal Basis: We process this information based on contract performance, legitimate interests, and your consent where required.

b. Payment Information

We use trusted third-party payment gateways (such as Razorpay) to handle transactions. While you may enter card or UPI details at checkout, we do not store or access your complete payment credentials.

What we store:
  • Transaction IDs
  • Payment status
  • Last 4 digits of card (masked)
What we don't store:
  • Complete card numbers
  • CVV codes
  • Banking passwords

c. Technical and Usage Data

When you browse our website, certain data is automatically collected through cookies and tracking technologies:

IP address and location data
Browser type, version, and language
Device information and screen resolution
Time spent on pages and click patterns
Referring URLs and search terms
Session recordings (anonymized)

Analytics Tools: We may use Google Analytics, Hotjar, or similar tools to understand user behavior and improve our services. You can opt out of these through your browser settings or our cookie preferences.

d. Communication and Support Data

When you contact us through various channels, we collect:

Email correspondence and chat logs
Phone call records (with consent)
Support ticket details and attachments
Feedback and survey responses
Social media interactions
WhatsApp messages (if you contact us there)

3. How We Use Your Information

The information we collect helps us provide you with a seamless, safe, and personalized shopping experience. We process your data for the following purposes:

Primary Business Operations

1
Order processing and fulfillment
2
Payment processing and invoicing
3
Customer service and support
4
Account management and authentication
5
Shipping and delivery coordination
6
Return and refund processing

Business Improvement & Marketing

1
Product recommendations and personalization
2
Website optimization and user experience improvement
3
Marketing communications (with consent)
4
Analytics and business intelligence
5
Fraud prevention and security monitoring
6
Legal compliance and regulatory reporting

Our Commitment: We only use your information for legitimate business purposes and with appropriate legal basis. You can withdraw consent for marketing communications at any time.

4. Sharing and Disclosure of Information

πŸ”’ Your Trust Matters

We value your trust and never sell your personal data. We only share information with trusted partners for specific business purposes:

πŸ’³

Payment Processing Partners

Razorpay, PayPal, and other PCI-compliant payment providers for secure transaction processing.

Data Shared:

Transaction details, billing information

Safeguards:

PCI DSS compliance, encryption, contractual obligations

πŸ“¦

Logistics and Shipping Partners

Shiprocket, Blue Dart, and courier services for order delivery and tracking.

Data Shared:

Name, address, phone number, order details

Safeguards:

Data processing agreements, limited access, purpose limitation

βš™οΈ

Technology Service Providers

Cloud hosting, analytics, customer support, and security services.

Data Shared:

Technical data, usage analytics, support interactions

Safeguards:

Data protection agreements, anonymization where possible

βš–οΈ

Legal and Regulatory Authorities

Government agencies when required by law or to protect our rights and safety.

Data Shared:

Information relevant to legal proceedings or compliance

Safeguards:

Limited to legal requirements, judicial oversight

Protection Guarantee: All third parties are contractually bound to protect your data and use it only for agreed purposes. We regularly audit our partners' compliance.

5. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your browsing experience, analyze website traffic, and provide personalized content.

Essential Cookies

Required for website functionality

Examples: Session management, security, shopping cart

Control: Cannot be disabled

Analytics Cookies

Help us understand user behavior

Examples: Google Analytics, page views, user flow

Control: Can be opted out

Marketing Cookies

Used for advertising and personalization

Examples: Social media pixels, retargeting ads

Control: Requires explicit consent

Managing Your Cookie Preferences

  • β€’ Use our cookie banner to accept or decline non-essential cookies
  • β€’ Adjust browser settings to block or delete cookies
  • β€’ Visit our Cookie Settings page to modify preferences anytime
  • β€’ Use browser extensions or privacy tools for additional control

6. Data Retention

We retain your data only as long as necessary for the purposes outlined in this policy or as required by law.

Account Data

Duration: Active account + 3 years after closure

Reason: Customer service, legal compliance

Order Records

Duration: 7 years from purchase

Reason: Tax compliance, warranty support

Payment Data

Duration: As per payment provider policies

Reason: Fraud prevention, chargebacks

Marketing Data

Duration: Until consent withdrawal

Reason: Marketing communications

Analytics Data

Duration: 26 months maximum

Reason: Business insights, anonymized

Support Tickets

Duration: 3 years from resolution

Reason: Quality improvement, patterns

Automated Deletion: We have automated systems in place to delete data when retention periods expire, unless legal obligations require longer retention.

7. How We Protect Your Data

We implement comprehensive security measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction.

