Sparkle Studio Legal Hub
This policy center outlines our structural commitments, practices, and guidelines under applicable privacy acts and ecommerce regulations.
Framework Alignment
Designed in compliance with the Information Technology Act 2000, Consumer Protection Rules 2020, and addressing DPDP 2023 guidelines where applicable.
1. Information We Collect
At Sparkle Studio, we collect personal informationⓘ necessary to offer custom jewelry visualization. (a) Account Registration: We collect names, email addresses, contact phone numbers, and optional shipping addresses (including geo-coordinates for delivery mapping). (b) Design Metadata: We collect prompt text inputs, generated rendering configurations, and interactive 3D model modifications. (c) Technical Diagnostics: We collect browser versioning details, IP addresses, session cookiesⓘ, and interface telemetry.
We collect account details (name, email, phone, shipping addresses) and platform interactions (jewelry design parameters, prompt history).
2. How We Use Your Information
We process personal informationⓘ under the following legal bases: (a) Fulfillment of Contract: To authenticate client logins, load vendor workspaces, and manage billing profiles. (b) Operational Security: To perform rate-limiting, detect double billingⓘ anomalies, and block suspicious session activities. (c) Service Optimization: To analyze viewport sizes, diagnostic logs, and compile rendering latency metrics.
We use your data to maintain your account, process payments, route orders, optimize UI speed, and secure the platform.
3. Data Sharing & Third-Party Integrations
We do not sell, rent, or trade your personal informationⓘ. We share relevant data with trusted sub-processors: (a) Payment Gateways: Transaction details and billing information are securely routed to Stripeⓘ and Razorpayⓘ. (b) Analytics and Performance: Telemetry logs are routed to Vercel Speed Insights for layout speed optimizations. (c) Legal Compliance: We may disclose details if required by Indian or international law to protect against cyber incidents or system fraud.
We share data with payment gateways (Razorpayⓘ, Stripeⓘ) and analytics tools. We do not sell your personal dataⓘ.
4. International Data Rights (GDPR & CCPA)
The policy is designed to address requirements relevant to applicable privacy laws, including the European Union General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) where applicable. You have the right to: (a) Request a copy of your compiled personal records. (b) Request correction of inaccurate details. (c) Demand permanent deletion of your profile history from our databases. (d) Object to the processing of cookiesⓘ. To trigger any of these rights, please contact our privacy compliance desk.
Under GDPR and CCPA, you have the right to access, edit, download, or delete your personal dataⓘ. You can opt-out of cookiesⓘ.
5. Digital Personal Dataⓘ Protection (DPDP) Act, 2023
The policy is designed to address requirements relevant to India's Digital Personal Dataⓘ Protection (DPDP) Act, 2023. As a Data Principalⓘ, you have specific rights: (a) Right to information regarding processing operations. (b) Right to correction and erasure of your personal dataⓘ. (c) Right to register grievances. (d) Right to withdraw consent at any time. When you withdraw consent, we will stop processing your personal dataⓘ, though this may limit your access to custom jewelry styling tools.
For users in India, we process data based on clear consent. You can view, correct, or request deletion of your data and withdraw consent.
6. Data Security & Storage Integrity
We implement production-grade security safeguards: (a) Encryption: Highly sensitive database fields (such as vendor PAN records or authentication salts) are encrypted at-rest using AES-256-GCM configurations. (b) Session Integrity: Accounts use session version tracking to invalidate logins across devices upon password changes. (c) Retention: Personal dataⓘ is retained only as long as necessary to fulfill active subscriptions or comply with statutory auditing cycles.
We encrypt sensitive data (such as financial records, tax PAN details) and secure active sessions. We keep data only as long as needed.
7. Grievance Redressal Officerⓘ
In compliance with the Indian Information Technology Act, 2000 and Rules made thereunder, as well as the DPDP Act, 2023, the contact details of the Grievance Redressal Officerⓘ are published below: Name: Mr. Karthik Sundaram Designation: Compliance Officer & Grievance Redressal Lead Address: Sparkle Studio Private Limited, Anna Salai, Chennai, TN - 600002, India. Email: grievance@sparklestudio.co.in Contact Window: Monday to Friday, 10:00 AM to 5:00 PM IST.
If you have any privacy issues or queries, contact our Grievance Officerⓘ, as required under Indian IT Rules.
Version Revision History
Initial compliance release. Designed to address requirements of India's DPDP Act 2023, GDPR, and CCPA. Appointed Grievance Redressal Officer and established security encryption disclosures.