Privacy Policy for Customers
Effective Date: 30 March 2026 | Version: 4.0
THC Store India Private Limited ("THC Store", "Platform", "we", "us", "our"), a company incorporated under the Companies Act, 2013, with its registered office in New Delhi, India, is committed to protecting the privacy and security of your personal data. This Privacy Policy explains in comprehensive detail how we collect, process, use, disclose, store, and safeguard your personal information when you access or use the THC Store platform โ including our website, mobile applications, and all related services โ as a customer.
By registering, browsing, or transacting on the Platform, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Platform.
1. Definitions & Interpretation
For the purposes of this Privacy Policy:
- "Personal Data" means any data about an individual who is identifiable by or in relation to such data, as defined under the Digital Personal Data Protection Act, 2023 (DPDPA).
- "Sensitive Personal Data or Information" (SPDI) means personal data relating to passwords, financial information, health conditions, medical records, biometric data, sexual orientation, and any data designated as sensitive under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
- "Data Fiduciary" means THC Store, as the entity that determines the purpose and means of processing your Personal Data.
- "Data Principal" means you, the individual whose Personal Data is processed.
- "Data Processor" means any entity that processes Personal Data on behalf of THC Store.
- "Processing" means any operation performed on Personal Data โ including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, alignment, combination, restriction, erasure, or destruction.
- "Health Data" means any Personal Data relating to your physical or mental health, including medical history, prescriptions, consultation records, diagnostic reports, allergies, and treatment plans.
- "Consent Artefact" means a record of your consent, including the purpose, scope, and timestamp of consent given.
2. Legal Framework & Regulatory Compliance
This Privacy Policy is governed by and compliant with the following Indian laws and regulations:
- Digital Personal Data Protection Act, 2023 (DPDPA) โ India's comprehensive data protection legislation governing the processing of digital personal data
- Information Technology Act, 2000 (as amended 2008) โ Sections 43A (compensation for failure to protect data), 72A (punishment for disclosure of information in breach of lawful contract)
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 โ SPDI classification, consent requirements, body corporate obligations
- Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 โ Intermediary due diligence, content moderation, grievance redressal
- Consumer Protection Act, 2019 and Consumer Protection (E-Commerce) Rules, 2020 โ Marketplace obligations, unfair trade practices, consumer data protection
- Drugs and Cosmetics Act, 1940 and Rules โ Prescription data handling, controlled substance documentation
- Telemedicine Practice Guidelines, 2020 (Board of Governors in supersession of MCI / National Medical Commission) โ Patient data during teleconsultation
- Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002 โ Doctor-patient confidentiality
- Digital Information Security in Healthcare Act (DISHA) framework โ Electronic health records security
- Income Tax Act, 1961 โ Transaction data retention (Section 194O TDS, Section 206C TCS)
- Central Goods and Services Tax Act, 2017 โ Invoice and transaction data retention
- Indian Evidence Act, 1872 (now Bharatiya Sakshya Adhiniyam, 2023) โ Electronic records as evidence
- CERT-In Directions, April 2022 โ Cyber incident reporting within 6 hours, log retention for 180 days
3. Information We Collect
3.1 Information You Provide During Registration
| Data Category |
Specific Data Points |
Classification |
Mandatory? |
| Identity | Full name, date of birth, gender | Personal Data | Yes |
| Contact | Email address, mobile phone number, alternate phone number | Personal Data | Email & phone: Yes; alternate: No |
| Authentication | Password (stored only as bcrypt hash with salt โ never in plaintext), OTP verification status | SPDI | Yes |
| Preferences | Newsletter subscription opt-in, marketing communications preference, notification preferences (email, SMS, push), language preference | Personal Data | No (defaults applied) |
| Social Login | Google account email, name, profile picture URL (if you choose Google Sign-In). We receive only the data Google shares via OAuth 2.0 โ we never receive or store your Google password. | Personal Data | No (optional login method) |
| Referral | Referral code used at registration (links you to the referring customer for rewards) | Personal Data | No |
3.2 Information You Provide During Use
