This Privacy Policy explains how Nav Organic Foods Private Limited (trading as Fix Coffee) collects, uses, stores, shares, and protects your personal data when you use our website at fixcoffee.shop, place an order with us, or otherwise interact with us. We are the "Data Fiduciary" for the personal data described in this policy, within the meaning of the Digital Personal Data Protection Act, 2023 ("DPDP Act").
We take your privacy seriously. This policy is written plainly so you can understand what we do with your data and how to exercise your rights.
1. Who we are
-
Legal name: Nav Organic Foods Private Limited
-
Brand: Fix Coffee
-
CIN: U15100UP2019PTC119293
-
Registered office: A-304, Amrapali Awadh, Faizabad Road, Indira Nagar, Lucknow, Uttar Pradesh 226016, India
-
Email: hello@fixcoffee.in
2. The personal data we collect
We collect only what we need to run our business and serve you.
Data you give us directly:
- Name, shipping address, billing address, email, phone number (required to process an order)
- GSTIN, if you choose to provide one (for invoicing to a business)
- Order history and wishlist items
- Messages you send us by email, WhatsApp, or contact form
- Reviews, photos, or other content you choose to submit
- Account credentials if you create an account (your password is hashed — we do not see it)
Data we collect automatically when you use the Site:
- IP address, device type, browser type, operating system, screen size
- Pages viewed, time on page, click paths, referring URL, search terms used on the Site
- Cookies and similar technologies (see Section 9)
Data we receive from third parties:
- Payment metadata from our payment gateway, Razorpay (we do not receive or store your full card number, UPI VPA, or bank credentials — Razorpay handles those directly under RBI and PCI-DSS rules)
- Shipping status from our courier partners (Delhivery, Blue Dart, Shiprocket, and others)
- Delivery confirmations and signatures/photos collected by couriers at the time of delivery
We do not knowingly collect sensitive personal data such as biometric information, health records, or financial account credentials. If you send us such data unsolicited (for example, in a support email), we will delete it unless it is necessary to resolve your request.
3. Why we process your data (purposes)
We process your personal data for the following specified purposes, each tied to a lawful basis under the DPDP Act:
-
To fulfil your order — accepting your order, processing payment, arranging dispatch and delivery, issuing your invoice, handling returns, and providing warranty support. Legal basis: performance of the contract you enter into with us (DPDP Act §7 legitimate use).
-
To keep you informed about your order — order confirmation, shipping updates, delivery notifications, and service messages by email, SMS, or WhatsApp. Legal basis: performance of the contract.
-
To provide customer service — answering questions, handling grievances, troubleshooting faults, processing warranty claims. Legal basis: performance of the contract and compliance with our obligations under the Consumer Protection (E-Commerce) Rules, 2020.
-
To comply with the law — issuing GST-compliant tax invoices, retaining records for the periods required by the Income Tax Act, 1961, the Central Goods and Services Tax Act, 2017, and other laws; responding to lawful requests from courts, tax authorities, or law-enforcement agencies. Legal basis: compliance with applicable law.
-
To send marketing communications — occasional updates on new products, offers, and guides by email, SMS, or WhatsApp. Legal basis: your consent, which you give at the time of signing up or checking an opt-in box at checkout, and which you can withdraw at any time (see Section 6).
-
To improve the Site and our products — analysing how the Site is used (in aggregate), identifying bugs, improving product descriptions and recommendations. Legal basis: legitimate use for purposes reasonably expected in the course of business.
-
To prevent fraud and keep the Site secure — detecting fraudulent orders, chargebacks, abusive behaviour, or attempts to break into our systems. Legal basis: legitimate use for the security of our operations.
We do not profile you or use your data for automated decision-making that has a legal or similarly significant effect on you.
4. How long we keep your data
We keep your personal data only for as long as we need it for the purpose for which it was collected, or for a longer period where the law requires us to keep it.
-
Order and invoice records — 8 years from the end of the financial year in which the order was placed (to meet our tax and audit obligations).
-
Warranty and return case files — 3 years from the date the case is closed, or the length of the warranty period plus 90 days, whichever is later.
-
Account data — for as long as your account is active; on request, we will delete it within 30 days, subject to the retention periods above.
-
Marketing list — until you unsubscribe, after which we keep a minimal suppression record to honour your opt-out.
-
Website analytics — aggregated analytics are kept for up to 26 months; individual IP-level records are kept for up to 13 months.
-
Support correspondence — 3 years from the last message.
After these periods, we securely delete or anonymise the data.
5. Who we share your data with
We share your personal data only with the following categories of recipients, and only to the extent necessary for the purpose:
-
Payment gateway (Razorpay Software Private Limited) — to collect your payment. They act as an independent Data Fiduciary for payment data under RBI regulation.
-
Shipping and logistics partners — name, shipping address, phone, and order details to deliver your package (e.g. Delhivery, Blue Dart, Shiprocket, India Post).
-
E-commerce platform (Shopify Inc.) — we use Shopify to operate the Site; Shopify stores order and account data in accordance with its own privacy policy.
-
Cloud infrastructure and IT providers — email hosting (Zoho / Google Workspace), customer-service platforms, analytics, backup, and other operational tools used by us under contract.
-
Chartered accountants, auditors, and legal advisers — to meet our statutory, audit, and legal obligations, under professional confidentiality duties.
