Privacy Policy & Data Protection Notice
Effective Date: August 18, 2026 | Last Updated: October 3, 2026 | Governing Law: DPDP Act 2023 & IT Act 2000 (India)
At SolBombay Haute Pâtisserie ("SolBombay", "we", "us", or "our"), safeguarding your personal data and upholding your digital privacy is a paramount commitment. This Privacy Policy details our data stewardship practices, explaining what personal information we collect, the lawful basis for processing, how your data is secured, and your statutory rights under India's Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 (including the Reasonable Security Practices and Procedures and Sensitive Personal Data or Information Rules, 2011), the Consumer Protection (E-Commerce) Rules, 2020, and international standards such as the General Data Protection Regulation (GDPR).
Table of Contents
- 1. Data Fiduciary Identity & Contact Details
- 2. Principles of Data Minimization & Purpose Limitation
- 3. Categories of Personal Data We Collect
- 4. Purpose & Lawful Basis of Processing
- 5. Payment Data Security (Zero Card Storage via Razorpay)
- 6. Data Sharing & Third-Party Service Processors
- 7. Data Security Architecture & Encryption Standards
- 8. Data Retention & Disposal Policies
- 9. Your Statutory Rights as a Data Principal
- 10. Cookies, Web Storage & Telemetry
- 11. Children's Privacy (Under 18 Years)
- 12. Grievance Redressal Officer & Dispute Resolution
- 13. Policy Amendments & Notifications
1. Data Fiduciary Identity & Contact Details
For the purposes of applicable data privacy legislation, the Data Fiduciary responsible for the processing of your personal information is:
| Entity / Trade Name: | SolBombay Haute Pâtisserie & Masterclass Atelier |
|---|---|
| Registered Studio / Kitchen: | Andheri East, Mumbai, Maharashtra, Postal Code 400069, India |
| Order Concierge Helpline: | +91 9769633976 |
| Official Support Email: | support@solbombay.com |
| Grievance Redressal Officer: | Grievance Officer, SolBombay Pâtisserie (support@solbombay.com) |
2. Principles of Data Minimization & Purpose Limitation
In accordance with Section 4 of the DPDP Act 2023, SolBombay adheres strictly to the doctrine of Data Minimization and Purpose Limitation. We only collect the minimal personal data strictly necessary to fulfill your pastry orders, execute hand-delivery logistics across Mumbai, manage your customer profile, facilitate access to unlocked pastry masterclasses, prevent fraudulent promotional manipulation, and comply with statutory tax and food safety requirements.
We never sell, rent, trade, or monetize your personal data to third-party data brokers or unauthorized advertisers.
3. Categories of Personal Data We Collect
We may collect and process the following categories of information:
- Identity & Contact Information: Full Name, Email Address, 10-Digit Mobile / WhatsApp Telephone Number.
- Delivery & Logistics Details: Street Address, Suite / Apartment / Floor number, Landmark, City, State, and Postal Pincode (required for delivery of fragile, temperature-controlled bakery goods).
-
Order & Transaction Records: Items purchased, custom cake specifications (flavors, tier counts, dietary notes like 100% Eggless, personalized cake inscriptions), order reference numbers (e.g.
SB-XXXXXX), payment confirmation tokens, invoice timestamps, and coupon usage records. - Account Authentication Data: Secure salted and cryptographically hashed passwords (using bcrypt algorithms), persistent session tokens, and account creation timestamps.
- Masterclass Subscription Records: Records of unlocked pastry tutorial masterclasses and ratio recipe cards bound to your registered customer ID.
- Promotional Telemetry & Anti-Fraud Fingerprinting: IP address, browser user-agent, timestamp, and hardware canvas device telemetry collected exclusively to enforce our strictly audited 1-spin-per-24-hour limit on the Spin & Win promotional wheel.
- Corporate & Bespoke Inquiries: Company name, designated contact person, estimated event quantity, custom branding requirements, and event dates submitted through our inquiry portals.
4. Purpose & Lawful Basis of Processing
Under the DPDP Act 2023 and global privacy frameworks, we process your personal data under the following lawful bases:
| Processing Purpose | Data Elements Used | Lawful Basis |
|---|---|---|
| Order Fulfillment & Delivery Logistics | Name, Phone, Delivery Address, Pincode, Cake Inscription | Performance of Contract (Order Execution) |
| Transactional Communications & Invoicing | Email, Mobile Number, Order Breakdown | Performance of Contract & Legal Obligation (Tax Invoices) |
| Customer Account Management | Name, Email, Phone, Hashed Password, Address Book | Explicit User Consent & Contractual Service |
| Masterclass Streaming & Recipe Access | Customer ID, Email, Unlocked Tutorial IDs | Performance of Digital License Contract |
| Anti-Fraud & Wheel Promotion Security | IP Address, Device Canvas Telemetry, Phone, Email | Legitimate Use & Security Verification (Section 7 DPDP Act) |
| Corporate & Bespoke Cake Quotations | Organization Name, Contact Info, Event Date, Specs | Explicit Consent / Pre-Contractual Inquiries |
| Statutory Tax & GST Compliance | Order Invoices, Billing Address, Payment Transaction IDs | Legal Obligation (GST Act & Companies Act) |
5. Payment Data Security (Zero Card Storage via Razorpay)
SolBombay does not collect, process, or store your credit card numbers, debit card details, CVV/CVC codes, Net Banking passwords, or UPI PINs on our servers. All digital transactions are processed directly through Razorpay (Razorpay Software Private Limited), an RBI-authorized Payment Aggregator certified with the highest international security standard: PCI-DSS Level 1 (Payment Card Industry Data Security Standard).
