Effective Date: July 15, 2026
Our platform is deeply committed to safeguarding your privacy, ensuring transparency in how your information is collected, processed, stored, protected, and used while also establishing clear terms and conditions that govern your access to and use of our website, mobile application, and related services. By visiting, accessing, browsing, registering an account, or making a purchase on our platform, you acknowledge and agree to the practices outlined herein.
1. INFORMATION WE COLLECT
We collect information to provide a secure, customized, and smooth shopping experience. The information may be collected directly from you, automatically from your device, or from third-party partners.
1.1 Personal Identification Information (Directly Provided)
We collect personal information that helps identify you as an individual. This includes sensitive contact and profile details that are essential for performing e-commerce services.
This includes (but is not limited to):
Full Name
Phone Number
Email Address
Gender (optional)
Date of Birth (optional)
Primary & Alternate Shipping/Billing Address
Business/GST Details (for business buyers)
Purpose: This information is required for creating your account, validating your identity, delivering orders, sending updates, and providing customer support.
1.2 Payment Information (Securely Processed)
When you make a purchase on our platform, we facilitate secure payment processing through industry-leading payment gateways and financial service providers. Your payment information is handled with the highest level of security and compliance standards to ensure safe and seamless transactions.
Flint & Thread (India) Private Limited does not directly store, process, or have access to your sensitive financial credentials. All payment transactions are routed through certified Payment Card Industry Data Security Standard (PCI-DSS) compliant payment processors, which employ advanced encryption technologies, secure tokenization, and fraud detection mechanisms to protect your financial data during transmission and processing.
We collect and store (for order processing and customer support):
Payment Method Selected: The type of payment option you choose (Credit/Debit Cards, Net Banking, UPI, Digital Wallets like Paytm, PhonePe, Google Pay, Amazon Pay, or Cash on Delivery)
Transaction Details: Unique transaction identification numbers, payment confirmation codes, order reference numbers, and transaction timestamps
Billing Information: Billing address, billing name, and contact details associated with the payment method for invoice generation and tax compliance
Payment Status: Transaction status (successful, failed, pending, refunded, or cancelled) for order management and customer service
Refund/Return Transaction Details: Information related to refund requests, return processing, and reimbursement transactions, including refund method and status
Payment Gateway Information: The name of the payment service provider used (e.g., Razorpay, PayU, Instamojo, or other authorized gateways) for transaction tracking
Partial Payment Information: For split payments or installment orders, we may store partial payment records and remaining balance information
We DO NOT collect, store, or have access to:
Complete Card Numbers: Full credit or debit card numbers are never stored on our servers
CVV/CVC Codes: The three or four-digit security codes on your card are never requested or stored
ATM PINs: Personal Identification Numbers for debit card transactions are never collected
Net Banking Passwords: Online banking credentials are never accessed or stored by our platform
UPI PINs: UPI transaction PINs are handled directly by your bank or UPI service provider
Wallet Passwords/PINs: Digital wallet credentials remain with the respective wallet service providers
Bank Account Details: Complete bank account numbers, IFSC codes, or account holder names are not stored unless explicitly required for specific payment methods (like NEFT/RTGS) and only with your explicit consent
Security Assurance: All payment data is processed through PCI-DSS Level 1 compliant payment gateways that use 256-bit SSL encryption, secure tokenization, and comply with international security standards including ISO 27001. Your payment information is encrypted during transmission and processed on secure servers that undergo regular security audits and vulnerability assessments.
Third-Party Payment Processors: When you make a payment, you may be redirected to secure payment gateway pages operated by our authorized payment partners. These partners have their own privacy policies and terms of service. We recommend reviewing their policies to understand how they handle your payment information. Flint & Thread is not responsible for the privacy practices of third-party payment processors, but we only work with certified and trusted payment service providers.
1.3 Device, System & Usage Information (Automatically Collected)
To provide you with an optimized, secure, and personalized shopping experience, our platform automatically collects certain technical and usage-related information from your device and browsing session. This data collection occurs through standard web technologies, analytics tools, and security systems that are commonly used across e-commerce platforms to ensure functionality, prevent fraud, and enhance user experience.
This information is collected passively as you interact with our website or mobile application, without requiring any additional input from you. We use this data to understand how our platform is being used, identify technical issues, optimize performance, detect suspicious activities, and provide you with relevant content and recommendations based on your browsing behavior.
We automatically collect the following information:
IP Address: Your Internet Protocol (IP) address, which helps us identify your approximate geographic location, prevent fraudulent activities, diagnose technical issues, and comply with legal requirements. We may also collect your IPv6 address if applicable.
Browser Information: Browser type (Chrome, Firefox, Safari, Edge, etc.), browser version, browser language settings, screen resolution, color depth, time zone, and browser plugins/extensions installed
Device Information: Device type (Smartphone, Tablet, Desktop, Laptop), device manufacturer (Apple, Samsung, Dell, etc.), device model, device identifiers (such as device ID, advertising ID, or unique device identifiers), and device capabilities
Operating System Details: Operating system name (Windows, macOS, iOS, Android, Linux), OS version, system architecture (32-bit or 64-bit), and system language preferences
Network Information: Internet service provider (ISP) details, connection type (Wi-Fi, 4G, 5G, Ethernet), network speed, and mobile carrier information (for mobile devices)
Location Data: Approximate geographic location derived from IP address geolocation, GPS coordinates (if you grant location permissions on mobile apps), and location-based preferences for delivery and regional content
Cookies & Tracking Technologies: Session cookies, persistent cookies, local storage data, session storage, pixel tags, web beacons, and other tracking identifiers that help us remember your preferences, maintain your session, and track your interactions
Browsing Behavior: Pages visited, time spent on each page, click patterns, scroll depth, search queries entered, products viewed, categories browsed, items added to cart, items removed from cart, and navigation paths through the website
Interaction Data: Mouse movements, clicks, taps, swipes, form field interactions, button clicks, link clicks, video play/pause actions, image zoom interactions, and other user interface interactions
Performance Metrics: Page load times, server response times, error messages encountered, JavaScript errors, network latency, and overall application performance data
Referral Information: Website or application that referred you to our platform (referrer URL), search engine used, search keywords entered, social media platform referrals, and marketing campaign identifiers
Session Information: Session start time, session duration, session end time, number of sessions, frequency of visits, and session identifiers for tracking user journeys
Mobile App Specific Data: App version, app installation date, push notification preferences, app permissions granted, device orientation, accelerometer data (if applicable), and mobile app crash reports
Security & Fraud Prevention Data: Login attempt patterns, failed login attempts, suspicious activity indicators, device fingerprinting data, and security event logs to protect your account and prevent unauthorized access
How We Use This Information:
Security & Fraud Prevention: To detect and prevent fraudulent transactions, identify suspicious login attempts, protect against cyber threats, and maintain platform security
Performance Optimization: To identify slow-loading pages, optimize server performance, improve website speed, fix technical bugs, and ensure smooth user experience across different devices and browsers
Personalization: To provide personalized product recommendations, customize homepage content, show relevant offers and promotions, and tailor the shopping experience based on your preferences and browsing history
Analytics & Insights: To understand user behavior patterns, analyze website traffic, identify popular products and categories, measure marketing campaign effectiveness, and make data-driven business decisions
Technical Support: To diagnose technical issues, troubleshoot problems, provide customer support, and improve platform functionality
Compliance & Legal: To comply with legal obligations, respond to law enforcement requests, protect our legal rights, and ensure regulatory compliance
User Experience Enhancement: To remember your preferences, maintain your shopping cart across sessions, provide location-based services, and optimize the interface for your specific device and browser
Your Control: You can control the collection of certain information through your browser settings (e.g., disabling cookies, blocking location access) or mobile device settings. However, please note that disabling certain data collection may affect the functionality of our platform, including the ability to complete purchases, access personalized features, or receive location-based services. Most of this information is collected through standard web technologies and analytics tools that are essential for the basic functioning of e-commerce websites.
Data Retention: Device and usage information is typically retained for analytical and security purposes for a period as specified in our Data Retention Policy. Aggregated and anonymized data may be retained longer for statistical and research purposes. We do not use this information to personally identify you unless it is necessary for security, fraud prevention, or legal compliance purposes.
1.4 Communication & Interaction Information
To provide you with exceptional customer support, resolve queries efficiently, maintain service quality, and ensure compliance with legal and regulatory requirements, we collect and store information related to all communications and interactions you have with Flint & Thread (India) Private Limited through various channels. This information helps us understand your needs, track issue resolution, improve our services, and maintain a comprehensive record of your relationship with our platform.
All communication records are maintained securely and are used solely for customer service purposes, quality assurance, training, dispute resolution, and legal compliance. We ensure that sensitive information shared during communications is protected and handled in accordance with applicable data protection laws and our internal privacy standards.
We collect and store the following communication and interaction information:
Support Tickets & Help Requests: All support tickets created through our helpdesk system, including ticket ID, subject line, detailed description of the issue, priority level, status (open, in-progress, resolved, closed), timestamps, assigned support agent, resolution details, and follow-up communications
Live Chat Conversations: Real-time chat messages exchanged with our customer support team, including chat session ID, message timestamps, chat duration, agent responses, file attachments shared (if any), chat transcripts, and satisfaction ratings provided after chat sessions
Email Communications: All email correspondence sent to and received from our official email addresses (support@flintandthread.com, etc.), including email subject, body content, attachments, sender and recipient information, timestamps, email thread history, and any email forwarding or replies
Phone Call Records: For phone-based customer support, we may record call audio (with your consent where required by law), call duration, call timestamps, phone numbers (yours and ours), call routing information, IVR (Interactive Voice Response) selections, and call disposition notes made by support agents
Social Media Interactions: Messages, comments, reviews, and interactions on our official social media pages (Facebook, Instagram, Twitter, LinkedIn, etc.), including direct messages, public comments, mentions, tags, and responses to our posts
Feedback & Reviews: Product reviews, ratings, seller reviews, service feedback, survey responses, testimonials, and any other feedback you voluntarily provide through our platform or third-party review platforms
Complaint & Grievance Records: Formal complaints filed through our grievance redressal system, complaint reference numbers, complaint details, investigation notes, resolution steps taken, compensation or refund details (if applicable), and closure status
Return & Refund Requests: Return request forms, refund applications, reason for return/refund, product condition descriptions, photos or videos submitted, return authorization numbers, refund processing details, and related correspondence
Order-Related Communications: Messages related to order status inquiries, delivery updates, shipping notifications, order modifications, cancellation requests, and any special instructions or requests related to your orders
Account-Related Communications: Account verification requests, password reset requests, account update notifications, security alerts, account suspension or termination communications, and identity verification interactions
Marketing & Promotional Interactions: Responses to promotional emails, SMS, or push notifications (opens, clicks, unsubscribes), participation in contests or surveys, newsletter subscription preferences, and marketing consent records
Technical Support Interactions: Technical issue reports, bug reports, feature requests, website/app feedback, error logs shared, troubleshooting steps taken, and technical resolution details
Legal & Compliance Communications: Legal notices sent or received, compliance-related queries, data subject access requests, privacy-related inquiries, and any communications related to legal proceedings or regulatory matters
Interaction Metadata: Communication channel used (email, chat, phone, social media), response times, resolution time, customer satisfaction scores, Net Promoter Score (NPS) responses, and interaction quality metrics
Documentation & Attachments: Any documents, images, screenshots, videos, or files shared during communications, including invoices, receipts, product photos, identity documents (for verification), and other supporting materials
How We Use This Information:
Customer Service Delivery: To respond to your queries, resolve issues, provide technical support, process returns and refunds, and ensure timely resolution of complaints
Quality Assurance: To monitor service quality, train customer support staff, improve response times, and enhance overall customer experience
Dispute Resolution: To investigate disputes, resolve conflicts, process refunds or compensations, and maintain records for legal and regulatory compliance
Service Improvement: To identify common issues, improve products and services, develop new features, and address customer pain points
Legal & Regulatory Compliance: To comply with consumer protection laws, maintain records as required by regulations, respond to legal requests, and protect our legal rights
Fraud Prevention: To detect and prevent fraudulent activities, verify user identity, and protect against abuse of our services
Communication History: To maintain a complete record of your interactions with us, enable continuity in customer support, and provide context for future communications
Privacy & Security: All communication records are stored securely using encryption and access controls. Only authorized personnel with a legitimate business need can access these records. Phone call recordings (where applicable) are conducted only with your consent and in compliance with applicable laws. You have the right to request access to your communication records, request corrections, or request deletion (subject to legal and regulatory retention requirements).