| Data Category |
Specific Data Points |
Classification |
Consent Basis |
| Delivery Addresses | Full name, phone number, address line 1, address line 2, city, state, pincode, address type (home/office/other), GPS coordinates (if permitted) | Personal Data | Contractual |
| Age Verification Documents | Government-issued ID type (PAN Card, Aadhaar, Voter ID, Driving Licence, Passport) and document scan/photograph โ collected only when age verification is required for restricted products | SPDI | Explicit Consent + Legal Obligation |
| Medical Profile | Health conditions, current symptoms, known allergies, ongoing medications, medical history, diagnostic reports, lab results | SPDI (Health Data) | Explicit Consent |
| Prescriptions | Digital prescriptions issued by doctors on the Platform, prescriptions uploaded by you, linked medications and dosages, prescription validity period | SPDI (Health Data) | Explicit Consent + Legal Obligation |
| Consultation Records | Doctor consultation notes, follow-up schedules, medical certificates received, appointment history, consultation type (video/in-person), duration | SPDI (Health Data) | Explicit Consent |
| Consultation Recordings | Audio/video recordings of telemedicine consultations โ only with your explicit, separate consent before each recording begins. You may refuse recording without affecting the consultation. | SPDI (Health Data) | Explicit, Separate Consent |
| Payment Data | Transaction history, wallet balance, refund records, payment method preferences, subscription billing records. Important: Full card numbers, CVV, bank login credentials, and UPI PINs are never stored by THC Store โ they are processed exclusively by Razorpay (PCI-DSS Level 1 certified). | SPDI (Financial) | Contractual |
| User-Generated Content | Product reviews, star ratings, questions, uploaded photos/videos in reviews | Personal Data | Consent |
| Support Communications | Customer support tickets, live chat transcripts, AI chatbot conversation history, email correspondence, phone call metadata (if applicable) | Personal Data | Contractual + Legitimate Interest |
| Loyalty & Membership | Loyalty points balance, tier status (Bronze/Silver/Gold/Platinum), membership plan, daily check-in streak, referral history, coupon redemption history | Personal Data | Contractual |
| Wishlist & Saved Items | Products saved to wishlist, price drop alert preferences, saved collections | Personal Data | Contractual |
3.3 Information Collected Automatically
| Data Category |
Details |
Retention |
| Device Information | IP address, browser type and version, operating system, device type (mobile/desktop/tablet), screen resolution, device identifiers, time zone | 180 days (CERT-In) |
| Usage Analytics | Pages visited, products viewed, search queries, time spent per page, click patterns, scroll depth, feature interactions, navigation paths | 90 days (clearable) |
| Browsing History | Recently viewed products, search history, category browsing patterns โ used for personalised recommendations. You can clear this from your account settings at any time. | 90 days (clearable) |
| Location Data | Approximate location from IP geolocation (city-level); precise GPS location only if you explicitly grant browser/device permission (used for delivery estimation, pincode auto-fill). You can revoke location permission at any time through your browser settings. | Session only (precise); 90 days (approximate) |
| Server Logs | HTTP request/response logs, API call records, error logs, authentication attempt logs (success/failure), rate limiting events | 180 days (CERT-In mandate) |
| Security Events | Login attempts (IP, timestamp, success/failure), password change events, 2FA events, suspicious activity flags, account lockout events | 1 year |
3.4 Cookies & Tracking Technologies
| Cookie Category |
Purpose |
Examples |
Duration |
Can You Refuse? |
| Strictly Essential | Authentication, session management, CSRF protection, cart persistence, security | accessToken (httpOnly), csrfToken, cartSession | Session / 24 hours | No โ Platform cannot function without these |
| Functional | Language preferences, recently viewed products, cookie consent state, theme preferences | locale, recentlyViewed, cookieConsent | 1 year | Yes โ some features may not personalise |
| Analytics | Anonymous page views, feature usage metrics, performance monitoring, A/B testing | _ga, _gid (if Google Analytics enabled) | Up to 2 years | Yes โ no impact on functionality |
We do not use advertising or retargeting cookies. We do not serve third-party ads on the Platform. You can manage non-essential cookies through the cookie consent banner displayed on first visit, or through your browser settings. Declining non-essential cookies does not affect core Platform functionality.
