01. The promise behind this page
Painamaa believes that privacy should not be hidden behind complicated language. When you visit an online store, you should be able to understand what information is collected, why it is collected, where it may go, how long it may be kept, and what choices you have.
This Privacy Policy applies to personal information processed through Painamaa's website, including product pages, blog content, checkout experiences, contact forms, newsletter forms, customer-support communications, promotional experiences, and other digital interactions that expressly link to this policy.
This policy should be read together with Painamaa's Terms & Conditions, Shipping Policy, Refund and Cancellation Policy, Cookie information, and any additional privacy notices presented when information is collected.
Clear collection
We aim to explain what information is requested at the point where it is requested.
Purpose first
Personal information should be used for legitimate and understandable business purposes.
Reasonable protection
We use appropriate technical and organisational safeguards for information we handle.
Respect for choices
Where applicable, we provide ways to manage communications and privacy choices.
Who is responsible?
The entity responsible for the website and processing described in this policy is: [INSERT LEGAL BUSINESS / ENTITY NAME] , operating the Painamaa brand and website painamaa.com .
Registered or principal business address: [INSERT FULL BUSINESS ADDRESS] .
Privacy-related communications: [INSERT PRIVACY EMAIL] .
General customer support: [INSERT SUPPORT EMAIL] .
02. Information we may collect
The exact information Painamaa collects depends on how you interact with the website. A visitor reading a blog article may provide no information directly, while a customer placing an order may provide contact, delivery and transaction-related information.
| Category | Examples | Why it may be needed |
|---|---|---|
| Identity / contact | Name, email address, phone number | Customer service, account functions, order communication and delivery coordination. |
| Delivery information | Address, locality, city, state and PIN code | To fulfil and deliver an order. |
| Order information | Products purchased, quantities, order date, order status and coupon use | Order processing, customer support, accounting and fulfilment. |
| Payment-related information | Transaction reference, payment status, method and limited payment metadata | To confirm and reconcile payments. Full card credentials should generally be handled by the payment provider. |
| Account information | Login identifier, account preferences, saved addresses where enabled | To operate optional customer-account functionality. |
| Communications | Support requests, messages, feedback and reviews | To respond, resolve issues and improve service. |
| Technical information | IP address, browser, device and operating system | Security, diagnostics and site performance. |
| Usage information | Pages visited, clicks and session information | Site improvement and analytics where enabled. |
| Marketing preferences | Newsletter status and communication preferences | To manage promotional communications. |
Information you provide directly
You may voluntarily provide information when you create an account, complete checkout, subscribe to a mailing list, submit a contact form, request support, participate in a promotion, submit a review, respond to a survey, or communicate with Painamaa.
Information generated automatically
Like most modern websites, painamaa.com may receive technical information automatically from your browser or device. Depending on the website configuration, this can include IP address, browser characteristics, device type, referring page, timestamps, requested pages, approximate region, error information and security logs.
Information from third parties
Information may also reach Painamaa through service providers involved in payment, delivery, website hosting, analytics, customer support, fraud prevention, marketing or other legitimate operations.
03. How information reaches us
Personal information can enter our systems through several ordinary ecommerce touchpoints.
When you browse
When you shop
When you contact us
When you subscribe
04. How we use personal information
Painamaa may process personal information for purposes connected with operating an ecommerce website and providing products and customer service.
Provide the website
Deliver pages, products, account functionality and requested digital services.
Process orders
Create orders, confirm transactions and coordinate fulfilment and delivery.
Customer support
Answer questions, troubleshoot issues and process complaints.
Improve experience
Understand website performance and improve content, navigation and usability.
Security
Detect suspicious activity and protect systems.
Communications
Send transactional messages and permitted promotional communications.
Business records
Maintain appropriate accounting, tax and dispute records.
Legal compliance
Meet applicable legal and regulatory requirements.
Personalisation
If Painamaa introduces personalised product recommendations, offers or content, the website should disclose the relevant processing and provide choices where applicable.
Fraud prevention
Ecommerce websites face risks such as automated abuse, fraudulent transactions, account takeover attempts, spam and malicious traffic. Painamaa may process relevant technical or transactional signals where reasonably necessary to protect customers and the business.
