Privacy Policy

DPDP Act 2023 & IT Act 2000 compliance, inquiry confidentiality, and data protection practices.

Last Updated: August 2026 · Jurisdiction: Courts of Hyderabad, Telangana, India · DPDP Act 2023 Compliant

1. Introduction & Statutory Compliance

This Privacy Policy describes how the Food & Pantry Domain Portfolio ("we", "us", or "our") collects, processes, stores, and protects personal data obtained through this domain acquisition portal.

We comply with applicable Indian privacy and data protection legislations, including the Digital Personal Data Protection Act, 2023 (DPDP Act 2023), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, alongside international privacy standards (GDPR / UK GDPR) for foreign buyers.

2. Information We Collect (Data Principal Information)

We collect only the minimum necessary personal data required to evaluate acquisition inquiries, negotiate sales or lease-to-own agreements, and execute domain transfers:

  • Identification & Contact Data: Name, business email address, corporate entity name, and optional phone/WhatsApp number.
  • Inquiry & Transaction Data: Target domain selection, offer amounts, proposed lease terms, preferred escrow provider, and negotiation correspondence.
  • Technical & Diagnostic Logs: IP address, device type, browser specifications, timestamp, and Cloudflare Turnstile bot-suppression verification tokens.

3. Purpose & Legal Basis for Processing

Your personal data is collected and processed exclusively for specified, explicit, and legitimate purposes:

  • To review, evaluate, and respond to your domain acquisition offer, lease proposal, or inquiry.
  • To create and facilitate escrow transactions through accredited partners (Escrow.com, Dan.com, Sedo).
  • To fulfill domain technical delivery (EPP Auth-Code provisioning, DNS delegation for lease-to-own, and registrar account pushes).
  • To protect the website against malicious bots, automated scraping, and spam through Cloudflare Turnstile.
  • To maintain legal, financial, and tax records in compliance with Indian statutory requirements.

4. Non-Disclosure & Confidentiality Guarantee

We maintain strict confidentiality regarding all buyer identities, inquiries, offer amounts, and negotiated terms.

We do not sell, rent, monetize, or trade personal data to third-party marketing networks, commercial lead brokers, or unsolicited third parties.

5. Third-Party Service Providers & Data Transfers

We engage trusted, enterprise-grade service providers strictly necessary to operate our sales portal and conclude transactions:

  • Zoho ZeptoMail (Zoho Corporation Private Limited, India): Dispatches encrypted transactional email notifications from our inquiry form to our sales team.
  • Cloudflare Turnstile (Cloudflare, Inc.): Provides privacy-first bot detection and challenge verification without intrusive cookie tracking.
  • Licensed Escrow Providers (Escrow.com, Dan.com by GoDaddy, Sedo.com): Incurred upon mutual agreement to manage secure financial holding and title transfer.
  • ICANN & .IN Registry (NIXI) Accredited Registrars: Technical administrative contact data is updated during WHOIS / EPP domain transfers in accordance with registrar guidelines.

6. Cookie Policy & Local Browser Storage

We use minimal, privacy-centric browser storage mechanisms:

Theme Preference: Stored in localStorage under "ffb-theme" to persist your visual mode ("light" or "dark").

Cookie Consent Record: Stored in localStorage under "ffb_cookie_consent" to record your privacy preferences.

You can update your cookie preferences at any time using the "Cookie Preferences" link in the footer.

7. Technical & Organizational Security Measures

We implement robust industry-standard technical security practices, including TLS/HTTPS encryption in transit, strict file-system permissions (0700/0600), server-side input sanitization, CRLF stripping, and rate limiting to prevent unauthorized access, alteration, or disclosure.

All backend API keys and server configuration secrets reside outside the public web root directory.

8. Data Principal Rights (DPDP Act 2023 & GDPR)

Under the Digital Personal Data Protection Act, 2023, and applicable international laws, you possess the following rights:

  • Right to Access: Request a summary of personal data processed by us and the processing activities undertaken.
  • Right to Correction & Erasure: Request the correction of inaccurate data or erasure of your inquiry records once negotiations conclude.
  • Right to Grievance Redressal: Access a designated grievance redressal mechanism regarding any privacy concerns.
  • Right to Nominate: Nominate an individual to exercise your rights in the event of death or incapacity.

9. Grievance Redressal Officer & Contact Details

In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, the details of the Grievance Redressal Officer are as follows:

Grievance Officer: Data Protection & Legal Operations

Email: domainforsale@freshfoodbasket.com

Location: Hyderabad, Telangana, India

We endeavor to address and resolve all data grievances within thirty (30) business days of receipt.

10. Governing Law & Jurisdiction (Courts of Telangana)

This Privacy Policy shall be governed by and interpreted in accordance with the laws of the Republic of India.

Any legal disputes or proceedings arising out of or related to this Privacy Policy or personal data processing shall be subject to the exclusive jurisdiction of the competent courts in Hyderabad, Telangana, India.

Back to Domain PortfolioView Terms of Service