സ്വകാര്യതാ നയം
MARS COSMETICS PRIVATE LIMITED
Privacy Policy
Effective Date: April 21, 2026 | Governing Law: Digital Personal Data Protection Act, 2023
|
This Privacy Policy has been prepared in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and all rules framed thereunder. It applies to all individuals who interact with MARS Cosmetics Private Limited through our website, mobile platforms, or any related digital service. We encourage you to read this Policy carefully before using our services. |
1. Introduction & Definitions
MARS Cosmetics Private Limited (“MARS Cosmetics”, “we”, “us”, or “our”) is a company incorporated under the Companies Act, 2013, engaged in the retail and distribution of cosmetic and personal care products. We are committed to protecting the privacy and personal data of our customers, website visitors, and all other individuals who interact with our digital platforms.
This Privacy Policy sets out the manner in which we collect, use, store, disclose, and otherwise process your personal data. It also describes your rights as a Data Principal under the DPDP Act and the mechanisms available to you to exercise those rights.
Key Definitions
|
Data Principal |
The individual to whom the personal data relates — that is, you, the user or customer. |
|
Data Fiduciary |
MARS Cosmetics Private Limited, which determines the purpose and means of processing your personal data. |
|
Personal Data |
Any data about an individual who is identifiable by or in relation to such data, as defined under the DPDP Act. |
|
Processing |
Any operation performed on personal data, including collection, storage, use, sharing, disclosure, or deletion. |
|
Consent Manager |
A registered entity that enables Data Principals to manage, review, and withdraw consent through an accessible platform. |
|
Data Processor |
Any third party that processes personal data on behalf of MARS Cosmetics pursuant to a contractual obligation. |
2. Scope & Applicability
This Policy applies to all personal data collected by MARS Cosmetics in connection with your use of our website, mobile application, customer service channels, loyalty programmes, and any other digital or physical touchpoints operated by us. It applies to customers, prospective customers, visitors, and any other individual whose personal data we process.
This Policy does not apply to third-party websites, platforms, or services that may be linked from our website. We encourage you to review the privacy policies of those third parties independently, as we have no control over their data practices.
3. Notice & Consent
In accordance with Section 5 of the DPDP Act, we provide this notice to inform you of the personal data we collect, the purposes for which it is processed, and your rights in relation to such processing. Consent is obtained prior to, or at the time of, collecting your personal data.
Categories of Personal Data Collected
We may collect the following categories of personal data: full name, email address, phone number, delivery address, billing address, payment information, device and browser data, purchase history, and communication preferences.
Purposes of Processing
|
Purpose |
Description |
|
Order fulfilment |
Processing, dispatching, and delivering your purchases; managing returns and refunds. |
|
Customer support |
Responding to queries, complaints, and providing post-sale assistance. |
|
Marketing communications |
Sending promotional offers, product updates, and newsletters — only where you have opted in. |
|
Website improvement |
Analysing usage patterns to enhance user experience and platform performance. |
|
Legal compliance |
Meeting statutory obligations under applicable Indian laws, including tax and consumer protection laws. |
|
Fraud prevention |
Detecting and preventing fraudulent transactions and unauthorised account access. |
Consent and Withdrawal
By using our website and submitting your personal data, you provide unambiguous, affirmative, and informed consent to the processing of your data for the purposes described above. Consent is specific, granular, and freely given. You may withdraw your consent at any time by accessing your account settings or by contacting our Data Protection Officer. Withdrawal of consent will not affect the lawfulness of processing carried out prior to such withdrawal. Upon withdrawal, we will cease processing your data for the relevant purpose, subject to any legal retention obligations.
4.Data Minimization Retention
MARS Cosmetics adheres strictly to the principle of data minimization. We collect only such personal data as is adequate, relevant, and limited to what is necessary for the specified processing purposes. We do not collect personal data speculatively or beyond the scope of the identified purpose.
Retention Periods
|
Data Category |
Retention Period |
|
Order & transaction records |
7 years from the date of transaction (as required under tax laws) |
|
Customer account data |
Duration of account activity, plus 2 years post-closure |
|
Marketing preferences |
Until consent is withdrawn or account is deleted |
|
Communication logs |
3 years from the date of communication |
|
Fraud prevention records |
As required by law or until the matter is resolved |
Upon expiry of the applicable retention period, or upon withdrawal of consent (whichever is earlier), your personal data will be permanently deleted or de-identified in a manner that renders re-identification impossible, unless we are required by law to retain it for a longer period.
5. Disclosure & Third-Party Sharing
We do not sell, rent, or trade your personal data to any third party. We may, however, share your personal data with trusted third-party service providers and Data Processors engaged to assist us in delivering our services, strictly on a need-to-know basis and pursuant to binding contractual obligations that require them to protect your data.
Third-Party Categories
|
Category |
Purpose |
|
Logistics & delivery partners |
To fulfill and deliver orders to your specified address. |
|
Payment gateway providers |
To process transactions securely; we do not store card details on our servers. |
|
Cloud hosting providers |
To store and manage data on secure, compliant infrastructure. |
|
Marketing platforms |
To send communications where you have opted in, subject to strict data processing agreements. |
|
Analytics providers |
To analyse website traffic and user behaviour in aggregate, anonymised form. |
|
Legal & regulatory authorities |
Where required by law, court order, or regulatory direction. |
All third-party Data Processors are contractually bound to process personal data solely as instructed by us, to implement appropriate security measures, and to notify us promptly in the event of any breach or non-compliance.
