Privacy Policy
This notice tells you what personal data GradeGuard collects, why, how long we keep it, who else sees it, and what you can make us do about it. It is written to satisfy Section 5 of the Digital Personal Data Protection Act, 2023, which requires a notice in clear and plain language giving an itemised description of the personal data, the purpose of processing, and the manner of exercising your rights and of complaining to the Data Protection Board. Last updated 11 September 2026.
The Data Fiduciary
GradeGuard (sole proprietorship), Shop No. 123, 1st Floor, Regency Road, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh 226010, India.
E-mail for all data questions and requests: contact@swizzwatches.com (subject line: DPDP request)
Person to answer questions about processing (Section 13(3)): Kuldeep Patel, Proprietor.
Under the Act we are the Data Fiduciary and you are the Data Principal. We are not a Significant Data Fiduciary and have not been notified as one.
The one thing we never hold
This store is cash on delivery only. There is no payment gateway on this site. We never see, receive or store a card number, a CVV, a UPI ID, a bank account number, a net-banking credential or an OTP. Nobody from GradeGuard will ever ask you for any of them. If someone does, they are not us — report it to the address above.
Itemised description of the personal data we process
| Data | When we get it | Why (specified purpose) |
|---|---|---|
| Full name | At checkout | To address the parcel, raise the invoice and identify you on a warranty claim |
| Delivery address with pincode | At checkout | To deliver, and to arrange reverse pickup on a return |
| Mobile number | At checkout | The COD confirmation call, courier calls at the door, and delivery alerts |
| E-mail address | At checkout, or when you write to us | Order confirmation, tracking, invoice and replies |
| Order contents and value | On order | To fulfil the order and to keep the books tax law requires |
| IMEI or serial number of the unit sent to you | At dispatch | Printed on your invoice and shown in your account. It is your proof of which physical device you own. It is never published anywhere public, because a public IMEI can be used by a stranger to file a malicious CEIR block against your phone |
| Account username and hashed password | Only if you choose to create an account | To let you sign in and see your orders |
| Product review text and name | Only if you write one | Published on the product page as you wrote it |
| Photographs or video you send with a claim | Only if you send them | To assess a return or warranty claim |
| Bank or UPI details for a refund | Only when a refund is actually due, and only then | To pay you. Deleted once the payment clears and the mandatory accounting record is made |
| IP address, browser, pages viewed, timestamps | Automatically, in server logs | Security, fraud prevention and diagnosing faults |
We do not ask for your date of birth, gender, Aadhaar, PAN, income, occupation or photograph, and there is no field on this site to give them to us.
Our basis for processing
- Certain legitimate uses — Section 7(a). When you place an order you voluntarily provide your name, address and phone for the specified purpose of receiving that order, and you have not indicated that you object. That covers fulfilment.
- Consent — Section 6. Anything beyond fulfilment — for example an offers e-mail — needs your separate, specific, informed, unconditional and unambiguous consent given by a clear affirmative action. No checkbox on this site is pre-ticked, and we do not treat continued browsing as consent.
- Legal obligation. Invoices and sale records are retained because tax and company law require it, independent of your consent.
Withdrawing consent is as easy as giving it — Section 6(4). One e-mail to contact@swizzwatches.com is enough, or the unsubscribe link in any e-mail we send. Withdrawal does not undo processing that already happened lawfully, and it cannot stop us keeping the invoice records the law requires.
Who else your data reaches
We do not sell personal data. We do not rent it, trade it or hand it to data brokers. It goes to exactly these Data Processors, only for the purpose named, and each is bound by contract to use it for nothing else:
- The courier carrying your parcel — name, address, phone, order value for COD collection. Without this there is no delivery.
- Our hosting provider, who operates the dedicated server this site runs on and therefore holds the database and the logs.
- Our e-mail provider, which sends order and tracking mail from our own mail server.
- A service partner or the refurbishing supplier, on a warranty claim only — the order number, the IMEI and a description of the fault. Your address and phone are shared only where they physically collect from or deliver to you.
- Our chartered accountant, for the statutory books.
- A government authority, where the law compels disclosure. We disclose the minimum demanded and, unless we are legally barred from doing so, we tell you it happened.
