Privacy Policy
Privacy Policy
At Touch And Mend (TAM), we believe self-care should feel simple and safe and that includes how we handle your personal information. This policy explains what data we collect, why we collect it, how we use it, and the rights you have over it.
This Privacy Policy applies to all personal data collected through our website touchandmend.com, our communications, and any purchases you make with us. By using our website, you agree to the practices described in this policy.
Applicable Law: This policy is aligned with India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000, and the rules framed thereunder.
1. Who We Are
Anaso Enterprises is the registered company behind Touch And Mend (TAM), a skincare brand operating through (website). For the purposes of the DPDP Act, Anaso Enterprises is the “Data Fiduciary” — the entity that determines why and how your personal data is processed.
Contact: Anaso Enterprises | info@touchandmend.in
2. What Data We Collect
We collect only what we genuinely need. Here is what that looks like:
A. Information You Give Us Directly
- Name, email address, phone number, and delivery address — when you place an order or create an account
- Payment details — securely processed by third-party payment gateways; we do not store card or UPI credentials
- Messages, queries, or feedback submitted through our contact form or email
B. Information Collected Automatically
- IP address, browser type, device type, and operating system
- Pages visited, time spent on the site, and the source through which you arrived
- Cookies and similar tracking technologies (see Section 6 for details)
C. Information From Third Parties
- If you place an order via a marketplace (e.g., Amazon, Nykaa), we may receive basic order fulfilment data from them
- If you interact with our social media pages, those platforms may share limited data with us as per their own policies
3. Why We Collect Your Data
We process your data only for clear, specific purposes. We do not use your data for anything beyond what is listed here without your knowledge.
- To process and fulfil your orders, including packaging, shipping, and delivery
- To send you order confirmations, shipping updates, and delivery notifications
- To respond to your customer service queries and resolve complaints
- To improve our website experience and understand how people use our products
- To send promotional offers, new launch updates, or skincare tips via email or WhatsApp — only if you have explicitly opted in
- To detect and prevent fraud, abuse, or unauthorised access
- To comply with legal obligations under applicable Indian law
We will never sell, rent, or trade your personal data to third parties for their marketing purposes.
4. Legal Basis for Processing
Under the DPDP Act, we process your data on the following bases:
- Consent: For marketing communications via email or WhatsApp, and for non essential cookies — we ask for your explicit agreement before processing
- Contractual Necessity: To fulfil the order, you have placed with us
- Legitimate Use: For fraud prevention, security, and legal compliance as permitted under the DPDP Act
You can withdraw your consent at any time by contacting us at info@touchandmend.in, using the unsubscribe link in any marketing email, or replying STOP to any WhatsApp marketing message from us.
5. Who We Share Your Data With
We share your data only with parties who need it to help us serve you — and never beyond that.
- Logistics & Courier Partners: To dispatch and deliver your order to your address
- Payment Gateway Providers: To securely process your transaction (e.g., Razorpay, PayU, or similar)
- Analytics Providers: To understand website traffic and improve user experience (e.g., Google Analytics — data is anonymised where possible) • Marketing Platforms: To send you email newsletters or promotional content — only where you have consented
- Meta (WhatsApp Business Platform): If you have opted in to WhatsApp marketing, your phone number and messaging data are processed via Meta’s WhatsApp Business API. Meta processes this data under its own Privacy Policy (whatsapp.com/legal/privacy-policy). We use WhatsApp only to send you brand updates, offers, and order-related information you have consented to receive.
- Legal & Regulatory Authorities: Where required by law, court order, or government direction
All third parties who process your data on our behalf are required to handle it in accordance with applicable law and our instructions.
6. Cookies
Cookies are small text files stored on your device when you visit our website. We use them to make the site work properly and to understand how it is used.
Types of Cookies We Use
- Essential Cookies: Required for the website to function (e.g., your shopping cart, login session). These do not require your consent.
- Analytics Cookies: Help us understand how visitors use our website. We ask for your consent before placing these.
- Marketing Cookies: Used to show you relevant content or offers. We ask for your explicit consent before placing these.
In line with India’s DPDP Act, we will ask for your consent before placing non-essential cookies on your device. You can manage, accept, or decline cookies at any time via the cookie settings on our website or through your browser settings.
Please note that disabling certain cookies may affect your experience on the website (for example, items may not stay in your cart).
7. WhatsApp Marketing
We use WhatsApp as a marketing channel to share product updates, offers, skincare tips, and order-related information with customers who have opted in.