Data Retention: Communication and interaction records are retained for a period necessary to fulfill the purposes outlined above, comply with legal obligations (typically 3-7 years for financial and legal records), resolve disputes, and maintain service quality. After the retention period, records are securely deleted or anonymized. However, certain records may be retained longer if required by law, ongoing legal proceedings, or regulatory requirements.
1.5 Marketing, Preference & Behavioral Data
To enhance your shopping experience, provide personalized recommendations, deliver relevant offers and promotions, and improve our marketing effectiveness, we collect and analyze data related to your shopping preferences, browsing behavior, and interactions with our marketing communications. This data helps us understand your interests, predict your needs, and tailor our platform to better serve you.
We use advanced analytics, machine learning algorithms, and behavioral tracking technologies to analyze your shopping patterns and preferences. This enables us to show you products you're likely to be interested in, offer discounts on items you've been considering, and create a more personalized and efficient shopping experience. All marketing activities are conducted in compliance with applicable laws and with respect for your privacy preferences.
We collect and analyze the following marketing, preference, and behavioral data:
Wishlist & Saved Items: Products added to your wishlist, saved for later items, favorite products, bookmarked items, and items you've marked as "interested" or "notify me when available"
Saved Addresses & Delivery Preferences: Multiple shipping addresses saved, billing addresses, preferred delivery locations, delivery time preferences, and address labels (home, office, etc.)
Recently Viewed Products: Products you've viewed, browsed, or searched for, including product categories, brands, price ranges, and viewing frequency
Search History & Queries: Search terms entered, search filters applied, search results clicked, autocomplete selections, and search refinement patterns
Purchase History & Patterns: Products purchased, purchase frequency, average order value, preferred payment methods, seasonal buying patterns, and brand preferences
Cart Behavior: Items added to cart, items removed from cart, cart abandonment patterns, time spent in cart, and cart value trends
Category & Brand Preferences: Product categories frequently browsed, favorite brands, brand loyalty indicators, and category-specific browsing patterns
Price Sensitivity & Preferences: Price ranges you typically shop in, discount responsiveness, price drop alerts subscribed to, and willingness to pay indicators
Notification Preferences: Email notification settings, SMS notification preferences, push notification preferences, marketing communication opt-in/opt-out status, and notification frequency preferences
Marketing Communication Engagement: Email open rates, email click-through rates, SMS response rates, push notification interactions, promotional campaign participation, and unsubscribe history
Offer & Discount Engagement: Coupons used, discount codes applied, promotional offers clicked, flash sale participation, and special deal responsiveness
Social Sharing & Referral Activity: Products shared on social media, referral links clicked, referral codes used, and social media engagement with our content
Review & Rating Behavior: Products reviewed, ratings given, review helpfulness votes, review photos/videos shared, and review engagement patterns
Comparison & Research Behavior: Products compared, comparison features used, product detail page time spent, specification reviews, and research patterns before purchase
Platform Customization Preferences: Language preferences, currency preferences, display settings, layout preferences, theme selections, and accessibility settings
Subscription & Membership Data: Newsletter subscriptions, loyalty program enrollment, membership tier, reward points balance, and subscription preferences
Event & Campaign Participation: Participation in contests, surveys, feedback programs, beta testing programs, and special events or promotions
Cross-Device Behavior: Shopping patterns across different devices (mobile, tablet, desktop), device preferences for different activities, and multi-device journey tracking
Seasonal & Temporal Patterns: Shopping patterns by time of day, day of week, month, season, and special occasions (festivals, birthdays, anniversaries)
Predictive Analytics Data: Machine learning-generated insights, purchase probability scores, churn risk indicators, lifetime value predictions, and next purchase predictions
How We Use This Information:
Personalized Product Recommendations: To show you products that match your interests, browsing history, and purchase patterns on our homepage, category pages, product detail pages, and email communications
Targeted Marketing Campaigns: To send you relevant promotional offers, discounts, and marketing communications based on your preferences and shopping behavior
Price Alerts & Notifications: To notify you when products you're interested in go on sale, when wishlist items become available, or when price drops occur
Cart Recovery: To remind you about items left in your cart and offer incentives to complete your purchase
Content Personalization: To customize website content, homepage layout, category recommendations, and featured products based on your preferences
Search Optimization: To improve search results relevance, suggest search terms, and enhance autocomplete functionality based on your search patterns
Marketing Analytics: To measure campaign effectiveness, optimize marketing spend, analyze customer segments, and improve return on marketing investment
Customer Segmentation: To group customers with similar preferences and behaviors for targeted marketing, product recommendations, and service customization
Service Enhancement: To identify trends, improve product offerings, optimize inventory, and enhance overall platform functionality based on user behavior patterns
Your Control & Preferences: You have full control over your marketing preferences and behavioral data collection. You can opt-out of marketing communications at any time through your account settings, email unsubscribe links, or by contacting our customer support. You can also manage your notification preferences, clear your browsing history, remove items from your wishlist, and adjust your privacy settings. However, please note that opting out of certain data collection may limit the personalization features available to you on our platform.
Data Sharing & Third-Party Marketing: We may share aggregated and anonymized behavioral data with trusted marketing partners, analytics providers, and advertising networks to improve our marketing efforts and deliver relevant advertisements. However, we do not sell your personal information to third parties for their marketing purposes. Any third-party marketing is conducted in compliance with applicable privacy laws and with appropriate safeguards in place. You can opt-out of third-party advertising through your account settings or by using industry-standard opt-out mechanisms.
2. HOW WE USE YOUR INFORMATION
Your information is used strictly for improving your shopping experience and fulfilling legal obligations.
2.1 To Deliver and Improve Our Services
Your personal information is essential for us to provide you with a seamless, efficient, and reliable e-commerce experience. We use your data to fulfill orders, deliver products, process payments, provide customer support, and continuously improve our platform's functionality, performance, and user experience. This section outlines the comprehensive ways in which we utilize your information to deliver and enhance our services.
We use your data to:
Process and Confirm Orders: To verify your identity, validate payment information, confirm order details, process payment transactions through secure gateways, generate order confirmations, allocate inventory, and initiate order fulfillment processes. This includes validating shipping addresses, calculating taxes and shipping charges, applying discounts or promotional codes, and creating order records in our system.
Deliver Products: To coordinate with logistics partners, generate shipping labels, provide delivery addresses to courier services, send shipment tracking information, schedule delivery appointments, handle delivery exceptions, manage return pickups, and ensure timely and accurate product delivery to your specified location.
Provide Invoice & Transaction Records: To generate digital invoices, create tax-compliant receipts, maintain transaction history, provide order summaries, issue refund receipts, generate GST invoices (where applicable), maintain financial records for accounting purposes, and enable you to download or access your purchase history at any time.
Customize Website Content: To personalize your homepage, show relevant product categories, display location-based content, adjust currency and language settings, remember your preferences, customize navigation menus, and tailor the overall website experience based on your browsing history, location, and account settings.
Solve Technical Issues: To diagnose website or app problems, troubleshoot payment failures, resolve login issues, fix delivery tracking problems, address account access problems, investigate transaction errors, and provide technical support. This includes analyzing error logs, reviewing user-reported issues, and working with technical teams to resolve platform bugs or glitches.
Improve Features & Functionality: To identify areas for platform enhancement, develop new features based on user needs, optimize existing features, improve search functionality, enhance checkout processes, streamline navigation, add new payment options, improve mobile app performance, and implement user-requested improvements.
Account Management: To create and maintain your user account, manage login credentials, handle password resets, verify email addresses and phone numbers, manage account settings, process account updates, handle account deactivation requests, and maintain account security.
Customer Support Services: To respond to your inquiries, resolve complaints, process return and refund requests, handle warranty claims, provide product information, assist with order modifications, answer billing questions, and deliver comprehensive customer service through various communication channels.
Quality Assurance & Testing: To test new features before launch, conduct user experience testing, perform quality checks on order processing, verify payment gateway integrations, test delivery workflows, and ensure platform reliability and performance across different devices and browsers.
Performance Monitoring & Optimization: To monitor website performance, analyze server response times, identify slow-loading pages, optimize database queries, improve page load speeds, reduce bounce rates, enhance mobile responsiveness, and ensure optimal platform performance for all users.
Inventory Management: To track product availability, manage stock levels, predict demand based on browsing patterns, optimize inventory allocation, prevent overselling, manage pre-orders, and ensure products are available when you need them.
Fraud Prevention & Security: To detect and prevent fraudulent transactions, verify user identity, monitor suspicious account activity, protect against unauthorized access, implement security measures, conduct risk assessments, and maintain platform security to protect both you and our business.
Legal & Regulatory Compliance: To comply with applicable laws and regulations, maintain records as required by tax authorities, respond to legal requests, fulfill regulatory obligations, maintain audit trails, and ensure compliance with consumer protection laws, data protection regulations, and e-commerce guidelines.
Communication & Notifications: To send order confirmations, shipping updates, delivery notifications, payment confirmations, account-related alerts, security notifications, service updates, and important platform announcements to keep you informed about your orders and account status.
Analytics & Business Intelligence: To analyze user behavior patterns, measure service effectiveness, generate business insights, make data-driven decisions, identify trends, optimize business operations, and improve overall service delivery based on aggregated and anonymized usage data.
Service Excellence: The use of your data for service delivery and improvement is fundamental to providing you with a high-quality e-commerce experience. We continuously strive to optimize our services, enhance platform functionality, and deliver exceptional customer satisfaction. All data usage is conducted in compliance with applicable privacy laws and our commitment to protecting your personal information.
Data Minimization: We only collect and use the minimum amount of personal information necessary to deliver and improve our services. We regularly review our data collection practices to ensure we are not collecting more information than required, and we delete or anonymize data that is no longer needed for service delivery or improvement purposes, subject to legal retention requirements.
2.2 Personalization & Recommendation
We leverage advanced analytics, machine learning algorithms, and behavioral data to create a personalized shopping experience tailored specifically to your preferences, interests, and shopping patterns. Our personalization engine analyzes your browsing history, purchase behavior, search patterns, and interaction data to deliver relevant product recommendations, customized content, and targeted offers that match your unique preferences.
Personalization helps you discover products you're likely to be interested in, saves you time by showing relevant content upfront, and enhances your overall shopping experience. We use a combination of collaborative filtering, content-based filtering, and hybrid recommendation algorithms to provide accurate and diverse product suggestions across various categories and price ranges.
