1. Introduction
Welcome to Shivra Ecom. We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we look after your personal data when you visit our website and tells you about your privacy rights and how the law protects you.
Shivra Ecom ("we", "us", or "our") is the data controller and is responsible for your personal data.
2. The Data We Collect About You
We may collect, use, store, and transfer different kinds of personal data about you, including:
- Identity Data: First name, last name, username or similar identifier, and title.
- Contact Data: Billing address, delivery address, email address, and telephone numbers.
- Business Data: Company registration details, VAT numbers, eCommerce platform store links, and performance metrics necessary for our service delivery.
- Financial Data: Bank account and payment card details processed securely via our payment gateways.
- Technical Data: IP address, browser type, location, operating system, and platform details.
- Usage Data: Information about how you use our website and services.
3. How We Use Your Personal Data
We will only use your personal data when the law allows us to. Most commonly, we use your personal data for:
- Performance of a Contract: To provide eCommerce management, compliance, web, or marketing services.
- Legitimate Interests: To improve services, manage operations, and support business growth.
- Legal Obligation: To comply with legal or regulatory requirements, including UK HMRC requirements.
- Consent: For marketing communications where required. You can withdraw consent at any time.
4. Disclosures of Your Personal Data
We may share your personal data with trusted parties for service delivery and legal compliance.
- Internal Third Parties: Our technology and development partner, Cyber Drift Solutions Private Limited, for web infrastructure, app development, or automation services.
- External Third Parties: IT providers, professional advisers, payment processors, auditors, insurers, HM Revenue & Customs, or other UK/EU authorities where required.
We require all third parties to respect the security of your personal data and treat it in accordance with the law.
5. International Data Transfers
Some external partners may be based outside the UK or European Economic Area. Whenever we transfer personal data outside the UK/EEA, we ensure appropriate safeguards are in place, such as adequate protection standards or approved contractual safeguards.
6. Data Security & Retention
We use appropriate security measures to prevent your personal data from being accidentally lost, used, accessed, altered, or disclosed without authorization.
We retain personal data only for as long as reasonably necessary to fulfil the purpose it was collected for, including legal, regulatory, tax, accounting, or reporting requirements.
7. Your Legal Rights
Under UK GDPR and EU GDPR, you have rights in relation to your personal data, including:
- Request access to your personal data
- Request correction of your personal data
- Request erasure of your personal data
- Object to processing of your personal data
- Request restriction of processing
- Request transfer of your personal data
- Withdraw consent at any time