Legal

Privacy Policy

Your privacy matters to us. This policy explains exactly what data we collect, why we collect it, and how you can control it.

Last updated: April 19, 2026
PDPB + IT Act Compliant
Tamil Nadu, India
πŸ›‘ Our Privacy Commitment
OtakuIsland does not sell your personal data to third parties. We collect only what we need to fulfill your orders and improve your experience. This policy is designed to be clear, honest, and easy to understand.
1

Overview

OtakuIsland ("we", "us", "our") operates the website otakuisland.in and associated digital platforms. This Privacy Policy describes how we collect, use, disclose, and safeguard your personal information when you visit our website or make a purchase from us.

This policy is drafted in accordance with India's Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and in alignment with the forthcoming Digital Personal Data Protection Act, 2023.

By using our website, you consent to the data practices described in this policy. If you do not agree with this policy, please do not use our services.

2

Data We Collect

We collect different types of data depending on your interaction with our platform:

CategoryData PointsRequired?
IdentityFull name, email address, phone numberYes – to process orders
DeliveryShipping address, PIN code, city, stateYes – to deliver orders
PaymentTransaction IDs, payment method type (not card numbers)Yes – for records
AccountUsername, password (hashed), order history, wishlistOptional – only if you register
UsagePages visited, products viewed, search queries, time on siteNo – collected automatically
DeviceIP address, browser type, OS, device type, referral URLNo – collected automatically
CommunicationsSupport chat messages, emails, product reviews submittedNo – only when you contact us
βœ“ What We Do NOT Collect
We do not collect your full card number, CVV, or net banking credentials. Payment is processed entirely by Razorpay on their secure servers. We only receive a transaction reference ID confirming payment success.
3

How We Collect Your Data

We collect data through the following means:

  • Directly from you: When you fill in checkout forms, register an account, contact support, or submit reviews
  • Automatically: When you browse our website, we automatically collect usage data via cookies, log files, and analytics tools
  • From third parties: Payment processors (Razorpay), logistics partners (Shiprocket/Delhivery), and social login providers (Google) may share relevant data with us
  • From your device: Browser metadata, IP address, and device information collected via standard web server logs
4

Why We Use Your Data

We use your personal data for the following purposes:

PurposeLegal BasisData Used
Process and fulfill your ordersContract performanceName, address, phone, payment data
Send order confirmations & shipping updatesContract performanceEmail, phone
Manage your account and loginContract performanceEmail, hashed password
Respond to support queries and complaintsLegitimate interestEmail, phone, order data
Send promotional offers, new arrivals & newslettersConsentEmail, phone (if opted in)
Improve website performance and user experienceLegitimate interestUsage data, device data
Prevent fraud and abuseLegitimate interest / Legal obligationIP, device, order patterns
Comply with legal and tax obligationsLegal obligationIdentity, payment, GST data
Conduct analytics and business improvementLegitimate interestAnonymized usage data

We will not use your data for purposes incompatible with those listed above without obtaining your explicit consent.

5

Data Sharing & Disclosure

5.1 We Do Not Sell Your Data. OtakuIsland does not sell, rent, or trade your personal information to any third party for their marketing purposes.

5.2 Service Providers. We share your data with trusted third-party service providers who process it strictly on our behalf and under our instructions. These include:

PartnerPurposeData Shared
RazorpayPayment processingName, email, phone, order amount
Shiprocket / Delhivery / BlueDartOrder delivery & trackingName, address, phone, order ID
Google AnalyticsWebsite traffic analyticsAnonymized usage data
Meta Pixel (optional)Ad performance trackingAnonymized browsing events
SupabaseDatabase & backend servicesAll customer data (encrypted)
CloudflareCDN, security, cachingIP addresses, request data
Email / SMS providerTransactional communicationsEmail address, phone number

5.3 Legal Disclosures. We may disclose your personal information if required by law, court order, government authority, or to protect the rights, property, or safety of OtakuIsland, our customers, or others.

5.4 Business Transfers. In the event of a merger, acquisition, or sale of all or part of our business, your data may be transferred to the acquiring entity. We will notify you via email and/or a prominent notice on our website before your data is transferred or becomes subject to a different privacy policy.

6

Cookies & Tracking Technologies

6.1 What Are Cookies? Cookies are small text files placed on your device when you visit a website. They help us provide a better, faster, and more personalised experience.

6.2 Types of Cookies We Use:

TypePurposeDurationCan Opt Out?
EssentialSession management, cart, login stateSessionNo – required for site function
PreferenceRemember your language, currency, display settings1 yearYes
AnalyticsGoogle Analytics – understanding site traffic2 yearsYes
MarketingMeta Pixel, retargeting ads90 daysYes

6.3 Managing Cookies. You can control and delete cookies through your browser settings. However, disabling essential cookies may impact the functionality of the website (e.g., your cart may not work correctly). Most browsers allow you to refuse cookies or accept them selectively.

6.4 Do Not Track. Some browsers include a "Do Not Track" (DNT) feature that signals websites not to track you. Our website does not currently respond to DNT signals, but you may use browser extensions or opt-out tools for analytics platforms directly.

7

Data Storage & Security

7.1 Where Is Your Data Stored? Your data is stored on secure cloud servers provided by Supabase (hosted on AWS) and protected by Cloudflare's security infrastructure. All data at rest is encrypted using industry-standard AES-256 encryption. All data in transit is protected using TLS/SSL.

7.2 Security Measures. We implement the following security controls to protect your data:

  • End-to-end SSL/TLS encryption for all web traffic
  • Password hashing using bcrypt (passwords are never stored in plain text)
  • Role-based access controls limiting employee access to customer data
  • Regular security audits and vulnerability assessments
  • