Privacy
Privacy notice
1. Who we are
JBS SEASONABLE is a proprietorship operated by Anita Nandkishor Rathod in India. For this service, JBS SEASONABLE determines why and how customer personal data is processed. The final registered business address will be added before orders open.
2. Personal data we process
- Account: name, email address, mobile number, Firebase user identifier, sign-in provider, and account status.
- Delivery and transaction: delivery address, cart, product, price, discount, tax, order, cancellation, refund, and support history.
- Payment: Razorpay order/payment identifiers, method category, payment state, signature-verification result, and refund/reconciliation events. JBS SEASONABLE does not intend to store full card, UPI PIN, CVV, or banking credentials.
- Security: App Check/Play Integrity signals, authentication events, IP/network and device-related risk signals, admin actions, rate-limit events, and fraud-review outcomes.
- Consent and notices: purpose, notice version and hash, language, app version, action, user identifier, and server timestamp.
- Optional communications: marketing or analytics choice and related withdrawal event. These are not required to buy.
We do not ask for date of birth. The service is adults-only and records an adult attestation. Public product images are separate from private customer records.
3. Purposes and use
| Purpose | Data | Why it is needed |
|---|---|---|
| Account and ordering | Account, cart, address, order | Provide the requested service and communicate transaction status |
| Payment and refund | Order/payment identifiers and state | Create, verify, reconcile, cancel, and refund prepaid orders |
| Security and fraud prevention | Integrity, authentication, device/network, order and risk events | Prevent abuse, investigate incidents, and protect customers and JBS SEASONABLE |
| Legal and grievance handling | Consent, transaction, complaint and audit records | Respond to lawful requests, exercise rights, and resolve disputes |
| Optional analytics/marketing | Only data covered by the separate choice | Measure and communicate where the customer has chosen this purpose |
4. Notices, consent, and choices
Required account, privacy, and transaction notices are presented separately from optional marketing and analytics choices. We record consent and withdrawal as append-only events using the fields described above. You can withdraw an optional choice as easily as you gave it. Withdrawal does not invalidate earlier lawful processing and does not stop processing necessary to complete an existing order, prevent fraud, or meet legal obligations.
India's Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 have phased commencement dates. JBS SEASONABLE is designing this flow for the applicable requirements as they come into force; final legal validation is a launch gate.
6. Retention
We keep data only for a documented purpose and period, then delete or irreversibly anonymise it unless a legal hold applies. Proposed schedules must be validated by counsel and a chartered accountant before launch.
- Abandoned quarantined product uploads: up to 24 hours.
- Consent and withdrawal evidence: for the period needed to demonstrate the notice and choice, subject to the approved legal schedule.
- Order, payment, refund, tax and accounting records: for the applicable Indian statutory period.
- Security and fraud logs: up to 365 days in India unless a longer legal hold is required. This is intended to meet the CERT-In rolling-log minimum while limiting indefinite retention.
- Account data: while active and through the verified deletion process, except protected records that must be retained.
7. Your choices and rights
Subject to applicable law, you may request access to a summary of personal data and processing, correction, completion, updating, erasure, withdrawal of optional consent, grievance redressal, and account deletion. You may also nominate another individual where the applicable DPDP provisions permit. We verify requests to prevent account takeover.
Use the in-app controls when available, follow the account-deletion instructions, or contact us. We will explain any information that must be retained and why.
8. Security
Controls include Firebase Auth, App Check with Play Integrity, admin MFA and claims, server-owned financial state, deny-by-default database rules, immutable audit events, HMAC-signed media callbacks, short-lived upload URLs, image decoding and re-encoding, secret managers, rate limits, fraud review, encrypted transport, dependency scanning, and incident response. No system is risk-free; suspected incidents should be reported promptly through the grievance channel.
9. Contact and grievance
Privacy and grievance contact: Anita Nandkishor Rathod, Proprietor
Email: krishna.rakhi.bhandar@gmail.com
Phone: +91 88570 24662
See the grievance procedure. The registered postal address and response-hour commitment will be completed before sales launch.