Beauty Garage Limited — Privacy Policy & Customer Grievance Redressal Policy
Effective date: 08 September 2025
Last updated: DD Month YYYY
This Privacy Policy explains how Beauty Garage Limited previously known as Beauty Garage Private Ltd. collects, uses, discloses, and safeguards your Personal Information when you use our website, mobile applications, and any other online or offline channels that link to this Privacy Policy (collectively, the “Platform”).
While you may browse the Platform from outside India, please note we do not offer products or services outside India at this time. By visiting or using the Platform, or by otherwise providing information to us, you agree to be bound by this Privacy Policy and by the laws of India, including the Information Technology Act, 2000 and applicable rules, and, as relevant, the Digital Personal Data Protection Act, 2023 (“DPDP Act”).
If you do not agree with this Privacy Policy, please do not use or access the Platform.
Note on terms: “Personal Information / Personal Data”, “Processing”, “Data Principal (Data Subject)”, “Data Fiduciary (Controller)”, and “Data Processor” have the meanings given in applicable privacy laws. For ease of reading, we use “Personal Information” and “Personal Data” interchangeably.
Who we are
Beauty Garage Limited is a company incorporated under the Companies Act, 2013 with its registered office at Marol Industrial Area, Plot No. 17, Road No. 9,MIDC, Andheri East,Mumbai, Mumbai, Maharashtra, 400093. We are engaged in the business of facilitating the sale, marketing, and retail of beauty, personal care, and related products and services through our e-commerce Platform and, where applicable, offline stores/events.
The roles we play
- Data Fiduciary / Controller: We act as a Controller when we determine the purposes and means of processing Personal Information about you (e.g., operating our Platform, managing your account, marketing).
- Data Processor: We may act as a Processor when we process Personal Information on behalf of another Controller (e.g., for partner programs). In such cases, we process data strictly under that Controller’s instructions.
Our commitment
We take your privacy seriously. Our data handling practices are designed to comply with applicable Indian privacy laws. We implement administrative, technical, and physical safeguards appropriate to the risk to protect Personal Information.
What we collect
We collect Personal Information in the following ways:
1) Information you provide
- Identity and contact details (e.g., name, email address, phone number, shipping/billing addresses, date of birth, profile photo).
- Account details (e.g., username, preferences).
- Transaction details (e.g., order history; payment instrument type and masked card/bank identifiers-we do not store full card numbers or CVV).
- Communications you send us (e.g., emails, chats, calls, support tickets, feedback).
2) Information we collect automatically
- Device and log data: IP address, device identifiers, browser/app version, operating system, system language, crash reports, and diagnostic logs.
- Usage data: Pages viewed, features used, clickstream data, timestamps, referring/exit pages, and similar analytics.
- Location data: Approximate location derived from IP and/or device settings (if permissions are granted).
Depending on your jurisdiction and applicable law, you may be served different categories of cookies/trackers (e.g., strictly necessary, performance, functional). International users may receive only strictly necessary cookies for basic functionality.
3) Information from other sources
- Updated delivery information from couriers/logistics partners.
- Information from payments and fraud-prevention partners.
- Information from login providers (e.g., if you choose to sign in via a social account), in accordance with their policies and your settings.
- Publicly available information (e.g., from public profiles or records).
Categories of Personal Information we process
- Demographic & identity data: name, title, date of birth, profile image.
- Contact data: email address, phone number, postal/shipping address.
- Transaction & payment data: order amounts, method, masked instrument details, UPI handle (where applicable).
- Technical & online identifiers: device IDs, cookies, IP address, advertising identifiers.
- Usage & analytics data: app and site interactions, page views, features used.
- Communications metadata: email/chat/call timestamps and related metadata.
Legal bases & consent
We process Personal Information with your consent and/or as otherwise lawful under Indian law (for example, to perform a contract with you, comply with legal obligations, respond to emergencies, or for other legitimate uses permitted by the DPDP Act). Where we rely on consent, you may withdraw it at any time using the methods described in Your Rights below. Withdrawal will not affect prior lawful processing.
