Regulatory framework: This Privacy Policy is drafted in accordance with the Information Technology Act, 2000 (Act No. 21 of 2000) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — the currently operative data protection framework in India. It also voluntarily aligns with the principles of the Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023). Note: per Gazette notification G.S.R. 843(E) dated 13 November 2025, the DPDP Act's core Data Fiduciary obligations (Sections 3–17, 28–34, and related provisions) commence on 13 May 2027 and are not yet in force as of the date of this policy. We describe our voluntary alignment with these provisions below in anticipation of that date.

1. Data Fiduciary

Devaura (operated by its proprietor from Ghaziabad, Uttar Pradesh, India) would be classified as a Data Fiduciary within the meaning of Section 2(i) of the Digital Personal Data Protection Act, 2023 ("DPDP Act") once that Act's substantive provisions come into force (see note above). For any data-related queries, contact: care@devaura.co.in.

2. Personal Data We Collect

We collect personal data that you voluntarily provide when you create an account, book a pooja, place a shop order, or contact us. This includes:

Identity data: first name, last name, email address, phone number.

Ritual preference data: gotra, sampradaya, kuladevata, paddhati preference — collected solely for pandit-matching purposes.

Address data: ceremony or delivery address within NCR.

Transaction data: booking IDs, order IDs, payment mode preference (we do not store card numbers or UPI PINs).

Device and usage data: IP address, browser type, pages visited, referrer URL — collected automatically via server logs.

3. Purpose and Lawful Basis

We process your personal data only for lawful purposes disclosed to you at the point of collection, and only where you have given consent or where processing is necessary for the performance of a contract (your booking or order) — consistent with reasonable practices under the IT Act, 2000 and, in anticipation of its commencement, the "lawful purpose" principle under Section 4 of the DPDP Act, 2023. Specifically:

(a) To match you with a paddhati-appropriate pandit and deliver samagri kits.

(b) To send transactional communications (booking confirmations, pandit assignments, reminders).

(c) To process shop orders and arrange delivery.

(d) To respond to your support queries.

(e) To improve our services through aggregated, anonymised usage analytics.

4. Consent

We obtain your free, specific, informed, unconditional, and unambiguous consent at the point of account creation, in line with accepted consent standards and in anticipation of Section 6 of the DPDP Act, 2023 (not yet in force — see note above). You may withdraw consent at any time by writing to care@devaura.co.in. Withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal.

5. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes described above, or as required under applicable law. Booking records are retained for 8 years per the Limitation Act, 1963 (Act No. 36 of 1963). Upon account deletion, personal data is erased within 30 days, except where retention is required by law.

6. Data Principal Rights

In anticipation of Sections 11–14 of the DPDP Act, 2023 (commencing 13 May 2027 — see note above) and consistent with our current practice, you have the right to:

(a) Access — obtain a summary of your personal data and processing activities.

(b) Correction and erasure — request correction of inaccurate data or erasure of data no longer necessary.

(c) Grievance redressal — raise a grievance with our designated contact, who will respond within 30 days.

(d) Nominate — nominate another individual to exercise your rights in the event of your death or incapacity.

7. Data Security

We implement reasonable security safeguards as required under Rule 8 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and in anticipation of Section 8(4) of the DPDP Act, 2023 (not yet in force — see note above). These include encrypted data transmission (TLS 1.2+), access controls, and periodic security reviews.

8. Third-Party Sharing

We share personal data only with:

(a) Pandits on our panel — limited to ceremony-relevant details (name, address, gotra, sampradaya, booking time).

(b) Payment processors — for transaction processing only; we do not share data for marketing purposes.

(c) Legal authorities — where required under applicable Indian law.

We do not sell, rent, or trade your personal data to any third party.

9. Cookies

This website uses localStorage for session management (login state, cart, bookings). We do not use third-party tracking cookies. Google Fonts are loaded from Google servers, subject to Google's privacy policy.

10. Children

Devaura does not knowingly collect personal data from children (persons under 18 years of age). This is our current policy irrespective of the DPDP Act's commencement date; it also anticipates the children's-data provisions under Section 9 of the DPDP Act, 2023 (see note above on commencement). If we become aware that we have collected data from a child without verifiable parental consent, we will delete it promptly.

11. Grievance Officer

For any grievance or data protection query, please contact:

Grievance Officer
Email: care@devaura.co.in
Phone: +91 88888 88888
Response time: within 30 days of receipt.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. Continued use of Devaura after an update constitutes acceptance of the revised policy.