What Data We Collect
- Information that you provide: Your contact details such as customer name, email address, account password, phone number and shipping address.
- Your session log information on our site which includes your navigation within the site, source of traffic, IP address (from which we can approximately determine user location), browser type, browser language, operating system, date and time of request. Such data is primarily collected through Google Analytics and is often anonymized data. We do not do any individual specific profiling. The Google Analytics data is used to improve our website and make more information accessible to you with ease.
- Your previous orders and transactions including the product and pricing details, the date of purchase, payment history and information as might be required to help us trace back your previous orders to address any of your enquiries.
- Email communication by any user or customer directly with us such as product enquiry, order and transaction related information, disputes or complaints etc.
- Information from optional online surveys on our or third party sites such as Facebook which are explicitly posted by us which may include your demographic information (like gender, age, income) as well as product and service preferences.
- Third party sign in information shared on our website such as Facebook, Twitter, Pinterest sign in information
- Your transaction or banking details such as credit card number, cardholder name, expiration date and CVV or other information as required for internet banking or other payment instruments is not held by us but is held by our Payment Gateway partner, PayU Money. Our payment gateway partner is “VeriSign Secured” and “PCI-Compliant”. They attempt to ensure the highest standards of safety and security for your information.
What We Do with the Collected Data
We only collect user or customer information as required to conduct our business and to enable us to provide the best services to our users and customers. We do not sell or rent this information to third parties. User or customer information (as defined above) will be used as described below:
- User and customer information will be sharable with our subsidiaries, affiliates and partners which are also involved in delivering the service to you as a customer in your buying process. We will also need to share some or all of your information as governed in the case of acquisitions by or mergers with other business entities.
- We use some of the user and customer information defined above to understand customer behavior and thus offer better and more relevant experiences to you. We use certain information in an aggregated form across users to compile statistical and demographic profiles for our business and marketing activities.
- We use this information to inform you about offers and deals, new launches, information about products you have purchased, order and shipping status, as well as other promotional and informational content. We will provide you the option to opt-out of such services.
- Cookies would be used to provide a customized experience to our users such as identifying recently viewed items (of interest to the user) as well as implementing wish list and cart features.
- We use session log and traffic flow information to understand how users are interacting with our site and to make improvements. This will also be used by us to understand and analyze customer preferences, buying patterns and behavior at an aggregate level.
- We use IP address, traffic sources, user navigation across the site, browser and OS information etc. to measure overall site performance in terms of number of users, user engagement, time spent by users on the site etc.
- We will need to use user or customer information in case required in aspects such as legal disputes or other legal processes; comply with any statutory or regulatory requirement; troubleshoot problems; detect and protect against error, fraud and other criminal or illegal activity; collect fees owed; enforce our terms and conditions; prevent abuse of our services; prevent violation of the rights of third parties, other users or the general public
- We provide all users with the opportunity to opt-out of receiving non-essential communications from us after setting up an account. We also offer to remove your contact information from our customer database. For any such request please write to us at email@example.com.
- Notwithstanding anything contained in this Policy, Mankastu Impex Private Limited reserves the right to disclose any Personal Information that may be required to be disclosed under laws applicable in India, without prior notice to or consent of the User.
- Mankastu Impex Private Limited cannot guarantee that third parties will keep the Personal Information or Sensitive Personal Information 100% confidential or secure and we will not be liable in any manner for any loss of confidentiality attributable to such third parties.
Data Retention Time
Your data will be stored maximum for 5 years
Rights You Have Over Data Update or Change
a.) Right of Confirmation
You shall have the right granted by the European legislator to obtain the confirmation from us as to whether or not your personal data is being processed. If you wish to avail yourself of this right of confirmation, you may, at any time, establish contact with us for the same.
b.) Right of Access
You shall have the right granted by the European legislator to obtain information about your personal data stored from us at any time and a copy of this information. If you wish to avail himself of this right of access, you may, at any time, establish contact with us for the same.
c.) Right to Rectification
You shall have the right granted by the European legislator to obtain from us the rectification of inaccurate personal data without undue delay concerning yourself. Taking into account the purposes of the processing, you shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
If you wish to exercise this right to rectification, you may, at any time, establish contact with us for the same.
d.) Right to Erasure
You shall have the right granted by the European legislator to obtain from us the erasure of your personal data without undue delay. We have the obligation to erase personal data without undue delay. If you wish to exercise this right to erasure, you may, at any time, establish contact with us for the same.
e.) Right to Restriction of Processing
You shall have the right granted by the European legislator to obtain the restriction of processing from us where one of the following applies:
The accuracy of the personal data is contested by you, for a period enabling the controller to verify the accuracy of the personal data.
The processing is unlawful and you oppose the erasure of the personal data and requests instead the restriction of their use instead.
We no longer need the personal data for the purposes of the processing, but they are required by you for the establishment, exercise or defence of legal claims.
You object to processing pursuant to Article 21(1) of the GDPR pending the verification whether the legitimate grounds put by us override those put by you.
If one of the aforementioned conditions is met, and you wish to request the restriction of the processing of personal data stored by us, you may at any time establish contact with us for the same. We will arrange the restriction of the processing.
f.) Right to data portability
You shall have the right granted by the European legislator, to receive the personal data concerning yourself, which was provided to us, in a structured, commonly used and machine-readable format. You shall have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, as long as the processing is based on consent pursuant to point (a) of Article 6(1) of the GDPR or point (a) of Article 9(2) of the GDPR, or on a contract pursuant to point (b) of Article 6(1) of the GDPR, and the processing is carried out by automated means, as long as the processing is not necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
Furthermore, in exercising his or her right to data portability pursuant to Article 20(1) of the GDPR, the data subject shall have the right to have personal data transmitted directly from one controller to another, where technically feasible and when doing so does not adversely affect the rights and freedoms of others.
In order to assert the right to data portability, the data subject may at any time contact any employee.
g.) Right to Object
You shall have the right granted by the European legislator to object, on grounds relating to your particular situation, at any time, to processing of personal data concerning yourself, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to profiling based on these provisions.
We shall no longer process the personal data in the event of the objection, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims.
If we process personal data for direct marketing purposes, you shall have the right to object at any time to processing of personal data concerning yourself for such marketing. This applies to profiling to the extent that it is related to such direct marketing. If you object to the processing for direct marketing purposes, we will no longer process the personal data for these purposes.
In addition,you have the right, on grounds relating to your particular situation, to object to processing of personal data concerning yourself for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
In order to exercise the right to object, you may establish contact for the same. In addition, you are free in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to use your right to object by automated means using technical specifications.
h.) Automated individual decision-making, including profiling
You shall have the right granted by the European legislator not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning yourself, or similarly significantly affects you, as long as the decision (1) is not is necessary for entering into, or the performance of, an agreement/ contract between the you and the company(us), or (2) is not authorised by Union or Member State law to which the company is subject and which also lays down suitable measures to safeguard your rights and freedoms and legitimate interests, or (3) is not based on your explicit consent.
If the decision (1) is necessary for entering into, or the performance of, an agreement/ contract between you and the company(us) or (2) it is based on your explicit consent, we shall implement suitable measures to safeguard the your rights and freedoms and legitimate interests, at least the right to obtain human intervention.
If you wish to exercise the rights concerning automated individual decision-making, you may, at any time,may establish contact with us.
i.) Right to Withdraw Data Protection Consent
You shall have the right granted by the European legislator to withdraw your consent to processing of your personal data at any time.
If you wish to exercise the right to withdraw the consent, you may, at any time, establish contact with us for the same.
CONTACT EMAIL: firstname.lastname@example.org