Effective date: August 3, 2026 Last updated: August 3, 2026
DRAFTING NOTE — remove before publishing. Replace every bracketed placeholder. Every statement here must match (a) what your app's code and third-party SDKs actually do, (b) your Apple App Privacy "Nutrition Label," and (c) your Google Play Data Safety form. App stores reject apps where these disagree. Have a qualified lawyer review the final version for your specific jurisdictions. This template is not legal advice.
This Privacy Policy explains how PINIT LLP("Pinit," "we," "us," or "our") collects, uses, shares, and protects information when you use the Pinit mobile application (the "App"), our website at pinitsarees.com (the "Site"), and related services (together, the "Services").
By using the Services, you agree to this Privacy Policy. If you do not agree, do not use the Services.
1. Who we are (Data Controller)
The entity responsible for your personal data is:
- Legal entity: PINIT LLP
- Registered address: 4th Floor, 8-2-309/3/B/1 & 8-2-309/3/B/2, Road no.14 Banjara Hills, Hyderabad, Telangana 500034
Contact email: support@pinitsarees.com
2. Summary of key points
- What we collect: account details, content you create (pins, boards, photos, notes), order, billing, and shipping/delivery details when you buy products, device and usage data, and—depending on features you use—location, contacts, and camera/photo access.
- Why: to provide the Services, process and deliver your orders, secure accounts, communicate with you, process payments (via Razorpay), and comply with law.
- Who we share with: our payment gateway Razorpay, logistics/delivery partners, service providers, third-party SDK vendors (analytics, crash reporting, advertising, authentication), and authorities where legally required. We do not sell personal information.
- Your control: you can access, correct, export, and delete your data, including deleting your account and all associated data from within the App (Settings → Account → Delete Account) and via [DELETION_REQUEST_URL].
- Children: the Services are intended for users 18 and older; we do not knowingly collect data from children (under 18 in India under the DPDP Act).
3. Information we collect
3.1 Information you provide to us
| Category | Examples | Required? |
|---|---|---|
| Account data | Name, username, email address, password (hashed), profile photo | Required to create an account |
| Authentication data | Sign-in via [Sign in with Apple / Google / Facebook], the identifiers those providers return | Optional |
| User content | Pins, boards/collections, saved links, images, captions, notes, comments | Created as you use the App |
| Order & booking data | Products ordered or selected; order history; Suitcase Mode booking details (chosen date/time slot, delivery address, deposit and visit records); recipient name and phone number; and (for COD/deposit refunds) bank/UPI details you provide | Required to place, schedule, and fulfill an order or booking |
| Payment data | Payments are processed by our gateway Razorpay and the methods it supports (card, UPI, net banking, wallets). Razorpay handles card/instrument data under PCI-DSS and RBI rules; we receive transaction status and limited details, not your full card number. | Required to pay for an order |
| Support data | Messages, attachments, and contact details you send to support | Optional |
| Survey/feedback data | Responses you choose to submit | Optional |
3.2 Information collected automatically
| Category | Examples |
|---|---|
| Device data | Device model, OS version, language, time zone, app version, unique device/installation identifiers |
| Usage data | Features used, screens viewed, taps, session length, referring/exit pages, crash logs and diagnostics |
| Log & network data | IP address, access times, browser type (Site), error reports |
| Cookies & similar tech (Site) | See Section 9 |
| Approximate location | Derived from IP address |
3.3 Information collected with your permission (device permissions)
We request the following only when you use the related feature, and only after the operating system prompts you:
| Permission | Why we use it | Can you decline? |
|---|---|---|
| Camera | To take photos to appeal for refund and return. | Yes — feature limited without it |
| Photo library | To select images to upload | Yes |
| approximate location | To pin or discover places near you, tag locations | Yes — location features disabled without it |
| Push notifications | To send activity, reminders, and updates | Yes |
3.4 Information from third parties
We may receive data about you from: social login providers, payment processors, advertising and analytics partners, and other users who share content with you or invite you.
3.5 Sensitive information
We do not intentionally collect special-category or sensitive data: Biometric Data, Protected Health Information (PHI), Sensitive Demographics, Financial and Identity Info, Background/Continuous Location, Communications and Contacts. We do not use it for purposes other than those disclosed here, and we obtain consent where required by law.
4. How we use your information
We use personal data to:
- Create and manage your account and authenticate you.
