Privacy Policy
We care about privacy because our work depends on trust. This page explains what data we collect, why we collect it, how long we keep it, and the choices you can make at any time.
Compliance and Data Protection
At Sun & Soil, we are committed to ensuring full compliance with all applicable laws and regulations, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). We prioritize the protection of your data and privacy, implementing industry-standard security measures to safeguard your personal information.
Data Collection and Usage
We collect, store, and process personal information strictly in accordance with legal requirements and ethical standards. Our data-handling practices are regularly reviewed to maintain compliance with evolving regulations and industry best practices.
Transparency and Accountability
Transparency is at the core of our operations. We clearly outline how your data is collected, used, and stored. Our policies reflect our ongoing efforts to maintain compliance and accountability.
User Rights and Choices
As part of our commitment to compliance, we respect your rights to access, update, and delete your personal information. You can request data modifications or removals by contacting us at hello@sunandsoil.in.
Scope of this Policy
This policy applies to our website, pop-up ordering tools, customer support channels, and any records we create while fulfilling produce orders in India. It does not govern third-party sites we link to; their terms apply independently.
Legal Bases for Processing
We process personal data under one or more lawful bases: your consent; performance of a contract (for example, preparing and delivering an order); compliance with legal obligations; and legitimate interests such as improving logistics and preventing fraud, always balanced against your rights.
Categories of Personal Data
Depending on how you interact with us, we may handle contact details, delivery information, order history, payment confirmations from our payment partners (tokenized and not stored by us), and communications you send to our support team.
How We Collect Information
Information is provided directly by you during checkout or inquiry, generated by our systems when we prepare and track crates, or supplied by reliable service providers (e.g., payment, analytics, and delivery partners) acting on our instructions.
How We Use Information
We use data to confirm and deliver orders, answer questions, manage returns, prevent misuse, forecast seasonal demand, and improve route planning. We never use customer data to build third-party marketing profiles or to sell advertising.
Data Retention
We keep personal data only as long as necessary for the purpose collected and as required by law. Typical retention periods: invoices and order records—up to 7 years; routine support messages—up to 24 months; server logs—up to 12 months. When data is no longer needed, we delete or irreversibly anonymize it.
International Transfers
Our primary systems are hosted within India with reputable providers. If data is transferred across borders, we use appropriate safeguards—such as Standard Contractual Clauses or equivalent legal mechanisms—to protect your information.
Security Practices
We apply layered security: encryption in transit, role-based access controls, regular patching, vendor due diligence, and staff training on privacy-by-design. We maintain an incident response plan and will notify you and regulators when legally required.
Cookies and Similar Technologies
We use a small number of cookies to keep sessions secure, remember preferences, and understand aggregate site usage. You can control cookies through your browser settings. Essential cookies are required for basic site functions such as login and cart integrity.
Sharing with Service Providers
We share information with processors who help us operate the service—hosting, payments, logistics, email, and analytics. They may use data only on our documented instructions. We do not sell or “share” personal information for cross-context behavioral advertising.
Children’s Privacy
Our website is not directed to children under 16, and we do not knowingly collect data from them. If you believe a child has provided personal information, please contact us so we can delete it promptly.
Policy Updates & Effective Date
We may update this policy to reflect operational, legal, or regulatory changes. Material changes will be announced on this page with a clear effective date. The current version is effective as of .
Contact & Complaints
Questions about privacy at Sun & Soil can be sent to hello@sunandsoil.in. You may also have the right to lodge a complaint with your local data protection authority; we encourage contacting us first so we can resolve concerns quickly and fairly.