Privacy Policy — Better Shopping Hub
Effective date: 05 September 2026 Last updated: 05 September 2026 Version: 2.0 (replaces version 1.0 dated 30 July 2025)
1. Who we are
Better Shopping Hub is an online store operated by Basil Varghese, sole proprietor, trading as “Better Shopping Hub”, with its place of business at Kakkanad, Kochi 682030, Kerala, India.
References to “we”, “us” and “our” mean that entity. References to “you” mean any person who visits www.bettershoppinghub.com (the “Site”), creates an account, places an order, or otherwise gives us personal data.
Under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”), we are the Data Fiduciary for the personal data described here. Under the GDPR, we act as a data controller.
Contact for anything in this policy:
| Grievance Officer / privacy contact | Basil Varghese |
| Email (primary) | privacy@bettershoppinghub.com |
| Email (alternate) | basilshmm@gmail.com |
| Postal | Better Shopping Hub, Kakkanad, Kochi 682030, Kerala, India |
| Response time | Acknowledged within 48 hours; resolved within 30 days (and in no case later than 90 days) |
This policy is published in English. If you would prefer it in any of the 22 languages listed in the Eighth Schedule to the Constitution of India, write to us at the address above and we will provide a translation.
2. The short version
- We collect what we need to sell you something and deliver it. Nothing more.
- We do not sell your personal data for money.
- We do share limited data with advertising and analytics partners, which some US state laws classify as a “sale” or “share”. You can switch that off — see Section 9.
- We do not store your full card number. Ever.
- You can get a copy of your data, correct it, or have it deleted. Section 8 tells you how.
- If you are under 18, you may not use this Site.
The rest of this document is the detail behind those points.
3. What we collect, itemised
We list this item by item rather than in general terms, as required by Rule 3 of the Digital Personal Data Protection Rules, 2025.
3.1 Data you give us directly
| Data item | When we collect it | Why |
|---|---|---|
| Full name | Account signup, checkout | Identify you; address the order and invoice |
| Email address | Account signup, checkout, newsletter signup | Order confirmations, delivery updates, support replies, marketing (only if you opt in) |
| Mobile number | Checkout, account | Delivery coordination by the courier; OTP login; order status by SMS/WhatsApp if you opt in |
| Shipping address | Checkout | Deliver the order |
| Billing address | Checkout | Invoice and tax records; payment verification |
| Username and password | Account signup | Secure your account. Passwords are stored as salted hashes, never in readable form |
| Payment identifiers | Checkout | Last four digits of the card, card brand, UPI handle or bank name, and the payment gateway’s transaction reference. See Section 3.4 |
| Order and return history | Every purchase | Fulfil orders, process returns and refunds, handle warranty claims, meet tax and accounting law |
| Support messages, review text, survey answers | When you write to us or post them | Resolve your issue; publish reviews you choose to publish |
| GSTIN and business name | Only if you request a GST invoice | Issue a compliant tax invoice |
3.2 Data collected automatically
| Data item | Source | Why |
|---|---|---|
| IP address | Your connection | Security, fraud screening, approximate region for currency and shipping estimates |
| Browser type and version, operating system, device type, screen size, time zone | Your browser | Render the Site correctly; diagnose bugs |
| Pages viewed, products searched, items added to cart, time on page, referring URL | Your activity on the Site | Fix broken journeys, measure which products people actually want, and — only with your consent — personalise recommendations and advertising |
| Cookie and device identifiers | Cookies, local storage, SDKs | See Section 5 |
| Server logs and error traces | Our hosting | Uptime, debugging, abuse detection |
3.3 Data from third parties
- Social login providers (if you sign in with Google or a similar service): your name, email address and profile picture, only where you approve it at the consent screen.
- Payment gateways: whether a transaction succeeded or failed, the reason code, and the risk score they assign.
- Logistics partners: delivery status, delivery attempt notes, and the RTO reason if a shipment comes back.
- Advertising platforms: aggregate campaign performance. We do not buy personal profiles from data brokers.
3.4 What we deliberately do not collect
- Full card numbers, CVV, PIN, expiry, or net banking passwords. Payments are processed entirely on the payment gateway’s own PCI-DSS certified systems. That data never touches our servers.
- Aadhaar, PAN, passport or any government ID, unless a specific tax or customs requirement makes it unavoidable, in which case we will ask you separately and explain why.
