Privacy Policy
This Privacy Policy applies to the TinyTotBooks website and orders, enquiries, and messages received through it.
TinyTotBooks is a small, home-run children's bookshop offering new, imported, and pre-loved books for delivery within India. This policy explains, in plain language, what personal data we collect, why we use it, which services may process it, how we retain it, and how you can contact us about your privacy.
We aim to handle personal information responsibly and in accordance with applicable Indian data protection and privacy laws, including the Digital Personal Data Protection Act, 2023 ("DPDP Act") and applicable rules.
The short version
- We collect information needed to process orders, arrange deliveries, communicate with customers, and provide support.
- Razorpay processes online payments. We also maintain order records and payment references needed to manage transactions.
- We do not sell personal information.
- We use third-party services to operate the shop, process payments, host the website, and deliver orders.
- We retain information for as long as reasonably necessary for business purposes and applicable legal obligations.
- You can contact us to ask about your personal information, request corrections, or request deletion where applicable.
- Our website is intended for adults placing orders for children's books.
Our approach as a small business
TinyTotBooks is a small, family-run home business, and our website is built and maintained in-house. While our technical resources and expertise are limited, we sincerely strive to handle personal information responsibly and comply with applicable laws. We aim to address issues when identified and continuously improve our practices as our capabilities grow.
1. Who we are
The business operating this website is TinyTotBooks, operated by Ayachi Priyadarshini Archa, at Shivdhara Chowk, Gehumi, Darbhanga, Bihar [PIN - 846005].
The person or entity responsible for deciding why and how personal information is processed is referred to under applicable data protection law as the Data Fiduciary.
In this policy, "we", "us", and "our" refer to TinyTotBooks. "You" refers to anyone who visits our website, places an order, tracks an order, or contacts us.
2. What personal data we collect
The information we collect depends on how you interact with our website and services.
| Where | Information | Purpose |
|---|---|---|
| Checkout | Full name | Identifying the purchaser and addressing the parcel |
| Checkout | Mobile or WhatsApp number | Order communication and order tracking |
| Checkout | Email address, if provided | Payment processing and alternative customer communication |
| Checkout | Delivery address, including house or flat, street, area, city, PIN code, district, and state | Delivering purchased books |
| Checkout | Coupon code, if provided | Applying discounts |
| Order records | Order number, purchased items, subtotal, shipping, discounts, total, order status, payment status, payment references, and timestamps | Order fulfilment, support, tracking, and business recordkeeping |
| Order tracking | Order number and phone number | Identifying the relevant order and displaying its status |
| Bulk and event enquiries | Information you choose to provide, such as your name, city, requirements, and preferred books | Responding to enquiries and preparing quotations |
| Customer communications | Messages and contact details you provide through WhatsApp, Instagram, or other communication channels | Responding to enquiries and providing support |
| Reviews | Reviewer name, rating, review text, and date, where applicable | Displaying customer feedback |
| Technical information | Information such as IP addresses and browser or device details that may be processed by hosting and other service providers | Delivering the website and supporting security and operations |
Incomplete checkouts
When you begin checkout and select the payment option, information may be transmitted to our backend to create an order before payment is completed.
If you close the payment window or do not complete the payment, some information may remain in our records. We handle these records according to the retention principles described in Section 8.
We do not promise a particular automatic deletion deadline for abandoned checkout information.
3. What we do not collect
Based on the intended functionality of our customer storefront:
- Customers do not create ordinary customer accounts or passwords to place orders. The administrative interface is separate from the customer storefront.
- Payment card, UPI, net-banking, and wallet authentication details are entered through the payment provider's interface. Razorpay processes these payment details.
- An OTP field may appear during checkout, but phone verification is not currently implemented through that field. Information entered there is not used to verify or authorise an order.
- The age-group filters help customers browse books and do not require them to submit a child's personal details.
We do not intentionally collect sensitive personal information unrelated to operating the shop.
Our website and third-party services may process technical information necessary to deliver the website, operate its features, and support security.
4. Why we use your data and the basis for doing so
Purposes
We use personal information for purposes such as:
- Processing and fulfilling orders.
- Calculating order totals, shipping charges, and discounts.
- Processing payments and confirming payment status.
- Reserving, packing, and dispatching books through India Post.
- Communicating with you about order confirmations, delivery updates, problems, returns, and support.
- Allowing you to track your order.
- Responding to enquiries, bulk orders, event requests, and collaboration proposals.