3.5 Information We Do NOT Collect
For clarity, THC Store does not collect:
- Aadhaar number (we accept Aadhaar only as a visual age-verification document โ the number itself is masked/redacted before storage)
- Biometric data (fingerprints, facial recognition, retina scans)
- Caste, religion, political affiliation, or trade union membership
- Sexual orientation or sex life details
- Genetic data or DNA information
- Criminal conviction records
- Full card numbers, CVV, or banking credentials (processed by Razorpay only)
4. Lawful Basis for Processing
Under the DPDPA 2023 and IT Act SPDI Rules, we process your data only on the following lawful bases:
| Lawful Basis |
When We Rely On It |
Your Right |
| Consent (DPDPA ยง6) | Marketing emails, newsletters, promotional notifications, consultation recordings, non-essential cookies, sharing medical profile with doctors, product recommendations based on health data | Withdraw at any time โ withdrawal does not affect prior lawful processing |
| Contractual Necessity | Account creation, order processing, delivery coordination, payment processing, consultation booking, loyalty/membership management, customer support | Data processing stops if you terminate the contract (delete account) |
| Legal Obligation | Tax invoice generation (GST), TDS/TCS compliance, age verification for restricted products, CERT-In log retention, law enforcement requests, court orders | Cannot be opted out โ required by Indian law |
| Legitimate Interest (DPDPA ยง7) | Fraud prevention, security monitoring, service improvement, anonymised analytics, abuse detection, rate limiting, bot prevention | Object if you believe our interest is overridden by your rights |
| Vital Interest | Emergency medical situations during consultation โ sharing patient data with emergency services if there is an immediate risk to life | Used only in genuine emergencies |
5. Consent Management
5.1 How We Obtain Consent
- Registration Consent: By creating an account, you consent to the processing necessary for Platform services (contractual basis). You explicitly accept this Privacy Policy, Terms & Conditions, and Store Policy during registration.
- Granular Consent: For optional processing (marketing, health data sharing, consultation recordings), we obtain separate, specific consent with clear opt-in mechanisms โ never pre-ticked boxes.
- Medical Data Consent: Before any Health Data is collected or shared with a doctor, you are presented with a separate consent notice explaining exactly what data will be shared, with whom, and for what purpose.
- Recording Consent: Consultation recordings require a separate, real-time consent prompt before the recording begins. You may decline without any impact on the consultation itself.
5.2 Consent Records
Every consent you grant is recorded as a Consent Artefact containing:
- Your user ID and the specific consent granted
- Timestamp (date and time in IST)
- IP address and device/browser information
- The version of the policy or notice you consented to
- Method of consent (registration checkbox, in-app toggle, modal acceptance)
These records are retained for the duration of your account plus 3 years, as evidence of lawful processing.
5.3 Withdrawing Consent
You may withdraw consent at any time through:
- Account Settings: Toggle marketing preferences, notification settings, data sharing options
- Unsubscribe Links: Every marketing email contains an instant unsubscribe link
- Newsletter Preference Centre: Granular control over email categories (health tips, promotions, product launches, wellness guides, seasonal offers, expert articles)
- Email Request: Send a withdrawal request to privacy@thcstore.in
Withdrawal of consent is processed within 48 hours. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal, and does not affect processing based on other lawful grounds (contractual necessity, legal obligation).
