Privacy Policy
Last updated: 1 January 2025
1. Who We Are
The Fishbox is a Chennai-based pre-order fish and meat delivery service operating at thefishbox.in. For privacy concerns, contact hello@thefishbox.in.
2. Information We Collect
2.1 Information you give us
- Email address โ to verify your identity via OTP and send order confirmations
- Phone number โ optional, used only for WhatsApp delivery updates
- Delivery address โ flat number, building, area, and pincode
- Order details โ items, weight, cut preference, delivery date
- Payment โ we do not store card or UPI details; all payments go through Razorpay (PCI-DSS compliant)
2.2 Collected automatically
- Device type, browser (for technical support only)
- Pincode entered for delivery area check
- Cart contents stored in your browser's local storage (not on our servers until checkout)
2.3 What we do NOT collect
- Passwords โ we use email OTP only
- Payment card numbers or UPI IDs
- Location data or GPS coordinates
- Advertising or tracking cookies
3. How We Use Your Information
| Purpose | Data used |
|---|---|
| Verify identity at login/checkout | Email (OTP) |
| Process and fulfil orders | Address, order details, payment status |
| Send order updates and confirmations | Email, phone (WhatsApp) |
| Generate and send invoices | Name, email, address, order total |
| Respond to support queries | Email, order number |
| Improve our service | Anonymous usage data |
4. Sharing Your Information
We do not sell, rent, or trade your personal information to any third party. We share data only with:
- Razorpay โ payment processing
- MSG91 โ OTP emails and WhatsApp notifications
- Delivery staff โ your name, phone, and address to complete delivery
We may disclose information if required by Indian law or court order.
5. Data Retention
- Order records retained for 3 years for GST compliance under Indian tax law
- OTP codes expire after 10 minutes and are deleted after use
- You may request account deletion at any time (see Section 7)
6. Cookies
We use only essential session cookies. We do not use third-party advertising or tracking cookies. Your cart is stored in your browser's localStorage, not in a cookie.
7. Your Rights
- Access โ request a copy of data we hold about you
- Correct โ update incorrect information in your profile
- Delete โ request deletion of your account and data (subject to legal retention requirements)
- Opt out โ unsubscribe from marketing messages at any time
Email hello@thefishbox.in with subject "Privacy Request".
8. Security
Your data is transmitted over HTTPS. Passwords are never stored. Payments are handled by Razorpay's PCI-DSS Level 1 certified infrastructure. Access to customer data within our team is restricted to those who need it to fulfil orders.
9. Children's Privacy
The Fishbox is not intended for anyone under 18. We do not knowingly collect information from children.
10. Changes to This Policy
We may update this policy. Significant changes will be notified via email or website notice. The "Last updated" date reflects the most recent change.