This Policy applies to personal data we process through our websites, brand stores, corporate-gifting platforms (KitUp, Rewards, GiftKart, BrandStore, Corporate Gifts), applications, and business operations.
| Data Principal | The individual to whom the personal data relates (for a child, the parent/lawful guardian). |
| Personal Data | Any data about an individual who is identifiable by or in relation to such data. |
| Data Fiduciary | The person/entity that determines the purpose and means of processing personal data. |
| Data Processor | A person/entity that processes personal data on behalf of a Data Fiduciary. |
| Processing | Any operation on personal data — collection, storage, use, sharing, erasure, etc. |
| Identity & contact | Name, email, phone, billing/delivery address, organisation, designation. |
| Gifting / recipient data | Recipient name, delivery address, phone/email, gift preference, occasion, message (often provided by a corporate client). |
| Transaction data | Orders, invoices, payment references (we do not store card numbers; payments are handled by PCI-DSS payment gateways). |
| Account & usage | Login credentials (hashed), preferences, support tickets, and technical/usage logs, cookies. |
We practise data minimisation — we collect only what is necessary for the stated purpose.
We process personal data on the basis of your consent, or for legitimate uses permitted under the DPDPA (e.g. a purpose for which you voluntarily provided data, or to fulfil a legal obligation). Purposes include:
Where we rely on consent, we present a clear notice at or before collection describing the personal data, the purpose, and how to exercise your rights. Consent is requested through a clear affirmative action (e.g. ticking an unticked box) and is free, specific, informed, unconditional and unambiguous, limited to the data necessary for the stated purpose.
Withdrawing consent: you may withdraw consent at any time — as easily as it was given — by contacting privacy@offineeds.com or using the controls in your account. Withdrawal does not affect processing already carried out, and we will stop further processing and erase data unless retention is legally required.
The notice is available in English and, on request, in any language listed in the Eighth Schedule to the Constitution of India.
When a corporate client (the Data Fiduciary) provides recipient personal data for gifting, we process it strictly to fulfil that engagement, under a written Data Processing Agreement. We do not use it for our own purposes, do not further share it except with delivery/logistics sub-processors necessary for fulfilment, and erase or return it on completion or on the client's instruction. The client is responsible for issuing notice and obtaining consent from the Data Principals.
We do not sell personal data. We may share it only with:
We retain personal data for a period of 1 year from the date of collection or last interaction, or for as long as necessary for the purpose for which it was collected, whichever is applicable, unless a longer period is required by law (e.g. tax/accounting records). Corporate-gifting recipient data processed on a client's behalf is retained until fulfilment plus a window of up to 1 year for delivery queries/returns, after which it is erased or returned. On expiry of the 1-year retention period, or once the purpose is served and no legal retention applies, we erase the data.
We implement reasonable technical and organisational measures, including TLS 1.3 encryption in transit and encryption at rest, role-based access control (least privilege) with MFA, edge protection (WAF/DDoS), centralised security monitoring (SIEM / file-integrity monitoring), patching and vulnerability management, and an ISO/IEC 27001:2022-certified ISMS.
Our services are intended for adults and businesses. We do not knowingly process the personal data of children (under 18) without verifiable parental/guardian consent, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
To exercise any right, contact our Grievance Officer (below). We respond within the period prescribed under the DPDPA Rules.
If your grievance is not resolved to your satisfaction, you may escalate to the Data Protection Board of India as provided under the DPDPA.
In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as required under the DPDPA and our Incident Response procedure (ISMS-IR / CERT-In timelines).
We may update this Policy from time to time. The current version and its effective date are published on our website.