- Biometric data, health data, caste, religion, political opinion, or sexual orientation. We have no use for any of it.
- Precise GPS location. We work from the pin code you type in.
4. Why we process your data, and on what legal basis
| Purpose | What it involves | Basis (DPDP Act) | Basis (GDPR, for EEA/UK visitors) |
|---|---|---|---|
| Take and fulfil your order | Payment, packing, shipping, invoicing, delivery updates | Consent / legitimate use for a specified purpose | Performance of a contract |
| Customer support | Answering queries, returns, refunds, replacements | Consent / legitimate use | Contract and legitimate interests |
| Account management | Login, saved addresses, order history | Consent | Contract |
| Fraud prevention and Site security | Risk scoring, rate limiting, blocking abuse | Legitimate use | Legitimate interests |
| Tax, accounting and statutory record-keeping | Retaining invoices and transaction records | Legal obligation | Legal obligation |
| Analytics and Site improvement | Understanding which pages and products work | Consent | Consent (analytics cookies) |
| Marketing emails, SMS and WhatsApp | Newsletters, offers, cart reminders | Consent, given separately and withdrawable | Consent |
| Personalised recommendations and retargeting ads | Showing you products based on what you browsed | Consent | Consent |
We do not use your personal data to train machine learning models that are made available outside Better Shopping Hub.
Automated decisions. Product recommendations and fraud risk scoring are automated. Neither produces a legal effect on you. If an order is held or cancelled by an automated fraud check, you can write to the contact in Section 1 and a person will review it.
5. Cookies and tracking
We group cookies into four categories. You control three of them through the consent banner shown on your first visit, and you can change your mind any time via the Cookie settings link in our footer.
| Category | Examples | Set without consent? |
|---|---|---|
| Strictly necessary | Session, cart contents, login, CSRF token, consent record | Yes — the Site does not work without them |
| Analytics | Google Analytics 4 | No |
| Functional | Language, currency, region, recently viewed | No |
| Advertising | Meta Pixel, Google Ads, retargeting partners | No |
For visitors in the EEA and UK, advertising and analytics tags fire only after consent, using Google Consent Mode v2 signals.
Global Privacy Control. If your browser or extension sends a GPC signal, we treat it as a valid opt-out of the sale or sharing of your personal information and of targeted advertising, and we apply it without asking you to confirm.
Refusing non-essential cookies does not block you from browsing or buying. It only removes personalisation.
6. Who we share data with
We do not sell your personal data for money.
Some of our advertising and analytics arrangements do count as a “sale” or “share” under California and other US state privacy laws, because data flows to a partner who may use it for cross-context behavioural advertising. Section 9 tells you how to stop that.
We share data with the following categories of recipients, each under a written contract that limits them to our instructions:
| Category | What they receive | Named partners |
|---|---|---|
| Payment gateways | Name, email, phone, billing address, amount | Cashfree Payments |
| Logistics and courier partners | Name, phone, shipping address, order contents | Varies by shipment. The courier assigned to your order is named in your dispatch email and tracking link |
| Cloud hosting and storage | All Site data, at rest | Our website hosting provider (India region) |
| Email (transactional and support) | Name, email, order details | Our business email provider, hosted alongside the Site |
| Analytics | Pseudonymised usage and device data | Google Analytics 4 |
| Advertising | Hashed email, device and event data | Meta, Google Ads |
| Professional advisers | Only what is necessary | Accountants, auditors, lawyers |
We also disclose data where the law requires it — a court order, a valid demand from a government agency, a tax authority, or a request under the Information Technology Act — and where we need to establish or defend a legal claim.
If the business is sold, merged, or transferred, your data goes with it. We will tell you before that happens and this policy continues to apply until the new owner publishes its own.
7. How long we keep things
Purpose-based, not indefinite.
| Data | Retention |
|---|---|
| Order, invoice and payment records | 8 years from the end of the financial year, as required by Indian tax and company law |
| Account profile, saved addresses | Until you delete the account, or 3 years of continuous inactivity, whichever is earlier |
| Support tickets and correspondence | 3 years from closure |
| Marketing consent and unsubscribe records | Until consent is withdrawn, plus 3 years to prove the withdrawal was honoured |
| Analytics data | 14 months, then deleted or aggregated |
| Server and security logs | 180 days |
| Cookie consent records | 12 months, then you are asked again |
| Abandoned carts (no order placed) | 90 days |
Where a DPDP retention limit applies to an inactive account, we will send you an email at least 48 hours before deleting your data, so you can log in and keep the account alive if you want to.