6. Rights of the Data Principal
Under the DPDP Act, you are entitled to the following rights with respect to your personal data. To exercise any of these rights, please contact our Data Protection Officer using the details provided in Section 7 of this Policy.
|
Right |
Description |
|
Right to Access |
Request a summary of your personal data being processed by us, the purposes of such processing, and the identities of third parties with whom it has been shared. |
|
Right to Correction |
Request the correction or completion of personal data that is inaccurate, incomplete, or outdated. |
|
Right to Erasure |
Request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, subject to legal retention requirements. |
|
Right to Grievance Redressal |
Access a dedicated grievance mechanism to raise and resolve complaints regarding the processing of your personal data in a timely manner. |
|
Right to Nominate |
Nominate an individual to exercise your data rights on your behalf in the event of your death or incapacity, in accordance with the DPDP Act. |
|
Right to Withdraw Consent |
Withdraw consent for any specific processing activity at any time, without affecting the lawfulness of prior processing based on that consent. |
We will respond to all valid requests within the timelines prescribed under the DPDP Act. We reserve the right to verify your identity before processing any request to protect against unauthorised access to your data.
7. Data Protection Officer & Grievance Redressal
In compliance with the DPDP Act, MARS Cosmetics has appointed a Data Protection Officer (DPO) responsible for overseeing our data protection strategy, ensuring regulatory compliance, and serving as the primary point of contact for Data Principals wishing to exercise their rights or raise concerns.
If you have any queries, concerns, or complaints regarding the processing of your personal data, please contact the DPO using the details below. We aim to acknowledge all complaints within 48 hours and resolve them within 30 days of receipt.
|
Abhishek Sethia Director & Data Protection Officer — MARS Cosmetics Private Limited Email: abhishek@marscosmetics.in Address: Unit No. 801, 8th Floor, D-Mall, Netaji Subhash Place, New Delhi – 110034 |
If you are not satisfied with our response to your complaint, you have the right to escalate the matter to the Data Protection Board of India, as constituted under the DPDP Act.
8. Data Security
MARS Cosmetics implements reasonable and appropriate technical, administrative, and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures include, but are not limited to: SSL/TLS encryption in transit, encrypted data storage, role-based access controls and multi-factor authentication, regular security audits and vulnerability assessments, employee data protection training, and rigorous vendor due diligence.
Notwithstanding the above, no method of electronic transmission or storage is completely secure. While we strive to protect your personal data using commercially reasonable means, we cannot guarantee absolute security.
Data Breach Notification
In the event of a personal data breach that is likely to result in harm to you, we are legally mandated under the DPDP Act to notify the Data Protection Board of India and the affected Data Principals promptly, in accordance with the prescribed statutory timelines and procedures. Such notification will include the nature of the breach, the data affected, and the remedial steps taken or planned.
9. Cookies & Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyse site traffic, and personalise content. Cookies are small text files stored on your device when you visit our website.
|
Cookie Type |
Purpose |
|
Strictly Necessary |
Required for the website to function; cannot be disabled without affecting core functionality. |
|
Performance |
Collect anonymised data on how visitors use the website to help us improve performance. |
|
Functional |
Remember your preferences, such as language and region settings. |
|
Marketing |
Track your activity to deliver relevant advertisements. Used only with your explicit consent. |
You may manage or withdraw your cookie preferences at any time through the cookie consent tool available on our website, or by adjusting your browser settings. Please note that disabling certain cookies may affect the functionality of the website.
10. Children’s Data
MARS Cosmetics does not knowingly collect or process personal data of children below the age of 18 years without verifiable parental or guardian consent, in accordance with the DPDP Act. Our services are directed at adults and are not intended for use by minors.
If we become aware that we have inadvertently collected personal data of a minor without appropriate consent, we will take immediate steps to delete such data from our records. If you believe we may have collected data relating to a child, please contact our DPO immediately.
11. Cross-Border Data Transfers
In certain circumstances, your personal data may be transferred to, stored in, or processed in countries outside India, for instance where our cloud hosting or analytics service providers operate internationally. Any such transfer will be carried out only to countries notified by the Central Government of India as permissible under the DPDP Act, and subject to appropriate contractual safeguards to ensure that your data receives a standard of protection equivalent to that provided under Indian law.
We will keep this section updated as the Central Government issues notifications regarding permissible transfer destinations under the DPDP Act.
We reserve the right to amend, update, or modify this Privacy Policy at any time to reflect changes in our data practices, applicable laws, or business operations. Any material changes to this Policy will be communicated to you via email or a prominent notice on our website, and the revised Policy will take effect from the date indicated at the top of this document.
We encourage you to review this Policy periodically to stay informed about how we protect your personal data. Your continued use of our website following notification of any changes constitutes acceptance of the revised Policy.
13. Governing Law & Jurisdiction
This Privacy Policy is governed by and shall be construed in accordance with the laws of India, including the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and all rules, regulations, and guidelines framed thereunder. Any dispute arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at New Delhi, India.
|
MARS Cosmetics Private Limited 8th Floor, Unit No. 801, D-Mall, Netaji Subhash Place, New Delhi – 110034 |