6. How We Use Your Information
6.1 Core Service Delivery
- Creating, managing, verifying, and securing your account
- Processing orders, calculating taxes (CGST/SGST/IGST), generating GST-compliant invoices with HSN/SAC codes
- Coordinating delivery with logistics partners (Shiprocket, Delhivery)
- Processing payments, refunds, wallet credits, and chargebacks through Razorpay
- Facilitating doctor consultations โ booking, video conferencing, follow-ups
- Managing prescriptions โ storage, validation, linking to prescription-required products
- Administering loyalty points (earning, redemption, tier upgrades, expiry)
- Managing memberships (Silver/Gold/Diamond), associated benefits, and renewal
- Processing referral rewards for both referrer and referee
6.2 Communications (Transactional โ Cannot Be Opted Out)
- Order confirmation, shipment tracking, and delivery notifications
- Payment confirmation and refund status updates
- Appointment booking confirmation, reminders (24h/2h before), and rescheduling notices
- Prescription issuance and expiry notifications
- Account security alerts (login from new device, password change, suspicious activity)
- Policy update notifications requiring re-acceptance
- Legal/regulatory notices
6.3 Communications (Marketing โ Consent-Based, Opt-Out Available)
- Promotional offers, sale announcements, flash deal alerts
- Newsletter with health tips, wellness guides, expert articles
- Product recommendations based on purchase history and browsing
- Membership upgrade offers and loyalty bonus campaigns
- Re-engagement campaigns for dormant accounts
- Festival/seasonal promotions
6.4 Personalisation & Recommendations
- Product recommendations based on browsing history, purchase history, and category preferences (not based on Health Data unless you consent)
- Search result ranking optimised for your preferences
- Recently viewed products and "customers also bought" suggestions
- Personalised homepage sections based on engagement patterns
6.5 Security & Fraud Prevention
- Detecting and preventing fraudulent transactions, fake accounts, and payment manipulation
- Rate limiting to prevent abuse (30 auth requests/15 min, 3 OTP/min, API endpoint limits)
- Account lockout after 5 consecutive failed login attempts
- IP-based anomaly detection for suspicious login patterns
- Bot and scraper detection to protect platform integrity
- Review fraud detection (fake reviews, coordinated review manipulation)
- Coupon/promotion abuse detection (multi-account exploitation, self-referral)
6.6 Analytics & Service Improvement
- Anonymised and aggregated analytics to improve product discovery, site performance, and user experience
- A/B testing of features (no personal data exposed โ only aggregate metrics)
- Monitoring Platform uptime, error rates, and page load performance
7. Artificial Intelligence & Automated Processing
THC Store uses AI and automated systems in the following ways:
7.1 AI Customer Support Chatbot
- Technology: Powered by Anthropic's Claude AI (Haiku model)
- Data Accessed: Your support query text, order history (for context), account type
- Data NOT Accessed: Medical records, prescriptions, financial data, passwords
- Purpose: First-line customer support for order tracking, FAQs, product information, and general inquiries
- Human Escalation: Complex queries, complaints, medical inquiries, and financial disputes are automatically escalated to human agents. You can request human escalation at any time.
- Data Retention: Chat transcripts are retained for 90 days for quality improvement; anonymised after that
- Opt-Out: You may request to skip the AI chatbot and connect directly with a human agent
7.2 Product Recommendations
- Mechanism: Algorithmic recommendations based on browsing history, purchase patterns, and category preferences
- No Health-Based Profiling Without Consent: We do not use your medical profile, prescriptions, or consultation data for product recommendations unless you explicitly consent
- Transparency: Recommended products are labelled as "Recommended for You" and can be dismissed
7.3 Fraud Detection
- Mechanism: Rule-based and pattern-matching algorithms analyse transactions, login patterns, and account behaviour
- Actions: May flag transactions for manual review, temporarily restrict accounts, or require additional verification
- Human Review: No account is permanently suspended by automated systems alone โ all enforcement decisions involve human review
- Right to Contest: You may contest any automated decision by contacting support@thcstore.in
7.4 No Automated Decision-Making with Legal Effects
THC Store does not make fully automated decisions that produce legal effects or similarly significant effects on you (such as credit scoring, insurance pricing, or employment decisions). All decisions that materially affect your account, access, or rights involve human review.