We analyze usage data and shopping patterns to personalize:
Home Page Suggestions: Personalized product carousels, featured products based on your interests, trending items in your preferred categories, recently viewed items, "You may also like" sections, and dynamic homepage layouts that adapt to your shopping behavior and preferences
Discounts & Promotions: Targeted discount offers on products you've viewed or wishlisted, personalized promotional codes, flash sale notifications for items in your interest categories, price drop alerts for saved items, exclusive deals based on your purchase history, and seasonal offers relevant to your shopping patterns
Search Results: Personalized search result rankings based on your preferences, search autocomplete suggestions tailored to your history, search filters pre-applied based on your past selections, "People who searched for this also viewed" recommendations, and search result relevance optimization based on your click patterns
Category-Wise Recommendations: Product recommendations within each category page based on your browsing history, "Frequently Bought Together" suggestions, "Complete the Look" recommendations, brand recommendations based on your preferences, and category-specific personalized content
Product Detail Page Personalization: "Customers who viewed this also viewed" suggestions, "Frequently bought together" product bundles, "You may also like" recommendations, similar product suggestions, alternative product options, and personalized product reviews and ratings display
Email & Notification Personalization: Personalized email newsletters with product recommendations, targeted promotional emails based on your interests, abandoned cart recovery emails with personalized product suggestions, back-in-stock notifications for wishlist items, and personalized push notifications on mobile apps
Browsing Experience Customization: Customized navigation menus showing your frequently visited categories, personalized category order, favorite brands section, recently browsed categories, and quick access to your preferred product types
Price Range Personalization: Product suggestions within your preferred price ranges, budget-based recommendations, price filter preferences, and value-for-money suggestions based on your purchase history
Style & Preference Matching: Fashion and style recommendations for apparel, color preferences for home decor, size recommendations based on past purchases, brand affinity matching, and lifestyle-based product suggestions
Seasonal & Occasion-Based Recommendations: Festive season product suggestions, occasion-based recommendations (birthdays, anniversaries, weddings), seasonal product recommendations, and time-based shopping suggestions
Cross-Category Recommendations: Product suggestions across different categories based on your interests, complementary product recommendations, lifestyle-based cross-selling, and discovery of new product categories you might like
Mobile App Personalization: Personalized app home screen, customized push notification content, location-based recommendations, app-specific personalized features, and mobile-optimized recommendation displays
Wishlist & Cart Personalization: Recommendations for items similar to your wishlist products, suggestions to complete your cart, bundle offers for items in your cart, and personalized reminders for saved items
Content & Editorial Personalization: Personalized blog content, relevant articles and guides, style tips based on your preferences, how-to guides for products you own, and curated content collections matching your interests
How Personalization Works:
Behavioral Analysis: We analyze your browsing patterns, click behavior, time spent on product pages, scroll depth, and interaction patterns to understand your interests and preferences
Purchase Pattern Recognition: We identify patterns in your purchase history, including preferred categories, brands, price ranges, and product types to predict future purchase interests
Collaborative Filtering: We use algorithms that identify users with similar preferences and recommend products that similar users have purchased or shown interest in
Content-Based Filtering: We analyze product attributes, descriptions, and features to recommend products similar to those you've previously viewed or purchased
Machine Learning Models: We employ advanced machine learning algorithms that continuously learn from your behavior and improve recommendation accuracy over time
Real-Time Personalization: We update recommendations in real-time based on your current browsing session, ensuring that suggestions remain relevant as your interests evolve
Multi-Factor Analysis: We combine multiple data points including browsing history, purchase history, search queries, wishlist items, reviews, ratings, and demographic information to create comprehensive user profiles for accurate personalization
Your Control: You have full control over personalization features. You can clear your browsing history, remove items from your wishlist, adjust your preferences in account settings, opt-out of personalized recommendations, or disable personalization features entirely. However, disabling personalization may result in a less tailored shopping experience. You can also provide explicit feedback on recommendations to help improve their accuracy.
Privacy & Data Protection: All personalization is conducted using aggregated behavioral data and does not involve sharing your personal information with third parties for recommendation purposes. We use anonymized and pseudonymized data where possible, and all personalization algorithms operate within our secure systems. Your personal information remains protected, and we do not use sensitive personal data (such as financial information or government IDs) for personalization purposes.
2.3 Advertising & Marketing
We use your information to deliver relevant advertising, promotional offers, and marketing communications that align with your interests and preferences. Our marketing activities are designed to keep you informed about new products, special offers, discounts, and platform updates that may be of value to you. We are committed to conducting all marketing activities in a transparent, ethical, and legally compliant manner, with full respect for your privacy preferences and choices.
All marketing communications are sent only with your explicit consent or in accordance with applicable laws. We provide clear and easy-to-use opt-out mechanisms, and we honor your preferences immediately upon receiving your request. We do not engage in spam, unsolicited marketing, or deceptive advertising practices.
We may send marketing communications, but only:
With Your Explicit Consent: We obtain your consent before sending marketing communications through clear opt-in mechanisms, checkboxes during account registration, preference centers, or explicit consent forms. We maintain records of your consent and respect your choice to opt-in or opt-out at any time.
With Unsubscribe Options: Every marketing email, SMS, and push notification includes clear and prominent unsubscribe links or instructions. You can opt-out through email unsubscribe links, SMS reply with "STOP", account settings, customer support, or our preference center. Unsubscribe requests are processed immediately, typically within 24-48 hours.
With Transparent Purpose: All marketing communications clearly identify Flint & Thread as the sender, include our contact information, state the purpose of the communication, and provide transparent information about how to opt-out. We do not use misleading subject lines, false claims, or deceptive marketing practices.
With Relevant Content: Marketing communications are tailored to your interests, preferences, and shopping behavior to ensure relevance. We use your browsing history, purchase patterns, and preferences to send you offers and promotions that are likely to be of interest to you.
With Frequency Controls: We respect your preferences regarding communication frequency. You can choose to receive daily, weekly, monthly, or no marketing communications. We also limit the number of marketing messages sent within a specific time period to avoid overwhelming you.
With Channel Preferences: You can choose your preferred communication channels (email, SMS, push notifications, in-app messages) and opt-out of specific channels while remaining subscribed to others. We honor your channel preferences and do not send marketing through channels you've opted out of.
With Legal Compliance: All marketing activities comply with applicable laws and regulations, including the Information Technology Act, 2000, Consumer Protection Act, 2019, and relevant advertising standards. We do not send marketing to minors without parental consent, and we comply with Do Not Disturb (DND) registry requirements for SMS marketing.
Types of Marketing Communications We Send:
Promotional Emails: Newsletters featuring new products, special offers, discount codes, flash sales, seasonal promotions, and exclusive deals tailored to your interests
SMS Marketing: Text messages with promotional offers, order updates with promotional content, flash sale alerts, and time-sensitive deals (only with explicit consent and DND compliance)
Push Notifications: Mobile app notifications about new products, personalized offers, cart reminders, wishlist item availability, and promotional campaigns
In-App Marketing: Banner advertisements, promotional pop-ups, featured product sections, and marketing content within the mobile app or website
Retargeting & Display Advertising: Personalized advertisements on third-party websites and platforms based on your browsing behavior (using cookies and tracking technologies, with opt-out options available)
Social Media Marketing: Targeted advertisements on social media platforms, sponsored posts, and promotional content in your social media feeds based on your interests and interactions with our platform
Abandoned Cart Recovery: Emails and notifications reminding you about items left in your shopping cart, with personalized product suggestions and special offers to encourage purchase completion
Product Recommendations: Marketing communications featuring personalized product recommendations based on your browsing and purchase history
Loyalty Program Communications: Information about loyalty program benefits, reward points, exclusive member offers, and program updates
Event & Campaign Notifications: Invitations to special events, contests, surveys, feedback programs, and participation in marketing campaigns or promotional activities
How We Use Your Data for Marketing:
Segmentation: We segment customers based on demographics, purchase history, browsing behavior, preferences, and engagement patterns to deliver targeted marketing campaigns
Personalization: We personalize marketing content, product recommendations, and offers based on your interests, past purchases, and browsing behavior to increase relevance
Campaign Optimization: We analyze campaign performance, open rates, click-through rates, conversion rates, and engagement metrics to optimize marketing effectiveness and improve future campaigns
Timing Optimization: We analyze your engagement patterns to determine optimal times to send marketing communications, ensuring messages reach you when you're most likely to engage
A/B Testing: We conduct A/B testing on marketing messages, subject lines, content, and design to identify the most effective marketing approaches
Cross-Channel Marketing: We coordinate marketing messages across different channels (email, SMS, push, in-app) to create a cohesive marketing experience while respecting your channel preferences
Attribution & Analytics: We track marketing campaign effectiveness, measure return on investment, analyze customer acquisition costs, and attribute sales to specific marketing campaigns for business intelligence and optimization
Your Marketing Preferences: You have complete control over marketing communications. You can manage your preferences through your account settings, unsubscribe from specific types of communications, opt-out of all marketing, or change your communication frequency and channel preferences at any time. Opting out of marketing communications will not affect transactional communications (order confirmations, shipping updates, account-related notifications) which are essential for service delivery.
Third-Party Advertising & Data Sharing: We may share aggregated and anonymized data with trusted advertising partners and marketing service providers to deliver relevant advertisements and measure campaign effectiveness. However, we do not sell your personal information to third parties for their marketing purposes. Any third-party advertising is conducted in compliance with applicable privacy laws, and you can opt-out of third-party advertising through your account settings or by using industry-standard opt-out mechanisms such as the Digital Advertising Alliance's opt-out page or your device's advertising ID settings.
2.4 Fraud Prevention & Security
Protecting your personal information, financial data, and account security is our top priority. We employ comprehensive fraud prevention and security measures to safeguard your data, prevent unauthorized access, detect fraudulent activities, and maintain the integrity of our platform. Your information plays a crucial role in these security efforts, enabling us to identify and prevent potential threats, verify legitimate users, and protect both you and our platform from various forms of fraud, cyberattacks, and misuse.
We use advanced security technologies, machine learning algorithms, behavioral analytics, and real-time monitoring systems to detect and prevent fraudulent activities. Our multi-layered security approach includes identity verification, transaction monitoring, device fingerprinting, anomaly detection, and continuous threat assessment to ensure a secure shopping environment for all users.
Security purposes include:
Account Verification & Authentication: To verify your identity during account creation, login attempts, password resets, and sensitive operations. We use email verification, phone number verification, OTP (One-Time Password) authentication, two-factor authentication (2FA), biometric verification (where available), and security questions to ensure only authorized users can access accounts.
Fraud Detection & Prevention: To detect and prevent various types of fraud including payment fraud, account takeover attempts, identity theft, fake account creation, fraudulent transactions, chargeback fraud, refund abuse, coupon code abuse, and other deceptive practices. We use machine learning models, pattern recognition, and real-time fraud scoring to identify suspicious activities.
Unauthorized Login Prevention: To detect and prevent unauthorized access attempts, brute force attacks, credential stuffing attacks, session hijacking, and account compromise. We monitor login patterns, IP addresses, device information, location data, and behavioral indicators to identify and block suspicious login attempts.
Monitoring of Suspicious Activities: To continuously monitor platform activity for suspicious patterns, unusual behavior, anomalies, and potential security threats. This includes monitoring transaction patterns, browsing behavior, account activity, payment methods, shipping addresses, and other indicators that may signal fraudulent or malicious activity.
Transaction Security: To verify the legitimacy of transactions, validate payment methods, detect unusual spending patterns, prevent duplicate transactions, identify stolen payment card usage, and ensure transactions are authorized by legitimate account holders.
Device & Network Security: To identify and authenticate devices used to access your account, detect compromised devices, prevent access from suspicious networks or locations, implement device-based security measures, and protect against malware and phishing attacks.
Identity Verification: To verify user identities for high-value transactions, sensitive operations, account recovery, and compliance with Know Your Customer (KYC) requirements. This may include document verification, address verification, and additional identity checks when necessary.
Risk Assessment & Scoring: To assess the risk level of transactions, accounts, and activities using risk scoring algorithms. High-risk activities may trigger additional verification steps, manual review, or temporary restrictions to protect users and the platform.
Security Incident Response: To investigate security incidents, data breaches, unauthorized access attempts, and security threats. We analyze security logs, audit trails, and forensic data to understand incidents, mitigate damage, and prevent future occurrences.
Compliance & Regulatory Security: To comply with security requirements under applicable laws, regulations, and industry standards including the Information Technology Act, 2000, Payment Card Industry Data Security Standard (PCI-DSS), and other data protection regulations.
Behavioral Analysis: To analyze user behavior patterns, establish baseline behaviors, detect deviations from normal patterns, identify account sharing or unauthorized usage, and flag activities that may indicate account compromise or fraudulent behavior.