- Provide core features (creating and personalizing bookings and orders ).
- Personalize content and recommendations.
- Process transactions, subscriptions, and refunds.
- Send transactional messages (e.g., security alerts, receipts) and—with your consent where required—marketing.
- Maintain safety, prevent fraud and abuse, and enforce our Terms.
- Analyze and improve the Services, fix bugs, and develop new features.
- Comply with legal obligations and respond to lawful requests.
Legal bases (GDPR/UK GDPR)
Where the EU/UK GDPR applies, we rely on: performance of a contract (providing the Services), consent (e.g., marketing, certain permissions, non-essential cookies), legitimate interests (e.g., security, analytics, improvement), and legal obligation. You may withdraw consent at any time without affecting prior processing.
5. How we share information
We share personal data with:
- Service providers / processors who act on our behalf: cloud hosting, customer support, email delivery, payment processing, content delivery.
- Third-party SDK and platform partners listed in Section 6.
- Other users, when you choose to make content public or share it.
- Authorities and third parties when required by law, to enforce our Terms, or to protect rights, safety, and security.
- In a business transfer (merger, acquisition, financing, or sale of assets), subject to this Policy.
- With your consent, for any other purpose disclosed at the time.
Sale / "sharing" of personal information: We do not sell or "share" as defined by the CCPA/CPRA personal information.
6. Third-party services and SDKs
The Services include third-party tools that may collect or process data. You are responsible for keeping this list accurate—it must match your store disclosures.
| Provider | Purpose | Data involved | Privacy policy |
|---|---|---|---|
| [Firebase / Google Analytics] | Analytics, crash reporting | Device IDs, usage, diagnostics | [URL] |
| Razorpay | Payment processing | Payment instrument data, transaction details, contact info | razorpay.com/privacy |
| [Logistics/delivery partners] | Order fulfillment & delivery | Recipient name, address, phone, order details | [URL] |
| [AdMob / Meta Audience Network] | Advertising | Device IDs, ad interactions | [URL] |
| [Sentry / Crashlytics] | Crash diagnostics | Device, crash logs | [URL] |
| [Cloud provider, e.g., AWS/GCP] | Hosting | All stored data | [URL] |
| [Push provider] | Notifications | Push tokens, device IDs | [URL] |
DRAFTING NOTE. List every SDK linked into your build—analytics, attribution, ads, crash, push, auth, monetization. Undisclosed SDK data collection is the #1 cause of rejection on both stores. Read each vendor's "Data Safety / Privacy Label" mapping and reflect those categories in your store forms too.
7. Advertising and analytics
If we display ads or measure performance, partners may use device identifiers and usage data to deliver and measure ads. We do engage in cross-app or cross-site tracking.
Apple App Tracking Transparency (ATT): On iOS, if we (or our partners) track you across apps and websites owned by other companies, we will request your permission through Apple's ATT prompt first, and we will honor your choice. If you decline, we will not track you.
You can also limit ad tracking via your device settings (iOS: Settings → Privacy & Security → Tracking; Android: Settings → Privacy → Ads).
8. Data retention
We keep personal data only as long as necessary for the purposes described, then delete or anonymize it.
| Data | Retention |
|---|---|
| Account & profile | Until you delete your account, then deleted within 30 days |
| User content | Until you delete it or your account |
| Transaction/payment records | 7 years for tax, accounting, and legal compliance |
| Support tickets | 24 months |
| Logs & diagnostics | 90 days |
| Backups | Purged on a rolling 30–90 day cycle |
Where retention is legally required (e.g., financial records, fraud prevention), we retain the minimum necessary even after account deletion and inform you here.
9. Cookies and similar technologies (Site)
Our Site uses cookies and similar technologies for: strictly necessary functions, preferences, analytics, and (where applicable) advertising. Where required, we request consent through a cookie banner and provide granular controls. You can manage cookies via the banner and your browser settings.
DRAFTING NOTE. If you serve EU/UK users you generally need a consent management banner that blocks non-essential cookies until consent. Add a cookie table or link to a separate Cookie Policy if your Site sets many cookies.
10. Data security
We use administrative, technical, and physical safeguards including encryption in transit (TLS), encryption at rest, access controls, least-privilege, logging, regular reviews. No method of transmission or storage is 100% secure; we cannot guarantee absolute security. If a breach affecting your data occurs, we will notify you and regulators as required by law.
