Privacy Policy

Monta Bella is committed to protecting your personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable laws in India. This Privacy Policy explains how we collect, process, store, disclose, and protect your personal data when you visit our website (www.montabella.in), purchase our products, or interact with us. By using our services, you consent to the practices described in this policy.

  1. Scope and ApplicabilityThis Privacy Policy applies to all individuals (“Data Principals”) whose personal data is collected by MontaBella, whether through our website, mobile application, or other interactions, such as purchases or customer service communications, within India or as permitted by law for cross-border processing.
  1. Personal Data We Collect

Under the DPDP Act, personal data is any data that can identify an individual. We may collect the following types of personal data:

a. Data Provided by You

Contact Information: Name, email address, phone number, billing address, and shipping address provided during purchases, account creation, or customer support interactions.

Payment Information: Credit card details, UPI IDs, or other payment method information processed through secure third-party payment processors.

Account Information: Username, password, and preferences if you create an account on our website.

Marketing Preferences: Consent for receiving newsletters, promotional offers, or SMS notifications.

Feedback and Reviews: Product reviews, ratings, or survey responses you voluntarily provide.

b. Data Collected Automatically

Browsing Data: IP address, browser type, device information, operating system, and browsing behavior (e.g., pages visited, time spent on the site) collected via cookies and similar technologies.

Analytics Data: Aggregated data about website usage, such as click patterns and traffic sources, collected through tools like Google Analytics.

c. Data from Third Parties

Service Providers: Information from payment processors, logistics partners, or marketing platforms.

Social Media: Data shared when you interact with us on platforms like Instagram or WhatsApp, subject to their privacy policies.

  1. Lawful Basis for Processing

We process your personal data based on:

Consent: When you provide explicit consent (e.g., for marketing communications or non-essential cookies).

Contractual Necessity: To fulfill orders, process payments, or provide customer support.

Legitimate Interest: For improving our services, preventing fraud, or analyzing website performance, provided it does not override your rights.

Legal Obligation: To comply with Indian laws, such as tax or consumer protection regulations.

  1. How We Use Your Personal Data

We use your personal data for the following purposes:

To process and fulfill your orders, including shipping, returns, and refunds.

To communicate with you about your account, orders, or customer service inquiries.

To send promotional emails, SMS, or WhatsApp messages (with your consent, as required under the DPDP Act).

To personalize your shopping experience, such as recommending perfumes based on your preferences.

To improve our website, products, and services through analytics and user feedback.

To detect and prevent fraud or unauthorized activities.

To comply with legal obligations, such as maintaining transaction records under Indian tax laws.

  1. How We Share Your Personal Data

We may share your personal data with:

Service Providers: Third-party vendors (e.g., payment gateways like Razorpay, logistics partners like Delhivery, or marketing platforms like Mailchimp) who assist in delivering our services. These vendors are contractually obligated to protect your data.

Legal Authorities: If required by law, court orders, or government authorities (e.g., tax authorities or law enforcement agencies in India).

Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity with appropriate safeguards.

Marketing Partners: With your consent, we may share limited data for targeted advertising or promotions.

We do not sell your personal data to third parties.

  1. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience, analyze website performance, and deliver personalized ads. You can manage cookie preferences through our website’s cookie consent tool or your browser settings. Essential cookies, necessary for website functionality, cannot be disabled. Non-essential cookies (e.g., for analytics or advertising) require your consent under the DPDP Act.

  1. Your Rights Under the DPDP Act

As a Data Principal under the DPDP Act, you have the following rights:

Right to Access: Request details of the personal data we hold about you and how it is processed.

Right to Correction: Request correction of inaccurate or incomplete personal data.

Right to Erasure: Request deletion of your personal data, subject to legal obligations (e.g., tax record retention).

Right to Data Portability: Request a copy of your personal data in a structured, machine-readable format.

Right to Withdraw Consent: Withdraw consent for processing (e.g., marketing communications) at any time.

Right to Nominate: Designate a nominee to exercise your rights in case of incapacity or death, as per the DPDP Act.

Right to Grievance Redressal: Raise concerns about data handling with our Data Protection Officer.

To exercise these rights, contact our Data Protection Officer at privacy@montabella.com. We will respond within 30 days, as required by the DPDP Act.

  1. Data Security

We implement reasonable technical and organizational measures to protect your personal data, such as encryption for payment processing, secure servers, and access controls. However, no system is completely secure, and we cannot guarantee absolute security.

  1. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy or comply with Indian laws. For example:

Order and payment data may be retained for 7 years to comply with tax laws.

Marketing data will be deleted upon withdrawal of consent.

Account data will be retained until you request deletion or the account becomes inactive for 2 years.

  1. Cross-Border Data Transfers

If your personal data is transferred outside India (e.g., to third-party service providers like cloud hosting services), we ensure compliance with the DPDP Act’s cross-border data transfer requirements. Appropriate safeguards, such as Standard Contractual Clauses or agreements with data fiduciaries, are implemented to protect your data.

  1. Third-Party Links

Our website may contain links to third-party platforms (e.g., social media or payment gateways). We are not responsible for their privacy practices. Please review their privacy policies before sharing data.

  1. Children’s Privacy

Our services are not intended for individuals under 18. We do not knowingly collect personal data from minors. If we learn that a minor’s data has been collected, we will delete it promptly.

  1. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. Significant changes will be communicated via email or a notice on our website. The “Last Updated” date at the top indicates the latest revision.

  1. Contact Us

For questions or concerns about this Privacy Policy or our data practices, please contact:

Email: montabella2025@gmail.com
Address: H.No.-45, Deeksha Estate, Nainana Jaat, Bamroli road, Agra 282001
Phone: +91 74528 90437