Privacy Policy
Last updated: 19 April 2026
Spread & Spine (“we”, “our”) respects your privacy. This policy explains how we handle personal data in line with the Digital Personal Data Protection Act 2023 (DPDP Act) and the EU General Data Protection Regulation (GDPR) for visitors from the EEA/UK.
1. What we collect
- Contact details: name, email, phone, shipping/billing address.
- Account details: hashed password, login provider, profile image.
- Order details: items, amounts, payment confirmation (not card numbers).
- Workshop and inquiry submissions.
- Device, browser, approximate location, and usage analytics (with consent).
2. Why we collect it
- To fulfil your orders, bookings, and custom-order inquiries.
- To provide customer support and transactional communications.
- To comply with Indian tax and accounting law.
- To improve the site (analytics), with your consent.
- To send marketing emails, only if you opt in.
3. Retention
Order records are retained for seven years for tax compliance. Account data is retained while your account is active and deleted within 90 days of closure. Newsletter data is deleted upon unsubscribe.
4. Your rights
Under the DPDP Act and GDPR you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Erase your data (right to be forgotten), subject to legal retention.
- Port your data in a machine-readable format.
- Withdraw consent for analytics or marketing at any time.
- Lodge a complaint with the Data Protection Board of India.
5. Grievance Officer
[Placeholder Name]
Email: privacy@spreadandspine.com
Address: [Placeholder studio address], Bengaluru, Karnataka, India
6. Cookies
We use essential cookies (cart, session, checkout) by default. With your consent we also enable analytics and marketing cookies. You can change your preferences at any time via the cookie banner.
7. Third-party processors
We share strictly necessary data with:
- Razorpay — Payment processing
- Resend — Transactional and marketing email delivery
- Supabase — Database hosting (Mumbai region)
- Vercel — Website hosting and edge delivery
- Google Analytics 4 — Website analytics (with consent)
- Microsoft Clarity — Session replay analytics (with consent)
- Algolia — Product search indexing
- Cloudflare R2 — Media asset storage and delivery
8. Contact
Questions? Email privacy@spreadandspine.com.
