Privacy Policy
Last updated: 22 August 2026
Last updated: 22 August 2026 · Compliant with the Digital Personal Data Protection Act, 2023 (India) and the IT (Reasonable Security Practices & Procedures) Rules, 2011
This Privacy Policy explains what personal data Intru (intru.in) collects when you visit or shop with us, how we use it, who we share it with, and the rights you have as a Data Principal under Indian law. We try to keep this document short and readable. If any part is unclear, email shop@intru.in and we'll explain.
1. Who's the Data Fiduciary
Intru — an Indian streetwear label operating from Hyderabad, Telangana — is the "Data Fiduciary" (under the DPDP Act 2023) for the personal data collected on intru.in. Our Grievance / Nodal Officer is contactable at shop@intru.in.
2. What Data We Collect & Why
We collect the minimum data needed to run the store. Concretely:
- Account & order data — name, email, phone, shipping address, order history. Used to: process orders, send tracking, manage Store Credit, provide support.
- Payment data — handled directly by Razorpay. We only ever see the last 4 digits / UPI VPA and a payment status. Used to: confirm the payment.
- Login data — if you sign in with Google, we receive your name, email, and profile picture from Google (nothing else). Used to: identify you across sessions.
- Browsing & device data — pages viewed, referrer, device type, approximate location (city-level, from IP), interaction events. Collected via Google Analytics 4 and Microsoft Clarity. Used to: understand what's working, fix broken flows, improve product pages.
- Cart & wishlist data — stored in your browser (localStorage) and, if you're signed in, mirrored to our database. Used to: keep your cart across devices.
- Support messages & AI Stylist chats — anything you type to us over email or the AI Stylist. Used to: answer you, improve the Stylist's replies. Please don't share sensitive personal information (Aadhaar, PAN, medical data, financial credentials) with the Stylist.
- Cookies — see section 6.
We do not knowingly collect data from anyone under 18. We do not process sensitive personal data (biometric, health, financial-instrument credentials) as part of ordinary shopping.
3. Lawful Basis for Processing
Under the DPDP Act 2023, we process your data on one of three bases:
- Consent — you tick a box, accept cookies, subscribe to email, or start a chat.
- Legitimate use for a specified purpose — mostly fulfilling an order you placed (a "voluntary purpose" for which you provided data).
- Legal obligation — retaining invoices & GST records under Indian tax law.
4. Who We Share Data With
We only share data with the vendors we genuinely need to run the shop. Each of them is bound by its own privacy policy and, where relevant, a Data Processing Agreement:
- Supabase (database, auth) — stores your account & order data. Hosted in Singapore region, encrypted at rest.
- Cloudflare (hosting, CDN, edge) — routes and secures every request to intru.in.
- Razorpay (payment processing) — handles payment credentials so we don't have to.
- Google — Sign-in with Google, Google Analytics 4, Google Tag Manager (measurement only, no ads pixel on this site at time of writing).
- Microsoft Clarity — anonymous heatmaps and session replays. IPs are anonymised by Clarity.
- Resend — sends transactional email (order confirmations, tracking, Store Credit notifications).
- Shiprocket & partner couriers — receive name, phone, and shipping address to deliver your parcel.
- Meta / Instagram — only if you interact with our embedded Instagram feed or click through to @intru.in.
- AI providers (OpenRouter / Groq / Google Gemini) — the AI Stylist forwards your chat message to a language model to generate a reply. Do not share sensitive data with the Stylist.
We do not sell or rent your personal data to anyone. We do not run behavioural ad pixels for third-party ad networks on this site at the time of writing.
5. Cross-Border Data Transfer
Some of the vendors above (Supabase, Cloudflare, Google, Resend, OpenRouter, Groq) may process data on servers located outside India. Where required under the DPDP Act, we rely on contractual safeguards and the Indian government's list of permitted jurisdictions. If you'd like a copy of the specific safeguards for a given vendor, email shop@intru.in.
6. Cookies & Similar Technologies
Cookies are small text files stored in your browser. We use:
- Strictly necessary — cart, session, CSRF, admin auth. Cannot be switched off (the site would break).
- Analytics — Google Analytics 4 & Microsoft Clarity. Off until you consent (if the cookie banner is enabled by our admin).
- Preferences — remembering your Store Credit balance, cookie choice, dark-mode preference.
You can clear cookies in your browser at any time and re-visit — you'll be re-asked for consent where relevant. Note: the cookie banner itself can be toggled off by the site admin (in which case only strictly necessary cookies are used).
7. Data Retention
- Order records & GST invoices — retained for 8 years as required by Indian tax law.
- Account profile — retained as long as your account is active. Deleted 30 days after you submit a deletion request.
- Analytics events — 14 months (GA4 default), 3 months (Clarity default).
- AI Stylist chats — up to 90 days for quality review, then deleted.
- Marketing consent & email opt-ins — kept until you unsubscribe.
8. Your Rights as a Data Principal
Under the DPDP Act 2023 you have the right to:
- Access a summary of the personal data we hold about you.
- Correct or update inaccurate data.
- Erase your data (subject to legal retention obligations above).
- Withdraw consent for marketing at any time (unsubscribe link in every email).
- Nominate another individual to exercise your rights on your behalf in case of death or incapacity.
- Register a grievance with our Grievance Officer, and if unresolved, with the Data Protection Board of India.
To exercise any right, email shop@intru.in from the address on your account with the subject line "Data Request — [access / correct / delete / withdraw-consent]". We respond within 7 business days.
9. How We Secure Your Data
- SSL/TLS across the entire site (HTTPS-only, HSTS enabled).
- Row-level security on the Supabase database — customer records are isolated per user.
- Admin dashboard is protected by password + rotated tokens; access is audit-logged.
- API rate-limiting and bot filtering at the edge (Cloudflare).
- Payment credentials never touch our servers — Razorpay handles the sensitive path end-to-end.
- Regular reviews of vendor security posture and access permissions.
No system is 100% breach-proof. If a personal-data breach affecting you occurs, we will notify you and the Data Protection Board of India within the timeframes required by law.
10. Grievance Redressal
Grievance / Nodal Officer: Intru Grievance Desk
Email: shop@intru.in (subject line: "Privacy — Grievance")
Acknowledgement: within 48 hours · Resolution: within 30 days of receipt.
If we can't resolve it to your satisfaction, you can escalate to the Data Protection Board of India (once operational) under section 27 of the DPDP Act 2023.
11. Changes to This Policy
Material changes will be flagged on the site or emailed to registered users. The "Last updated" date at the top always reflects the current version. Continuing to use intru.in after a change means you accept the revised policy.