How we use your information (purposes)
- Purchases & delivery: receive and process orders, enable payments and refunds, provide invoices, arrange shipping, and notify you about your orders.
- Operate, troubleshoot & improve the Platform: provide core functionality, ensure security, detect/prevent fraud and abuse, debug and fix errors, perform analytics and service improvement.
- Personalization & recommendations: tailor content, offers, and features to your preferences and behavior.
- Communications: send service messages (e.g., order updates, policy changes), and with your consent where required, marketing messages via SMS, WhatsApp, email, phone, rcs or in-app.
- Advertising: show interest-based ads on our properties and, where allowed, on third-party properties, using cookies/identifiers (see Cookies & trackers).
- Legal & compliance: comply with applicable laws, respond to lawful requests, enforce our terms, and protect our rights, users, and the public.
Cookies, permissions & other trackers
Cookies are small text files placed on your device. Our apps may also use SDKs and request device permissions (e.g., notifications, camera, storage) to deliver features.
Cookie/Tracker categories (examples):
- Strictly necessary: platform sign-in, session management, fraud prevention, security, regulatory compliance.
- Functional: remember preferences such as language, region, accessibility settings.
- Performance/analytics: understand usage and improve performance and features.
Most browsers let you control cookies in settings. Disabling strictly necessary cookies may impair site/app functionality. For more on cookies generally, visit https://www.allaboutcookies.org
Do Not Track: Browser DNT signals are not yet uniform; the Platform does not currently respond to DNT.
Third-party SDKs, partners & disclosures
We use carefully selected service providers and SDKs to operate and improve the Platform. These third parties process Personal Information under our instructions and contractual safeguards.
Typical categories of providers (illustrative only—replace with your actual list):
Category
Purpose
Examples (replace with your actual providers)
Analytics & engagement
App/web analytics, crash reporting, push notifications, A/B testing
[e.g., Firebase, Google Analytics, CleverTap, AppsFlyer, Crashlytics]
Payments
Process payments/refunds, prevent fraud
[e.g., Razorpay, PayU]
Login/Identity
Social/SSO login, reCAPTCHA
[e.g., Google, Facebook]
Communications
Email/SMS/WhatsA/RCS, customer support
[e.g.,Webengage, Consolto]
Logistics
Shipment, returns
[e.g., Delhivery, Blue Dart, Shiprocket]
We may disclose Personal Information where it is lawful and necessary, including to:
- Our group companies, affiliates, and service providers (under contract).
- Law enforcement, courts, regulators, auditors, and dispute-resolution bodies.
- Professional advisors (lawyers, auditors) under duty of confidentiality.
- Parties to whom you authorize us to disclose information.
- To protect safety, rights, property, or to detect/prevent fraud or security incidents.
Cross-border transfers
Your Personal Information may be transferred and processed outside India. Such transfers occur subject to appropriate safeguards and only for the purposes described in this Privacy Policy. Data in other jurisdictions may be subject to lawful access by courts, law enforcement, or government authorities there.
Data security
We use reasonable and appropriate technical and organizational measures to protect Personal Information, including encryption in transit, access controls, network segregation, continuous monitoring, and employee training. We require our service providers to implement comparable safeguards.
Data retention
We retain Personal Information for as long as necessary to fulfill the purposes in this Privacy Policy, meet legal, accounting, or reporting requirements, resolve disputes, and enforce agreements. When no longer needed, we delete or irreversibly de-identify the data.
Links to third-party sites
The Platform may contain links to third-party websites/apps. Their privacy practices are not governed by this Policy. We encourage you to review their privacy policies before using those services.
Children’s privacy
The Platform is intended for use by adults. If you are not an adult under applicable law, you may browse the Platform but should not register, purchase, or submit Personal Information. We do not knowingly collect Personal Information from minors.