8. Who We Share Your Data With
8.1 Data Sharing Matrix
| Recipient |
Data Shared |
Purpose |
Safeguards |
| Brand Partners (Sellers) | Name, delivery address, phone number | Order fulfilment and delivery coordination | Brands must delete your data within 90 days of order completion; prohibited from using your data for independent marketing; contractual DPA in place; violation = immediate termination |
| Doctors | Name, age, gender, medical profile (as shared by you) | Medical consultation | Doctors bound by medical ethics (IMC Regulations), IT Act, DISHA; patient data confidentiality is a legal and contractual obligation; access restricted to consultation context only |
| Logistics Partners (Shiprocket, Delhivery) | Recipient name, delivery address, phone number, package weight/dimensions, COD amount (if applicable) | Shipment pickup, transit tracking, and last-mile delivery | Contractual data processing agreements; data used only for delivery; no marketing use |
| Payment Gateway (Razorpay) | Transaction amount, order ID, payment method type, customer email (for payment receipts) | Secure payment processing | Razorpay is PCI-DSS Level 1 certified; RBI-regulated payment aggregator; full card data never touches THC Store servers |
| Cloud Infrastructure (AWS) | Uploaded documents, prescription images, profile pictures | Encrypted file storage (S3) | AES-256 encryption at rest; TLS in transit; access-controlled via IAM policies; data centre in Mumbai region (ap-south-1) |
| AI Service Provider (Anthropic) | Support chat text only (no PII unless you include it in your message) | AI customer support responses | Anthropic's data processing terms; chat data not used for model training; processed in secure API calls |
| Email Service Provider | Email address, name, email category preferences | Transactional and marketing email delivery | Contractual DPA; data used only for email delivery; no third-party sharing |
| Government Authorities | As required by law โ court orders, tax authorities (GST/TDS data), CERT-In (security incidents), law enforcement, Drug Controller (prescription records if required) | Legal compliance | Disclosed only upon valid legal process; we verify the legality of each request; you will be notified unless prohibited by law |
8.2 What We Never Do
- We never sell your Personal Data to any third party
- We never rent or trade your data for marketing purposes
- We never share your Health Data with employers, insurers, or data brokers
- We never allow Brand Partners or Doctors to use your data for independent marketing, solicitation, or any purpose beyond the specific service context
- We never use your medical records for advertising or targeted product marketing without your explicit consent
9. Health Data โ Special Protections
Given the sensitive nature of health information, THC Store applies additional protections beyond standard Personal Data safeguards:
9.1 Classification
All Health Data (medical profile, prescriptions, consultation records, consultation recordings, allergies, medications, diagnostic reports) is classified as Sensitive Personal Data or Information (SPDI) under the IT Act 2011 SPDI Rules and receives the highest level of protection.
9.2 Access Controls
- Doctor Access: A doctor can access your Health Data only during an active consultation or for follow-up within the prescribed period. Access is revoked when the doctor-patient relationship ends on the Platform.
- Brand Partner Access: Brand Partners never receive any Health Data. They receive only the minimum data required for order fulfilment (name, address, phone).
- Platform Staff Access: Only authorised THC Store personnel with specific role-based access can view Health Data, and only when necessary for support ticket resolution, dispute mediation, or legal compliance. All access is logged and auditable.
- AI Systems: The AI customer support chatbot does not have access to your Health Data. Medical queries are escalated to human agents.
9.3 Storage & Encryption
- Health Data is stored in encrypted database fields (AES-256) separate from general Personal Data
- Prescription images and medical documents are stored in access-controlled encrypted S3 buckets
- All Health Data in transit is protected by TLS 1.2 or higher
- Database backups containing Health Data are encrypted and access-restricted
9.4 Purpose Limitation
Your Health Data is used exclusively for:
- Facilitating doctor consultations you initiate
- Generating and managing prescriptions
- Verifying prescription validity for prescription-required product orders
- Follow-up care coordination between you and your doctor
- Medical certificate issuance at your request
Your Health Data is never used for product recommendations, advertising, profiling, insurance assessments, employment screening, or any purpose beyond direct healthcare delivery on the Platform โ unless you provide separate, explicit consent.