8. Your rights
Whoever you are and wherever you are, you can ask us to:
- Give you a copy of the personal data we hold about you, along with a summary of what we do with it and who we have shared it with.
- Correct anything that is wrong, incomplete, out of date or misleading.
- Delete your data, subject to what we are legally required to keep (see Section 7 — we cannot delete tax invoices on request).
- Withdraw consent, at any time, as easily as you gave it. Withdrawing consent does not undo processing that already happened lawfully.
- Raise a grievance with our Grievance Officer, and get a substantive reply.
If you are in India, you additionally have the right to:
- Nominate one or more people to exercise these rights on your behalf if you die or become incapable of exercising them yourself. Email us the nominee’s name and contact details.
- Complain to the Data Protection Board of India if we do not resolve your grievance. You are expected to approach us first.
If you are in the EEA or UK, you additionally have the right to:
- Object to processing based on legitimate interests.
- Ask us to restrict processing while a dispute is being sorted out.
- Receive your data in a portable, machine-readable format.
- Complain to your national supervisory authority.
How to exercise any of this: log in and use Account → Privacy where the option exists, or email the contact in Section 1. We will verify that the request is really coming from you before we act — usually with an email confirmation link, sometimes with an OTP to your registered mobile. We do not charge for this, unless a request is repetitive or clearly excessive.
9. Do Not Sell or Share My Personal Information
If you are a resident of California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, or any other US state with a comprehensive privacy law, you may opt out of the sale or sharing of your personal information and of targeted advertising.
Three ways to do it:
- Use the “Do Not Sell or Share My Personal Information” link in our footer.
- Turn off Advertising cookies in Cookie settings.
- Enable Global Privacy Control in your browser. We detect and honour it automatically.
We do not discriminate against you for exercising any privacy right. Prices, products and service stay the same.
10. Children
The Site is for adults. You must be 18 or older to create an account or place an order.
We do not knowingly collect personal data from anyone under 18. We do not track children, profile them, or serve them behavioural advertising. If we discover that we hold data belonging to a child without verifiable parental or guardian consent, we delete it and cancel any associated account.
If you believe a child has given us data, tell us at the contact in Section 1 and we will act on it.
11. Security
What we actually do:
- TLS 1.2 or higher on every page, not just checkout.
- Passwords stored as salted hashes using a modern algorithm. We cannot read your password and will never ask for it.
- Card data never touches our servers — payments run on the gateway’s PCI-DSS certified infrastructure.
- Access to the admin panel and customer database is limited to staff who need it, protected by two-factor authentication, and logged.
- Encrypted backups, taken regularly and restore-tested.
- Third-party plugins and dependencies patched on a regular schedule.
No system is perfectly secure, and we will not claim otherwise. If a breach affects your personal data, we will notify the Data Protection Board of India and tell you within 72 hours of becoming aware of it. Our notice to you will describe what happened in plain language, what data was involved, what we are doing about it, what you should do, and who to contact.
12. Where your data goes
Our website and business email are hosted on servers located in Mumbai, India. Some of our other service providers — analytics, advertising and payment processing — process data on servers outside India, including in the United States and the European Union.
For those transfers we rely on the provider’s contractual commitments, and, for personal data originating in the EEA or UK, on the European Commission’s Standard Contractual Clauses. We do not transfer personal data to any country that the Central Government has restricted under Section 16 of the DPDP Act.
13. Changes to this policy
We will post any updated version on this page and change the “Last updated” date at the top. Older versions stay available in our policy archive.
If a change materially affects how we use your data, we will email account holders at least 14 days before it takes effect, and where the change requires it, ask for fresh consent rather than assuming it.
14. Grievance redressal
For anything to do with your personal data — a request, a complaint, or a question:
Grievance Officer: Basil Varghese Email: privacy@bettershoppinghub.com (alternate: basilshmm@gmail.com) Post: Better Shopping Hub, Kakkanad, Kochi 682030, Kerala, India
We acknowledge every complaint within 48 hours and aim to resolve it within 30 days, and in no case later than 90 days.
If you are not satisfied with our response, you may escalate to the Data Protection Board of India. Consumers in India may also raise complaints on the National Consumer Helpline (1915) or the e-Daakhil portal.