Cookies and the advertising on this site
- Strictly necessary: a WooCommerce session cookie and a small cart-count cookie so your cart survives a page load, and a WordPress cookie if you sign in. These carry no advertising identifier.
- Caching: the server’s cache uses a cookie to decide whether to serve you a cached page. It holds no personal data.
- Advertising: this site carries no advertising at all. There is no ad code anywhere on it — not on the shop, product pages, the cart, the checkout, order tracking, your account, the order confirmation, the guides or any policy page, so no advertising network sets a cookie on you here. If that ever changes it will only be on editorial pages, never on shop or checkout pages, and this page will be updated before it does.
You can block cookies in your browser if you prefer; the store will still work, including checkout.
How long we keep it
| Record | Retention |
|---|---|
| Invoices and sale records (name, address, order, IMEI) | 8 years from the end of the financial year — the period the tax law requires. We cannot delete these earlier even if you ask |
| Warranty and claim correspondence | 6 months beyond the end of the warranty on that unit |
| Bank or UPI details given for a refund | Deleted once the payment clears and the accounting entry is made |
| An account you created | Until you close it, or after 3 years of no sign-in and no order |
| Enquiry e-mails that did not become an order | 12 months |
| Server access logs | 90 days |
| Marketing consent, if you gave one | Until you withdraw it |
Section 8(7) of the Act requires erasure once consent is withdrawn or the purpose is no longer being served, unless retention is required by law. That is the rule we apply, and the table above is where “required by law” bites.
Your rights, and how to use them
- Access — Section 11. A summary of the personal data we hold about you, what we have done with it, and the identities of everyone we shared it with.
- Correction, completion, updating and erasure — Section 12. We will correct anything inaccurate and erase anything we no longer have a legal reason to keep.
- Grievance redressal — Section 13. Complain to us first. We must respond, and the DPDP Rules set the outer limit at 90 days. We commit to 12 days.
- Nomination — Section 14. You may nominate someone to exercise these rights on your behalf if you die or become incapable. Write to us and we will record it.
- Withdraw consent — Section 6(4), at any time, as easily as you gave it.
How to make a request
E-mail contact@swizzwatches.com with the subject line DPDP request. Tell us which right you are exercising and give us the e-mail address or mobile number you used on the order — that is the identifier we use to find you, and the DPDP Rules, 2025 require us to publish it here so you know what to send. You do not need to send us an identity document, and you should not.
- Acknowledgement: 4 working hours, with a ticket number.
- Completion: 12 days. If a request is genuinely complex we will tell you inside those 12 days what is taking longer and why. We will not use the 90-day statutory ceiling as a default.
- There is no charge for any of this.
Your duties matter too — Section 15. Give us real details. Filing a false or frivolous complaint, or impersonating someone else to get at their data, is an offence under the Act and carries a penalty.
If we get it wrong
Complain to us first, at the address above. If our answer does not satisfy you, or we fail to respond, you may complain to the Data Protection Board of India — that is your right under Section 13(3) of the Act, and you do not need our permission. Consumer complaints that are not about data go to the National Consumer Helpline on 1915; see Grievance Redressal.
Security, and what happens after a breach
Section 8(5) requires reasonable security safeguards. Ours: HTTPS on every page, passwords stored as salted hashes and never in plain text, administrative access limited to the proprietor with two-factor authentication, a firewall on the server, and no payment data in the system at all because there is no gateway.
If a breach affects your data, Section 8(6) requires us to notify the Data Protection Board and every affected Data Principal. We will tell you directly — what happened, what data, what we have done, and what you should do — and we will not wait for it to become public first.
Children
This store is for buyers aged 18 and over, and we do not knowingly process the personal data of a child. Section 9 of the Act bars processing children’s data without verifiable parental consent and bars tracking or behavioural advertising directed at children. If you believe a child has given us data, write to us and we will delete it.
Where your data is
Our database and files sit on a dedicated server rented in our name. Some of the services we use — e-mail delivery and the advertising network on editorial pages — may process data outside India. Section 16 of the Act permits transfer outside India except to a country the Central Government has notified as restricted; we do not transfer to any restricted country, and we will update this page if that list changes in a way that affects us.
Changes
If this notice changes materially we update the date at the top and, where the change affects data we already hold about you, we e-mail you before it takes effect rather than relying on you to re-read a policy page.