Privacy Policy
Guitar Villa · Effective Date: June 2026 · Last Updated: June 2026
Business Name | Guitar Villa (Anuraag Jose, Proprietor) |
GSTIN | 22BDHPJ9550M1Z8 |
Udyam Registration | UDYAM-CG-01-0009692 |
Address | Jagdalpur, Bastar, Chhattisgarh, India |
Websites | guitarvilla.in | store.guitarvilla.in |
Grievance Officer | Anuraag Jose (Proprietor) |
Contact Email | privacy@guitarvilla.in |
Phone | +91-7587175871 |
Grievance Response Time | Within 90 days of receipt |
This Privacy Policy describes how Guitar Villa (“we”, “us”, “our”) collects, uses, stores, and shares personal data of individuals (“Data Principals”) who visit or transact on our websites. It is issued in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025.
By using our websites or services, you acknowledge that you have read this Policy. You may withdraw consent at any time using the mechanisms described below.
1. Personal Data We Collect
We collect the following categories of personal data, only for the purposes stated:
Category | Data Points | Purpose |
Account & Order | Name, email, phone, shipping address, billing address, order history | Processing and fulfilling your purchase; customer support |
Payment | Payment method type only (processed by PayU India) | Payment processing and fraud prevention. Full card data is never stored by Guitar Villa. |
Analytics (with consent) | IP address, device type, pages visited, session duration, browser (via Google Analytics 4) | Understanding how visitors use our site to improve content and performance. Only after explicit consent. |
Marketing (with consent) | Browsing behaviour on our store pages (via Meta Pixel / Facebook Pixel) | Showing relevant product advertisements on Meta platforms. Only after explicit consent. Never fires on checkout or payment pages. |
Enquiries & Courses | Name, email, phone (submitted via contact or booking forms) | Responding to your enquiry or registering you for music lessons. Not used for unsolicited marketing. |
2. Legal Basis for Processing
Under the DPDP Act 2023, we process your personal data on the following lawful bases:
- Consent — for analytics (GA4) and marketing (Meta Pixel) cookies, and for promotional communications. You may withdraw consent at any time.
- Contractual necessity — for processing orders, delivering products, and managing your customer account.
- Legal obligation — for maintaining transaction records required under the Goods and Services Tax Act, 2017 and other applicable law.
3. Third Parties We Share Data With
We share your personal data only with the following parties, strictly for the purposes listed:
Third Party | Data Shared | Purpose |
PayU Payments India | Order amount, billing name, email | Payment processing and fraud prevention |
Google LLC (GA4) | Anonymised usage data (only post-consent) | Website analytics |
Meta Platforms Inc. | Browsing events on product/catalog pages (only post-consent) | Retargeted advertising on Meta/Instagram |
Amazon MCF India | Shipping name and address (for fulfilled orders only) | Order fulfilment and shipping |
Zoho Books | Name, address, GSTIN (for B2B), invoice details | Accounting and GST invoice generation |
We do not sell, rent, or trade your personal data to any third party for their independent marketing purposes.
4. Data Retention
We retain your personal data only for as long as is necessary for the purpose it was collected, or as required by law:
- Order and transaction data: 7 years (as required under GST Act 2017 for audit and compliance)
- Customer account data: for the duration your account remains active, plus 2 years after last activity
- Analytics data (GA4): up to 14 months, as configured in Google Analytics
- Marketing / Pixel data: session-based; not stored by Guitar Villa independently
- Contact/enquiry form data: 1 year from the date of submission, unless the enquiry led to a transaction
- Consent records: 3 years from the date of consent or withdrawal
After the applicable retention period, data is deleted or anonymised.
5. Your Rights as a Data Principal
Under the DPDP Act 2023, you have the following rights regarding your personal data:
- Right to Access — You may request a summary of the personal data we hold about you and how it is being processed.
- Right to Correction — You may request correction of inaccurate or incomplete personal data.
- Right to Erasure — You may request deletion of your personal data where it is no longer necessary for the purpose it was collected, subject to legal retention obligations.
- Right to Withdraw Consent — You may withdraw consent for analytics or marketing at any time via the cookie preference centre on our website. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Right to Grievance Redressal — You may file a complaint with our Grievance Officer. If unresolved, you may escalate to the Data Protection Board of India.
To exercise any right, submit your request to: privacy@guitarvilla.in with subject line “DPDP Data Request – [Your Name]”. We will respond within 90 days of receiving a valid, complete request.
6. Consent Management & Cookies
When you first visit our website, a consent banner is displayed. You have three choices:
- Accept All — enables analytics (GA4) and marketing (Meta Pixel) cookies
- Reject All — only strictly necessary cookies are placed (shopping cart, session, login)
- Customise — choose which categories of cookies you allow
You may change your cookie preferences at any time by clicking the ‘Cookie Settings’ link in our website footer. Your consent choice is logged with a timestamp and will be honoured across all subsequent sessions on the same browser.
Strictly necessary cookies (which do not require consent) include: WooCommerce cart session (woocommerce_cart_hash, woocommerce_items_in_cart), WordPress login (wordpress_logged_in), and CSRF security tokens.
7. Security Safeguards
Guitar Villa implements the following technical and organisational measures to protect your personal data:
- HTTPS / SSL encryption on all pages of both websites
- Payment data is handled exclusively by PayU India and never stored on Guitar Villa servers
- Access to customer data in WooCommerce is restricted to the proprietor and authorised staff only
- Regular WordPress and plugin updates to address security vulnerabilities
- Automated daily backups retained for 30 days
In the event of a personal data breach that is likely to result in risk to Data Principals, we will notify the Data Protection Board of India and affected individuals without undue delay.
8. Children’s Data
Our services are not directed at children under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact our Grievance Officer immediately for deletion.
9. Cross-Border Data Transfers
Some of our data processors (Google LLC, Meta Platforms Inc.) are based outside India. Data transfers to these processors occur only post-consent, and these entities maintain their own data protection frameworks. We rely on their standard contractual clauses and privacy frameworks for adequate protection.
10. Grievance Redressal
For any complaint, concern, or request related to this Privacy Policy or your personal data:
Grievance Officer | Anuraag Jose (Proprietor, Guitar Villa) |
privacy@guitarvilla.in | |
Address | Guitar Villa, Jagdalpur, Bastar, Chhattisgarh |
Response Time | Within 90 days of a valid, complete request |
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India at www.meity.gov.in.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, our data practices, or services. The ‘Last Updated’ date at the top of this document indicates when the most recent changes were made. For material changes, we will place a notice on our website homepage for 30 days.
Continued use of our websites after any changes constitutes your acceptance of the updated Policy, to the extent permitted by law. For consent-based processing, we will re-seek your consent if required.
12. Hindi Summary (हिंदी सारांश)
यह गोपनीयता नीति डिजिटल व्यक्तिगत डेटा संरक्षण अधिनियम 2023 के अनुरूप है। Guitar Villa आपका नाम, ईमेल, पता और ऑर्डर जानकारी ऑर्डर पूरा करने के लिए एकत्र करता है। एनालिटिक्स (Google GA4) और मार्केटिंग (Meta Pixel) कुकीज़ केवल आपकी सहमति के बाद सक्रिय होती हैं। आप किसी भी समय सहमति वापस ले सकते हैं। शिकायत के लिए: privacy@guitarvilla.in पर संपर्क करें। हम 90 दिनों में जवाब देंगे।