Your rights
Subject to applicable law, you may have the right to:
- Access your Personal Information we hold.
- Correct inaccurate or incomplete Personal Information.
- Delete/erase Personal Information, subject to legal retention obligations.
- Withdraw consent where processing is based on consent.
- Opt out of marketing communications (service/transactional messages will continue).
- Grievance redressal through the mechanisms below.
- Nominate another individual to exercise your rights (as applicable under the DPDP Act).
How to exercise your rights:
Email help@beautygarage.com with the subject “Data Rights Request” and include sufficient information to verify your identity and locate your records (e.g., registered email/phone, order ID). We may request additional verification to protect your account and data.
Customer Grievance Redressal Policy
1) Background
Customer satisfaction is central to Beauty Garage’s values. This Policy outlines our framework for receiving, tracking, and resolving customer issues in a timely and fair manner.
2) Objectives
- Provide a transparent and accessible process to raise queries and complaints.
- Ensure prompt acknowledgment and effective resolution within reasonable timelines.
- Offer clear escalation paths if you are unsatisfied with the initial outcome.
3) Principles
- Fairness & respect: Every customer is treated courteously and fairly.
- Timeliness: Acknowledge swiftly and resolve within defined timeframes.
- Transparency: Keep customers informed of status and escalations.
4) How to reach us
You can contact our Customer Support via the following channels (update the placeholders with your actual details):
- Email: help@beautygarage.com
- Phone: 9987217646 (Mon–Sun, 10:30 AM-7:00 PM, IST)
- In-app / Web Chat: Available Mon–Sun, 10:30 AM-7:00PM IST
Service levels (illustrative; update if different):
- Acknowledgment: within 24 hours
- Resolution target: within 5-7 business days, depending on issue complexity
For payment/refund issues, timelines may depend on banks/payment partners. We will keep you informed of progress.
5) Fraud & safety reminders
- We never ask for sensitive information like OTP, CVV, PIN, full card/bank details.
- Beware of phishing calls/messages offering gifts or deep discounts.
- Report suspected fraud attempts to help@beautygarage.com or the Grievance Officer below.
- Beauty Garage is not liable for losses arising from information shared by customers with fraudsters.
6) Escalations
If you are not satisfied with the first response, you may escalate to our Grievance Officer:
Grievance/Nodal Officer – Customer Services
Name: Laxmi
Email: help@beautygarage.com Postal address: Marol Industrial Area, Plot No. 17, Road No. 9,MIDC, Andheri East,Mumbai, Mumbai, Maharashtra, 400093
Hours: Mon–Fri, 10:30 AM-7:00 PM IST
We aim to provide a final response to escalated complaints within 7 business days of acknowledgment.
Advertising & marketing preferences
You can manage marketing preferences via account settings (where available) or by using the unsubscribe/opt-out options in messages. You will still receive essential service communications (e.g., order confirmations, security alerts).
Changes to this Policy
We may update this Privacy Policy and Grievance Policy from time to time. We will post the updated version on this page with a revised “Last updated” date. Where required by law, we will notify you and/or seek your consent to material changes.
Contact us
For questions about privacy or this Policy, contact:
Email: help@beautygarage.com
Registered office: Marol Industrial Area, Plot No. 17, Road No. 9,MIDC, Andheri East,Mumbai, Mumbai, Maharashtra, 400093.
Quick implementation checklist (delete before publishing)
- Replace all placeholders (emails, phone numbers, addresses, officer name/hours).
- Insert your actual list of SDKs/service providers (or link to a live list you maintain).
- Confirm cookie categories and add a Cookie Notice/Banner if required.
- Verify refund/chargeback timelines with payment partners.
- Set realistic SLA targets and make sure support tools can meet them.
Have legal counsel review for compliance with the DPDP Act, IT Rules, and sectoral rules.