05. Legal bases, consent and lawful processing
Privacy requirements depend on applicable law, the nature of processing and the location of the individual. Painamaa should not describe every processing activity as consent-based.
Privacy should be understandable
Where consent is used, the request should be clear, specific and understandable. Optional choices should not be disguised as mandatory requirements for unrelated services.
For India, Painamaa should design its privacy processes with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 in mind, as applicable to the relevant processing and according to their commencement and implementation requirements.
Painamaa may also need to consider consumer protection, ecommerce, tax, accounting, advertising, payment, cybersecurity and other rules applicable to its activities.
Consent withdrawal
Where processing is based on consent, applicable law may provide a right to withdraw that consent. Withdrawal should be reasonably easy where such a mechanism applies.
06. Orders, checkout and payments
When you place an order, we process information needed to identify the order, communicate with you, arrange payment and fulfilment, and provide customer support.
Payment information
Painamaa should avoid storing full payment-card credentials unless there is a specific lawful and technically appropriate reason to do so. Many ecommerce stores use specialised payment gateways that process sensitive payment credentials directly.
Payment providers currently used by Painamaa: [INSERT PAYMENT GATEWAY / PROVIDER] .
Payment confirmation
Painamaa may receive transaction metadata such as payment status, transaction reference, amount, currency and timestamps.
Delivery partners
To deliver an order, relevant customer information may be shared with a courier, logistics or fulfilment provider. This can include recipient name, delivery address and phone number.
Delivery providers currently used: [INSERT ACTUAL COURIER / LOGISTICS PROVIDERS] .
Order communications
Customers may receive transactional communications such as order confirmation, payment confirmation, dispatch information, delivery updates, cancellation information, refund status and customer-support responses.
07. Cookies and similar technologies
Cookies are small files or identifiers stored or read by a browser. Similar technologies can include pixels, tags, local storage and other mechanisms.
| Type | Typical purpose | Example |
|---|---|---|
| Strictly necessary | Security, cart, checkout and sessions. | Shopping cart session. |
| Preference | Remember settings and preferences. | Saved display preference. |
| Analytics | Measure visits and website performance. | Analytics platform. |
| Marketing | Measure campaigns or promotional activity. | Advertising measurement tag. |
The exact cookies active on painamaa.com may change as plugins, themes, analytics tools, advertising services and integrations change.
Cookie audit checklist
08. Analytics, performance and marketing technologies
Painamaa may use analytics and performance tools to understand how visitors interact with the website.
If Painamaa uses Google Analytics, Meta Pixel, Google Ads conversion tracking, Microsoft Clarity, Hotjar, TikTok Pixel, email marketing software, WhatsApp integrations or similar services, the final policy should reflect the tools actually installed.
Marketing measurement
Marketing systems can sometimes receive information such as campaign identifiers, page interactions, approximate device information, cookie identifiers or appropriately transformed contact information.
Analytics and payment information
Analytics tools should not receive unnecessary payment-card information, passwords, authentication secrets or other sensitive values.
A good rule for every tracking script
If the business cannot explain what a script receives, why it receives it, who receives it, how long it is retained, and how visitors can control it where required, the script deserves a technical review.
09. When we may share information
Painamaa does not need to share every piece of information with every third party. Information should be disclosed only where reasonably necessary for a stated purpose, where required or permitted by law, or where another lawful basis applies.
Hosting & infrastructure
Servers, backups, CDN and security services.
Payments
Payment providers that facilitate transactions.
Logistics
Couriers and fulfilment partners.
Customer support
Email, messaging and support providers.
Analytics
Measurement providers where enabled.
Professional advisers
Accountants, lawyers and auditors where needed.
Lawful requests
We may disclose information where required by applicable law, court order, regulatory requirement or other lawful process.
Business transfers
If Painamaa is involved in a merger, acquisition, restructuring, sale of assets or change of ownership, relevant information may be transferred as part of that transaction, subject to applicable law.
What we do not promise
This policy should not say that Painamaa "never shares data" because operating an ecommerce business commonly requires limited sharing with payment, delivery, hosting, security and other service providers.
10. Security and protection of information
Painamaa takes reasonable steps to protect personal information against unauthorised access, misuse, alteration, loss or disclosure.