IP Address & Location Monitoring: To track and analyze IP addresses, geographic locations, and network information to detect suspicious login locations, identify VPN or proxy usage, detect location spoofing, and prevent access from high-risk regions or known malicious IP addresses.
Payment Method Validation: To verify payment methods, validate card information, check for stolen or compromised payment cards, verify billing addresses, and ensure payment methods are legitimate and authorized for use.
Security Audit & Compliance: To conduct security audits, vulnerability assessments, penetration testing, compliance reviews, and security certifications. We maintain security logs, audit trails, and documentation required for security compliance and incident investigation.
Security Technologies & Measures We Employ:
Encryption: End-to-end encryption for data transmission, encryption at rest for stored data, SSL/TLS protocols for secure connections, and encryption of sensitive information including passwords and payment data
Access Controls: Role-based access control, multi-factor authentication, strong password requirements, session management, and privileged access management to ensure only authorized personnel can access sensitive data
Firewalls & Network Security: Advanced firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), DDoS protection, and network segmentation to protect against external threats
Security Monitoring: 24/7 security monitoring, real-time threat detection, automated alerting systems, security information and event management (SIEM), and continuous security assessment
Fraud Detection Systems: Machine learning-based fraud detection, rule-based fraud prevention, behavioral analytics, anomaly detection, and real-time fraud scoring systems
Secure Infrastructure: Secure cloud infrastructure, regular security updates and patches, vulnerability management, secure coding practices, and infrastructure hardening
Incident Response: Comprehensive incident response plans, security breach notification procedures, forensic investigation capabilities, and rapid response teams to address security incidents
Your Role in Security: While we implement comprehensive security measures, you also play an important role in protecting your account. We recommend using strong, unique passwords, enabling two-factor authentication, not sharing your login credentials, being cautious of phishing attempts, keeping your devices secure, and immediately reporting any suspicious activity to our security team. If you notice any unauthorized access or suspicious activity on your account, please contact us immediately at support@flintandthread.com or call +91-9063499092.
Data Protection & Privacy: All security and fraud prevention activities are conducted in compliance with applicable privacy laws and data protection regulations. We use only the minimum necessary information for security purposes, implement appropriate safeguards to protect your data, and ensure that security measures do not unnecessarily infringe on your privacy. Security-related data is retained only as long as necessary for security purposes, fraud prevention, and legal compliance, after which it is securely deleted or anonymized.
2.5 Legal Compliance
As a registered business entity operating in India, Flint & Thread (India) Private Limited is subject to various laws, regulations, and legal obligations that require us to collect, process, maintain, and disclose certain information. We process your personal data to comply with applicable legal requirements, respond to lawful requests from government authorities, fulfill regulatory obligations, and maintain records as required by law.
Our legal compliance activities are conducted in accordance with applicable laws and regulations, and we ensure that any data processing for legal compliance purposes is done with appropriate safeguards, transparency, and respect for your privacy rights. We only process the minimum necessary information required to fulfill our legal obligations.
We process data to comply with:
Tax Laws & Regulations: To comply with the Income Tax Act, 1961, Goods and Services Tax (GST) Act, 2017, and other tax-related legislation. This includes maintaining records of transactions, generating tax-compliant invoices, filing tax returns, providing transaction data to tax authorities, maintaining records of sales, purchases, and payments, calculating and remitting taxes, and responding to tax notices or assessments. We retain financial and transaction records as required by tax laws (typically 6-7 years).
Regulatory Orders & Directives: To comply with orders, directives, and regulations issued by various regulatory authorities including the Ministry of Consumer Affairs, Food and Public Distribution, Reserve Bank of India (RBI), Securities and Exchange Board of India (SEBI), Competition Commission of India (CCI), and other relevant regulatory bodies. This includes providing information as required by regulatory orders, maintaining records as mandated, and complying with sector-specific regulations applicable to e-commerce businesses.
Investigation Requests: To respond to lawful requests from law enforcement agencies, courts, tribunals, investigating authorities, and government bodies conducting investigations, inquiries, or legal proceedings. This includes providing information in response to court orders, search warrants, subpoenas, investigation notices, and other legally binding requests. We verify the legitimacy of such requests and provide information only when legally required and after appropriate legal review.
Audits & Compliance Reviews: To facilitate internal audits, external audits, statutory audits, tax audits, compliance audits, and regulatory inspections. This includes providing access to records, transaction data, financial information, and operational data as required by auditors, chartered accountants, tax consultants, and regulatory inspectors. We maintain comprehensive records and documentation to support audit requirements.
Consumer Protection Laws: To comply with the Consumer Protection Act, 2019, and related consumer protection regulations. This includes maintaining records of consumer complaints, product information, warranty details, return and refund records, and providing information to consumer courts or consumer protection authorities when required.
Data Protection Regulations: To comply with the Information Technology Act, 2000, Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and other data protection laws. This includes implementing security measures, maintaining data processing records, responding to data subject requests, and fulfilling obligations under applicable data protection regulations.
E-Commerce Regulations: To comply with e-commerce guidelines, marketplace regulations, and online business requirements issued by the Government of India and relevant ministries. This includes maintaining seller information, product listings, transaction records, and providing information as required by e-commerce regulations.
Anti-Money Laundering (AML) & Know Your Customer (KYC): To comply with AML regulations and KYC requirements for high-value transactions, suspicious activity reporting, and customer due diligence. This includes verifying customer identities, maintaining KYC documents, reporting suspicious transactions, and complying with AML obligations where applicable.
Court Orders & Legal Proceedings: To comply with orders issued by courts, tribunals, and quasi-judicial bodies. This includes providing information in civil cases, criminal investigations, commercial disputes, intellectual property matters, and other legal proceedings where we are required to produce records or provide testimony.
Statutory Reporting Requirements: To fulfill statutory reporting obligations including filing annual returns, maintaining statutory registers, providing information to Registrar of Companies (ROC), and complying with Companies Act, 2013 requirements for corporate entities.
Export-Import Regulations: To comply with export-import laws, customs regulations, and international trade requirements when applicable. This includes maintaining records of cross-border transactions, providing customs documentation, and complying with trade regulations.
Labor & Employment Laws: To comply with labor laws, employment regulations, and workplace safety requirements. This includes maintaining employee records, processing payroll information, and fulfilling obligations under applicable labor legislation (for employee data processing).
Industry-Specific Regulations: To comply with industry-specific regulations applicable to products sold on our platform, including food safety regulations, pharmaceutical regulations, textile labeling requirements, electronics standards, and other product-specific compliance requirements.
How We Handle Legal Requests:
Verification of Requests: We verify the legitimacy and legal validity of all requests before providing information. We ensure requests are properly authorized, legally binding, and issued by competent authorities.
Scope Limitation: We provide only the minimum information necessary to comply with legal requirements and limit disclosure to the specific scope of the request. We do not provide more information than legally required.
User Notification: Where legally permissible and not prohibited by law or court order, we may notify users about legal requests for their information, unless such notification would compromise an investigation or is prohibited by law.
Legal Review: We conduct appropriate legal review of requests to ensure compliance with applicable laws, protect user privacy rights, and ensure requests are valid and enforceable.
Documentation: We maintain records of all legal requests received, information provided, and compliance actions taken for audit and accountability purposes.
Privacy Protection: Even when complying with legal requests, we take measures to protect user privacy, minimize data disclosure, and ensure that information is used only for the stated legal purpose.
Legal Compliance & Your Rights: While we are obligated to comply with legal requirements, we also respect your privacy rights and strive to balance legal compliance with privacy protection. We process data for legal compliance purposes only when necessary and in accordance with applicable laws. You have the right to be informed about legal requests affecting your data (where permitted by law), and you may have rights to challenge or appeal certain legal requests through appropriate legal channels.
Data Retention for Legal Compliance: We retain certain information for extended periods as required by law, including tax records (typically 6-7 years), financial records, transaction data, and other information necessary for legal compliance. Legal retention requirements may override standard data retention policies. After the legal retention period expires, we securely delete or anonymize the information unless there are ongoing legal proceedings or other legal requirements for continued retention.
We never sell your data. We only share it with trusted partners under strict confidentiality.
3.1 Logistics & Delivery Partners
To ensure timely and accurate delivery of your orders, we share necessary delivery information with trusted logistics and courier service partners. These partners are essential for fulfilling orders and providing you with reliable shipping services. We work only with reputable, certified logistics companies that have demonstrated commitment to data security, service quality, and customer privacy.
All logistics partners are bound by strict confidentiality agreements, non-disclosure agreements (NDAs), and data protection obligations. They are contractually required to use shared information solely for delivery purposes, maintain appropriate security measures, and not use your information for any other purpose without your explicit consent. We regularly audit our logistics partners to ensure compliance with our privacy and security standards.
Shared Data:
Recipient Name: Full name of the person receiving the delivery, as provided during order placement, to ensure proper delivery and identification
Delivery Address: Complete shipping address including street address, apartment/unit number, building name, locality, city, state, postal/ZIP code, and landmark details (if provided) necessary for accurate delivery
Contact Phone Number: Primary contact number for delivery coordination, delivery attempt notifications, delivery confirmation, and communication with delivery personnel
Alternate Phone Number: Secondary contact number (if provided) for backup communication in case primary number is unreachable
Order Contents & Product Details: Information about products being delivered including product names, quantities, product descriptions, package dimensions, weight, special handling instructions (if fragile, perishable, etc.), and order value for insurance and customs purposes
Order Reference Number: Unique order ID, tracking number, and order reference for tracking and delivery coordination
Delivery Instructions: Special delivery instructions provided by you such as preferred delivery time, delivery location preferences (front door, reception, etc.), security gate codes, and any specific delivery requirements
Delivery Preferences: Preferred delivery date/time windows, delivery method preferences (standard, express, scheduled), and any delivery-related preferences you've specified
Package Information: Package dimensions, weight, number of packages, packaging type, and shipping labels necessary for logistics processing
Return/Exchange Information: For return pickups or exchanges, we share return authorization details, pickup address, return reason, and product information necessary for return logistics
Delivery Status Updates: Information shared back from logistics partners including delivery status, delivery attempts, delivery confirmation, signature (if required), and delivery-related issues or exceptions
How Logistics Partners Use This Information:
Delivery Processing: To process shipments, generate shipping labels, route packages, coordinate delivery schedules, and ensure accurate delivery to the specified address
Communication: To contact you regarding delivery attempts, delivery confirmations, delivery issues, rescheduling requests, and delivery-related inquiries
Tracking Services: To provide real-time tracking information, delivery status updates, estimated delivery times, and shipment location updates
Proof of Delivery: To obtain delivery confirmation, capture signatures (where required), take delivery photos (if applicable), and maintain delivery records
Exception Handling: To handle delivery exceptions such as failed delivery attempts, address issues, recipient unavailability, damaged packages, and delivery disputes
Return Processing: To coordinate return pickups, process return shipments, handle exchange deliveries, and manage reverse logistics
Compliance & Documentation: To maintain delivery records, comply with shipping regulations, provide customs documentation (for international shipments), and fulfill regulatory requirements
Security & Privacy Safeguards:
Confidentiality Agreements: All logistics partners sign comprehensive NDAs and confidentiality agreements prohibiting unauthorized use or disclosure of your information
Data Minimization: We share only the minimum information necessary for delivery purposes and do not share sensitive information such as payment details, account passwords, or other non-delivery related data
Secure Data Transmission: Information is shared through secure, encrypted channels and protected during transmission to logistics partners
Access Controls: Logistics partners implement access controls to ensure only authorized personnel can access delivery information
Data Retention Limits: Logistics partners are contractually required to retain delivery information only for the period necessary for delivery and record-keeping purposes, after which it must be securely deleted
Prohibition on Secondary Use: Logistics partners are strictly prohibited from using your information for marketing, advertising, or any purpose other than order delivery without your explicit consent
Regular Audits: We conduct regular audits and assessments of logistics partners to ensure compliance with privacy and security requirements
Your Privacy Rights: You have the right to know which logistics partner is handling your delivery, and you can contact us if you have concerns about how your information is being used by logistics partners. We are committed to ensuring that your information is protected throughout the delivery process, and we take immediate action if any logistics partner fails to meet our privacy and security standards.