11. Your privacy rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and obtain a copy.
- Correct inaccurate or incomplete data.
- Delete your data ("right to erasure").
- Port your data to another service.
- Restrict or object to certain processing.
- Withdraw consent at any time.
- Opt out of the sale/sharing of personal information and of targeted advertising.
- Non-discrimination for exercising your rights.
- Lodge a complaint with a supervisory authority (EU/UK) or your local regulator.
How to exercise your rights: Use in-App controls (Settings → Account / Privacy) or contact us at support@pinitsarees.com. We will verify your identity and respond within the time required by law (generally 30–45 days). You may use an authorized agent where permitted.
Region-specific notices
- EU/UK (GDPR): See legal bases (Section 4), international transfers (Section 13), and your right to complain to a supervisory authority.
- California (CCPA/CPRA): You have the rights to know, delete, correct, and opt out of sale/sharing and of certain targeted advertising; and to limit use of sensitive personal information. We [do/do not] sell or share personal information. To opt out: [LINK or "Do Not Sell or Share My Personal Information" control].
- India (Digital Personal Data Protection Act, 2023): We process your personal data based on your consent or other lawful grounds. You have the right to access and correct your data, to withdraw consent, to nominate another person to exercise your rights, and to grievance redressal. To exercise these rights or raise a concern, contact our Grievance Officer (Section 19). We will respond within the timelines required by law. Processing of data of persons under 18 requires verifiable parental/guardian consent, and we do not direct the Services to children.
- Other U.S. states (e.g., Virginia, Colorado, Connecticut, Texas): Similar rights apply; contact us to exercise them.
- [Other jurisdictions you serve—e.g., Brazil LGPD, Canada PIPEDA]: [add as needed].
12. Account and data deletion
You can delete your account and associated personal data at any time:
- In the App: Settings → Account → Delete Account. This permanently deletes your profile, content, and associated personal data, except data we must retain by law (see Section 8).
- On the web / by request: Visit [DELETION_REQUEST_URL] or email support@pinitsarees.com with the subject "Delete my account."
We complete deletion within [30] days. If you used "Sign in with Apple," we also revoke the associated tokens.
DRAFTING NOTE. The web deletion link must be public, load without error, prominently feature the deletion pathway, and name "Pinit." Use the same URL in your Google Play Data Safety form and here. This is mandatory.
13. International data transfers
We may process and store data in India. We use appropriate safeguards such as Standard Contractual Clauses, the EU-U.S./UK/Swiss Data Privacy Framework (if certified), or adequacy decisions.
14. Children's privacy
The Services are intended for users 18 years and older and are not directed to children. We do not knowingly collect personal data from anyone under 18. Under India's DPDP Act, 2023, processing a child's data requires verifiable consent of a parent or lawful guardian. If you believe someone under 18 has provided us data, contact support@pinitsarees.com and we will delete it.
DRAFTING NOTE. India's DPDP Act treats anyone under 18 as a child (stricter than COPPA's under-13 in the US). For a shopping/payments app, restricting to 18+ is the cleanest path, and also aligns with the Indian Contract Act (minors cannot form valid contracts). If you ever allow under-18 users, you must comply with DPDP children's-data rules, COPPA (US), the UK Age-Appropriate Design Code, and the Google Play Families / Apple Kids rules—get legal advice.
15. Marketing communications
With your consent where required, we may send promotional messages. You can opt out anytime via the unsubscribe link or in-App notification settings. Transactional messages (security, billing) are not optional while you have an account.
16. Automated decision-making
We [do not / do] make decisions producing legal or similarly significant effects about you based solely on automated processing. [If you do, describe the logic, significance, and the right to human review.]
17. Third-party links
The Services may link to third-party sites or services we do not control. Their privacy practices are governed by their own policies.
18. Changes to this Privacy Policy
We may update this Policy. We will post the new version with a revised "Last updated" date and, for material changes, provide additional notice (e.g., in-App or email). Continued use after changes means you accept the updated Policy.
19. Contact us
- Email: support@pinitsarees.com
- Support: support@pinitsarees.com / +91 9177708629
- Grievance Officer (India — DPDP Act & IT Rules): support@pinitsarees.com, +91 9177708629
- Address: PINIT LLP, 4th Floor, 8-2-309/3/B/1 & 8-2-309/3/B/2, Road no.14 Banjara Hills, Hyderabad, Telangana 500034