How We Use WhatsApp
- We will only send you WhatsApp messages if you have explicitly opted in — for example, by ticking a consent box at checkout or on a sign-up form
- Messages may include new product launches, promotional offers, restocking alerts, and order or delivery updates
- We will not send unsolicited messages or share your number with third parties for their own marketing
Your WhatsApp Data
- Your phone number is shared with our WhatsApp Business Solution Provider to facilitate message delivery
- Meta (WhatsApp’s parent company) processes message metadata under its own Privacy Policy
- We do not have access to your WhatsApp conversations with others, nor do we store message content beyond what is necessary for the service
How to Opt Out
You can stop receiving WhatsApp messages from us at any time by:
- Replying STOP to any WhatsApp message from TAM
- Contacting us at info@touchandmend.in with your number and opt-out request
Once you opt out, we will remove your number from our WhatsApp marketing list within 48 hours. Please note that transactional messages related to an active order (e.g., shipping confirmation) may still be sent until your order is complete.
We treat WhatsApp as a conversation, not a broadcast. We will keep our messages relevant, infrequent, and easy to opt out of.
8. Your Rights as a Data Principal
Under the Digital Personal Data Protection Act, 2023, you have the following rights:
| Your Right | What It Means |
|---|---|
| Right to Access | Request a copy of the personal data we hold about you |
| Right to Correct | Ask us to update inaccurate or incomplete information |
| Right to Erasure | Request deletion of your data, subject to legal obligations |
| Right to Withdraw Consent | Opt out of marketing or data processing at any time |
| Right to Grievance Redressal | Raise a complaint with us or the Data Protection Board of India |
To exercise any of these rights, write to us at info@touchandmend.in. We will respond within 30 days of receiving your request. In some cases, we may need to verify your identity before processing your request.
If you are not satisfied with our response, you have the right to approach the Data Protection Board of India.
| Your Right | What It Means |
|---|---|
| Right to Access | Request a copy of the personal data we hold about you |
| Right to Correct | Ask us to update inaccurate or incomplete information |
| Right to Erasure | Request deletion of your data, subject to legal obligations |
| Right to Withdraw Consent | Opt out of marketing or data processing at any time |
| Right to Grievance Redressal | Raise a complaint with us or the Data Protection Board of India |
9. How Long We Keep Your Data
We do not keep your data longer than necessary. Here is our general approach:
- Order & transaction data: Retained for 7 years to comply with tax and accounting regulations
- Account information: Retained as long as your account is active; deleted upon verified request
- Marketing preferences: Retained until you withdraw consent
- Customer service records: Retained for up to 2 years from the date of resolution
- Analytics data: Anonymised or deleted within 26 months
When data is no longer needed, we securely delete or anonymise it.
10. Data Security
We take protecting your data seriously. Our security measures include:
- Encrypted data transmission (HTTPS/SSL) across our website
- Restricted access — only authorised team members can access personal data
- Secure, access-controlled storage systems
- Regular review of our data handling and security practices
However, no system is completely immune to risk. In the event of a data breach that may affect your rights, we will notify you and the Data Protection Board of India as required under the DPDP Act.
11. Children’s Privacy
Our website and products are intended for individuals aged 18 and above. We do not knowingly collect personal data from anyone under the age of 18. If we become aware that we have collected such data, we will delete it immediately.
As required under the DPDP Act, processing of data belonging to children requires verifiable parental or guardian consent. If you believe your child’s data has been collected, please contact us at info@touchandmend.in.
12. Links to Third-Party Websites
Our website may contain links to external sites such as payment gateways, social media platforms, or marketplaces. These websites have their own privacy policies, and we are not responsible for their practices. We recommend reviewing the privacy policy of any third-party site before sharing your data with them.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or business operations. When we make material changes, we will:
- Update the “Last Reviewed” date at the top of this document
- Post the revised policy on our website
- Notify you by email if the changes significantly affect how we handle your data
We encourage you to review this page periodically. Continued use of our website after changes are posted constitutes your acknowledgment of the updated policy.
14. Grievance Officer
In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, Anaso Enterprises has designated a Grievance Officer for privacy-related concerns.
Email: info@touchandmend.in
Response Time: We aim to acknowledge all grievances within 48 hours and resolve them within 30 days.
You may reach out to us directly at the email above for any privacy-related complaints or queries. If you feel your grievance has not been adequately addressed, you have the right to contact the Data Protection Board of India once it is operational.