We collect what we need to get your order to you — and nothing more. Your data is not our product; your display holder is. This policy tells you exactly what we hold, why we hold it, how we protect it, and how you can ask us to delete it.
This policy is issued by Mourya Dasgupta, sole proprietor trading as HexaHang (hereafter "HexaHang", "we", "us", "our"), in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), read with the Information Technology Act, 2000, and any Rules, Notifications, Directions, or amendments issued thereunder from time to time.
1. Who We Are (Data Fiduciary Identity)
- Data Fiduciary: Mourya Dasgupta, sole proprietor trading as HexaHang
- Principal place of business: Aparupa Apartments, Flat 3A, 2 G.B. Dutta Road, Sodepur, Kolkata – 700110, West Bengal, India
- GSTIN: 19AZAPD7805P1Z0
- Email: privacy@hexahang.com
- WhatsApp: +91 62934 01030
As a sole proprietor, Mr Mourya Dasgupta is the Data Fiduciary for the purposes of the DPDP Act and determines the purpose and means of processing your personal data.
2. What Personal Data We Collect, Why, and What It Powers
The following is our itemised notice under the DPDP Rules. We collect each data point for a specified purpose, linked to a specific service.
2.1 Data you provide directly
| Data | Purpose | Service / Feature Enabled | Lawful Ground |
|---|---|---|---|
| Full name, email, mobile | Notify you when orders open; deliver your order, including order confirmation, dispatch, and tracking notifications by email and WhatsApp; respond to enquiries | Registration; order fulfilment; customer support | Consent (registration, support); compliance with legal obligation under S.7(d) read with applicable tax law (invoicing) |
| Shipping address (line, city, pincode, state) | Deliver your order | Order fulfilment | Voluntary provision for a specified purpose under S.7(a) |
| Contact form / WhatsApp messages | Respond to your enquiry | Customer support | Voluntary provision for a specified purpose under S.7(a) |
| Age affirmation (18+) | Confirm we are not processing data of a minor | Compliance with the children's-data provisions of the Act and Rules | Compliance with statutory obligation |
2.2 Data collected via payment processing
Payments are processed by Razorpay Software Private Limited (Data Processor on our behalf). HexaHang does not store card numbers, UPI IDs, or netbanking credentials. We receive only: transaction reference ID, payment status, payment method category, and amount.
2.3 Data collected via analytics (post-consent only)
If you accept analytics cookies, we collect via Google Analytics 4 (Google LLC) and Microsoft Clarity (Microsoft Corporation): anonymised IP address, browser and device type, pages visited, session duration, and (for Clarity) anonymised on-screen interactions for UX improvement.
No analytics scripts fire before you consent via the cookie banner. Microsoft Clarity operates in Strict masking mode, masking text content and form inputs by default.
3. Lawful Grounds for Processing
Under the DPDP Act, we process personal data on the following grounds only:
- Consent (Section 6): Registration, marketing communications, and non-essential analytics. Consent is collected through clear affirmative action with no pre-ticked boxes.
- Certain Legitimate Uses (Section 7):
- S.7(a) — Voluntary provision by you for a specified purpose (for example, providing your shipping address at checkout enables order fulfilment).
- S.7(d) — Compliance with any judgment, decree, or order under Indian law, including tax and GST invoicing obligations.
We do not rely on any other lawful ground. We do not engage in automated decision-making or profiling that produces legal or similarly significant effects. Where personal data is processed because it is necessary to provide the services you have requested, that processing is carried out in accordance with the applicable provisions of the DPDP Act and the Rules framed thereunder, as amended from time to time.
4. Withdrawing Consent
You may withdraw consent at any time, with the same ease with which it was given:
- Marketing emails: click the unsubscribe link in any email
- Registration / communications list: reply to any HexaHang email with "REMOVE", or email privacy@hexahang.com
- Analytics cookies: clear cookies and decline the banner on your next visit, or use the Google Analytics Opt-out Browser Add-on / Microsoft Clarity opt-out
Withdrawal does not affect the lawfulness of processing carried out before withdrawal (Section 6(4) of the Act). We will cease the affected processing within 7 days of receiving a valid withdrawal request, subject to retention required by law (see Section 7).