- Maintaining business, accounting, and tax records.
- Maintaining the security and functionality of the website.
- Meeting applicable legal obligations and responding to lawful requests.
We do not sell personal information. We do not use customer contact details for promotional messages unless this is consistent with our actual practices and applicable requirements.
Consent and other applicable grounds
We handle personal information in accordance with applicable law.
Where consent is required, we seek consent for the relevant processing and provide information about its purposes. You may withdraw consent where applicable by contacting us through the methods described in Section 14.
Withdrawing consent does not retrospectively invalidate processing that was lawful before withdrawal. However, it may affect our ability to complete an order or provide a service that requires the information.
Where information is voluntarily provided through WhatsApp, enquiries, or other communications, we use it to respond to the relevant request and for other purposes explained in this policy where permitted by law.
We may also retain or process information when necessary to meet applicable legal obligations.
Reviews
Our Reviews page may display customer feedback, including a reviewer's name, rating, text, and date.
Where reviews originate from Google or other external sources, the information may be subject to the relevant service's terms and privacy practices.
If you believe a review displayed on our website should be corrected or removed, contact us and we will review your request.
5. Who we share your data with
We do not sell or rent personal information.
We use third-party providers to help operate our shop. Depending on the service, these providers may process information on our behalf or handle it independently under their own terms and privacy practices.
| Provider | Purpose | Information potentially involved |
|---|---|---|
| Supabase | Backend services, database, server functions, and storage | Order records, checkout information, tracking records, and administrative authentication information, as applicable |
| Razorpay | Online payment processing | Customer and transaction information submitted through our payment integration |
| India Post | Delivery | Recipient name, delivery address, and contact information needed for delivery |
| WhatsApp / Meta | Customer communication | Contact details and messages exchanged through the service |
| GitHub Pages | Website hosting | Technical information that may appear in hosting or request logs |
| jsDelivr | Delivery of the JavaScript library used by our website | Technical information associated with loading the external resource |
| External links, reviews, and any linked Google Forms | Information you provide directly to Google services | |
| Instagram and YouTube | External social media profiles and book videos | Information processed by those services when you visit or interact with them |
Payment information
Razorpay processes online payments through its payment interface.
Our application also maintains order information and payment references needed to manage transactions.
Depending on our payment integration, information such as your name, phone number, email address, delivery address, and order details may be transmitted to Razorpay or included in its transaction records.
Razorpay separately processes payment instrument information under its own applicable terms and privacy practices.
Other disclosures
We may disclose information when required by applicable law or lawful requests from competent authorities. We may also take appropriate steps to address suspected fraud, abuse, or security incidents.
Third-party websites and services have their own privacy practices. This policy does not replace those policies.
6. Data stored in your browser
To make the shop work, our website uses browser local storage for certain information, including shopping cart contents, shipping-related settings, and cached catalogue information.
These items help the storefront remember information between visits. They are separate from the order records maintained by our backend.
The local storage items described above are intended to contain storefront information rather than your name, phone number, or delivery address.
You can clear local storage through your browser settings. Doing so may remove your saved cart and other locally stored storefront information.
Browser local storage is different from cookies. Third-party services may use their own technologies when you interact with them.
7. Children
TinyTotBooks sells books intended for children, but our website is intended for adults placing and managing orders.
The age-group filters on our website help customers browse books. They do not require customers to submit a child's personal details.
We do not intend to use the website to collect children's personal information directly.
If you believe that personal information relating to a child has been submitted to us inappropriately, please contact us using the details in Section 14. We will review the matter and take appropriate action in accordance with applicable law.
8. How long we keep data
We retain personal information for as long as reasonably necessary for the purposes described in this policy, including processing orders, responding to customer enquiries, maintaining business records, resolving disputes, and meeting applicable legal obligations.
Different types of information may need to be retained for different periods.
For example:
- Order and checkout information: We may retain order records, including records of incomplete or abandoned checkouts, while they are needed for order management, customer support, transaction reconciliation, or other legitimate business purposes.
- Transaction and accounting records: Some order and payment records may need to be retained to meet applicable accounting, tax, or other legal requirements.
- Customer communications: Messages and enquiries may be retained while we respond to the matter and for as long as reasonably necessary for follow-up, recordkeeping, or resolving related issues.
- Reviews and published content: Customer feedback may remain published while we have an appropriate basis to display it, subject to applicable requirements and requests for correction or removal.