-
Government authorities and courts — where we are required to share data by law, a court order, or a lawful investigation request (for example, GST authorities, Income Tax, law-enforcement agencies).
-
Successors in a corporate transaction — if we are acquired, merged, or reorganised, your data may be transferred to the successor entity, which will be bound to honour this policy.
We do not sell your personal data, we do not rent it out, and we do not share it with advertising networks or data brokers.
6. Consent — giving and withdrawing
Where we rely on your consent to process your data (mainly for marketing), we ask for that consent in a clear, specific way — for example, by asking you to tick a box when you subscribe, or to opt in at checkout. Your consent is always voluntary; you can place an order without consenting to marketing.
You can withdraw your consent at any time. The easiest ways are:
- Click the "unsubscribe" link at the bottom of any marketing email.
- Reply STOP to any marketing SMS.
- Reply STOP or UNSUBSCRIBE to any marketing WhatsApp message.
- Email hello@fixcoffee.in asking to be removed from our marketing lists.
Withdrawing consent does not undo processing that has already happened, and it does not affect processing that is based on a legitimate use (for example, we will still send you transactional messages about an order you have placed).
7. Your rights as a Data Principal
Under the DPDP Act, you have the following rights. We will act on a valid request within 30 days.
-
Right to information — to know what personal data of yours we hold, how we use it, and who we share it with.
-
Right to correction — to ask us to correct inaccurate or incomplete data.
-
Right to erasure — to ask us to delete your data, subject to our legal retention obligations (for example, GST records we are required to keep for 8 years).
-
Right to nominate — to nominate another person who can exercise your rights on your behalf if you die or lose capacity.
-
Right to withdraw consent — for any processing based on consent (see Section 6).
-
Right to grievance redressal — to raise a grievance with us, and if you are not satisfied, to complain to the Data Protection Board of India.
To exercise any of these rights, email shashwat@fixcoffee.in. We may ask you to verify your identity before we act on the request — this protects you against someone impersonating you. Requests are free. If a request is manifestly unfounded or excessive, we may decline or charge a reasonable fee, and we will tell you why.
8. How we keep your data safe
We take reasonable security measures to protect your data, including:
- Transport-layer encryption (HTTPS/TLS) on every page of the Site and every API call.
- Payment processing through Razorpay, which is PCI-DSS certified — we never handle your full card number or bank credentials.
- Access controls on our systems — only authorised team members can access customer data, and only to the extent they need it for their role.
- Encryption at rest on our primary data stores and backups.
- Regular software updates, security patches, and periodic reviews of our access logs.
- Written contracts with our service providers requiring them to handle your data securely and only for the agreed purpose.
No system is perfectly secure. If a personal data breach happens that is likely to affect you, we will notify you and the Data Protection Board of India as required by the DPDP Act.
9. Cookies and similar technologies
We use cookies and similar technologies to make the Site work and to understand how it is used.
-
Essential cookies — needed for the Site to function (for example, to keep your cart, remember you are logged in, and secure your session). These are always on.
-
Analytics cookies — help us understand which pages are popular, where users drop off, and how to improve the Site. We use aggregated data and do not identify individual users from it.
-
Marketing cookies — used only with your consent, to show you relevant messages on other sites.
You can control cookies through your browser settings. Blocking all cookies may stop parts of the Site from working.
10. Children
Our products (espresso machines, grinders, and related equipment) are not designed for children, and our Site is not directed at people under 18 years of age. We do not knowingly collect personal data from a child. Under Section 9 of the DPDP Act, we do not profile, track, or direct advertising to children. If you believe we have unintentionally collected data from a child, email us at shashwat@fixcoffee.in and we will delete it.
11. Cross-border data transfer
Some of our service providers (including Shopify and Google Workspace) are based outside India and may store or process data on servers in other countries. We only transfer your data to countries that are not on the negative list notified by the Central Government under the DPDP Act, and we put contractual protections in place with these providers. If the Central Government issues a negative list that affects any of our providers, we will update our practices accordingly.
12. Third-party links
The Site may contain links to other websites that are not operated by us (for example, manufacturer websites, review platforms, or social media). We are not responsible for the privacy practices of those websites. When you follow a link, please read that site's privacy policy.
13. Changes to this policy
We may update this policy from time to time — to reflect a change in the law, a new service, or a change in how we operate. The updated policy takes effect from the date it is published. For material changes, we will also announce the update on the Site or by email. If an update narrows your rights or expands our processing in a way that needs your consent, we will ask for that consent separately.
14. Designated Person for data protection / Grievance Officer
For any question, request, or complaint about how we handle your personal data, please contact:
We acknowledge every data-protection request or grievance within 48 hours of receipt and aim to resolve it within 30 days, in line with the DPDP Act and Rule 4(5) of the Consumer Protection (E-Commerce) Rules, 2020.
15. Complaint to the Data Protection Board of India
If you are not satisfied with how we have handled a data-protection request or grievance, you can complain to the Data Protection Board of India established under the DPDP Act. Details of the Board and how to file a complaint are published at the Government of India's Ministry of Electronics and Information Technology portal and on the Board's official site once it is operational.
16. Contact
General privacy questions: hello@fixcoffee.in. Data-protection requests and grievances: shashwat@fixcoffee.in. By registered post: Nav Organic Foods Private Limited, A-304, Amrapali Awadh, Faizabad Road, Indira Nagar, Lucknow, Uttar Pradesh 226016, India.