When you check out, payment processing occurs via Razorpay's encrypted checkout modal over an end-to-end 256-bit TLS/SSL encrypted bridge. Razorpay transmits only an encrypted transaction token, payment ID, and payment status back to SolBombay for order reconciliation.
6. Data Sharing & Third-Party Service Processors
We only share strictly necessary information with verified third-party service providers (Data Processors) under binding confidentiality and data protection agreements:
- Payment Gateway: Razorpay (for automated payment processing, refunds, and fraud prevention).
- Transactional Notifications: Secure SMTP & transactional messaging services (for dispatching order confirmation invoices, password resets, welcome emails, and verification codes).
- Logistics & Delivery Drivers: In-house and verified white-glove pastry delivery couriers (provided only with recipient name, delivery address, contact phone, and time slot instructions).
- Statutory Authorities: Law enforcement or regulatory authorities only when strictly required by applicable Indian law, court order, or formal legal process.
7. Data Security Architecture & Encryption Standards
We employ industry-leading technical, organizational, and physical security measures to safeguard your personal data against unauthorized access, alteration, disclosure, or destruction:
- 256-Bit SSL/TLS Transport Encryption: All data transmitted between your browser and our web servers is protected using modern end-to-end cryptographic transport protocols.
- Cryptographic Password Protection: User passwords are secured using salted, one-way cryptographic hashing algorithms. Raw passwords are never visible, retrievable, or stored in plaintext.
- Multi-Layered Application Defenses: Strict input sanitization, parameterized database access models, and context-aware output encoding to prevent unauthorized injection, script execution, or data tampering.
- Anti-Forgery Token Enforcement: Sensitive forms and actions utilize cryptographically strong Cross-Site Request Forgery tokens to prevent unauthorized transaction execution.
- Secure Session & Cookie Architecture: Session cookies utilize modern security attributes (including
HttpOnly,SameSite, andSecureflags) and cryptographically verified tokens to prevent interception. - Resilient Infrastructure: Continuous automated database backup protocols, fault-tolerant infrastructure, and proactive security monitoring.
8. Data Retention & Disposal Policies
We retain personal data only for as long as necessary to accomplish the purposes outlined in this policy:
- Active Customer Accounts: Retained for the duration of your account's existence to allow you to track past orders, reorder easily, and access purchased masterclasses.
- Tax & Accounting Transaction Invoices: Stored for 8 statutory financial years in compliance with the Indian Goods and Services Tax (GST) Act, 2017, and the Companies Act, 2013.
- Promotional Spin Records & OTP Logs: Temporary verification tokens expire within 10 minutes. Daily spin timestamps are archived for anti-abuse audits.
- Data Erasure: Upon verified request for account deletion (where not required for active legal or tax obligations), your personal data is permanently deleted or irreversibly anonymized.
9. Your Statutory Rights as a Data Principal
Under Chapter III of India's DPDP Act 2023 and applicable privacy legislation, you possess the following actionable rights regarding your personal data:
Right to Access & Summary
You can request a summary of the personal data we hold about you and the processing activities undertaken.
Right to Correction & Update
You may edit your profile details, address book, and contact number at any time via your My Account portal or by contacting us.
Right to Erasure (Be Forgotten)
You may request the permanent deletion of your customer account and associated personal data, subject to mandatory tax retention laws.
Right to Withdraw Consent
You may withdraw your consent for promotional communications or optional processing at any time without affecting past lawful processing.
Right of Grievance Redressal
You have the statutory right to file a complaint with our Grievance Redressal Officer regarding any data processing concern.
Right to Nominate
You may designate a nominee to exercise your rights under the DPDP Act in the event of death or incapacity.
To exercise any of these rights, simply email our dedicated support desk at support@solbombay.com with the subject line "Data Principal Rights Request". We will verify your identity and respond within 30 calendar days.
11. Children's Privacy (Under 18 Years)
In strict compliance with Section 9 of the DPDP Act 2023, SolBombay does not knowingly collect personal data from or target online retail transactions directly to individuals under 18 years of age without verifiable parental or guardian consent. If we discover that personal data of a minor has been collected without requisite parental authorization, we will take prompt steps to delete such records from our databases.
12. Grievance Redressal Officer & Dispute Resolution
In accordance with the Information Technology Act, 2000, the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the DPDP Act 2023, the contact details of our designated Grievance Redressal Officer are published below:
Grievance Redressal Officer
Entity: SolBombay Haute Pâtisserie & Masterclass Atelier
Office Address: Andheri East, Mumbai, Maharashtra, 400069, India
Email: support@solbombay.com
Helpline: +91 9769633976 (Mon - Sun, 9:00 AM - 10:00 PM IST)
Resolution Timeline: We will acknowledge receipt of any privacy grievance within 48 hours and provide a comprehensive resolution within 30 calendar days.
13. Policy Amendments & Notifications
SolBombay reserves the right to amend or update this Privacy Policy periodically to reflect evolving legal frameworks, technological enhancements, or operational revisions. The latest version will always be published on this page with an updated "Last Updated" timestamp. For material modifications, prominent notices will be displayed on our website header or dispatched via email.
For any questions regarding this policy, please reach our support team at support@solbombay.com.