LEGAL & COMPLIANCE

Privacy Policy

Your trust is our priority. Learn how we collect, use, and protect your personal information.

Effective Date 01 January 2024
Last Updated 01 January 2024

A Note from B-Lady

Welcome to B-Lady. This Privacy Policy describes how we collect, use, store, process, share, and protect your personal information when you use our platform. By using B-Lady, you agree to the practices described here. We've made every effort to keep this policy clear and transparent — because you deserve to know exactly how your data is handled.

IT Act 2000 DPDPA 2023 Consumer Protection Act SPDI Rules 2011
01

Information We Collect

We collect various types of information to provide you with a seamless, secure, and personalized shopping experience.

1.1 Personal Information (Provided by You)

Information that you voluntarily provide to us when you register, place an order, subscribe, participate in promotions, or contact our support team:

  • Full Name
  • Email Address
  • Mobile Number
  • Date of Birth
  • Gender
  • Postal Address (billing and shipping)
  • Payment Information (credit card, debit card, UPI, net banking, wallet details)
  • Account Login Credentials (username and password)
  • Product Reviews and Ratings
  • Wishlist and Saved Items
  • Any other information you choose to provide voluntarily

1.2 Sensitive Personal Data or Information (SPDI)

As defined under the IT (SPDI) Rules 2011, we may collect the following with your explicit consent:

  • Financial Information (bank account details, card numbers, payment instrument details)
  • Passwords and authentication credentials
  • Any other data categorized as sensitive personal data under applicable Indian law
Important: We do not collect biometric data, medical records, or sexual orientation data unless explicitly required and consented to.

1.3 Automatically Collected Information

When you access our Platform, certain information is collected automatically:

  • IP Address
  • Browser Type and Version
  • Operating System
  • Device Type and Unique Device Identifiers
  • Pages Viewed and Time Spent
  • Referring URL and Exit Pages
  • Click Patterns and Navigation Behavior
  • Date and Time of Access
  • Geographic Location (approximate, based on IP)
  • Language Preferences

1.4 Information from Third-Party Sources

We may receive information about you from:

  • Social Media Platforms (Google, Facebook, Instagram login)
  • Payment Gateways and Financial Partners
  • Logistics and Delivery Partners
  • Marketing and Analytics Partners
  • Brand Partners and Affiliates
02

How We Use Your Information

📦

Order Fulfillment

  • Process, confirm, and fulfill orders
  • Arrange delivery and tracking
  • Generate invoices and receipts
  • Process payments and refunds
👤

Account Management

  • Create and maintain your account
  • Verify identity and authenticate access
  • Maintain order history and preferences
✉️

Communication

  • Send order updates and notifications
  • Respond to inquiries and support
  • Share service announcements
🎁

Marketing (With Consent)

  • Send promotional offers
  • Notify about new launches
  • Share personalized recommendations
  • Opt-out available anytime

Personalization

  • Customize your shopping experience
  • Display relevant products
  • Improve navigation
⚖️

Legal Compliance

  • Comply with Indian laws
  • Enforce Terms and Conditions
  • Prevent and detect fraud
  • Protect rights and safety
03

Cookies & Tracking Technologies

3.1 What Are Cookies

Cookies are small text files stored on your device when you visit our Platform. They help us recognize your device, remember your preferences, and provide a more personalized experience.

3.2 Types of Cookies We Use

3.3 Third-Party Cookies

We may allow third-party service providers such as Google Analytics, Facebook Pixel, and other marketing and analytics tools to place cookies on your device. These third parties have their own privacy policies.

3.4 Managing Cookies

You have the right to accept or reject cookies. You can manage your cookie preferences through your browser settings at any time. Please note that disabling certain cookies may affect the functionality of our Platform.

04

Sharing & Disclosure

We do not sell, rent, or trade your personal information. We may share your information only in the circumstances outlined below.

4.1 Service Providers and Business Partners

We share information with trusted third-party providers including:

  • Payment Gateway Providers (Razorpay, Paytm, PhonePe, CCAvenue)
  • Logistics and Delivery Partners (Delhivery, BlueDart, Shiprocket, India Post)
  • Cloud Storage and Hosting Providers
  • Email and SMS Communication Services
  • Customer Support and CRM Platforms
  • Marketing, Advertising, and Analytics Partners

4.2 Brand Partners

When you purchase from specific brands, order-related information may be shared for warranty registration, product recalls, or customer support.

4.3 Legal Requirements

We may disclose information if required by law, regulation, court order, or governmental request, including compliance with subpoenas, law enforcement, and prevention of fraud.

4.4 Business Transfers

In case of merger, acquisition, reorganization, or sale of assets, your information may be transferred. We will notify you of any such changes.

