Privacy Policy
Last updated: July 9, 2026 | Sonh Mart Srinagar
At Sonh Mart, we value your trust and are committed to protecting your personal data. This Privacy Policy details how we collect, use, and secure your information in compliance with the **Digital Personal Data Protection (DPDP) Act, 2023** of India.
๐ 1. Data We Collect
We only collect data necessary to process your grocery orders and coordinate quick deliveries in Srinagar and surrounding areas:
- Phone Number & OTP Authentication: Collected during login to authenticate your session and contact you regarding order issues.
- Delivery Address & Landmarks: Required to transport your order directly to your doorstep.
- GPS Coordinates (Latitude & Longitude): Collected via our interactive map component at checkout to verify your location within our geofenced delivery zones.
- Order & Payment Proof History: Stored to track transaction statuses, verify manual UPI references (UTR), and manage refunds.
โ๏ธ 2. Third-Party Data Processors
We utilize industry-standard cloud partners to store and process your data securely:
- Supabase: Used as our primary cloud database host (for orders, addresses, catalog, and store parameters) protected by Row-Level Security (RLS) policies.
- Firebase: Powering our customer push notification alerts and authentication logic.
These services are strictly processors and do not have authorization to share or utilize your personal information for marketing purposes.
๐ฎ๐ณ 3. DPDP Act Compliance & Consent
In alignment with the Digital Personal Data Protection Act, 2023:
- Consent-Based Processing: We process your data (phone, address, coordinates) only upon your explicit consent at signup and checkout.
- Right to Erasure & Access: You have the right to request access to your stored personal data or request deletion of your account.
- Data Minimization: We do not collect unnecessary data (e.g. we do not record generic browsing behavior outside our storefront or track your location when the app is closed).
๐ 4. Data Security & Retention
We employ SSL/TLS encryption for all api routes and strictly enforce Row-Level Security (RLS) in Supabase. A customer cannot query another customer's address or order details directly.
We retain your data as long as your account remains active. If your account is inactive for more than 24 months, or if you submit a deletion request, we will permanently purge or anonymize your personal records.
๐ฌ 5. Grievance Redressal
If you have any questions, concerns, or requests regarding your data, you can reach out directly to our Grievance Officer via the WhatsApp support chat widget.
