Privacy Policy

Effective: May 2026  ·  Compliant with DPDP Act 2023 & IT Act 2000  ·  Last reviewed: May 2026

Amstaz is committed to protecting your privacy. This policy explains what personal data we collect, why, how we use it, who we share it with, and your rights under Indian law — including the Digital Personal Data Protection Act 2023 (DPDP Act).

1. Who We Are (Data Fiduciary)

Amstaz is operated by Priyabrata Chowdhury, sole proprietor, Durgapur, West Bengal, India. Under the DPDP Act 2023, Amstaz is the Data Fiduciary — the entity responsible for decisions about the purpose and means of processing your personal data.

Privacy contact: priyabrata.amstaz@gmail.com  |  +91 6294152501

2. What Personal Data We Collect

CategoryDataPurpose
IdentityFull name, genderAccount creation and personalisation
ContactEmail address, phone numberOrder confirmation, communication, support
DeliveryFull delivery address, PIN code, stateShipping your orders accurately
TransactionProducts ordered, amounts paid, Order IDs, UPI payment confirmationProcessing and fulfilling orders, accounting
AccountEncrypted password, AMS points balanceSecure account management
TechnicalCart data stored in browser (localStorage)Maintaining your shopping cart between sessions

We do not collect: government ID numbers, biometric data, financial account details, health records, or any sensitive personal data as defined under the DPDP Act 2023.

3. Legal Basis for Processing

We process your personal data under these lawful bases under the DPDP Act 2023:

4. How We Use Your Data

5. Data Sharing

We share your data only in these strictly limited situations:

We never sell, rent, or share your data with advertisers or data brokers. We do not run advertisements on Amstaz.

6. Data Storage & Security

Your personal data is stored on Supabase servers (AWS, Singapore region). Supabase is SOC 2 Type 2 certified.

Security measures we have in place:

No digital system is 100% immune to breaches. If you suspect unauthorized access to your account, contact us immediately at priyabrata.amstaz@gmail.com.

7. Data Retention

8. Your Rights Under DPDP Act 2023

As a Data Principal, you have these rights:

To exercise any right, email priyabrata.amstaz@gmail.com. We will respond within 30 days.

9. Cookies & Local Storage

Amstaz uses browser localStorage only to save your shopping cart between visits. We do not use tracking cookies, advertising cookies, or third-party analytics that track you across websites. No cookie consent banner is required as we do not set tracking cookies.

10. Children's Privacy

Amstaz is strictly for users aged 18 and above. We do not knowingly collect personal data from anyone under 18. If we discover a minor has registered, we will immediately delete their account and data. To report such a case, email priyabrata.amstaz@gmail.com.

11. Third-Party Links

Our website may link to external sites (brand websites, social media). We are not responsible for their privacy practices. Please review their policies before sharing any data with them.

12. Changes to This Policy

We may update this Privacy Policy as our platform or applicable law changes. We will notify you by email or on-site notice. Continued use of Amstaz after notification means acceptance of the updated policy.

13. Grievance Officer

As required by the Consumer Protection (E-Commerce) Rules 2020 and the DPDP Act 2023:

If unresolved within 30 days, you may approach the Data Protection Board of India (once constituted under DPDP Act 2023) or the National Consumer Helpline at 1800-11-4000.

14. Contact

For any privacy questions: priyabrata.amstaz@gmail.com  |  +91 6294152501