Privacy Policy
Last updated: October 4, 2025.
At HandyPanda, we are committed to protecting your privacy and ensuring transparency about how we collect, use, and safeguard your personal information. This Privacy Policy explains our practices regarding your data.
1) Who we are
SJARSG MATERIALS PRIVATE LIMITED
First Floor, House No. 746, Panchkula Sector 12
Panchkula, Haryana – 134112, India
Phone: +91 83685 51630
Website: www.handypanda.in
2) What we collect
Account & Identity
- Name
- Phone number (for OTP login)
- Email address (optional)
Delivery & Order Details
- Addresses you provide (house/flat, locality, city, PIN)
- Optional location (approximate or precise) if you allow location access for faster address entry
- Cart contents, orders, invoices, and support interactions
Payments (via Razorpay)
- Order and transaction metadata: order ID, amount, currency, payment status, timestamps
We do not store card numbers, CVV, UPI PIN, or full bank details on HandyPanda systems. Card/UPI/wallet details are entered in and processed by Razorpay on their infrastructure.
Device & Usage (Diagnostics)
- Device information, app version, OS version
- IP address, timestamps, screens viewed, performance logs
- Crash and error logs (to improve reliability)
Communications
- Your preferences for SMS, email, and push notifications
- Support messages (in-app, email, phone, or WhatsApp)
We do not access your photos or camera. If a future feature needs a permission, the app will ask first and explain why.
3) How we use your data
- Provide the Service: OTP login, catalog, orders, delivery, payments, invoices
- Customer support: respond to queries and resolve issues
- Communications: order updates, delivery alerts, service notices, and (if you opt in) offers
- Safety & integrity: prevent fraud and misuse; secure the Service
- Analytics & improvements: understand usage, fix crashes, improve performance
- Legal: comply with laws (e.g., invoicing/GST) and enforce our terms
4) Payments with Razorpay
Razorpay's role
We use Razorpay as our payment processor for cards, UPI, net-banking, and wallets. For payment processing and fraud prevention, Razorpay may act as an independent data controller over certain information it collects directly, and as our processor for some order/transaction data we send.
Information we share with Razorpay
(only as needed to process your payment):
- Your name, email, and phone number
- Billing/shipping address (if required for risk checks or tax invoices)
- Order ID, amount, currency, item summary (generic), and IP/address info relevant to the transaction
Information Razorpay may collect directly
(examples during checkout):
- Card details (handled/tokenised by Razorpay; not stored by HandyPanda)
- UPI VPA or bank account details where applicable
- Device, network, and telemetry data for fraud detection and risk scoring (e.g., device identifiers, browser attributes, geolocation approximations derived from IP)
- One-time passwords (3-D Secure/SCA) and authentication artifacts required by card networks/banks
Security & compliance
Razorpay is PCI-DSS compliant for card processing. Payment pages, SDKs, and APIs used for card entry are provided by Razorpay. HandyPanda does not receive or store your full card number or CVV.
Disputes/chargebacks
If there's a dispute or chargeback, we may share relevant order and contact information with Razorpay, banks, card networks, or law enforcement to investigate and resolve the claim.
Third-party terms. Your use of Razorpay's checkout and services is also subject to Razorpay's own terms and privacy policy.
5) Legal bases / grounds
We process data to perform our contract with you (orders, delivery, payments), based on your consent (e.g., marketing messages, location access), to meet legal obligations (tax records, KYC/AML if required), and for our legitimate interests (security, service improvement, fraud prevention).
6) Sharing your data
We share data only with service providers who help us run HandyPanda, under confidentiality and data-protection commitments:
- Payments: Razorpay (processing, authentication, fraud checks)
- SMS/OTP: Licensed OTP providers (e.g., 2Factor/MSG91)
- Delivery & Logistics: Partners to pick, ship, and deliver orders
- Cloud/Tech: Hosting, analytics, crash reporting, push notifications
- Compliance & Safety: Government/regulators or law enforcement when required by law
- Business transfers: In a merger or reorganisation, data may transfer under this Policy
We do not sell your personal data. We do not share data for third-party advertising, and we do not track you across other companies' apps or sites.
7) Data retention
- Account & order records: retained while your account is active and as required by law (e.g., tax/GST).
- Payment metadata: kept as necessary for accounting, dispute resolution, and fraud prevention.
- Diagnostics/crash logs: retained for a limited period to improve reliability.
- Marketing preferences: until you change preferences or unsubscribe.
Where data is no longer needed, we delete or anonymise it per legal requirements and our policies. Note: Razorpay may retain certain transaction records as required by their legal and regulatory obligations.
8) Your choices & rights
- Access/Update: Edit your profile and saved addresses in the app.
- Delete: Request account deletion; we will remove data not required by law (invoice/financial records may be retained).
Opt-outs:
- Marketing SMS/email: use the unsubscribe link or reply "STOP" (where supported)
- Push notifications: disable in device settings
- Location access: disable in device settings; you can enter addresses manually
If your request concerns data that Razorpay controls (e.g., device fingerprinting or card token data), we may guide you to contact Razorpay directly in addition to us.
9) Children's privacy
Not directed to children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided data, contact us to remove it.
10) Security
We use reasonable technical and organisational measures (encryption in transit, access controls, monitoring) to protect your data. However, no method of transmission or storage is 100% secure.
11) International transfers
Our providers (including Razorpay and cloud vendors) may be located in India or other countries. When data is transferred, we take reasonable steps to ensure protection consistent with this Policy and applicable laws.
12) Third-party links
The app may link to third-party sites (e.g., brand catalogs). Their privacy practices are their own; please review their policies.
13) Changes to this Policy
We may update this Policy to reflect changes in our practices or legal requirements. We'll update the "Last updated" date and, where appropriate, notify you in-app or by email.
Contact Us
If you have questions about this Privacy Policy, please contact us:
SJARSG MATERIALS PRIVATE LIMITED
First Floor, House No. 746, Panchkula Sector 12
Panchkula, Haryana – 134112, India
Phone: +91 83685 51630
Email: info@handypanda.in