9.5 Your Health Data Rights
- You may view all Health Data held about you from your account dashboard at any time
- You may download your complete medical records in a structured format
- You may request correction of any inaccurate Health Data
- You may request deletion of Health Data โ subject to minimum retention periods required by healthcare regulations (3 years from last consultation)
- You may revoke access for a specific doctor at any time (this does not affect records from past consultations)
10. Data Security Measures
10.1 Technical Security
| Measure |
Implementation Details |
| Encryption in Transit | TLS 1.2+ (HTTPS enforced via HSTS) for all client-server communication; internal service-to-service communication via encrypted channels |
| Encryption at Rest | AES-256 for sensitive database fields; encrypted S3 storage for uploaded documents; encrypted database backups |
| Password Security | bcrypt with per-user salt (cost factor 10); minimum 8 characters with complexity requirements (uppercase, lowercase, digit, special character); passwords never logged, displayed, or stored in plaintext |
| Authentication | JWT access tokens with short expiration; httpOnly secure cookies; refresh token rotation; token blacklisting on logout; session invalidation on password change |
| Two-Factor Authentication | Optional OTP-based 2FA via SMS/email; OTP codes are hashed before storage; time-limited validity |
| Rate Limiting | Redis-backed rate limiting: 30 auth requests/15 min, 3 OTP requests/min, per-endpoint API limits; in-memory fallback if Redis unavailable |
| Account Lockout | Automatic lockout after 5 consecutive failed login attempts; unlock via email/OTP verification |
| Security Headers | HSTS (Strict-Transport-Security), Content-Security-Policy with nonce-based scripts, X-Frame-Options (DENY), X-Content-Type-Options (nosniff), Referrer-Policy, Permissions-Policy |
| Input Validation | Server-side validation on all inputs; parameterised database queries (SQL injection prevention); HTML sanitisation (XSS prevention); CSRF tokens on state-changing requests |
| File Upload Security | Strict MIME type validation; file size limits (2MB profile pictures, 5MB documents); format whitelist (JPEG, PNG, PDF); malware scanning |
| Access Control | Role-Based Access Control (RBAC) with 59 granular permission modules; principle of least privilege; separate authentication paths for customers, brands, doctors, admins |
| Audit Logging | Comprehensive audit trails for all sensitive operations โ login events, data access, data modifications, administrative actions, payment events |
10.2 Organisational Security
- Access Control: Platform staff access to customer data is role-restricted and logged; only authorised support and compliance personnel can access personal data
- Vendor Assessment: All third-party service providers (Razorpay, AWS, logistics partners) are assessed for security compliance before engagement
- Incident Response: Documented incident response plan with defined roles, escalation procedures, and communication protocols (see Section 14)
- Data Minimisation: We collect only the data necessary for each specific purpose; we do not collect data "just in case"
- Regular Reviews: Periodic security assessments and vulnerability reviews of the Platform
11. Data Retention
| Data Category |
Retention Period |
Legal Basis for Retention |
After Retention |
| Account & Profile Data | Active account + 3 years post-deletion | Limitation Act (3 years for civil claims) | Permanently purged |
| Order & Transaction Records | 8 years from transaction date | Income Tax Act ยง149 (reassessment period); GST Act ยง36 (record keeping) | Permanently purged |
| Medical Records & Prescriptions | Minimum 3 years from last consultation | Medical Council Regulations; DISHA framework; Consumer Protection Act limitation | Anonymised or purged |
| Consultation Recordings | 1 year from recording date | Quality assurance; dispute resolution | Permanently deleted |
| Age Verification Documents | Deleted within 30 days of verification completion | Only retained until verification is complete | Permanently deleted |
| Payment Data (transaction records) | 8 years | Income Tax Act; GST Act; RBI regulations | Permanently purged |
| Support Tickets & Chat Logs | 2 years from resolution | Consumer Protection Act; service improvement | Anonymised |
| Browsing & Search History | 90 days (clearable by you anytime) | Personalisation (consent-based) | Auto-deleted |
| Server & Security Logs | 180 days | CERT-In Directions (April 2022) mandate | Permanently deleted |
| Security Events (login, lockout) | 1 year | Fraud prevention; legal proceedings | Permanently deleted |
| Loyalty & Membership Records | Active account + 1 year | Contractual; potential disputes | Permanently purged |
| Consent Records (Consent Artefacts) | Active account + 3 years | DPDPA compliance; evidence of lawful processing | Permanently deleted |
| Review & User Content | Duration of account (deleted with account or on request) | Consent-based | Anonymised or deleted |
Account Deletion Process: Upon account deletion, Personal Data is immediately soft-deleted (made inaccessible) and scheduled for permanent purging after the applicable retention period. Data required by law (tax records, medical records) is retained in encrypted, access-restricted storage until the statutory period expires, then permanently destroyed.
