Privacy Policy
Last updated 10 May 2026
This policy explains what information we collect when you use Organified, why we collect it, and what we do with it. We try to keep this short and plain — if anything is unclear, message us on WhatsApp at +91 88822 01313.
What we collect
- Account info: name, email, and password hash when you register.
- Order info: shipping address, phone number, and order contents.
- Payment info: we do not store card or UPI details. Razorpay (when live) handles them per their own policy. For COD, no payment data is stored.
- Communication: messages you send us via WhatsApp, email, or the contact form.
- Technical data: IP address, browser, and pages visited — used for site reliability and abuse prevention.
Data collected by the Organified mobile app
The Android app (available on Google Play) collects additional data beyond what the website collects. This section provides the notice required under Section 6 of India’s Digital Personal Data Protection Act 2023 (DPDP Act) and Google Play’s Data Safety requirements.
- Phone number (for OTP login): your mobile number is used as the primary login credential on the app. A one-time password is sent to verify ownership. The phone number is stored against your account and is also already collected for Cash-on-Delivery orders on the website. Purpose: identity verification and secure authentication.
- FCM token (push notifications): when you allow notifications, the app registers a Firebase Cloud Messaging (FCM) token — a random, per-install identifier generated by Google. It is stored in our database linked to your account and is used solely to deliver order-status and promotional push notifications. Purpose: sending you push notifications you have opted into. Retention: the token is deleted when you log out of the device or uninstall the app, or upon account deletion.
- Device metadata: when you register the app, we record your device platform (Android), app version, and the date the device was last active. Purpose: diagnosing compatibility issues and enforcing app-version deprecation policies. Retention: deleted with your device registration (on logout or account deletion).
- Authentication tokens:the app issues short-lived JWT access tokens (stored in the device’s secure keystore, never sent to our servers after issuance) and refresh tokens (stored as a one-way hash in our database). Refresh tokens carry an expiry date and are revoked immediately on logout. Purpose: maintaining a secure login session without requiring repeated OTP entry.
- Firebase Crashlytics & Performance Monitoring (planned):the app is being prepared to integrate Firebase Crashlytics and Firebase Performance Monitoring. Once enabled, these services will collect anonymised crash stack traces, performance metrics, and a Crashlytics installation ID. This section will be updated, and a new “last updated” date will be published, before those features are activated.
How we use it
- To process and ship your orders.
- To send order confirmations, shipping notifications, and reply to your queries.
- To prevent fraud and abuse.
- If you opt in, to send occasional product updates and seasonal offers — you can unsubscribe at any time.
Who we share it with
We share the minimum required data with: courier partners (to deliver your order), payment gateways (Razorpay, when live), and email delivery services (Resend, for transactional emails). We do not sell or rent your data to anyone.
How long we keep it
Account and order records are retained as long as your account is active, plus the period required by Indian tax and accounting laws. You can request deletion of your account at any time — message us on WhatsApp or email hello@organified.com.
Cookies
We use cookies for sign-in sessions and your shopping cart. We don’t use third-party advertising cookies. You can clear cookies in your browser at any time, but you’ll need to sign in again.
Your rights
You can ask us to: show you the data we hold on you, correct anything that’s wrong, or delete your account. We’ll respond within 30 days. Contact us via the channels below.
Withdrawing consent and deleting your data
Under the DPDP Act 2023, you have the right to withdraw consent for data processing at any time. You may also request erasure of your personal data. Here is how:
- Remove a device / disable push notifications: log out of the Organified app on that device. This deregisters the device and revokes the associated FCM token and refresh token immediately.
- Full account deletion: email us at support@organified.com with the subject “Delete my account”. We will erase your personal data (account, addresses, device records, and push tokens) within 30 days, except records we are legally required to retain for tax or accounting purposes.
- Marketing opt-out:reply “STOP” to any marketing message, or email us and we will remove you from all marketing lists immediately.
Data Protection Contact (Grievance Officer)
In accordance with the Information Technology Act 2000 and the DPDP Act 2023, you may direct any grievance regarding the processing of your personal data to:
Grievance / Data Protection Contact
Email: support@organified.com
We will acknowledge your grievance within 48 hours and resolve it within 30 days.
Changes to this policy
If we change this policy in a material way, we’ll update the date at the top and, where appropriate, notify you by email.
Contact
WhatsApp: +91 88822 01313 · Email: hello@organified.com
See also: Terms of Service · Shipping · Returns & Refunds