Marketing consent is separate and explicit. Registration does not constitute consent to receive marketing communications. Marketing opt-in is a distinct, non-pre-ticked checkbox.
5. Third-Party Sharing
We share personal data with the following third parties only:
| Recipient | Role | Data Shared | Location | Agreement |
|---|---|---|---|---|
| Razorpay Software Pvt. Ltd. | Data Processor (payments) | Name, email, mobile, order amount | India | Razorpay merchant agreement (acts as DPA) |
| Shipway Technology Private Limited and its courier network (which may include Blue Dart, Delhivery, DTDC, and similar carriers) | Data Processor (fulfilment) | Name, mobile, shipping address | India | Logistics SLA / DPA with data-handling clause |
| Resend, Inc. | Data Processor (transactional email) | Name, email address | USA (see Section 6) | Resend Data Processing Addendum |
| AISENSY Communications Pvt. Ltd. (AiSensy) | Data Processor (WhatsApp messaging) | Name, mobile number | India | AiSensy DPA |
| Google LLC (GA4) | Data Processor (analytics) | Anonymised session data | USA (see Section 6) | Google's standard data processing terms |
| Microsoft Corporation (Clarity) | Data Processor (UX analytics) | Anonymised session data | USA (see Section 6) | Microsoft's standard data processing terms |
We do not sell, rent, or share your personal data with any third party for their own marketing purposes.
6. Cross-Border Transfers
The following processors operate on servers outside India:
- Resend, Inc. (Delaware, USA) — transactional email delivery
- Google LLC (USA) — Google Analytics 4
- Microsoft Corporation (USA) — Clarity analytics
Personal data may be processed outside India by service providers acting on our behalf, subject to applicable contractual, technical, and organisational safeguards and applicable law. Transfers are permitted under Section 16 of the DPDP Act read with Rule 15 of the DPDP Rules 2025, subject to any restrictions notified by the Central Government from time to time. As of the last updated date, no jurisdictions are restricted.
If you prefer not to have analytics data transferred internationally, decline the analytics cookie consent on your first visit. Transactional emails (order confirmations, shipping updates) are operationally essential and cannot be opted out of while you have an active order — withdrawing consent here would prevent us from fulfilling your order.
7. Retention Periods
We retain personal data only for as long as necessary:
| Data | Retention | Reason |
|---|---|---|
| Registration entries (pre-order) | Until you unsubscribe, or 24 months from collection — whichever is earlier | Re-engagement window |
| Order records (name, address, payment metadata) | 8 years from the end of the relevant financial year | Section 36 of the CGST Act 2017; supplementary tax records under the Income Tax Act 1961 |
| Customer support correspondence | 12 months from last interaction | Support reference and dispute resolution |
| Analytics data | 14 months (GA4 platform default); Clarity platform default | Platform retention limit |
After the applicable period, data is erased or anonymised so it can no longer be linked to you. Where you have an active relationship with us, we will notify you 48 hours before erasure of data we are no longer required to retain, in accordance with the DPDP Rules.
8. Your Rights as a Data Principal
Under Sections 11–14 of the DPDP Act, you have the right to:
- Access (Section 11) — request a summary of personal data we hold about you and how it is being processed
- Correction and erasure (Section 12) — request that inaccurate data be corrected, and that data no longer necessary be erased. Some data is retained as required by law even after an erasure request — we will tell you what and why.
- Grievance redressal (Section 13) — raise a complaint with our Grievance Officer (see Section 9)
- Nominate (Section 14) — appoint another individual to exercise your rights on your behalf in the event of your death or incapacity
How to exercise your rights
- Email: privacy@hexahang.com
- Subject line format: Rights Request — [Your Name] — [Request type]
We will acknowledge your request within 72 hours and respond substantively as soon as reasonably practicable. Grievances are resolved within 90 days of receipt, in accordance with the DPDP Rules. If your grievance remains unresolved within that period, you may approach the Data Protection Board of India, or such other authority, board, tribunal, or forum as may be designated under applicable data protection laws in force at the relevant time.