International Shipments: For international deliveries, we may share additional information required for customs clearance, including product descriptions, values, country of origin, and customs documentation. This information is shared only with authorized customs brokers and international shipping partners, and is necessary for compliance with international trade regulations and customs requirements.
3.2 Payment Gateways
To process your payments securely and efficiently, we work with PCI-DSS (Payment Card Industry Data Security Standard) compliant payment gateway service providers. These payment gateways handle the actual processing of credit card, debit card, UPI, net banking, wallet, and other payment method transactions on our behalf. We share only the minimum information necessary for payment processing, and all sensitive payment data is handled directly by the payment gateways using industry-standard encryption and security measures.
All payment gateway partners are certified, regulated financial service providers that comply with strict security standards, data protection regulations, and banking regulations. They are contractually bound to maintain the highest levels of security, protect your payment information, and use shared data solely for payment processing purposes. We work only with trusted, reputable payment gateway providers that have demonstrated commitment to security and compliance.
Shared Data:
Transaction Amount: The total transaction value including product cost, taxes, shipping charges, discounts applied, and final payable amount necessary for payment processing and authorization
Order Information: Order reference number, order ID, order date, and order details required for transaction reconciliation and payment tracking
Payment Method Details: Type of payment method selected (credit card, debit card, UPI, net banking, wallet, COD), payment method identifier (last 4 digits of card, UPI ID, wallet name), and payment method metadata necessary for processing
Billing Information: Billing name, billing address, billing email, and billing phone number required for payment verification, fraud prevention, and transaction authorization
Payment Confirmation: Payment status (successful, failed, pending), transaction ID, payment gateway reference number, authorization code, payment timestamp, and payment confirmation details
Refund Details: For refunds and returns, we share refund amount, refund reason, original transaction reference, refund request details, and refund processing information necessary for processing refunds through the original payment method
Customer Information: Customer name, email address, and phone number for payment verification, transaction notifications, and customer support related to payment issues
Currency Information: Transaction currency, currency conversion rates (for international transactions), and currency-related metadata for multi-currency payment processing
Payment Metadata: Payment gateway-specific metadata, transaction routing information, merchant account details, and payment processing parameters necessary for transaction execution
Transaction Status Updates: Real-time payment status updates, payment failure reasons, retry information, and payment gateway notifications shared back to us for order processing and customer communication
What We DO NOT Share with Payment Gateways:
Complete Card Numbers: Full credit or debit card numbers are never shared with us or stored on our servers. Card numbers are entered directly on secure payment gateway pages
CVV/CVC Codes: Card security codes are never shared with us. They are entered directly on payment gateway pages and are not stored
PINs & Passwords: ATM PINs, net banking passwords, UPI PINs, and wallet passwords are never shared with us. They are handled exclusively by payment gateways and banks
Account Details: Complete bank account numbers, IFSC codes, and other sensitive banking information are not shared unless specifically required for certain payment methods (like NEFT/RTGS) and only with your explicit consent
Non-Payment Data: We do not share product details, delivery addresses, shopping history, or other non-payment related information with payment gateways unless specifically required for payment processing or fraud prevention
How Payment Gateways Use This Information:
Payment Processing: To process payment transactions, authorize payments, verify payment methods, execute fund transfers, and complete payment transactions securely
Fraud Prevention: To detect and prevent fraudulent transactions, verify transaction legitimacy, perform risk assessments, and protect against payment fraud using advanced fraud detection algorithms
Transaction Authorization: To authorize payments with issuing banks, card networks, UPI providers, and other financial institutions, and obtain payment approval or decline decisions
Payment Verification: To verify payment methods, validate billing information, perform address verification (AVS), and ensure payment authenticity
Refund Processing: To process refunds, reverse transactions, credit funds back to original payment methods, and handle refund-related communications with banks and financial institutions
Transaction Reconciliation: To reconcile transactions, generate payment reports, maintain transaction records, and provide settlement information for accounting and financial reconciliation
Compliance & Reporting: To comply with banking regulations, financial reporting requirements, anti-money laundering (AML) obligations, and regulatory compliance requirements applicable to payment processors
Customer Support: To provide payment-related customer support, resolve payment issues, handle payment disputes, and assist with payment-related inquiries
Security & Privacy Safeguards:
PCI-DSS Compliance: All payment gateways are PCI-DSS Level 1 certified, ensuring the highest standards of payment data security and compliance with international payment security standards
End-to-End Encryption: All payment data is encrypted during transmission using SSL/TLS protocols and encrypted at rest using industry-standard encryption algorithms
Tokenization: Payment gateways use tokenization to replace sensitive payment data with secure tokens, reducing the risk of data exposure
Secure Payment Pages: Payment processing occurs on secure, hosted payment pages operated by payment gateways, ensuring that sensitive payment information never passes through our servers
Access Controls: Payment gateways implement strict access controls, multi-factor authentication, and role-based access to ensure only authorized personnel can access payment data
Regular Security Audits: Payment gateways undergo regular security audits, vulnerability assessments, and compliance reviews to maintain security standards
Data Minimization: Payment gateways collect and store only the minimum information necessary for payment processing and regulatory compliance
Prohibition on Secondary Use: Payment gateways are contractually prohibited from using your payment information for marketing, advertising, or any purpose other than payment processing without your explicit consent
Incident Response: Payment gateways have comprehensive incident response plans and are required to notify us immediately of any security incidents or data breaches affecting payment data
Payment Security: Your payment information is processed through secure, PCI-DSS compliant payment gateways that employ bank-level security measures. We never have access to your complete card numbers, CVV codes, or payment passwords. All payment transactions are encrypted and processed on secure servers. If you have concerns about payment security or notice any unauthorized transactions, please contact us immediately at support@flintandthread.com or call +91-9063499092.
Payment Gateway Partners: We work with multiple payment gateway providers to offer you various payment options. Some of our payment gateway partners may include Razorpay, PayU, Instamojo, Cashfree, and other authorized payment service providers. Each payment gateway operates under its own privacy policy and terms of service, which we recommend you review. However, all payment gateways we work with are required to meet our security and privacy standards and comply with applicable regulations.
3.3 Third-party Service Providers
To provide you with comprehensive e-commerce services, we work with various third-party service providers who assist us in operating our platform, delivering services, and enhancing functionality. These service providers perform specialized functions that are essential for our business operations, and we share only the minimum information necessary for them to perform their services.
All third-party service providers are carefully vetted, contractually bound by strict confidentiality agreements, non-disclosure agreements (NDAs), and data protection obligations. They are required to implement appropriate security measures, use information solely for the specified service purposes, and comply with applicable privacy laws. We regularly monitor and audit our service providers to ensure compliance with our privacy and security standards.
Third-party Service Providers Include:
SMS/Email Service Providers: Companies that facilitate sending transactional SMS, OTP messages, email notifications, marketing emails, and other communications. We share recipient contact information (phone numbers, email addresses), message content, and delivery status information. Examples include Twilio, MessageBird, SendGrid, Mailchimp, and similar communication service providers.
Cloud Hosting & Infrastructure Providers: Cloud service providers that host our website, applications, databases, and data storage systems. We share data necessary for hosting, backup, disaster recovery, and infrastructure management. Examples include AWS (Amazon Web Services), Google Cloud Platform, Microsoft Azure, and similar cloud infrastructure providers.
Customer Support Vendors: Third-party customer support service providers, helpdesk software providers, and customer service platforms that assist in managing customer inquiries, support tickets, and customer communications. We share customer contact information, inquiry details, support ticket information, and communication history.
Advertising Networks & Marketing Platforms: Digital advertising platforms, marketing automation tools, and advertising networks that help us deliver targeted advertisements and measure marketing effectiveness. We share aggregated and anonymized behavioral data, advertising identifiers, and marketing campaign data. Examples include Google Ads, Facebook Ads, programmatic advertising platforms, and marketing analytics tools.
Data Analytics Partners: Analytics service providers that help us analyze website traffic, user behavior, platform performance, and business metrics. We share aggregated and anonymized usage data, analytics identifiers, and performance metrics. Examples include Google Analytics, Adobe Analytics, Mixpanel, and similar analytics platforms.
Security & Fraud Prevention Services: Security service providers, fraud detection platforms, and cybersecurity companies that help us protect the platform, detect fraud, and maintain security. We share transaction data, behavioral patterns, device information, and security-related data necessary for fraud prevention and security monitoring.
Content Delivery Networks (CDN): CDN providers that help deliver website content, images, videos, and other media files quickly to users. We share content files, user location data (for optimal content delivery), and CDN-related metadata.
Search & Recommendation Engines: Service providers that power our search functionality, product recommendations, and personalization features. We share product data, user preferences, search queries, and behavioral data necessary for search and recommendation services.
Social Media Integration Services: Social media platforms and integration services that enable social login, social sharing, and social media features. We share authentication information, social profile data (with your consent), and social interaction data.
Review & Rating Platforms: Third-party review platforms and rating services that help collect, manage, and display product reviews and ratings. We share product information, customer information (with consent), and review content.
Inventory Management Systems: Inventory management and warehouse management system providers that help manage product inventory, stock levels, and warehouse operations. We share product data, inventory information, and order details necessary for inventory management.
Accounting & Financial Software: Accounting software providers, financial management platforms, and bookkeeping services that help manage financial records, generate reports, and maintain accounting data. We share transaction data, financial information, and accounting-related data necessary for financial management.
Backup & Disaster Recovery Services: Backup service providers and disaster recovery solutions that help maintain data backups and ensure business continuity. We share data necessary for backup and recovery operations.
Other Specialized Service Providers: Other third-party service providers that perform specialized functions such as image processing, document management, translation services, quality assurance testing, and other operational services necessary for platform functionality.
How Third-party Service Providers Use Information:
Service Delivery: To provide the specific services they are contracted to perform, such as sending communications, hosting data, processing analytics, or delivering advertisements
Service Improvement: To improve their services, optimize performance, enhance functionality, and provide better service quality (using aggregated and anonymized data where possible)
Technical Operations: To maintain and operate their technical infrastructure, ensure service availability, perform maintenance, and handle technical issues
Compliance & Legal: To comply with applicable laws, respond to legal requests, and fulfill regulatory obligations applicable to their services
Security & Fraud Prevention: To implement security measures, detect fraud, prevent abuse, and protect against security threats
Analytics & Reporting: To generate analytics reports, provide insights, measure service effectiveness, and create business intelligence (using aggregated data where possible)
Security & Privacy Safeguards:
Strict NDAs & Confidentiality Agreements: All service providers sign comprehensive non-disclosure agreements and confidentiality agreements that prohibit unauthorized use, disclosure, or sharing of your information
Data Processing Agreements: We enter into data processing agreements (DPAs) with service providers that define their obligations, data protection requirements, security standards, and limitations on data use
Security Requirements: Service providers are contractually required to implement appropriate security measures, encryption, access controls, and security practices to protect your information
Data Minimization: We share only the minimum information necessary for service providers to perform their functions, and we regularly review data sharing to ensure minimization
Purpose Limitation: Service providers are contractually prohibited from using your information for any purpose other than providing the contracted services
Prohibition on Secondary Use: Service providers are strictly prohibited from using your information for their own marketing, advertising, or other commercial purposes without your explicit consent
Data Retention Limits: Service providers are required to retain information only for the period necessary to provide services, after which they must securely delete or return the information
Sub-processor Controls: Service providers are required to obtain our approval before engaging sub-processors and ensure sub-processors meet the same security and privacy standards
Regular Audits & Assessments: We conduct regular audits, security assessments, and compliance reviews of service providers to ensure they meet our standards
Incident Notification: Service providers are contractually required to immediately notify us of any security incidents, data breaches, or privacy violations affecting your information
Right to Audit: We retain the right to audit service providers' security practices, data handling procedures, and compliance with contractual obligations
Service Provider Accountability: While we work with trusted third-party service providers, we remain responsible for protecting your personal information. We carefully select service providers based on their security practices, privacy commitments, and compliance track records. If you have concerns about how a service provider is handling your information, please contact us at support@flintandthread.com. We take immediate action if any service provider fails to meet our privacy and security standards.