12. Your Rights Under Indian Law
12.1 Rights Under DPDPA 2023
- Right to Access (ยง11): Request a summary of all Personal Data we hold about you, the processing activities performed, and the categories of Data Processors involved
- Right to Correction (ยง12): Request correction of inaccurate, incomplete, or misleading Personal Data
- Right to Erasure (ยง12): Request deletion of your Personal Data when it is no longer necessary for the purpose it was collected โ subject to legal retention requirements
- Right to Nominate (ยง14): Nominate another individual to exercise your data rights in the event of your death or incapacity. You may designate a nominee through your account settings or by written request to privacy@thcstore.in
- Right to Grievance Redressal (ยง13): Lodge complaints with our Data Protection Officer and, if unsatisfied, with the Data Protection Board of India
12.2 Additional Rights Under IT Act SPDI Rules
- Right to Withdraw Consent: Withdraw consent for processing of SPDI at any time (this may affect your ability to use certain Platform features)
- Right to Know: Know what SPDI is being collected, the purpose of collection, and the intended recipients
- Right to Data Portability: Receive your Personal Data in a structured, commonly used, machine-readable format (JSON or CSV)
- Right to Object: Object to processing based on legitimate interest where your rights override our interest
- Right to Restrict Processing: Request restriction of processing in certain circumstances (while a complaint is being investigated)
12.3 How to Exercise Your Rights
- Self-Service: Many rights (access, correction, consent withdrawal, data download) can be exercised directly through your account settings dashboard
- Email: Send requests to privacy@thcstore.in with subject line "Data Rights Request โ [Your Request Type]"
- Identity Verification: We will verify your identity before processing any request (via OTP to your registered phone/email)
- Response Time: We will acknowledge your request within 48 hours and action it within 30 days. If an extension is needed (complex requests), we will inform you within the initial 30-day period with reasons.
- No Fee: Exercise of data rights is free of charge. We may charge a reasonable fee only for manifestly unfounded or excessive repeated requests.
- Refusal: If we must refuse a request (e.g., legal retention requirement prevents deletion), we will provide clear reasons in writing.
13. Cross-Border Data Transfer
- Primary Processing: Your Personal Data is primarily stored and processed on servers located in India (GCP Mumbai region and AWS ap-south-1).
- Limited Cross-Border Transfer: Certain data may be processed outside India in the following cases:
- AI Support (Anthropic): Support chat text is processed via Anthropic's API (servers may be in the US). Only anonymised query text is sent โ no personal identifiers, Health Data, or financial data.
- Email Delivery: Email service infrastructure may route through global servers. Only email address and message content are transmitted.
- Safeguards: All cross-border transfers are subject to contractual data processing agreements that require at minimum the same level of protection as Indian law. We transfer data only to jurisdictions or service providers that maintain adequate data protection standards.
- DPDPA Compliance: When the Central Government notifies restricted jurisdictions under DPDPA ยง16, we will ensure compliance. We will not transfer data to any jurisdiction blacklisted by the Government of India.
- Notification: If the cross-border transfer landscape changes materially, we will update this Privacy Policy and notify you.