- Technical and security information: Technical records may be retained as needed for website operations, security, troubleshooting, and applicable legal requirements.
We do not promise a fixed automatic deletion deadline for each category of information.
Our retention and deletion practices depend on the type of information, the purpose for which it was collected, the systems in which it is stored, and any applicable legal requirements.
When personal information is no longer needed for its intended purposes and no applicable legal obligation requires its retention, we will take appropriate steps to delete it or otherwise dispose of it in accordance with applicable requirements.
Requests for deletion
You may contact us to request deletion of your personal information.
We will review your request and take appropriate action where deletion is permitted and applicable. Some information may need to be retained where required by law or where another lawful basis for retention applies.
Where we cannot fulfil a deletion request in full, we will explain the reason to the extent appropriate and permitted by law.
Deletion from our active systems may not immediately remove copies held in backups, technical logs, or records controlled by third-party providers. Those copies are subject to the applicable systems' retention and deletion processes.
9. Security and personal-data breaches
We take reasonable steps to protect personal information against unauthorised access, disclosure, alteration, loss, or misuse.
Our security measures depend on the systems and configurations in use and may include encrypted HTTPS connections, restricted administrative access, backend access controls, and server-side payment verification.
We do not store customers' complete payment card or UPI authentication credentials as part of our intended storefront functionality.
However, no website, database, or electronic storage system can be guaranteed to be completely secure.
What happens if a personal-data breach occurs?
If we become aware of a suspected or confirmed personal-data breach, we will take appropriate steps to investigate the incident, contain it where possible, assess its potential impact, and reduce the risk of further harm.
Where notification is required by applicable law, we will notify affected individuals and relevant authorities in accordance with the applicable requirements and timelines.
Depending on the circumstances and the information available, a notification may explain:
- What happened.
- The likely consequences of the incident.
- The steps taken or planned to address it.
- Any measures individuals can take to protect themselves.
- How to contact us for further information.
The information provided will depend on the circumstances of the incident and the information available at the time. Where additional information must be provided later, we will address it as required.
Not every security incident necessarily requires the same type of notification. Our response will depend on the nature and seriousness of the incident and the obligations applicable to us.
10. Your rights and how to use them
Depending on applicable law, you may have rights concerning personal information we hold about you.
These may include the right to:
- Access: Request information about the personal data we hold about you and how it is used.
- Correction and updating: Request correction of inaccurate information, such as an incorrect delivery address or phone number.
- Erasure: Request deletion of personal information where applicable, subject to lawful retention requirements.
- Withdraw consent: Withdraw consent where processing is based on consent and withdrawal is permitted under applicable law.
- Grievance redressal: Raise a concern about how your personal information is handled.
- Nomination: Exercise any applicable right to nominate another person in accordance with the relevant legal requirements.
How to make a request
Contact us using the WhatsApp or email details in Section 14.
Please provide enough information for us to identify the relevant order or record. We may ask you to verify your identity to help prevent unauthorised access to or alteration of another person's information.
We will handle requests in accordance with applicable law and the procedures and timelines that apply to us.
Some information may need to be retained where required by law or another applicable lawful basis.
11. Grievances and complaints
If you have a concern about how your personal information is handled, please contact us first using the details in Section 14.
We will review your concern and respond in accordance with the procedures and timelines applicable to our business.
Where applicable law provides a right to approach the Data Protection Board of India or another competent authority, you may exercise that right in accordance with the relevant procedures.
12. Processing outside India
Some service providers may use infrastructure located in different countries. Depending on the service, your personal information may therefore be processed or stored outside India.
Such processing is subject to the arrangements and safeguards applicable to the relevant service providers and to applicable Indian law.
We do not specify a particular database hosting region in this policy until that region has been verified.
13. Changes to this policy
We may update this policy when our business practices, services, or applicable legal requirements change.
The "Last updated" date at the top of this page indicates when the policy was last revised.
Where required by applicable law, we will provide notice of changes or obtain any necessary consent.
14. Contact us
For privacy questions, requests concerning personal information, or complaints, please contact TinyTotBooks using the details below.
Business: TinyTotBooks
Business owner / grievance contact: Ayachi Priyadarshini Archa / Amritesh Divyanshu
WhatsApp: +91 87896 77337 or +91 7322923985
Email: amriteshdivyanshu2006@gmail.com
Postal address: Shivdhara Chowk, Gehumi, Darbhanga, Bihar, India [PIN-846005]
Thank you for trusting TinyTotBooks with your little reader's next story.
