Saylee Naturals (“Company”, “we”, “our”, “us”) operates www.sayleenaturals.com as a Direct-to-Consumer (D2C) e-commerce platform delivering cosmetic and personal care products. We collect, use, store, and process your personal data in compliance with:
- Digital Personal Data Protection Act, 2023 (DPDP Act)
- Information Technology Act, 2000
- IT (Reasonable Security Practices & Procedures) Rules
- IT (Intermediary Guidelines & Digital Media Ethics Code) Rules, 2021
- Consumer Protection (E-Commerce) Rules, 2020
- Legal Metrology (Packaged Commodities) Rules, 2011 & Amendments
- Cosmetics Rules & Labelling Requirements
- PCI-DSS requirements (via payment gateways)
Categories of Personal Data Collected
- Personal Data: Name, phone number, email address, delivery address, billing address, order history, login data.
- Sensitive Payment Data: Processed exclusively by PCI DSS Level-1 compliant payment gateways (Razorpay, PayU, Cashfree). We do NOT store card numbers, CVV, UPI PIN, or banking credentials.
- Online Identifiers: IP address, device details, browser information, analytics tags, cookies, ad identifiers.
- User-Generated Content: Reviews, photos, comments, feedback.
- Children’s Data: We do not knowingly process data of persons under 18 years.
Purpose of Processing
We process data for lawful and consented purposes:
- Order processing & shipping
- Payment processing
- Account management
- Customer support
- Marketing & communication (only with consent)
- Fraud detection
- Analytics & website performance improvement
- Legal compliance (GST, tax records, audits)
- Product recommendations
Consent & User Rights (DPDP Act)
You have the right to:
- Access your data
- Correct inaccurate data
- Delete your personal data
- Withdraw marketing consent
- Nominate another person to manage your data
- Seek grievance redressal
Requests: query@sayleenaturals.com
Data Sharing & Disclosure
We share data only with lawful processors:
- Payment Gateways: Razorpay, PayU, Cashfree — PCI-DSS compliant.
Logistics Partners: Delhivery, Blue Dart, and other carriers. - IT Infrastructure: ISO/SOC certified secure hosting & cloud storage partners.
- Marketing & Analytics (Cross-Border Notice): Meta (Facebook/Instagram), Google Ads, WhatsApp Business API.
- Government Authorities: Only when legally required.
We never sell or rent your data.
Data Storage, Retention & Security
- Encrypted servers
- Strict access controls
- Data minimisation practices
- Retention:
- Order/Invoice data: 5–7 years (legal requirement)
- Account data: until account deletion
- Marketing data: until consent is withdrawn
Cookies & Tracking Technologies
We use:
- Essential cookies
- Performance cookies
- Analytics cookies
- Advertising tags (Meta Pixel, Google Ads)
- Users can disable cookies through browser settings.
Grievance Officer
(As required under DPDP Act & IT Act)
- Grievance Officer: Ankit
- Email: query@sayleenaturals.com
- Address: 106, Sanvid Nagar, Kanadia Road, Indore - 452018
- Response Time: Within 2 business days
Policy Updates
Any update will be posted with a revised “Last Updated” date.