Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, protect, and share your personal information.
Last Updated: December 2025SSL Encrypted
Never Sold
Transparent Use
Your Control
1 Information We Collect
We collect different types of information to provide and improve our services to you. The information we collect falls into the following categories:
1.1 Personal Information You Provide
| Data Type | Examples | Purpose |
|---|---|---|
| Identity Information | Full name, username, title, date of birth | Account creation, identity verification |
| Contact Information | Email address, phone number, billing/shipping address | Order fulfillment, communication |
| Professional Information | Company name, job title, profession, GST number | B2B verification, invoicing |
| Financial Information | Payment card details, bank account information | Payment processing (via secure gateways) |
| Transaction Information | Order history, payment records, delivery details | Order management, customer support |
| Communication Data | Support tickets, emails, chat transcripts, feedback | Customer service, quality improvement |
1.2 Information Collected Automatically
Device Information
Device type, operating system, browser type and version, unique device identifiers, mobile network information
Technical Data
IP address, login data, time zone, browser plug-ins, language preferences
Usage Information
Pages visited, products viewed, time spent on pages, search queries, click patterns
Location Data
General location based on IP address, precise location if you grant permission
2 How We Collect Information
We collect information through various methods:
- Direct Interactions: When you create an account, place an order, fill out forms, subscribe to newsletters, contact customer support, or participate in surveys
- Automated Technologies: Through cookies, server logs, pixel tags, and similar tracking technologies as you navigate our Platform
- Third-Party Sources: From business partners, payment processors, analytics providers, advertising networks, and public databases
- Social Media: If you connect your social media accounts or interact with our social media pages
3 How We Use Your Information
We use your personal information for the following purposes:
3.1 Service Delivery
- Process and fulfill your orders, including shipping and delivery
- Manage your account and provide customer support
- Send order confirmations, shipping updates, and delivery notifications
- Process payments and prevent fraudulent transactions
- Provide product recommendations based on your preferences
3.2 Communication
- Respond to your inquiries and support requests
- Send important updates about your account or our services
- Notify you about changes to our terms, policies, or services
- Send promotional communications (with your consent)
- Conduct surveys and request feedback
3.3 Platform Improvement
- Analyze usage patterns to improve our website and services
- Develop new products, features, and functionality
- Personalize your experience and content recommendations
- Conduct research and analytics
- Test new features and measure their effectiveness
3.4 Legal and Security
- Comply with legal obligations and regulatory requirements
- Enforce our terms of service and protect our rights
- Detect, prevent, and address fraud, security issues, or technical problems
- Respond to legal requests and prevent harm
Legal Basis: We process your personal data based on: (1) your consent, (2) contractual necessity for order fulfillment, (3) our legitimate business interests, and (4) compliance with legal obligations.
4 Information Sharing
We do not sell your personal information. We only share your data with third parties in the following circumstances and for legitimate business purposes:
4.1 Service Providers
We share information with trusted third parties who assist us in operating our business:
- Payment Processors: Razorpay, PayU, and other certified payment gateways to process transactions securely
- Shipping Partners: Logistics companies (Delhivery, BlueDart, etc.) to deliver your orders
- Cloud Services: Amazon Web Services, Google Cloud for data storage and processing
- Analytics Providers: Google Analytics, Mixpanel for website analytics and insights
- Communication Services: Email and SMS providers for transactional communications
- Customer Support: Helpdesk and CRM platforms to manage customer inquiries
4.2 Brand Partners
We may share necessary information with our Brand Partners to:
- Fulfill orders that are shipped directly by manufacturers
- Process warranty claims and product support requests
- Coordinate returns and replacements
4.3 Legal Requirements
We may disclose your information when required to:
- Comply with applicable laws, regulations, or legal processes
- Respond to lawful requests from government authorities
- Protect our rights, property, or safety, or that of our users or others
- Investigate potential violations of our terms of service
4.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal information may be transferred to the acquiring entity. We will notify you of any such change and any choices you may have.
5 Data Security
We implement comprehensive security measures to protect your personal information:
SSL/TLS Encryption
All data transmitted between your browser and our servers is encrypted using industry-standard SSL/TLS protocols
PCI-DSS Compliance
Payment processing through certified gateways that meet Payment Card Industry Data Security Standards
Secure Storage
Data stored in encrypted databases with access controls and regular security audits
Access Controls
Strict access controls ensuring only authorized personnel can access personal data
Security Monitoring
Continuous monitoring for suspicious activity and regular vulnerability assessments
Employee Training
Regular training for employees on data protection and security best practices
While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we continuously work to protect your data.