Service Provider Privacy Policies: Each third-party service provider operates under its own privacy policy and terms of service. While we require service providers to meet our privacy and security standards, we recommend that you review their privacy policies to understand how they handle information. However, our contractual agreements with service providers ensure that they cannot use your information in ways that violate our privacy commitments to you, even if their own policies might allow broader use.
3.4 Legal or Government Authorities
As a law-abiding business entity operating in India, Flint & Thread (India) Private Limited may be required to disclose your personal information to legal authorities, government agencies, regulatory bodies, courts, and law enforcement agencies when legally obligated to do so. We take our legal obligations seriously and comply with lawful requests while also protecting your privacy rights to the maximum extent permitted by law.
We carefully review all legal requests to ensure they are valid, legally binding, and issued by competent authorities. We provide only the minimum information necessary to comply with legal requirements and take measures to protect your privacy even when responding to legal requests. We may challenge or seek clarification on requests that appear overly broad, invalid, or not properly authorized.
Information may be shared if required for:
Crime Investigation: To assist law enforcement agencies, police departments, investigating authorities, and crime investigation units in investigating criminal activities, fraud, cybercrimes, financial crimes, identity theft, and other illegal activities. This includes providing information in response to First Information Reports (FIRs), investigation notices, and lawful investigation requests from authorized law enforcement agencies.
Court Orders & Legal Proceedings: To comply with orders, judgments, decrees, and directions issued by courts, tribunals, quasi-judicial bodies, and judicial authorities. This includes providing information in response to summons, subpoenas, court orders, writ petitions, and other legally binding court directives in civil cases, criminal cases, commercial disputes, and other legal proceedings.
Tax Proceedings & Tax Authorities: To comply with requests from tax authorities including the Income Tax Department, Goods and Services Tax (GST) authorities, and other tax regulatory bodies. This includes providing transaction records, financial information, customer data, and other information required for tax assessments, tax audits, tax investigations, and compliance with tax laws including the Income Tax Act, 1961, and GST Act, 2017.
National Security Reasons: To comply with requests from national security agencies, intelligence agencies, and government bodies when required for national security, public safety, or prevention of terrorism. This includes responding to requests from authorized security agencies in accordance with applicable laws and regulations.
Regulatory Compliance: To comply with requests from regulatory authorities including the Ministry of Consumer Affairs, Reserve Bank of India (RBI), Competition Commission of India (CCI), Securities and Exchange Board of India (SEBI), and other sector-specific regulatory bodies for regulatory compliance, investigations, and enforcement actions.
Consumer Protection Authorities: To provide information to consumer courts, consumer protection authorities, and consumer dispute resolution forums when required for consumer protection proceedings, complaint investigations, and consumer dispute resolution.
Anti-Money Laundering (AML) & Financial Intelligence: To comply with AML regulations and provide information to Financial Intelligence Unit (FIU), banks, and financial institutions when required for suspicious transaction reporting, AML compliance, and financial crime prevention.
Intellectual Property Enforcement: To provide information in response to requests related to intellectual property infringement, trademark violations, copyright disputes, and other IP-related legal matters when required by law or court orders.
Data Protection Authorities: To respond to inquiries, investigations, and enforcement actions by data protection authorities, privacy regulators, and information technology regulatory bodies regarding data protection compliance and privacy violations.
Corporate Affairs & Company Law: To comply with requests from the Registrar of Companies (ROC), Ministry of Corporate Affairs, and company law authorities for corporate compliance, statutory filings, and company law investigations.
Customs & International Trade: To provide information to customs authorities, Directorate General of Foreign Trade (DGFT), and international trade regulatory bodies for customs clearance, export-import compliance, and international trade investigations.
Other Statutory Authorities: To comply with requests from other statutory authorities, government departments, and regulatory bodies when legally required, including labor departments, environmental authorities, and other sector-specific regulatory bodies.
How We Handle Legal Requests:
Request Verification: We verify the legitimacy, validity, and legal authority of all requests before providing information. We ensure requests are properly authorized, legally binding, issued by competent authorities, and comply with applicable legal procedures.
Legal Review: We conduct appropriate legal review of all requests, consult with legal counsel when necessary, and ensure requests are valid and enforceable before responding. We may seek clarification or challenge requests that appear invalid or overly broad.
Scope Limitation: We provide only the minimum information necessary to comply with legal requirements and limit disclosure to the specific scope of the request. We do not provide more information than legally required.
User Notification: Where legally permissible and not prohibited by law, court order, or investigation requirements, we may notify users about legal requests for their information. However, we may be prohibited from notifying users in certain circumstances such as ongoing criminal investigations, national security matters, or when notification would compromise an investigation.
Documentation: We maintain comprehensive records of all legal requests received, information provided, legal review conducted, and compliance actions taken for audit, accountability, and legal defense purposes.
Privacy Protection: Even when complying with legal requests, we take measures to protect user privacy, minimize data disclosure, ensure information is used only for the stated legal purpose, and implement appropriate safeguards.
Challenging Requests: We may challenge, seek clarification, or appeal legal requests that appear invalid, overly broad, not properly authorized, or violate privacy rights, where legally permissible and appropriate.
Cooperation with Authorities: We cooperate with legal authorities in good faith while ensuring that requests are valid, legally binding, and comply with due process requirements. We balance legal compliance with privacy protection.
Legal Compliance & Your Rights: While we are obligated to comply with lawful requests from legal and government authorities, we also respect your privacy rights and strive to protect your information. We carefully review all legal requests, provide only necessary information, and take measures to protect your privacy. You have the right to be informed about legal requests affecting your data (where permitted by law), and you may have rights to challenge or appeal certain legal requests through appropriate legal channels. If you believe a legal request is invalid or violates your rights, you may seek legal advice or file appropriate legal challenges.
Transparency & Accountability: We are committed to transparency in our handling of legal requests while respecting legal restrictions on disclosure. We maintain records of legal requests and may publish transparency reports (where legally permissible) to provide information about the number and types of legal requests we receive. We comply with all applicable laws regarding legal requests while also advocating for privacy rights and due process protections for our users.
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, enforce our agreements, and protect our legitimate business interests. Our data retention practices are designed to balance the need to provide you with services, maintain business records, comply with legal requirements, and respect your privacy rights.
Different types of information are retained for different periods based on their purpose, legal requirements, and business needs. We regularly review our data retention practices and securely delete or anonymize information that is no longer needed, subject to legal retention requirements and ongoing business needs.
We retain your information only as long as:
Your Account is Active: We retain your account information, profile data, preferences, and account-related information for as long as your account remains active. If you deactivate or delete your account, we will delete or anonymize your personal information within a reasonable period (typically 30-90 days), subject to legal retention requirements and ongoing business needs such as order history for warranty purposes.
Required by Law: We retain certain information for extended periods as required by applicable laws and regulations. This includes tax records (typically 6-7 years under Income Tax Act, 1961), financial records, transaction data, GST records (typically 6 years), consumer protection records, and other information required by various statutes. Legal retention requirements may override standard data retention policies.
Necessary for Resolving Disputes: We retain information related to disputes, complaints, legal proceedings, and ongoing investigations until disputes are resolved, legal proceedings are concluded, or until the applicable limitation period expires (typically 3-7 years depending on the nature of the dispute). This includes order disputes, payment disputes, return/refund disputes, and other customer service issues.
Required for Audits: We retain financial records, transaction data, accounting records, and audit-related information for the period required by auditing standards, tax laws, and regulatory requirements (typically 6-7 years). This includes records necessary for internal audits, external audits, tax audits, and regulatory inspections.
Ongoing Business Relationships: We retain information necessary for ongoing business relationships, such as order history for warranty claims, product support, repeat customer service, and maintaining business continuity. This includes purchase history, product information, and transaction records that may be needed for future service delivery.
Legal Proceedings: We retain information that may be relevant to ongoing or potential legal proceedings, investigations, or regulatory actions until such proceedings are concluded and all appeal periods have expired.
Security & Fraud Prevention: We retain security logs, fraud detection records, and security-related information for extended periods (typically 1-3 years) to maintain security, prevent fraud, investigate security incidents, and protect against future threats.
Consent-Based Retention: For information collected based on your consent (such as marketing preferences), we retain the information until you withdraw consent or until it is no longer needed for the consented purpose.
Data Retention Periods by Category:
Account Information: Retained while account is active, and for 30-90 days after account deletion (subject to legal requirements)
Transaction & Financial Records: Retained for 6-7 years as required by tax laws and accounting standards
Order & Purchase History: Retained for 3-7 years for warranty, support, and business purposes, or as required by law
Communication Records: Retained for 1-3 years for customer service and dispute resolution purposes
Marketing & Behavioral Data: Retained until you opt-out or until no longer needed for marketing purposes (typically 2-3 years)
Security & Fraud Records: Retained for 1-3 years for security and fraud prevention purposes
Legal & Compliance Records: Retained as required by applicable laws, typically 3-7 years depending on the specific legal requirement
Anonymized Data: Aggregated and anonymized data may be retained indefinitely for statistical, analytical, and business intelligence purposes, as it no longer identifies individuals
Data Deletion & Anonymization:
Secure Deletion: When data is no longer needed, we securely delete it using industry-standard secure deletion methods that ensure data cannot be recovered. This includes permanent deletion from active systems, backup systems, and archived storage.
Anonymization: Instead of deletion, we may anonymize data by removing personally identifiable information, making it impossible to identify individuals. Anonymized data may be retained for statistical and analytical purposes.
Account Deletion: When you request account deletion, we will delete or anonymize your personal information within 30-90 days, subject to legal retention requirements. Some information may be retained in anonymized form for business analytics.
Third-Party Data Deletion: We request third-party service providers to delete your information when it is no longer needed, in accordance with our contractual agreements and data processing agreements.
Backup Retention: Information in backup systems may be retained for a limited period (typically 30-90 days) for disaster recovery purposes, after which it is securely deleted.
Your Right to Deletion: You have the right to request deletion of your personal information at any time, subject to legal retention requirements. We will honor deletion requests and delete your information within a reasonable period (typically 30-90 days), except where we are legally required to retain the information (such as tax records, transaction records, or information related to ongoing disputes). To request deletion, please contact us at support@flintandthread.com or call +91-9063499092.
Exceptions to Deletion: Certain information may be retained even after deletion requests if required by law (tax records, financial records), necessary for ongoing legal proceedings, required for dispute resolution, necessary for fraud prevention, or if retention is necessary to protect our legal rights or the rights of others. We will inform you if any information cannot be deleted and explain the reason for retention.
5. DATA PROTECTION MEASURES
Protecting your personal information is our highest priority. Flint & Thread (India) Private Limited implements comprehensive, multi-layered data protection measures using industry-leading security technologies, best practices, and continuous monitoring to safeguard your data against unauthorized access, data breaches, cyberattacks, and other security threats. We employ a defense-in-depth security strategy that combines technical, administrative, and physical security controls to protect your information at every level.
Our security measures are regularly updated, tested, and enhanced to address evolving threats and maintain the highest standards of data protection. We comply with international security standards and best practices, and we continuously invest in security infrastructure, technologies, and expertise to protect your information.
