KAALI~KRAFT
Privacy Policy
Effective Date: 29 April 2026 │ Version 3.0
This Privacy Policy describes how KAALI~KRAFT (“we”, “us”, or “our”) collects, uses, stores, shares, and protects your personal data when you visit kaalikraft.com, register an account, place an order through any of our channels, or otherwise interact with us.
This Privacy Policy is published in accordance with Section 4 of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), Section 43A and Section 79 of the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Consumer Protection (E-Commerce) Rules, 2020.
Note: References to legal provisions are provided for compliance context. They are not exhaustive and do not constitute legal advice.
1. Data Fiduciary Details
Relevant Legal Framework: Section 2(i) of the Digital Personal Data Protection Act, 2023.
For the purposes of the DPDP Act, KAALI~KRAFT is a Data Fiduciary in respect of personal data collected from customers.
| Business Name | KAALI~KRAFT |
| Proprietor | Indhumathi Ambati |
| Address | Sachivalayam Road, Chendodu Village, Vidyanagar, Kota Mandal, Nellore District, Andhra Pradesh – 524413 |
| Customer Care | +91 95028 93506 │ +91 94946 14904 |
| kaali.kraft007@gmail.com | |
| Website | https://kaalikraft.com |
2. Personal Data We Collect
Relevant Legal Framework: Section 5 of the Digital Personal Data Protection Act, 2023; Rule 3 of the IT (SPDI) Rules, 2011.
2.1 Data You Provide Directly
- Full name
- Mobile number and WhatsApp contact
- Email address
- Billing and shipping address with PIN code
- Order history, preferences, and feedback
- Allergy or dietary information voluntarily disclosed
- Communications you send to our customer care
2.2 Data Collected Automatically
- IP address, browser type, device type, and operating system
- Pages visited, time spent on the Website, and referrer URL
- Cookies and similar technologies (see our Cookie Policy below)
2.3 Payment Data
Online payments are processed by Razorpay Software Private Limited, a Reserve Bank of India authorised Payment Aggregator. KAALI~KRAFT receives only the transaction reference (UPI reference or Razorpay payment ID) and the payment status (success / failure / refunded). We do NOT collect, store, or process:
- Card numbers, CVV, or expiry dates
- Net banking passwords or PINs
- UPI PINs
- Any other confidential payment credentials
3. Purposes of Processing
Relevant Legal Framework: Section 4 and Section 6 of the Digital Personal Data Protection Act, 2023.
We process your personal data for the following specified, lawful purposes:
- To process and fulfil your Orders, including coordinating delivery with courier partners
- To communicate Order status, dispatch updates, and customer support responses
- To verify identity, prevent fraud, and ensure transaction security
- To comply with applicable accounting, tax (GST), regulatory, and legal obligations
- To respond to grievances and resolve disputes
- To send marketing communications (only with your explicit consent and with the option to opt out)
- To improve our Website, products, and services through aggregated, non-personally-identifiable analytics
4. Lawful Basis for Processing
Relevant Legal Framework: Section 6 (Consent) and Section 7 (Certain Legitimate Uses) of the Digital Personal Data Protection Act, 2023.
We process your personal data based on the following lawful grounds:
- Consent: Where you have provided explicit consent, such as for marketing communications.
- Performance of contract: To fulfil the Order you have placed.
- Legitimate use: For purposes such as compliance with court orders, tax filings, fraud prevention, and other purposes specified under Section 7 of the DPDP Act.
- Legal obligation: Where processing is required by Indian law (for example, retention of GST records under the CGST Act, 2017).
5. Sharing and Disclosure of Data
Relevant Legal Framework: Section 8 of the Digital Personal Data Protection Act, 2023; IT Act, 2000.
5.1 We Share Personal Data With
- Courier and logistics partners (Delhivery, BlueDart, DTDC, India Post, and similar) — strictly limited to delivery-relevant information.
- Payment processors (Razorpay) — for payment transaction processing only.
- Cloud and email service providers — for hosting and communication infrastructure.
- Tax consultants and chartered accountants — for accounting, GST filings, and audit purposes.
- Government authorities — when required by law, court order, regulatory direction, or in response to a lawful request.
5.2 We DO NOT
- Sell your personal data to any third party.
- Rent your personal data to any advertiser or marketer.
- Share your data with third parties for their own marketing purposes without your consent.
