How D.G. Ayurvedic Sangrah collects, uses, shares and protects your personal data, and the rights you have over it under the Digital Personal Data Protection Act 2023. Last updated August 2026.

1. Who is responsible for your data

D.G. Ayurvedic Sangrah is the Data Fiduciary for the personal data collected through dgayurvedic.com. That means we decide what data is collected and why, and we are accountable for it.

Store D.G. Ayurvedic Sangrah

Website dgayurvedic.com

Address Shop No. 142/A, J. P. Road, behind Ram Mandir, Fish Market Area, Navneet Colony, Andheri West, Mumbai, Maharashtra 400058, India

Customer care contact@dgayurvedic.com · +91 99753 31313

2. What we collect

Data When
Name, email address, phone number When you create an account, place an order, or contact us
Billing and delivery address At checkout, and stored on your account for reuse
Order history: what you bought, when, for how much, delivery status Every order
Account password Stored only as a salted cryptographic hash. We cannot read it.
Payment reference, method and status Returned to us by the payment gateway. See section 4.
IP address, browser and device type, pages viewed Automatically, in server logs, for security and troubleshooting
Product reviews and any message you send us When you submit them

We do not ask for and do not want any health information about you. Please do not send us medical records or diagnoses.

3. Why we use it, and on what basis

  • To fulfil your order — take payment, pack, ship, track, and handle returns. Without this data we cannot sell to you.
  • To run your account — log you in, show your order history, save your addresses.
  • To support you — answer questions, resolve complaints, process refunds.
  • To meet legal obligations — keep invoices, tax and accounting records for the periods Indian law requires.
  • To keep the site secure — detect fraud and abuse, investigate incidents.
  • To send you marketing — only if you have opted in. You can opt out at any time; see section 7.

We rely on your consent, and on the “certain legitimate uses” permitted by section 7 of the Digital Personal Data Protection Act 2023 where you have voluntarily given us data for a purpose you would reasonably expect — such as delivering the order you placed.

4. Payments

Online payments are processed by Razorpay Software Private Limited. Your card number, CVV, UPI PIN and net-banking credentials are entered on Razorpay’s own systems, which are PCI-DSS compliant. We never see them and we never store them. What comes back to us is the payment reference, the amount, the method and whether it succeeded. Razorpay handles that data under its own privacy policy.

5. Who else sees your data

  • Courier and postal partners — your name, delivery address and phone number, so they can deliver the parcel. Which one depends on your location and the shipping mode you chose; the list is in the Shipping Policy.
  • Razorpay — as described above.
  • Our email provider — order confirmations and service messages are sent through Google Workspace.
  • Government authorities — where we are required by law to disclose, or to establish or defend a legal claim.

We do not sell your personal data. We do not share it with advertisers or data brokers. This site does not run advertising trackers or behavioural profiling.

6. Cookies

We use cookies that are necessary for the shop to work — keeping your cart, keeping you signed in, and protecting the checkout. There are no advertising or profiling cookies on this site. You can block or delete cookies in your browser, but the cart and checkout will stop working if you block the necessary ones.

7. Your rights

Under the Digital Personal Data Protection Act 2023 you can:

  • Ask what we hold about you and who we have shared it with (section 11).
  • Have it corrected if it is wrong, incomplete or out of date (section 12).
  • Have it erased when it is no longer needed for the purpose you gave it for, unless we are required by law to keep it (section 12).
  • Withdraw your consent at any time, as easily as you gave it. Withdrawing consent does not undo processing already done, and we may not be able to continue serving you if the data was necessary to do so.
  • Nominate someone to exercise these rights on your behalf if you die or become incapacitated (section 14).
  • Complain to us first, using section 9 below (section 13).

To exercise any of these, email contact@dgayurvedic.com from the address on your account, or write to the Grievance Officer at the address in section 9. We will respond within the timelines in section 9.

To stop marketing email, use the unsubscribe link in any marketing message or tell us at the same address. Order confirmations, dispatch notices and refund notices are not marketing; you will keep receiving those for as long as you have live orders.

8. How long we keep it

  • Order, invoice and tax records — for as long as tax, accounting and company law require us to keep them.
  • Account data — while your account is open. Ask us to close it and we will erase what we are not legally required to keep.
  • Server logs — kept only as long as they are useful for security and troubleshooting, then discarded.
  • Marketing consent records — kept so we can prove you opted in, until you opt out.

9. Complaints and the Grievance Officer

Grievance Officer — see the note below

Email contact@dgayurvedic.com

Phone +91 99753 31313

Post Grievance Officer, D.G. Ayurvedic Sangrah, J.P. Road, Behind Ram Hanuman Mandir, Andheri West, Mumbai 400058, Maharashtra, India

We acknowledge every complaint within 48 hours of receiving it and resolve it within one month, as required by the Consumer Protection (E-Commerce) Rules 2020. Please quote your order number so we can find the order straight away.

If you are not satisfied with how we have handled a complaint, you can escalate it to the National Consumer Helpline on 1915 or through the National Consumer Helpline portal, or file a complaint with the consumer commission that has jurisdiction over you.

If you are still not satisfied after we have responded, you may complain to the Data Protection Board of India in the manner it prescribes.

10. How we protect your data

We do not make vague promises here. Concretely:

  • The site is served over an encrypted connection (HTTPS).
  • Card details never reach us — they are handled entirely by Razorpay.
  • Passwords are stored only as salted hashes.
  • Administrative access to customer records is limited to staff who need it, and the site is hosted on servers we control in India.
  • Databases and uploaded files are backed up nightly on a rotating schedule.

No system is perfectly secure. If a personal data breach occurs, we will intimate the Data Protection Board of India and every affected user, in the form and within the time the Act requires.

11. Children

This shop is not intended for anyone under 18. We do not knowingly collect data from children, and we do not track, profile or advertise to them. If you believe a child has given us personal data, tell the Grievance Officer and we will erase it.

12. Changes to this policy

We will update this page when our practices change, and change the “last updated” date above. Material changes affecting how we use data you have already given us will be notified to you by email.