Effective Date: [Insert Date]
Indishreshtha Private Limited, under the brand “SHAITAAN” (“Company“, “we“, “our“, or “us“), operates an online platform offering the sale of sexual wellness and related products, as described in our https://shaitaan.in/terms-conditions/ (“Terms”).
This Privacy Policy (“Policy“) sets out our practices regarding the collection, use, disclosure, processing, transfer, and retention of your personal data, in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Digital Personal Data Protection Act, 2023 (to the extent applicable), and other applicable Indian laws.
Please read this Policy carefully to understand how we collect, use, handle, and protect your personal information.
- AGE RESTRICTION AND INTENDED USE
- The Platform – shaitaan.in and Services, including all content and products, are intended exclusively for individuals aged 18 years and above. By accessing or using the Platform, you confirm that you are at least 18 years old. We do not knowingly collect personal data from individuals under 18. If you believe a minor has provided us with personal information, please contact us immediately so that we may delete it.
- Disclaimer: The Platform offers products for adult use only. Content is for informational purposes only and should not be construed as medical advice. Please consult a qualified healthcare professional for medical concerns.
- COLLECTION OF PERSONAL DATA
We collect, process, and store the following categories of personal information:
- Contact Information: Name, phone number, email address, postal address.
- Financial and Transactional Data: UPI details, credit/debit card data, payment gateway references, transaction history.
- Technical Data: IP address, device information, browser type, OS, login timestamps, cookies, session data.
- Usage Data: Browsing history, purchase behavior, feedback, clickstream paths, and communication preferences.
We collect data through direct interactions, automated technologies (e.g., cookies), and from third-party service providers.
- LEGAL BASIS & USAGE OF DATA
By using our Platform, you expressly consent to:
- The collection, use, and processing of your personal and sensitive personal data, as necessary to provide Services;
- The sharing and retention of data as described in this Policy;
- Receiving service, transactional, and promotional communications from us.
Where required under applicable law, we rely on your explicit consent, contractual necessity, compliance with legal obligations, or other lawful bases to process your data.
- WITHDRAWAL OF CONSENT & DATA RIGHTS
You may at any time:
- Withdraw consent for processing of your personal or sensitive personal data;
- Request access, correction, update, or deletion of your personal data.
To exercise these rights, please write to our Grievance Officer at the details provided in Section 13.
Note: Withdrawal of consent will not affect the lawfulness of any processing prior to such withdrawal. However, it may result in deactivation of your account or discontinuation of Services.
- SECURITY MEASURES
We implement reasonable security practices and procedures, including administrative, technical, and physical safeguards as mandated under Indian law (including, where applicable, ISO/IEC 27001 standards), to protect your personal data from unauthorized access, loss, misuse, or alteration.
- DISCLOSURE & TRANSFER OF INFORMATION
We may disclose your personal information:
- To third-party service providers, logistics and payment partners, and affiliates strictly for providing Services, under contractual confidentiality obligations;
- In response to valid legal requests by law enforcement or government authorities;
- During any merger, acquisition, restructuring, or business transition, subject to legal safeguards;
- To entities outside India, only where such transfer complies with Indian laws and is subject to adequate data protection safeguards or with your explicit consent.
- DATA RETENTION POLICY
We retain your personal data only for as long as it is necessary for the purposes for which it was collected, including:
- To fulfill our contractual obligations to you;
- To comply with legal and regulatory requirements (including tax, accounting, and compliance obligations);
- For legitimate business purposes, including customer service, dispute resolution, and fraud prevention; or
- Until you withdraw your consent, where applicable.
Retention Period
Unless a longer retention period is required or permitted by law, we will retain your personal data for a maximum of 7 (seven) years from the date of your last interaction with us or termination of your account, whichever is later.
Certain categories of data may be retained for shorter or longer durations based on:
- The nature of the data (e.g., financial, transactional, or sensitive personal data);
- Statutory requirements or regulatory obligations applicable to the Company;
- Ongoing legal proceedings or claims.
Archival Policy
Personal data that is no longer actively used but is retained for compliance, legal, or archival purposes will be:
- Securely archived in encrypted formats;
- Restricted in access to authorized personnel only; and
- Reviewed periodically to assess necessity of continued retention.
Archived data will not be processed for any purpose other than storage, unless mandated by law.
Data Disposal
Upon expiry of the retention or archival period (whichever is longer), we will securely: - Delete the data from our systems;
- Or anonymize it so that it can no longer be associated with an individual;
- Or destroy physical records through certified secure destruction methods.
- DATA HOSTING AND LOCALISATION
All personal data collected by the Company is stored and processed on servers located within India or in jurisdictions that provide equivalent levels of data protection, subject to applicable Indian laws.
In compliance with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and other applicable regulations:
- All sensitive personal data or information (SPDI) including but not limited to sexual wellness preferences, health information, passwords, and financial information, shall be stored and processed only on secure servers physically located within India, or mirrored in India if processed outside the country.
- The Company ensures that such data is subject to robust access controls, encryption standards, and restricted access protocols, in compliance with applicable security standards such as ISO/IEC 27001.
- Any cross-border transfer of such sensitive personal data shall only be undertaken where:
- It is necessary for the performance of lawful contract with the user;
- The user has explicitly consented to such transfer; and
- The recipient country or entity ensures the same level of data protection as under Indian law.
The Company does not sell or rent your personal data to third parties for marketing purposes.
- COOKIES AND TRACKING TECHNOLOGIES
We use cookies and similar technologies to enhance your browsing experience, personalize content, analyze traffic, and deliver tailored recommendations.
You may modify cookie settings in your browser at any time. Disabling cookies may impact some Platform features or functionality.
- YOUR PRIVACY RIGHTS
Subject to applicable laws, you have the right to:
- Access your personal data held by us;
- Request correction, update, or deletion of your data;
- Withdraw consent for processing of personal or sensitive personal data;
- Nominate a representative to act on your behalf in case of incapacity (as per DPDPA 2023);
- Lodge complaints with the Grievance Officer or relevant statutory authority.
- OPT-OUT OPTIONS
To opt out of marketing communications, do-not-disturb preferences, or promotional updates:
- Email support@shaitaan.in from your registered email ID with the subject line: “Opt-Out Request” and include your contact details.
- We will process such requests within a reasonable time in accordance with applicable law.
- POLICY UPDATES
We may periodically update or amend this Policy. All changes will be posted on the Platform with the revised effective date.
Your continued use of the Platform following any such update shall constitute your acceptance of the revised Policy.
- CONTACT US / GRIEVANCE REDRESSAL
For any questions, concerns, or to exercise your rights under this Policy, please contact our Grievance Officer:
- Name: Ganesh Kadam
- Designation: Grievance Officer
- Email: support@shaitaan.in
- Address: 801, Swastik Chambers, Sion Trombay road, Chembur, Mumbai, Maharashtra – 400071
We aim to address all grievances within 30 days, or as required under applicable law.
Effective from 1st July 2025
BY USING THE PLATFORM OR ENGAGING WITH OUR SERVICES, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREED TO THIS PRIVACY POLICY.