Privacy Policy
Last updated: —
FREAKFITS ("FreakFits", "we", "us", "our") operates the e-commerce storefront www.freakfits.com. This Privacy Policy is published in accordance with Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), framed under Section 43A of the Information Technology Act, 2000 ("IT Act"), and with the disclosure requirements of the Consumer Protection (E-Commerce) Rules, 2020 framed under the Consumer Protection Act, 2019. It describes what personal information and sensitive personal data or information ("SPDI") we collect, why we collect it, how it is used, disclosed, stored and protected, and the choices and rights available to you.
By accessing the site, creating an account, or placing an order, you consent to the collection and processing of your information as described in this Policy. If you do not agree with this Policy, please do not use the site or provide us your personal information.
1. Definitions
For the purposes of this Policy, and consistent with Rule 3 of the SPDI Rules:
- "Personal Information" means any information that relates to a natural person, which, either directly or indirectly, in combination with other information, is capable of identifying that person — such as your name, email address, mobile number, and shipping address.
- "Sensitive Personal Data or Information" (SPDI) includes, among other things, passwords and financial information such as bank account or card details. FreakFits's own systems collect only your password as SPDI (stored irreversibly hashed — see Section 6). We never receive, process, or store your card, UPI, or bank account details; these are handled entirely by our payment partner, Razorpay, under its own PCI-DSS-compliant systems.
2. Information We Collect
2.1 Information you provide directly
- Account information — full name, email address, mobile number, and a password (SPDI, hashed with bcrypt and never stored or logged in plain text).
- Shipping addresses — full name, phone number, street address, city, state, postal code, and country, for one or more saved delivery addresses.
- Order and customization details — items purchased, sizes, quantities, and any custom jersey name/number you request.
- Reviews — star rating, written comment, and an optional photo, submitted under your authenticated account (never a free-text name, so reviews cannot be posted under a false identity).
- Support, contact-form, and return/exchange submissions — your name, email, the reason for contacting us, your message, and, for returns, mandatory unboxing video proof (uploaded directly, up to 10MB, or a link from YouTube or Google Drive only).
- Newsletter subscription — your email address, if you choose to subscribe.
2.2 Information collected automatically
- Authentication session — a signed session token stored in an HttpOnly, Secure cookie, used to keep you logged in without exposing the token to page scripts.
- Cart and coupon data — items in your cart and any applied coupon, held in your browser if you are not logged in, or against your account on our server if you are.
- One-Time Passcodes (OTPs) — generated to verify your email during registration or password reset. OTPs automatically expire and are never included in any API response or log.
- Basic technical/server logs — standard request data (such as IP address) captured for security monitoring and abuse prevention, as described in our Cookie Policy.
We do not collect any other category of SPDI listed under Rule 3 of the SPDI Rules — such as health data, biometric data, sexual orientation, or physical/mental health records — as none of these are relevant to operating a jersey storefront.
3. Purpose of Collection & Use
In line with Rule 5(2) of the SPDI Rules, we collect and use your information only for identified, lawful purposes connected with our business:
- To create, verify (via OTP), and manage your account.
- To process and fulfil orders — calculating accurate, database-verified prices and stock, accepting payment via Razorpay, and shipping your order.
- To communicate with you: order confirmations, shipping and delivery updates, cancellation and return confirmations, password-reset OTPs, and replies to support enquiries.
- To send marketing/drop-alert emails, only if you've opted in via newsletter subscription; you may unsubscribe at any time.
- To detect, prevent, and investigate fraud, abuse, or unauthorized access — including per-IP rate limiting on login, OTP, checkout, and order-tracking endpoints.
- To maintain an internal, tamper-evident audit trail of administrative actions taken on your order or account, for accountability and dispute resolution.
- To comply with our obligations under Indian tax, accounting, and consumer-protection law.
4. Consent
Per Rule 5(1) of the SPDI Rules, we obtain your consent before collecting SPDI (your password) at the point of registration. You have the right to:
- Not provide certain information. Providing your name, email, mobile number, and password is necessary to create an account and check out; without them, we cannot provide these services. Optional information — such as saved addresses beyond what a single order needs, newsletter subscription, or a review photo — can be withheld without affecting your ability to shop with us.
- Withdraw consent at any time, by writing to us at the contact details in Section 12. Withdrawing consent for account-essential data will mean we can no longer maintain your account or fulfil pending orders tied to it, and may require you to close your account (Section 9).
5. Disclosure of Information to Third Parties
Per Rule 6 of the SPDI Rules, we do not disclose your personal information or SPDI to any third party without your consent, except where disclosure is necessary to perform a contract with you, is required by law, or has been agreed to under a lawful contract with our service providers. We do not sell your personal data. We share data only with the following categories of service providers, strictly for the purpose stated, and each is contractually restricted from using it for any other purpose or disclosing it further:
| Recipient | Purpose | Data shared |
|---|---|---|
| Razorpay | Payment processing | Order amount and contact details needed for the transaction. We never receive or store your card/UPI/bank details. |
| Cloudinary | Image hosting | Product photos and photos you choose to upload with a review. |
| Resend | Transactional email delivery | Your email address and the content of order, OTP, and support emails. |
| Hosting & database infrastructure providers | Running the application | All data in Section 2, as needed to operate the service. |
We may also disclose information where required by an order of a court, government agency, or law enforcement authority acting under lawful authority, or where necessary to investigate fraud or protect the rights, property, or safety of FreakFits, our customers, or the public.