6 Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience on our Platform:
6.1 Types of Cookies We Use
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential Cookies | Required for basic site functionality, login sessions, shopping cart | Session / 30 days |
| Functional Cookies | Remember your preferences, language settings, location | 1 year |
| Analytics Cookies | Track site usage, page views, user behavior to improve our services | 2 years |
| Marketing Cookies | Deliver relevant advertisements, measure ad campaign effectiveness | 90 days |
6.2 Managing Cookies
You can control cookies through your browser settings:
- Most browsers allow you to refuse or accept cookies
- You can delete cookies that have already been stored
- You can set your browser to notify you when you receive cookies
- Note: Disabling essential cookies may affect site functionality
7 Your Rights as a Data Principal
Under the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable laws, you have the following rights as a Data Principal regarding your personal data:
Right to Access
Request a summary of your personal data being processed, the processing activities undertaken, and details of any data sharing
Right to Correction
Request correction of inaccurate, incomplete, or misleading personal data, and update outdated information
Right to Erasure
Request deletion of your personal data when it is no longer necessary for the purpose it was collected (subject to legal retention requirements)
Right to Nominate
Nominate another individual to exercise your rights on your behalf in the event of your death or incapacity, as per DPDPA provisions
Right to Portability
Receive your personal data in a structured, commonly used, machine-readable format
Right to Opt-Out
Unsubscribe from marketing communications at any time via email preferences or account settings
Right to Grievance Redressal
File a complaint with our Grievance Officer or escalate to the Data Protection Board of India
Right to Withdraw Consent
Withdraw your consent at any time with the same ease as it was given, subject to legal requirements
DPDPA Compliance: As a Data Fiduciary under the Digital Personal Data Protection Act, 2023, we process your personal data only for lawful purposes with your consent or as permitted by law. You may withdraw consent at any time through your account settings or by contacting us.
To exercise any of these rights, please contact us at hello@econstru.com. We will acknowledge your request within 48 hours and respond within 30 days. Identity verification may be required before processing your request.
8 Data Retention
We retain your personal information for as long as necessary to fulfill the purposes for which it was collected:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account Information | Until account deletion + 90 days | Account management, fraud prevention |
| Transaction Records | 7 years | Tax compliance, legal requirements (GST, Income Tax) |
| Communication Records | 3 years | Customer support, dispute resolution |
| Analytics Data | 26 months | Business analytics, service improvement |
| Marketing Preferences | Until consent withdrawn | Respect your communication preferences |
After the retention period expires, we will securely delete or anonymize your personal data. You can request early deletion of your account data, subject to legal retention requirements.
9 Third-Party Links
Our Platform may contain links to third-party websites, applications, or services that are not operated by us. These include:
- Brand partner websites for additional product information
- Social media platforms (Facebook, Instagram, LinkedIn)
- Payment gateway portals
- External review and rating platforms
We are not responsible for the privacy practices of these third-party sites. We encourage you to review the privacy policies of any third-party sites you visit. This Privacy Policy applies only to information collected through our Platform.
10 Children's Privacy
Our Platform is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18 years of age.
If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at hello@econstru.com. If we discover that we have collected personal information from a child under 18, we will take steps to delete that information promptly.
11 International Data Transfers
Your personal information may be transferred to and processed in countries other than India where our service providers operate. These countries may have different data protection laws than India.
When we transfer your data internationally, we ensure appropriate safeguards are in place:
- Contractual clauses with service providers to ensure data protection
- Ensuring recipients are certified under recognized privacy frameworks
- Implementing technical and organizational security measures
12 Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes:
- We will update the "Last Updated" date at the top of this policy
- We will notify you via email or prominent notice on our Platform
- For significant changes, we may seek your consent where required by law
We encourage you to periodically review this Privacy Policy to stay informed about how we protect your information. Your continued use of our Platform after changes constitutes acceptance of the updated policy.
13 Data Fiduciary & Grievance Officer
In accordance with the Digital Personal Data Protection Act, 2023 (DPDPA) and the Information Technology Act, 2000, Atala Procure Pvt Ltd acts as a Data Fiduciary responsible for the processing of your personal data. We have appointed a Grievance Officer to address any concerns or complaints:
Contact Our Grievance Officer
Our Obligations as Data Fiduciary
As a Data Fiduciary under DPDPA 2023, we are committed to:
- Lawful Processing: Processing your personal data only for legitimate purposes with valid consent or as permitted by law
- Purpose Limitation: Using your data only for the specific purposes communicated to you at the time of collection
- Data Minimization: Collecting only the personal data that is necessary for the stated purposes
- Accuracy: Ensuring that personal data is accurate, complete, and kept up-to-date
- Security: Implementing appropriate technical and organizational measures to protect your data
- Accountability: Maintaining records of processing activities and demonstrating compliance
Grievance Redressal Process
We will acknowledge your complaint within 48 hours and endeavor to resolve it within 30 days. If you are not satisfied with our response, you have the right to file a complaint with the Data Protection Board of India as established under the DPDPA 2023.
Privacy Questions?
Our team is here to address any concerns about your personal data.