Examples of reasonable safeguards
- Use HTTPS/TLS for website traffic.
- Limit administrative access.
- Use strong authentication and MFA where available.
- Keep WordPress, WooCommerce, themes and plugins appropriately updated.
- Use reputable hosting and security services.
- Protect backups.
- Review installed plugins and remove unused integrations.
- Avoid unnecessary storage of payment credentials.
- Maintain a process for suspected security incidents.
No internet transmission or storage system can be guaranteed to be completely secure. Painamaa should therefore avoid absolute claims such as "your information is 100% secure."
11. Retention, deletion and lifecycle management
Personal information should not be retained indefinitely simply because storage is inexpensive. Painamaa may retain information for as long as reasonably necessary for the relevant purpose or to satisfy legitimate legal, accounting, dispute or security requirements.
| Information | Reason | Retention |
|---|---|---|
| Order records | Fulfilment, accounting, tax and disputes. | [INSERT ACTUAL PERIOD] |
| Support messages | Customer service and dispute history. | [INSERT ACTUAL PERIOD] |
| Marketing preferences | Respect unsubscribe and consent preferences. | [INSERT ACTUAL PERIOD] |
| Security logs | Security monitoring and investigation. | [INSERT ACTUAL PERIOD] |
The placeholders above are intentional. Replace them with periods that match Painamaa's actual operational, accounting and legal requirements.
Deletion requests
Where applicable, you may request deletion of personal information. Deletion may be subject to lawful exceptions, including information that must be retained for tax, accounting, fraud-prevention or dispute requirements.
12. Your privacy rights and choices
Depending on applicable law and circumstances, individuals may have rights concerning their personal information.
Access
You may have a right to access certain personal information or information about its processing.
Correction
You may ask for inaccurate information to be corrected where applicable.
Deletion
You may request deletion where applicable and where no legal exception applies.
Withdraw consent
Where consent is the basis, you may have a right to withdraw it.
Opt out
You can generally use the unsubscribe mechanism in promotional communications.
Grievance
You may contact Painamaa using the published privacy or grievance route.
How to submit a privacy request
Send a request to [INSERT PRIVACY / GRIEVANCE EMAIL] with enough information for us to understand and respond to your request.
We may need to verify identity or authority before disclosing or changing personal information. This helps prevent someone else from accessing a customer's data.
Do not send passwords, OTPs, CVV numbers, full payment card numbers or authentication codes by email.
Requests involving another person
If you are making a request on behalf of another person, Painamaa may ask for evidence that you are authorised to do so.
13. Children, minors and age-related considerations
Painamaa is an ecommerce brand and should not knowingly design its services to collect children's personal information in circumstances where special consent or protections are required without putting appropriate safeguards in place.
If a person is not legally able to provide valid consent for a particular processing activity, applicable requirements relating to parental or guardian consent and verification should be followed where required.
If you believe a child has provided personal information to Painamaa in circumstances where it should not have been collected, contact: [INSERT PRIVACY EMAIL] .
14. International processing and transfers
Some technology or service providers used by Painamaa may process information in India or other countries. Hosting, email, analytics, cloud infrastructure, payment, security and customer-support providers can operate across multiple jurisdictions.
Where personal information is processed outside the country in which it was collected, Painamaa should consider applicable transfer requirements, provider commitments, security measures and other relevant restrictions.
The final version should accurately describe meaningful international processing where required. Do not promise that all data is stored exclusively in India unless the technical architecture actually supports that claim.
15. Third-party websites and services
Painamaa may link to third-party websites or use third-party services for payment, delivery, social media, analytics, communications, reviews and other functions.
A link to another website does not mean Painamaa controls that website's privacy practices. When you leave painamaa.com or interact directly with a third-party service, that provider may process information under its own privacy notice.
Embedded content
Embedded videos, social posts, maps, payment widgets, review systems and other content can cause a third party to receive technical information from your browser.
16. Email, WhatsApp, SMS and promotional communications
Painamaa may communicate with customers about orders, support requests, products, promotions, launches, educational content, offers and brand updates.
Promotional email
If you subscribe to promotional email, we may use your email address and marketing preferences to send the communications you requested.