6. Security Practices & Procedures
Per Rule 8 of the SPDI Rules, we maintain reasonable security practices and procedures appropriate to the sensitivity of the information we hold, including:
- Passwords hashed using bcrypt (a slow, salted, one-way algorithm) — never stored or logged in plain text, and never recoverable by us.
- Session authentication via signed JSON Web Tokens delivered in HttpOnly, Secure cookies, inaccessible to page scripts.
- Automatic invalidation of all existing sessions the moment a password is changed, even before the old token's natural expiry.
- HTTPS enforced site-wide via HTTP Strict Transport Security (HSTS), with additional browser-security headers (X-Content-Type-Options, X-Frame-Options, Content-Security-Policy, Referrer-Policy).
- Ownership checks on every customer data endpoint — cart, orders, addresses, wishlist, reviews — so a customer can never view or modify another customer's records.
- Role-based access control across our internal admin systems, with sensitive administrative actions recorded in a tamper-evident audit log.
- Per-IP rate limiting on authentication, OTP, checkout, and order-tracking endpoints to blunt automated attacks.
- OTP codes that expire automatically, are single-use, and are never exposed in an API response or log file.
7. Data Retention
- Account, order, and address data is retained for as long as your account remains active, and thereafter for as long as required to meet our accounting, taxation, and consumer-dispute-resolution obligations under Indian law.
- OTP codes automatically expire within 10–15 minutes of issue.
- Internal administrative audit-log entries are automatically purged after 7 days.
- Return/exchange video proof is deleted once the associated claim is closed.
- Where you request account deletion (Section 9), we retain only the minimum transaction records legally required, and delete the rest.
8. Cookies
We use a limited set of cookies and browser-storage entries necessary to keep you logged in, remember your cart, and secure the site. We do not use third-party advertising or tracking cookies. Full details are in our Cookie Policy, and you can manage optional preferences on our Cookie Preferences page.
9. Your Rights, Account Correction & Deletion
Per Rule 5(6) of the SPDI Rules, you have the right to review and correct the personal information you've provided. You can update your name and mobile number, and manage saved addresses, directly from your Profile page.
You can also permanently delete your FreakFits account from the Profile page. As a safeguard against accidental or unauthorized deletion, this requires you to re-enter your account password to confirm. Once confirmed, deletion is immediate and permanent, and cannot be undone. Specifically:
- Deleted immediately and completely: your cart, wishlist, saved addresses, any reviews you've posted (including photos you uploaded with them, which are also removed from our image storage), and any pending email verification codes tied to your account.
- Your login is deactivated and your session is ended immediately.
- Orders you've placed are not deleted. They are unlinked from your account — you will no longer be able to access them by logging in, and no account will be associated with them going forward — but the order record itself continues to show the name, email address, and phone number you provided at the time of that specific purchase. We retain this because Indian tax, GST, and accounting law requires sellers to preserve complete, unaltered transaction and invoice records for a statutory period, and altering historical financial records after the fact is not permitted. This is the only personal data retained after account deletion, and it is limited to what already exists on past invoices — no new data is collected or added to it.
If you'd like a copy of your personal data before deleting your account, contact us using the details in Section 12 first — this cannot be done after deletion.
10. Children's Privacy
FreakFits is not directed at individuals under the age of 18, and we do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, please contact us and we will take steps to remove it.
11. Data Localization & Cross-Border Transfer
Your information is processed and stored using infrastructure and service providers as described in Section 5. Where any service provider processes data outside India, we take reasonable steps to ensure it is handled under contractual confidentiality and security obligations at least as protective as those described in this Policy.
12. Grievance Redressal
In accordance with Rule 5(9) of the SPDI Rules and Rule 5(3) of the Consumer Protection (E-Commerce) Rules, 2020, we have appointed a Grievance Officer to address any complaints or concerns regarding this Policy or the handling of your personal information.
Grievance Officer: Aritra Das
Email: supportfreakfits@gmail.com
Phone: +91 - 7872245362
Address: 41 Badra Baroaritala Bye Lana, P.O. Italgacha, P.S. DUM DUM, Dist. North 24
Parganas, West Bengal, India, 700 079
We will acknowledge your grievance within 48 hours of receipt and endeavour to redress it within one month from the date of receipt, as required under applicable law.
13. Governing Law
This Policy is governed by the laws of India, including the Information Technology Act, 2000 and the rules framed thereunder, and the Consumer Protection Act, 2019 and rules framed thereunder. Any dispute arising from this Policy is subject to the exclusive jurisdiction of the courts at [City], India.
14. Changes to this Policy
We may revise this Policy from time to time to reflect changes in our practices or in applicable law (including as the Digital Personal Data Protection Act, 2023 and its Rules come into full force). We will update the "Last updated" date at the top of this page whenever we do, and material changes will be highlighted where appropriate.
15. Contact Us
For any questions about this Policy or how your data is handled, write to us via our Contact page, or reach our Grievance Officer directly using the details in Section 12.