We use industry-grade security including:
SSL/TLS Encryption: End-to-end encryption using Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols (TLS 1.2 and above) to encrypt all data transmitted between your device and our servers. This ensures that your information cannot be intercepted or read during transmission. We use 256-bit encryption for maximum security.
Data Encryption at Rest: All sensitive data stored in our databases and storage systems is encrypted at rest using Advanced Encryption Standard (AES-256) encryption. This protects your information even if physical storage media is compromised.
Firewalls & Network Security: Advanced firewall systems, intrusion detection systems (IDS), intrusion prevention systems (IPS), and network segmentation to protect our network infrastructure from external threats, unauthorized access, and cyberattacks. We implement both hardware and software firewalls with strict access control rules.
24×7 Security Monitoring: Continuous, round-the-clock security monitoring using Security Information and Event Management (SIEM) systems, automated threat detection, real-time alerting, and security operations center (SOC) monitoring to detect and respond to security threats immediately.
Secure Servers & Infrastructure: Secure, hardened servers hosted in certified data centers with physical security controls, environmental controls, redundant power systems, and disaster recovery capabilities. We use cloud infrastructure providers that meet international security standards including ISO 27001, SOC 2, and other certifications.
Two-Factor Authentication (2FA) Support: Multi-factor authentication options including SMS-based OTP, email-based verification, authenticator app support, and biometric authentication (where available) to add an extra layer of security to account access and sensitive operations.
Regular Security Audits: Comprehensive security audits, vulnerability assessments, penetration testing, and security reviews conducted by internal security teams and independent third-party security firms. We perform regular security assessments to identify and remediate vulnerabilities.
Access Controls & Authentication: Role-based access control (RBAC), strong password requirements, password hashing using bcrypt/argon2, session management, privilege escalation controls, and regular access reviews to ensure only authorized personnel can access sensitive data.
Secure Coding Practices: Secure software development lifecycle (SDLC), code reviews, security testing, input validation, output encoding, and protection against common vulnerabilities (OWASP Top 10) to ensure our applications are secure by design.
DDoS Protection: Distributed Denial of Service (DDoS) protection, traffic filtering, rate limiting, and network-level protections to prevent service disruptions and ensure platform availability.
Data Backup & Disaster Recovery: Regular automated backups, encrypted backup storage, off-site backup replication, disaster recovery plans, and business continuity measures to ensure data availability and recovery in case of incidents.
Vulnerability Management: Regular vulnerability scanning, patch management, security updates, and timely remediation of identified security vulnerabilities to maintain a secure environment.
Security Incident Response: Comprehensive incident response plans, security breach notification procedures, forensic investigation capabilities, and rapid response teams to quickly detect, contain, and remediate security incidents.
Employee Security Training: Regular security awareness training for employees, security policies and procedures, background checks for personnel with access to sensitive data, and strict confidentiality agreements to ensure human security.
Third-Party Security Assessments: Security assessments of third-party service providers, vendor security reviews, and contractual security requirements to ensure our partners maintain appropriate security standards.
Compliance & Certifications: Compliance with international security standards including ISO 27001 (Information Security Management), PCI-DSS (for payment data), and adherence to security best practices and frameworks.
Additional Security Measures:
Tokenization: Sensitive data is tokenized where possible, replacing actual sensitive values with secure tokens to reduce exposure risk
Data Masking: Sensitive data is masked in non-production environments and logs to prevent accidental exposure
Secure API Endpoints: All API endpoints are secured with authentication, authorization, rate limiting, and encryption
Security Headers: Implementation of security headers (HSTS, CSP, X-Frame-Options, etc.) to protect against common web vulnerabilities
Logging & Audit Trails: Comprehensive logging of security events, access attempts, and system activities for security monitoring and forensic analysis
Physical Security: Physical security controls at data centers including access controls, surveillance, and environmental protections
Security Testing: Regular security testing including penetration testing, vulnerability scanning, code analysis, and security assessments
Security Limitations: While we implement comprehensive security measures and maintain industry-leading security standards, no digital system can guarantee 100% absolute security. The internet and digital technologies inherently carry some security risks. We continuously work to minimize these risks and maintain maximum protection, but we cannot guarantee that your information will be completely secure from all possible threats. We recommend that you also take appropriate security measures on your end, such as using strong passwords, enabling two-factor authentication, keeping your devices secure, and being cautious of phishing attempts.
Security Incident Response: In the unlikely event of a security incident or data breach, we have comprehensive incident response procedures in place. We will immediately investigate the incident, take steps to contain and remediate the threat, notify affected users as required by law, and report the incident to relevant authorities. We will also take measures to prevent similar incidents in the future and provide support to affected users. If you suspect a security issue or notice any suspicious activity, please contact us immediately at support@flintandthread.com or call +91-9063499092.
Under applicable data protection laws, including the Information Technology Act, 2000, and related regulations, you have certain rights regarding your personal information. We are committed to respecting and facilitating the exercise of these rights. This section outlines your privacy rights and how you can exercise them.
You can exercise most of these rights directly through your account settings, or by contacting our Data Protection Officer. We will respond to your requests in a timely manner and in accordance with applicable laws. Some rights may be subject to legal limitations or exceptions, which we will explain if applicable.
You have the right to:
Access Your Data (Right to Information): You have the right to request and receive a copy of your personal information that we hold, including account information, order history, transaction records, communication history, preferences, and any other personal data we have collected about you. You can access most of this information through your account dashboard, or request a comprehensive data export by contacting us.
Request Corrections (Right to Rectification): You have the right to request correction of inaccurate, incomplete, or outdated personal information. You can update most information directly through your account settings, or request corrections by contacting us. We will verify the accuracy of corrections and update your information promptly.
Request Deletion (Right to Erasure): You have the right to request deletion of your personal information, subject to legal retention requirements. We will delete your information within a reasonable period (typically 30-90 days) after receiving your request, except where we are legally required to retain it (such as tax records, transaction records, or information related to ongoing disputes).
Withdraw Marketing Consent (Right to Object): You have the right to withdraw your consent for marketing communications, personalized advertising, and non-essential data processing at any time. You can opt-out through your account settings, email unsubscribe links, or by contacting us. Withdrawal of consent will not affect the lawfulness of processing based on consent before withdrawal.
Deactivate Your Account: You have the right to deactivate or delete your account at any time. Account deactivation will restrict access to your account, and account deletion will result in deletion of your personal information (subject to legal retention requirements). You can deactivate or delete your account through account settings or by contacting us.
Data Portability: You have the right to receive your personal information in a structured, commonly used, and machine-readable format, and to transmit that information to another service provider. We can provide your data in formats such as JSON, CSV, or PDF for easy transfer.
Restrict Processing: You have the right to request restriction of processing of your personal information in certain circumstances, such as when you contest the accuracy of data, when processing is unlawful, or when you object to processing pending verification of legitimate grounds.
Object to Processing: You have the right to object to processing of your personal information for certain purposes, such as direct marketing, profiling, or processing based on legitimate interests. We will respect your objection unless we have compelling legitimate grounds for processing that override your interests.
Lodge Complaints: You have the right to lodge a complaint with data protection authorities, consumer protection authorities, or other relevant regulatory bodies if you believe your privacy rights have been violated. We will cooperate with any investigation and work to resolve complaints.
Know About Data Sharing: You have the right to know which third parties we share your information with, the purpose of sharing, and the categories of information shared. This information is provided in this Privacy Policy, and you can request additional details by contacting us.
Opt-Out of Cookies: You have the right to opt-out of non-essential cookies and tracking technologies through your browser settings or our cookie preference center. However, disabling essential cookies may affect platform functionality.
Request Information About Processing: You have the right to request information about how we process your personal information, including the purposes of processing, categories of data processed, retention periods, and your rights regarding the data.
How to Exercise Your Rights:
Through Account Settings: Many rights can be exercised directly through your account settings, including updating information, managing preferences, opting out of marketing, and accessing your data
By Contacting Us: You can exercise any of your rights by contacting our Data Protection Officer at support@flintandthread.com or calling +91-9063499092. Please include your account information and specify which right you wish to exercise
Written Requests: For formal requests, you may submit a written request with your identity verification. We may require proof of identity to ensure we are responding to the correct person
Response Time: We will respond to your requests within a reasonable period, typically within 30 days, though complex requests may take up to 60 days. We will inform you if we need additional time
No Fees: Exercising your rights is generally free of charge, unless requests are manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable administrative fee
Appeals: If you are not satisfied with our response to your request, you may appeal or lodge a complaint with relevant data protection or consumer protection authorities
Limitations & Exceptions:
Legal Requirements: Some rights may be limited when we are legally required to retain or process information, such as tax records, transaction records, or information related to ongoing legal proceedings
Legitimate Business Interests: We may continue processing information when necessary for legitimate business interests, contract fulfillment, or legal compliance, even if you object to processing
Third-Party Rights: We may be unable to delete information if it would affect the rights of third parties or if deletion would violate legal obligations
Identity Verification: We may require identity verification before processing certain requests to protect your privacy and prevent unauthorized access to your information
Technical Limitations: Some requests may be subject to technical limitations, such as information stored in backup systems or information that has been anonymized
Exercising Your Rights: We are committed to facilitating the exercise of your privacy rights. If you wish to exercise any of these rights, please contact our Data Protection Officer at support@flintandthread.com or call +91-9063499092. We will process your request promptly and in accordance with applicable laws. We may ask for additional information to verify your identity and ensure we are responding to the correct person.
Children's Rights: If you are a parent or guardian and believe we have collected information from a child under 18 years of age, you have the right to request deletion of that information. We do not knowingly collect information from children under 18, and we will delete such information immediately upon becoming aware of it.
Cookies and similar tracking technologies are small text files or data stored on your device that help us provide you with a secure, personalized, and efficient shopping experience. Cookies enable our platform to remember your preferences, maintain your session, analyze platform usage, and deliver relevant content. We use cookies in compliance with applicable laws and with respect for your privacy choices.
This section provides detailed information about the types of cookies we use, their purposes, how they enhance your experience, and how you can manage your cookie preferences. For comprehensive information about our cookie practices, please also refer to our dedicated Cookies Policy page.
Types of cookies used:
Essential Cookies (Authentication & Security): These cookies are strictly necessary for the platform to function and cannot be disabled. They enable core functionality such as user authentication, session management, security features, shopping cart functionality, and fraud prevention. Essential cookies include session cookies that maintain your login state, security tokens for authentication, and cookies that remember your basic preferences during a session. Without these cookies, you would not be able to log in, make purchases, or use essential platform features.
Performance Cookies (Speed & Optimization): These cookies help us understand how visitors interact with our platform, identify performance issues, and optimize website speed and functionality. They collect information about page load times, error rates, navigation patterns, and user interactions to help us improve platform performance, fix bugs, and enhance user experience. Performance cookies are typically aggregated and anonymized, and they do not personally identify you.
Advertising Cookies (Relevant Ads): These cookies are used to deliver relevant advertisements, measure advertising effectiveness, and personalize marketing content. They track your browsing behavior, interests, and interactions to show you advertisements for products and services that may be of interest to you. Advertising cookies also help us limit the number of times you see the same advertisement and measure the effectiveness of our marketing campaigns. You can opt-out of advertising cookies through your account settings or browser preferences.
Analytics Cookies (User Behavior Analysis): These cookies help us analyze how users interact with our platform, which pages are most popular, how users navigate through the site, and what features are most used. Analytics cookies provide insights that help us improve platform design, optimize user flows, enhance functionality, and make data-driven decisions. The information collected is typically aggregated and anonymized to protect your privacy.
Functional Cookies (Preferences & Customization): These cookies remember your preferences, settings, and choices to provide a personalized experience. They remember your language preferences, currency selection, display settings, location preferences, and other customizations so you don't have to set them every time you visit. Functional cookies enhance your experience by making the platform more convenient and tailored to your preferences.
Social Media Cookies: These cookies are set by social media platforms when you interact with social features on our platform, such as social login, social sharing buttons, or embedded social media content. They enable social media functionality and may track your activity across websites for advertising purposes. These cookies are controlled by the respective social media platforms, and you can manage them through your social media account settings.