WhatsApp or messaging
If Painamaa offers customer support or marketing through WhatsApp or another messaging service, relevant contact information and message content may be processed by that service.
Stopping marketing communications
You can use the unsubscribe mechanism in promotional emails where provided or contact: [INSERT MARKETING PRIVACY EMAIL] .
Even after opting out of promotional communications, you may still receive essential transactional messages relating to an order or customer-support interaction.
17. Reviews, testimonials and user-submitted content
If Painamaa allows customers to submit product reviews, photographs, comments or other content, information submitted may become visible to other visitors depending on the feature.
Users should avoid publishing phone numbers, addresses, payment information or other private details in public reviews.
If Painamaa wants to reuse a customer photograph, review or testimonial in advertising, social media, product pages or other promotional materials beyond the original review context, the business should obtain the permission or other lawful authorisation required for that reuse.
18. Changes to this Privacy Policy
Painamaa may update this Privacy Policy when its website, services, technologies, business operations or applicable legal requirements change.
The updated version will be published on this page with an updated "Last updated" date.
If a change materially affects how personal information is processed and applicable law requires additional notice or consent, Painamaa will take appropriate steps.
Version history
Version 1.0
— Initial publication.
Date:
Owner:
[INSERT LEGAL BUSINESS / ENTITY NAME]
19. Contact us about privacy
If you have a question about this Privacy Policy, want to make a privacy request, need to correct information, want to withdraw applicable consent, or want to raise a privacy-related concern, contact us using the details below.
Privacy email
[INSERT PRIVACY EMAIL]
Customer support
[INSERT SUPPORT EMAIL]
Business address
[INSERT FULL BUSINESS ADDRESS]
Phone / WhatsApp
[INSERT PHONE NUMBER]
Grievance contact
Name / role:
[INSERT GRIEVANCE OFFICER / PRIVACY CONTACT]
Email:
[INSERT GRIEVANCE EMAIL]
Address:
[INSERT ADDRESS]
What to include in a request
- Your name and reliable contact method.
- The nature of your request.
- Relevant order number where useful.
- Enough information to locate the relevant record.
For your safety, do not send passwords, OTPs, CVV numbers, full payment-card numbers, authentication codes or other confidential credentials when contacting us.
Privacy should feel understandable.
A privacy notice should help you make an informed choice, not make you feel like you need a law degree before buying a packet of dried fruit.
20. Simple privacy glossary
Personal data / personal information
Processing
Consent
Data Fiduciary
Data Principal
Cookie
Data minimisation
Regulatory context
This page is designed for a modern Indian ecommerce brand and covers common privacy topics. It should be reviewed against Painamaa's actual business model, technology stack and current law before publication.
In particular, Painamaa should consider the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, together with other applicable consumer, ecommerce, tax, payment, advertising and cybersecurity requirements.
Final transparency checklist for Painamaa
Before publishing this page, complete the following checklist. The quality of a privacy policy depends as much on the website's actual configuration as on the words displayed on the page.
| Check | Status | What to verify |
|---|---|---|
| Legal entity | ☐ | Correct legal name and business address. |
| Privacy email | ☐ | Mailbox exists and is monitored. |
| Payment providers | ☐ | Verify actual gateways and data received. |
| Courier partners | ☐ | Confirm delivery information shared. |
| Hosting | ☐ | Identify hosting, CDN, backup and security providers. |
| Analytics | ☐ | Audit analytics scripts actually installed. |
| Marketing pixels | ☐ | Audit advertising and campaign tags. |
| Cookies | ☐ | Perform a browser-level cookie scan. |
| WordPress plugins | ☐ | Review every plugin for external data collection. |
| Forms | ☐ | Check Contact Form 7 and other forms. |
| Retention | ☐ | Replace all retention placeholders. |
| Rights process | ☐ | Create a real request-handling process. |
| Security | ☐ | Review passwords, MFA, updates and backups. |
| Checkout | ☐ | Verify WooCommerce data storage. |
| International vendors | ☐ | Identify providers processing data outside India. |
| Policy links | ☐ | Link privacy policy from footer and checkout. |
| Legal review | ☐ | Have the final policy reviewed professionally. |
