PRIVACY POLICY
PRIVACY POLICY
This Privacy Policy (the "Policy") outlines the manner in which [Insert Legal Company Name, e.g., Floria Naturals Private Limited] (the "Company," "We," "Us," or "Our"), operating the website www.florianaturals.com (the "Website"), collects, uses, stores, processes, discloses, and protects your Personal Information and Sensitive Personal Data or Information ("SPDI") in compliance with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the "SPDI Rules").
By providing your information, you signify your explicit consent to the collection, use, and disclosure of your information as described in this Policy.
Effective Date 09-10-2025
1. DEFINITION AND SCOPE
1.1 Personal Information (PI): Information that relates to a natural person, which, either directly or indirectly, in combination with other information available or likely to be available with a body corporate, is capable of identifying such person.
1.2 Sensitive Personal Data or Information (SPDI): Means certain types of PI specified under the SPDI Rules, which are mandatorily protected, including:
-
Passwords.
-
Financial information (Bank account, credit card, debit card, or other payment instrument details).
-
Physical, physiological, and mental health condition (not typically collected by us, but covered for legal robustness).
-
Medical records and history (not typically collected by us, but covered for legal robustness).
-
Biometric information (not typically collected by us).
2. INFORMATION WE COLLECT
We only collect information that is necessary for a lawful purpose connected with our business functions, such as fulfilling product orders and enhancing your experience. The information we collect falls into three categories:
A. Personal Information (PI): This includes data that can identify you directly or indirectly. We collect your Name, Email Address, Phone Number, Shipping Address, Billing Address, and records of your Purchase History and product preferences. This information is primarily collected when you register an account, subscribe to our newsletter, or place an order.
B. Sensitive Personal Data or Information (SPDI): This includes data requiring a higher level of protection under the SPDI Rules. When you make a purchase, we collect your Financial Information (Credit/Debit Card details, UPI IDs, or other payment instrument details). Crucially, this financial SPDI is processed entirely by PCI DSS compliant third-party payment gateways and is NOT stored on our servers.
C. Technical and Usage Data: We automatically collect data about your device and browsing activity, such as your IP address, browser type, operating system, pages viewed, and time spent on the Website. This data helps us ensure website security, prevent fraud, and optimize the site for a better shopping experience.
3. CONSENT AND OPT-OUT MECHANISM
3.1 Explicit Consent for SPDI: We only collect your SPDI when you actively provide it during checkout. By proceeding with a purchase, you provide your explicit, informed consent for the collection and processing of your SPDI necessary to complete the transaction.
3.2 Option to Withhold or Withdraw Consent (MANDATORY):
-
You have the option not to provide the personal data or SPDI sought to be collected.
-
You have the right to withdraw your consent given earlier for the collection and processing of any PI or SPDI.
-
To withdraw consent, you must send a request in writing to the Grievance Officer (details below).
-
Consequence of Withdrawal: If you withdraw consent, we may no longer be able to provide you with access to our services, including processing pending orders or managing your account.
4. USE AND DISCLOSURE OF INFORMATION (PURPOSE LIMITATION)
4.1 Internal Use: We process your information strictly for the purposes for which it was collected, including:
-
Fulfilling your e-commerce purchase orders and delivering our mass premium products.
-
Improving the Website and customizing your experience.
-
Communicating with you about new Aromatherapy products, offers, and promotions (only with explicit consent).
-
Conducting internal quality assessment and security checks.
4.2 Disclosure to Third Parties (Prior Permission Required):
-
We DO NOT sell or rent your Personal Information or SPDI to third parties for their independent marketing purposes.
-
Disclosure of SPDI to any third party requires your prior permission, except in the following necessary circumstances:
-
Service Providers: Sharing with trusted partners (e.g., shipping carriers for delivery, payment gateways for secure processing, cloud hosting providers for storage).
-
Legal Compliance (MANDATORY): Sharing with Government agencies mandated by law (e.g., Police, Courts, Tax Authorities) for the purpose of identity verification, prevention of cyber incidents, or investigation. Such requests are always made in writing.
-