4.5 With Your Consent

We may share information in any other circumstances where you have provided explicit prior consent.

05

Data Storage & Retention

5.1 Storage Location

Your personal information is stored on secure servers located in India, managed by us or authorized third-party hosting providers. All storage complies with the IT Act 2000 and SPDI Rules 2011.

5.2 Retention Period

We retain your personal information only for as long as necessary:

Active Account
For the duration of your active account
After Closure
Reasonable period for legal compliance and dispute resolution
Financial Data
Minimum 8 years (Indian taxation requirements)
Marketing Data
Until consent is withdrawn or opted out

Upon expiration of the retention period, your personal data will be securely deleted or anonymized.

06

Data Security

We take the security of your personal information seriously and implement industry-standard security measures.

🔒

SSL Encryption

Secure Socket Layer encryption for all data transmitted between your browser and our servers

🛡️

Data Encryption

Sensitive personal data encrypted at rest and in transit

💳

PCI-DSS Compliant

Secure payment processing through PCI-DSS compliant gateways

🔐

Access Controls

Strict authentication mechanisms to restrict data access

🔍

Security Audits

Regular vulnerability assessments and penetration testing

🚧

Firewalls

Intrusion detection and prevention systems

Please Note: While we strive to protect your information, no method of transmission over the Internet is 100% secure. We are committed to promptly addressing any security breach in accordance with applicable laws.
07

Your Rights

You have the following rights regarding your personal information under applicable Indian laws:

01

Right to Access

Access and review the personal information we hold about you through your account or by contacting us.

02

Right to Correction

Request correction or updating of any inaccurate or incomplete personal information.

03

Right to Withdraw Consent

Withdraw your consent at any time for any consent-based processing of your information.

04

Right to Erasure

Request deletion of your personal information from our records, subject to legal retention requirements.

05

Right to Opt-Out of Marketing

Opt out of marketing communications via unsubscribe links, account settings, or by contacting us.

06

Right to Nominate

Under DPDPA 2023, nominate an individual to exercise your rights in case of death or incapacity.

07

Right to Grievance Redressal

File complaints or grievances regarding the processing of your personal information.

08

Children's Privacy

B-Lady does not knowingly collect personal information from children under 18 years. Our services are intended for users 18 years or older, or under parental supervision.

If we become aware that we have inadvertently collected personal information from a child without verifiable parental consent, we will take immediate steps to delete such information from our records.

If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us immediately.

09

Third-Party Links & Services

Our Platform may contain links to third-party websites, applications, or services that are not owned, operated, or controlled by B-Lady:

  • Social media platforms (Instagram, Facebook, YouTube)
  • Brand partner websites
  • Third-party payment gateways
  • External blogs, review sites, and beauty forums
  • Advertising and affiliate networks

We are not responsible for the privacy practices, content, or security of third-party websites. We strongly encourage you to read their privacy policies before providing any personal information.

10

Changes to This Policy

We reserve the right to update, modify, or revise this Privacy Policy at any time to reflect changes in our practices, technologies, legal requirements, or business operations.

Any changes will be effective immediately upon posting on this page with a revised "Last Updated" date. For material changes that significantly affect data processing, we will notify you through prominent notice on our Platform, via email, or other communication channels.

Your continued use of our Platform after any changes constitutes acceptance of the revised policy.

11

Grievance Redressal

In accordance with the IT Act 2000, the contact details of our Grievance Officer are provided below:

Grievance Officer

Authorized Contact
Name [To be appointed]
Designation Data Protection Officer
Company B-Lady Beauty Pvt. Ltd.
Address Mumbai, Maharashtra, India
Phone [Phone Number]
Hours Monday to Saturday, 10:00 AM to 6:00 PM IST
Resolution Time: The Grievance Officer shall address complaints within thirty (30) days from the date of receipt, as per IT Act 2000 and SPDI Rules 2011.

If unsatisfied with the resolution, you may escalate to the Data Protection Board of India as constituted under the Digital Personal Data Protection Act, 2023.

12

Governing Law & Jurisdiction

This Privacy Policy shall be governed by and construed in accordance with the laws of India, including:

The Information Technology Act, 2000
IT (SPDI) Rules, 2011
Digital Personal Data Protection Act, 2023
Consumer Protection Act, 2019
Consumer Protection (E-Commerce) Rules, 2020
The Indian Contract Act, 1872

Any disputes arising out of or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the competent courts located in Mumbai, India.

14

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or the handling of your personal information, please reach out to us:

Registered Office

B-Lady Beauty Pvt. Ltd.
Mumbai, Maharashtra, India
Working Hours: Monday to Saturday, 10:00 AM to 6:00 PM IST