6. Data Retention
Relevant Legal Framework: Section 8(7) of the Digital Personal Data Protection Act, 2023; Section 36 of the Central Goods and Services Tax Act, 2017.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:
- Order records and invoices: 8 years from the end of the relevant financial year, as required under the CGST Act, 2017.
- Customer account data: For the duration of your active account plus 3 years thereafter, unless you request deletion.
- Marketing data: Until you withdraw consent or opt out.
- Grievance records: For 3 years from resolution, for legal and audit purposes.
7. Data Security
Relevant Legal Framework: Section 8(5) of the Digital Personal Data Protection Act, 2023; Section 43A of the Information Technology Act, 2000; IT (SPDI) Rules, 2011.
We implement reasonable security practices and procedures to protect your personal data:
- HTTPS / TLS encryption for all data transmitted between your browser and our Website.
- Access controls limiting personal data to authorised personnel only.
- Razorpay handles all payment processing under PCI-DSS Level 1 compliance.
- Regular security updates, malware scanning, and firewall protection on our Website.
- Secure password storage using industry-standard hashing.
Despite our best efforts, no security system is impenetrable. In the event of a personal data breach affecting your data, we will notify you and the Data Protection Board of India in accordance with Section 8(6) of the DPDP Act.
8. Your Rights as a Data Principal
Relevant Legal Framework: Sections 11–14 of the Digital Personal Data Protection Act, 2023.
Subject to applicable law, you have the following rights with respect to your personal data:
- Right to access (Section 11): You may request a summary of your personal data we process.
- Right to correction and erasure (Section 12): You may request correction of inaccurate data, or erasure of personal data that is no longer required.
- Right to grievance redressal (Section 13): You may raise a grievance with our Grievance Officer (details below).
- Right to nominate (Section 14): You may nominate a person to exercise your rights in the event of your death or incapacity.
- Right to withdraw consent: You may withdraw consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, please contact our Grievance Officer using the contact details in Section 12.
9. Children’s Privacy
Relevant Legal Framework: Section 9 of the Digital Personal Data Protection Act, 2023.
Our Website and services are not directed at children below 18 years of age. We do not knowingly collect personal data from minors. If we become aware that personal data of a child has been collected without verifiable parental consent, we will take steps to delete such data promptly.
10. Cookies and Tracking Technologies
Our Website uses cookies and similar tracking technologies for the following purposes:
- Essential cookies: Required for Website functionality (shopping cart, login session, checkout).
- Analytics cookies: To understand how visitors use our Website (anonymised).
- Preference cookies: To remember your settings and preferences.
You can control cookies through your browser settings. Disabling certain cookies may affect Website functionality. We do not currently use third-party advertising cookies.
11. Cross-Border Data Transfer
Relevant Legal Framework: Section 16 of the Digital Personal Data Protection Act, 2023.
Some of our service providers (such as cloud hosting and email infrastructure) may process data on servers located outside India. Such transfers are made only to countries permitted under the DPDP Act, with appropriate contractual safeguards in place.
12. Grievance Officer
Relevant Legal Framework: Section 8(10) of the Digital Personal Data Protection Act, 2023; Rule 3(11) of the IT (Intermediary Guidelines) Rules, 2021.
In compliance with the above provisions, KAALI~KRAFT has designated the following Grievance Officer for handling personal data complaints and other grievances:
| Name | Indhumathi Ambati |
| Designation | Proprietor and Grievance Officer |
| Address | Sachivalayam Road, Chendodu Village, Vidyanagar, Kota Mandal, Nellore District, Andhra Pradesh – 524413 |
| Phone | +91 95028 93506 │ +91 94946 14904 |
| kaali.kraft007@gmail.com | |
| Hours | 10:00 AM – 6:00 PM IST, Monday to Saturday |
| Acknowledgement | Within 48 hours of receipt |
| Resolution Timeline | Within 30 days from receipt of complaint, or such other period as prescribed under applicable law |
If your grievance is not resolved within the prescribed timeline, or if you are dissatisfied with the resolution, you may approach the Data Protection Board of India established under Chapter V of the Digital Personal Data Protection Act, 2023.
13. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The revised Privacy Policy will be posted on the Website with an updated Effective Date.
14. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact our Grievance Officer using the details in Section 12 of this Policy.
Thank you for trusting KAALI~KRAFT with your personal data.