9. Grievance Officer
- Grievance Officer: Mourya Dasgupta (sole proprietor, and the contact mechanism for data-protection grievances under the DPDP Act)
- Email: grievance@hexahang.com
- WhatsApp: +91 62934 01030
- Acknowledgement SLA: 72 hours
- Resolution SLA: within 90 days
If a grievance remains unresolved within 90 days, you may approach the Data Protection Board of India, or such other authority, board, tribunal, or forum as may be designated under applicable data protection laws in force at the relevant time.
10. Security Safeguards
We implement the following reasonable security safeguards:
- In transit: All traffic between your device and our site is encrypted using TLS 1.2 or higher (HTTPS), enforced at both our CDN edge and origin server.
- At rest: Personal data is stored in a PostgreSQL database on a dedicated virtual private server (Hostinger, Mumbai region). Selected high-risk fields are encrypted at the application layer. Access to the server and database is restricted to the proprietor.
- Payment data: Card and UPI credentials are never stored by HexaHang. Razorpay is PCI-DSS Level 1 certified and handles all card data
- Access control: Access to customer data is restricted to the proprietor; no employees currently
- Logging: Access logs are retained for one year as per the DPDP Rules
- Vendor management: All third-party processors operate under their respective data processing terms
If you discover or suspect a security vulnerability, please email privacy@hexahang.com immediately.
11. Cookies and Tracking Technologies
We use the following cookies and tracking technologies:
| Technology | Provider | Type | Purpose | Consent Required |
|---|---|---|---|---|
| Session / functional cookies | First-party | Strictly necessary | Site navigation, form state | No (essential) |
| Google Analytics 4 | Google LLC | Analytics | Anonymised site usage analytics | Yes |
| Microsoft Clarity | Microsoft Corporation | Analytics | UX heatmaps and session replay | Yes |
We do not use advertising cookies, retargeting pixels, third-party ad networks, or social media tracking pixels.
A cookie consent banner is displayed on your first visit. Non-essential cookies do not load until you accept. You may change your preferences at any time via the cookie settings link in the site footer.
12. Children's Data
HexaHang's products and services are not directed at individuals under 18, and the Site is not intended for independent use by minors. We do not knowingly collect personal data from minors.
Mechanisms:
- All registration and checkout flows include an age affirmation that the user is at least 18 years old
- We do not deploy behavioural tracking, profiling, or targeted advertising
If we become aware that we have inadvertently collected personal data of a minor without verifiable parental consent (as required under the children's-data provisions of the DPDP Act and Rules), we will erase that data promptly upon discovery.
13. Data Breach Notification
In the event of a personal data breach:
- To the Data Protection Board: Initial notification without delay; detailed report within 72 hours of becoming aware, in accordance with the DPDP Rules
- To affected Data Principals: Notification without delay through registered email or WhatsApp, in plain language describing the nature of the breach, likely impact, mitigation steps taken, and what you can do
- To CERT-In: Cyber incidents reported within 6 hours of discovery, per MeitY Notification 20(3)/2022-CERT-In dated 28 April 2022 under Section 70B(6) of the IT Act 2000
14. Changes to This Policy
We may update this policy to reflect changes in our data practices, the law, or our services. Material changes will be communicated to active customers and subscribers by email. The last updated date at the top reflects the most recent revision.
15. Related Policies
This Privacy Policy is read together with: Terms of Use; Refund Policy; Cancellation Policy; Shipping Policy; Returns Policy.
16. Contact
- Privacy queries: privacy@hexahang.com
- Grievance Officer: Mourya Dasgupta — grievance@hexahang.com
- WhatsApp: +91 62934 01030
- Address: Aparupa Apartments, Flat 3A, 2 G.B. Dutta Road, Sodepur, Kolkata – 700110, West Bengal, India