How Cookies Enhance Your Experience:
Session Management: Cookies maintain your login session, keep you logged in as you navigate the platform, and remember your authentication state
Shopping Cart Persistence: Cookies remember items in your shopping cart across page visits and browser sessions
Personalization: Cookies enable personalized content, product recommendations, and customized experiences based on your preferences
Performance Optimization: Cookies help us identify and fix performance issues, optimize page load times, and improve overall platform speed
Security: Cookies help detect and prevent fraud, verify user identity, and protect against unauthorized access
Convenience: Cookies remember your preferences and settings, saving you time and making your experience more convenient
Cookie Duration:
Session Cookies: Temporary cookies that are deleted when you close your browser. These are used for session management and temporary preferences
Persistent Cookies: Cookies that remain on your device for a specified period (days, weeks, or months) or until you delete them. These remember your preferences across sessions
First-Party vs. Third-Party Cookies: First-party cookies are set by our platform, while third-party cookies are set by external service providers (such as analytics or advertising partners). We use both types, and you can manage them through browser settings or our cookie preference center
Managing Your Cookie Preferences:
Browser Settings: You can control cookies through your browser settings. Most browsers allow you to block all cookies, block third-party cookies, delete existing cookies, or receive notifications when cookies are set. However, blocking essential cookies may affect platform functionality
Cookie Preference Center: We provide a cookie preference center (where available) that allows you to manage your cookie preferences and opt-out of non-essential cookies while keeping essential cookies enabled
Opt-Out Tools: You can use industry-standard opt-out tools such as the Digital Advertising Alliance's opt-out page, Network Advertising Initiative opt-out, or your device's advertising ID settings to opt-out of targeted advertising cookies
Mobile Device Settings: On mobile devices, you can manage cookies and tracking through your device's privacy settings, advertising ID settings, and app-specific privacy controls
Account Settings: You can manage certain cookie-related preferences through your account settings, including marketing preferences and personalization settings
Cookie Management Impact: Disabling or blocking cookies may affect your experience on our platform. Essential cookies are required for basic functionality, and disabling them may prevent you from logging in, making purchases, or using core features. Non-essential cookies can be disabled without affecting core functionality, but you may miss out on personalized features, recommendations, and optimized experiences. We recommend keeping essential cookies enabled while managing your preferences for other cookie types.
Third-Party Cookies & Tracking: We work with third-party service providers who may set cookies on our platform for analytics, advertising, and other purposes. These third-party cookies are subject to the privacy policies of the respective service providers. We recommend reviewing their privacy policies to understand how they use cookies and tracking technologies. You can opt-out of many third-party cookies through browser settings or industry opt-out mechanisms. For more detailed information about our cookie practices, please visit our Cookies Policy page.
The protection of children's privacy is of utmost importance to us. We are committed to complying with applicable laws and regulations regarding the collection, use, and protection of children's personal information. This section outlines our policies and practices regarding children's privacy, age restrictions, and parental rights.
Our platform is designed for users who are 18 years of age or older. We do not knowingly collect, use, or disclose personal information from children under the age of 18 without appropriate parental consent or as permitted by law. If we become aware that we have collected personal information from a child under 18 without proper authorization, we will take immediate steps to delete such information and terminate the associated account.
Age Restrictions & Account Requirements:
Minimum Age Requirement: You must be at least 18 years old to create an account, make purchases, or use our platform. By creating an account or using our services, you represent and warrant that you are 18 years of age or older
Age Verification: During account registration, we may request age verification information. We reserve the right to request additional proof of age if we have reason to believe an account belongs to a minor
Account Termination: If we discover that an account belongs to a user under 18 years of age, we will immediately terminate the account and delete all associated personal information, subject to legal retention requirements
No Collection from Minors: We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately
Parental Supervision: We strongly encourage parents and guardians to supervise their children's online activities and to teach them about safe internet practices, including not providing personal information online without parental permission
What Happens If We Detect a Minor's Account:
Immediate Account Suspension: Upon detection of an account belonging to a user under 18, we will immediately suspend the account to prevent further use
Data Deletion: We will delete all personal information associated with the account, including account details, order history (if any), preferences, and communication records, subject to legal retention requirements
Notification: If possible and appropriate, we may notify the account holder or their parent/guardian about the account termination and data deletion
Order Cancellation: Any pending orders associated with a minor's account will be cancelled, and refunds will be processed in accordance with our refund policy
Prevention Measures: We implement technical and procedural measures to detect and prevent accounts from being created by minors, including age verification checks and monitoring systems
Parental Rights & Responsibilities:
Right to Review: Parents and guardians have the right to review any personal information we may have collected from their child, if such information was collected in error
Right to Delete: Parents and guardians can request deletion of their child's personal information by contacting us at support@flintandthread.com or calling +91-9063499092
Right to Refuse Further Collection: Parents and guardians can refuse to permit further collection or use of their child's information
Supervision: Parents and guardians are responsible for supervising their children's online activities and ensuring they do not create accounts or make purchases without permission
Education: We encourage parents and guardians to educate their children about online privacy, safe internet practices, and the importance of not sharing personal information online
Reporting: If you believe your child has created an account or provided personal information to us, please contact us immediately so we can take appropriate action
How We Protect Children's Privacy:
Age Verification: We implement age verification measures during account registration to prevent minors from creating accounts
Monitoring Systems: We use automated and manual monitoring systems to detect accounts that may belong to minors
No Targeted Marketing to Minors: We do not knowingly target marketing communications, advertisements, or promotional content to children under 18
Data Minimization: We do not collect more information from users than necessary, and we do not collect information from minors at all
Secure Storage: If we inadvertently collect information from a minor, we store it securely and delete it immediately upon discovery
Compliance: We comply with applicable laws and regulations regarding children's privacy, including the Information Technology Act, 2000, and related rules
Special Considerations:
Gift Purchases: Adults may purchase products as gifts for children, but the account and transaction must be made by an adult (18+)
Family Accounts: If multiple family members use the same account, the account must be registered and managed by an adult (18+)
Educational Use: Educational institutions or organizations may use our platform, but accounts must be created and managed by authorized adult representatives
Third-Party Services: We do not knowingly allow third-party services to collect information from children through our platform
Important Notice for Parents & Guardians: If you believe your child under 18 has created an account on our platform or provided us with personal information, please contact us immediately at support@flintandthread.com or call +91-9063499092. We will promptly investigate and take appropriate action, including account termination and data deletion. We take children's privacy seriously and are committed to protecting minors from unauthorized data collection.
Contact for Children's Privacy Concerns: If you have any questions, concerns, or requests regarding children's privacy, please contact our Data Protection Officer at support@flintandthread.com or call +91-9063499092. We will respond to your inquiry promptly and take appropriate action to address any concerns related to children's privacy.
We may update this Privacy Policy and Terms & Conditions periodically to reflect changes in our practices, services, legal requirements, or for other operational, legal, or regulatory reasons. We are committed to keeping you informed about how we collect, use, and protect your personal information, and we will notify you of any material changes to this policy.
This section explains how we handle policy updates, how we notify you of changes, and what your rights are when policies are updated. We encourage you to review this policy periodically to stay informed about our privacy practices and terms of service.
When We Update This Policy:
Legal or Regulatory Changes: We may update this policy to comply with new laws, regulations, or legal requirements, such as changes to data protection laws, consumer protection regulations, or industry standards
Service Changes: When we introduce new services, features, or functionalities, we may update this policy to explain how we collect and use information related to those new services
Business Changes: If we undergo business changes such as mergers, acquisitions, or restructuring, we may update this policy to reflect new ownership or operational structures
Technology Changes: As we adopt new technologies, data processing methods, or security measures, we may update this policy to reflect these changes
User Feedback: Based on user feedback, questions, or concerns, we may clarify or expand certain sections of this policy to provide better transparency
Best Practices: We may update this policy to align with industry best practices, security standards, or privacy frameworks
How We Notify You of Changes:
Email Notification: For material changes that significantly affect your rights or how we use your information, we will send you an email notification to the email address associated with your account. The email will highlight the key changes and provide a link to the updated policy
In-App/Platform Notification: We may display a prominent notification on our platform or mobile app when significant policy changes are made, alerting you to review the updated policy
Policy Page Updates: All policy changes will be reflected on this page with an updated "Last Updated" date at the top of the policy. We recommend checking this page periodically for updates
Account Dashboard: We may display policy update notifications in your account dashboard or settings page, ensuring you are aware of important changes
Social Media & Communications: For major policy changes, we may announce updates through our social media channels, newsletters, or other communication channels
Effective Date: Each policy update will include an effective date, indicating when the changes take effect. Your continued use of our platform after the effective date constitutes acceptance of the updated policy
What Constitutes Material Changes:
New Data Collection: If we start collecting new types of personal information or collect information for new purposes
Data Sharing Changes: If we change how we share your information with third parties, including new categories of third parties or new sharing purposes
User Rights Changes: If we modify your rights regarding your personal information or how you can exercise those rights
Security Changes: If we make significant changes to our security practices or data protection measures
Retention Changes: If we change how long we retain your personal information
Legal Basis Changes: If we change the legal basis for processing your personal information
Your Rights When Policies Change:
Review Changes: You have the right to review all policy changes and understand how they affect your privacy and rights
Ask Questions: You can contact us at any time to ask questions about policy changes or request clarification on how changes affect you
Withdraw Consent: If policy changes affect your consent for certain data processing activities, you may withdraw your consent as described in the "Your Rights" section
Account Deletion: If you do not agree with policy changes, you have the right to deactivate or delete your account and request deletion of your personal information (subject to legal retention requirements)
Opt-Out: You can opt-out of certain data processing activities that may be affected by policy changes, such as marketing communications or personalized advertising
Lodge Complaints: If you believe policy changes violate your rights or applicable laws, you can lodge a complaint with relevant data protection or consumer protection authorities
Policy Version History:
Version Control: We maintain a version history of policy changes, including effective dates and summaries of key changes. You can request access to previous versions of this policy by contacting us
Change Summaries: For significant updates, we may provide a summary of changes highlighting what has been added, modified, or removed from the previous version
Last Updated Date: The "Last Updated" date at the top of this policy indicates when the most recent changes were made. This helps you identify if you have reviewed the latest version
Archive: Previous versions of this policy may be archived and made available upon request for reference purposes
Continued Use After Changes:
Acceptance: Your continued use of our platform, services, or website after policy changes become effective constitutes your acceptance of the updated policy
Notification Period: We typically provide advance notice (usually 7-30 days) before material policy changes take effect, giving you time to review and understand the changes
Opt-Out Period: If you do not agree with policy changes, you have a reasonable period to opt-out, delete your account, or take other actions before the changes take effect
Grandfathering: In some cases, we may grandfather certain practices for existing users, meaning existing users may continue under previous terms for a transition period, while new users are subject to updated terms
Stay Informed: We encourage you to review this Privacy Policy and Terms & Conditions periodically to stay informed about how we protect your privacy and what terms govern your use of our platform. We will notify you of material changes via email or platform notifications, but you are responsible for reviewing this policy regularly. If you have questions about policy changes or need clarification, please contact us at support@flintandthread.com or call +91-9063499092.
Contact for Policy Questions: If you have questions about policy changes, need clarification on updated terms, or want to request a previous version of this policy, please contact our Data Protection Officer at support@flintandthread.com or call +91-9063499092. We are committed to transparency and will help you understand any changes to this policy.
Contact Us
For any questions, concerns, or requests related to privacy, please contact our Data Protection Officer (DPO):
Company: Flint & Thread (India) Private Limited
Email: support@flintandthread.com
Address: Hyderabad
Acknowledgment
By using our website and services, you acknowledge that you have read and understood this Privacy Policy and agree to its terms. If you do not agree with this policy, please do not use our services.