14. Data Breach Notification
14.1 Our Obligations
In the event of a personal data breach that is likely to cause harm to your rights and interests:
- Within 6 hours: Report to CERT-In (Indian Computer Emergency Response Team) as mandated by CERT-In Directions, April 2022
- Within 72 hours: Notify the Data Protection Board of India (once constituted under DPDPA) and all affected Data Principals (you)
- Notification Contents: Nature of the breach, categories of data affected, approximate number of individuals affected, likely consequences, measures taken to address the breach, measures you can take to protect yourself, contact details of our Data Protection Officer
- Ongoing Updates: We will provide periodic updates as the investigation progresses and final remediation report
14.2 Health Data Breach โ Enhanced Response
If the breach involves Health Data (medical records, prescriptions, consultation data):
- Immediate isolation and containment of affected systems
- Notification to affected patients within 48 hours
- Notification to the treating doctor(s) involved
- Notification to relevant medical regulatory authorities if warranted
- Offer of free credit monitoring and identity protection services if financial data is also compromised
- Detailed guidance on protecting yourself from potential misuse of exposed health information
14.3 Your Responsibilities
- Use a strong, unique password for your THC Store account
- Enable two-factor authentication
- Do not share your login credentials with anyone
- Report suspicious account activity immediately to support@thcstore.in
- Keep your contact information current so we can reach you in case of a breach
15. Children's Privacy
- THC Store is not intended for individuals under 18 years of age. You must be at least 18 to create an account.
- We do not knowingly collect Personal Data from anyone under 18.
- If a parent or guardian discovers that their child has provided Personal Data to us, they should contact privacy@thcstore.in immediately.
- Upon verification, we will promptly delete all Personal Data associated with the minor's account.
- If we become aware that we have inadvertently collected data from a minor, we will delete it within 72 hours of discovery.
- Age verification may be required for certain product categories (alcohol-based wellness products, products with age restrictions) via government-issued ID.
16. Third-Party Links & External Services
- The Platform may contain links to third-party websites, services, or applications (e.g., brand websites, health information portals, government regulatory sites).
- This Privacy Policy applies only to THC Store. We are not responsible for the privacy practices, content, or security of any third-party service.
- We recommend reviewing the privacy policy of any third-party site before providing your Personal Data.
- THC Store does not endorse or control third-party services linked from the Platform.
17. Data Anonymisation & Aggregation
- THC Store may create anonymised or aggregated datasets from Personal Data for analytics, research, and service improvement purposes.
- Anonymised data has all personally identifiable information irreversibly removed โ it cannot be linked back to you.
- Aggregated data is statistical summaries (e.g., "40% of customers prefer UPI payments") that do not identify any individual.
- Anonymised and aggregated data is not considered Personal Data and may be used without restriction.
18. Changes to This Privacy Policy
- We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or Platform features.
- Material Changes: For changes that significantly affect your rights or how we process your data, we will publish a new version with a changes summary and require you to accept the updated policy before continuing to use the Platform. You will be notified via email and/or in-app notification.
- Non-Material Changes: Minor clarifications, formatting updates, or corrections may be made without requiring re-acceptance. The effective date and version number will always be updated.
- Your continued use of the Platform after accepting an updated policy constitutes your consent to the updated terms.
- If you do not agree with a material change, you may delete your account. Data retained under legal obligations will continue to be handled as described in Section 11.
19. Grievance Officer & Data Protection Officer
In accordance with the Information Technology Act, 2000 (Section 5(9) of SPDI Rules) and DPDPA 2023:
| Role | Grievance Officer / Data Protection Officer |
| Email | grievance@thcstore.in |
| Acknowledgement | Within 24 hours of receipt |
| Resolution | Within 30 days of receipt (or extension with reasons communicated) |
| Escalation | If unsatisfied with our response, you may approach the Data Protection Board of India (once constituted) or file a complaint with the relevant consumer forum |
20. Governing Law & Jurisdiction
- This Privacy Policy is governed by the laws of the Republic of India.
- Any disputes arising from this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of New Delhi, India.
- Nothing in this Privacy Policy limits your statutory rights under Indian data protection laws, which cannot be waived or restricted by contract.
21. Contact Information
| Privacy Inquiries | privacy@thcstore.in |
| Grievance Officer | grievance@thcstore.in |
| General Support | support@thcstore.in |
| Legal Department | legal@thcstore.in |
| National Consumer Helpline | 1800-11-4000 (toll-free) |
Last updated: 30 March 2026 | Version 4.0