Legal · Privacy

Privacy Policy

How Thriftizer Solutions LLP collects, uses, stores, shares and protects your personal information when you visit thriftizer.com or any associated Shopify store, submit an enquiry, place an order, or interact with our team. We treat your privacy as a contract, not a checkbox.

📅 Last updated · April 28, 2026🛡 Effective immediately ⚖️ Indian Contract Act 1872 🏢 Bangalore jurisdiction

1. Who we are

This Privacy Policy is published by Thriftizer Solutions LLP, a limited liability partnership registered in Bangalore, Karnataka, India (LLP Identification Number AAB-1234, GST registered, principal place of business 4th Floor, JP Nagar, Bangalore 560078). Throughout this policy 'Thriftizer', 'we', 'us', and 'our' refer to Thriftizer Solutions LLP. 'You' refers to any visitor, prospective client, customer, employee of a client, or anyone else who provides personal information to us through this website, our Shopify storefront, our forms, our email at task@thriftizer.in, our WhatsApp business line, or any other channel.

This policy is governed by the Indian Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011, the Digital Personal Data Protection Act 2023, and — where applicable — the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) and the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021).

2. Information we collect

We collect personal information in three broad categories: information you give us directly, information collected automatically when you browse, and information we receive from third parties such as payment processors and analytics providers.

2.1 Information you provide

  • Identity and contact details — full name, business name, email address, phone number, WhatsApp number, postal/billing/shipping address, country, and (where you choose to share it) Skype, LinkedIn or other social handle.
  • Project information — your Shopify store URL, monthly revenue range, current platform (WooCommerce, Magento, Wix, Shopify, BigCommerce, custom), service requirements, project budget, timelines, and any reference assets you share.
  • Account credentials — temporary access tokens or staff accounts you create for us in your Shopify Admin, Meta Business Manager, Google Ads, Klaviyo, Razorpay, Stripe or other tools — strictly for the duration of the engagement.
  • Payment details — for orders we route through Razorpay or Stripe; we never see or store full card numbers, UPI IDs or bank account numbers. We retain only the order ID, last four digits, transaction reference, and GST invoice copy.
  • Communications — emails to task@thriftizer.in, WhatsApp messages on +91 88613 24254, contact form submissions, comments on our blog, and recordings of voluntarily-recorded video calls.

2.2 Information collected automatically

When you visit any Thriftizer-operated site we automatically collect, via cookies and similar technology, the following: IP address, approximate geolocation (country/city), device and browser type, operating system, referrer URL, pages visited, time spent on each page, click and scroll behaviour, and Shopify Analytics events. We use this to operate, secure, and improve the site — not to identify you personally beyond what is necessary.

2.3 Information from third parties

We may receive information about you from: Razorpay and Stripe (payment confirmation, fraud signals), Shopify (Shopify Partner Directory enquiries, your store metadata when you authorise our app), Meta and Google (lead-ad form submissions when you opt in), Clutch, DesignRush and Omnisend (review and partner directory enquiries), and from public sources where you have made information public (LinkedIn, your storefront).

3. How we use your information

We process personal information only when one of the following lawful bases applies:

  • Contract — to deliver the Shopify services you have ordered or are evaluating, including project communication, design and development, marketing campaign management, and post-delivery support.
  • Consent — for marketing emails, WhatsApp updates, blog newsletters, and any non-essential cookies. You can withdraw consent at any time by emailing task@thriftizer.in or clicking 'unsubscribe' in any marketing email.
  • Legitimate interest — to secure the website against fraud and abuse, to invoice and collect payment, to improve our services through analytics, to maintain client records for at least seven years for tax and audit compliance, and to defend or pursue legal claims.
  • Legal obligation — where required by Indian tax law, the Companies Act, the Information Technology Act, or by valid court order in India or the country where you reside.

4. Cookies and similar technologies

We use cookies for three purposes: essential (login state, cart contents, fraud detection — these cannot be disabled if you wish to use the site), analytics (Shopify Analytics, Google Analytics 4 — anonymised page-view and conversion data), and marketing (Meta Pixel and CAPI, Google Ads conversion tag — fired only after you give consent through our cookie banner). You can clear cookies, block third-party cookies, or use Do Not Track in your browser settings; we honour Global Privacy Control headers and treat them as a request to opt out of marketing tracking.