Technical Safeguards

  • β€’ SSL/TLS encryption for data transmission
  • β€’ AES-256 encryption for data at rest
  • β€’ Regular security audits and penetration testing
  • β€’ Secure cloud infrastructure with AWS/Google Cloud
  • β€’ Multi-factor authentication for admin access
  • β€’ Automated backup and disaster recovery

Organizational Measures

  • β€’ Privacy training for all staff members
  • β€’ Access controls and need-to-know basis
  • β€’ Regular policy updates and compliance reviews
  • β€’ Incident response and breach notification procedures
  • β€’ Third-party security assessments
  • β€’ Data protection impact assessments

Important: While we implement industry-standard security measures, no system is 100% secure. Please keep your login credentials confidential and report any suspicious activity immediately.

8. Your Rights and Choices

Under applicable data protection laws, you have the following rights regarding your personal information:

πŸ‘οΈ

Right to Access

Request a copy of all personal data we hold about you

Response time: Within 30 days

✏️

Right to Rectification

Correct or update inaccurate or incomplete information

Response time: Immediately upon request

πŸ—‘οΈ

Right to Erasure

Request deletion of your data (subject to legal exceptions)

Response time: Within 30 days

⏸️

Right to Restrict Processing

Limit how we process your data in certain circumstances

Response time: Immediately upon valid request

πŸ“

Right to Data Portability

Receive your data in a structured, machine-readable format

Response time: Within 30 days

βœ‹

Right to Object

Object to processing based on legitimate interests or for marketing

Response time: Immediately for marketing

πŸ€–

Rights Related to Automated Decision-Making

Object to purely automated processing that affects you

Response time: Upon request

πŸ“§

Right to Withdraw Consent

Withdraw consent for marketing or optional data processing

Response time: Immediate effect

How to Exercise Your Rights: Contact us at privacy@datebox.in with your request. We may need to verify your identity before processing requests.

9. Third-Party Services and Links

Our website may contain links to third-party websites, plugins, or services. We also integrate with various external services to provide you with better functionality.

Integrated Services

Payment Gateways

Razorpay, PayPal

Their privacy policies apply to payment data

Analytics

Google Analytics

Subject to Google's privacy policy

Customer Support

Chatbot, Help desk

Conversation data processed by third parties

Social Media

Instagram, Facebook widgets

Subject to respective platform policies

External Links

Our website may contain links to:

  • Partner websites and affiliate links
  • Social media profiles and content
  • Review platforms and testimonials
  • Educational resources and blog posts
  • Third-party tools and applications

We are not responsible for the privacy practices of external websites. Please review their privacy policies before sharing personal information.

Important: When you click on external links or use third-party services, you are subject to their terms and privacy policies. We encourage you to read them carefully.

10. Children's Privacy

21+

Age Restriction Policy

DateBox is exclusively intended for adults aged 21 and above. We do not knowingly collect, use, or share personal information from individuals under 21 years of age.

Our Commitments:
  • Age verification during registration
  • Immediate deletion of underage user data
  • Monitoring and content filtering
If You're a Parent:
  • Contact us if you suspect underage use
  • We'll investigate and remove accounts
  • Consider parental control software

Report Underage Users: If you believe someone under 21 has created an account or provided personal data, please contact us immediately at privacy@datebox.in.

11. International Data Transfers

While DateBox is based in India, some of our service providers may store or process your data in other countries. We ensure appropriate safeguards are in place for any international transfers.

Countries Where Data May Be Processed

  • β€’ India (Primary location)
  • β€’ United States (Cloud services)
  • β€’ European Union (Analytics services)
  • β€’ Singapore (Payment processing)

Transfer Safeguards

  • β€’ Standard Contractual Clauses
  • β€’ Adequacy decisions recognition
  • β€’ Certification schemes compliance
  • β€’ Approved codes of conduct

Your Rights: You have the right to request information about the safeguards we have in place for international transfers and to object to transfers in certain circumstances.

12. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or business operations.

How We Notify You

  • β€’ Email notification for significant changes
  • β€’ Website banner for 30 days
  • β€’ In-app notifications
  • β€’ Social media announcements

Types of Changes

  • β€’ New data collection practices
  • β€’ Changes in data sharing
  • β€’ Updated legal requirements
  • β€’ Modified retention periods

Version Control: This policy is version 2.1, last updated January 8, 2025. Previous versions are archived and available upon request. Continued use after changes indicates acceptance.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us through any of the following channels:

Privacy Officer

privacy@datebox.in

Customer Support

support@datebox.in

Website

datebox.in

Response Time

Within 48 hours

Data Protection Authority

If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction. In India, you may contact the appropriate authorities under the Digital Personal Data Protection Act.

Your Privacy is Protected

SSL Encrypted

All data transmission secured with industry-standard encryption

Secure Storage

Personal information stored in protected, compliant databases

Your Rights

Complete control over your data with easy access and deletion

Global Standards

Compliance with international privacy laws and best practices