5. How we share your information

We do not sell, rent, or trade personal information to anyone — full stop. We share information only with the following categories of recipients, strictly for the purposes listed:

  • Shopify Inc. (Canada/USA, Privacy Shield-equivalent SCC) — to operate the storefront and process transactions.
  • Razorpay Software Private Limited (India) and Stripe Inc. (USA) — to securely process payments and issue refunds. Both are PCI-DSS Level 1 certified.
  • Omnisend Limited (UK) and Klaviyo Inc. (USA) — to send transactional and marketing emails when you have subscribed.
  • Google LLC, Meta Platforms Inc., LinkedIn Corporation — analytics and advertising platforms, processing aggregated and (where consented) hashed identifier data.
  • Cloud and infrastructure providers — Cloudflare (CDN, DDoS protection), AWS (backup storage), Sentry (error monitoring) — under DPAs that require equivalent protection.
  • Professional advisors — our chartered accountants, GST consultants and lawyers, under strict professional confidentiality.
  • Government authorities — only when legally compelled by a valid Indian or relevant foreign court/regulator order, after exhausting all reasonable challenges and notifying you (unless prohibited).

Where any of these recipients is outside India, we rely on Standard Contractual Clauses, the recipient's certifications (ISO 27001, SOC 2 Type II, PCI-DSS), and our written DPA with them.

6. International data transfers

Your information may be processed in India (our principal place of business), the European Economic Area, the United Kingdom, the United States, Canada, and Singapore (where Shopify, Stripe, Cloudflare and AWS host data). Each transfer is supported by either an Adequacy Decision, Standard Contractual Clauses, or your explicit consent. UAE, KSA, and other GCC clients can request that all production data is mirrored in a Mumbai (ap-south-1) AWS region for added latency and sovereignty benefit.

7. Data retention

We retain personal information only as long as needed for the purpose for which it was collected, plus the minimum statutory retention period:

CategoryRetention period
Active client project dataDuration of engagement + 12 months
Invoices, GST records, payment receipts7 years (Indian Income Tax Act, Sec 44AA)
Marketing consent and email logsUntil you unsubscribe
Website analytics (anonymised)26 months (Google Analytics default)
Customer support emails3 years from last contact
Server access logs90 days

8. How we secure your data

We hold ourselves to a security standard that mirrors what we sell: 256-bit TLS for every connection, encrypted-at-rest databases, role-based access for our team (least privilege), 2FA on every staff account, hardware-key 2FA for admin access to client stores, quarterly penetration testing, automated dependency scanning, and an incident response runbook reviewed twice a year. We will notify you of any personal-data breach affecting you within 72 hours of becoming aware, as required by the DPDP Act and GDPR.

9. Your rights

Depending on the jurisdiction you live in, you have some or all of the following rights — and we honour them globally regardless of jurisdiction unless prohibited:

  • Right to access — request a copy of all personal data we hold about you, in machine-readable format, within 30 days of request.
  • Right to rectification — correct inaccurate or incomplete personal data.
  • Right to erasure ('right to be forgotten') — request deletion of your personal data, subject to retention laws above.
  • Right to restriction — pause processing while a complaint is investigated.
  • Right to data portability — receive your data in a portable JSON or CSV format.
  • Right to object — opt out of marketing, profiling, or processing based on legitimate interest.
  • Right to withdraw consent — at any time, where consent is the lawful basis.
  • Right to complain — file a complaint with the Indian Data Protection Board, the UK ICO, an EU supervisory authority, or your local privacy regulator.

To exercise any of these rights, email task@thriftizer.in with the subject line 'Privacy Request — [your name]'. We will reply within 4 hours during business hours and complete the request within 30 days. We may need to verify your identity for sensitive requests.

10. Children's privacy

Our services and website are intended for a business audience and not directed at children under 18. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently collected such information, please write to us and we will delete it promptly.

11. Changes to this policy

We may update this policy from time to time to reflect changes in law, technology, or our practices. The 'Last updated' date at the top will always show the most recent revision. For material changes that affect your rights, we will email customers on our marketing list and post a banner on this site for at least 30 days before the change takes effect.

12. Contact

For privacy questions or to exercise any right above:

Email: task@thriftizer.in
WhatsApp: +91 88613 24254
Post: Thriftizer Solutions LLP, JP Nagar 4th Phase, Bangalore 560078, India
Reply window: Within 4 hours, Mon–Sat 9 AM – 8 PM IST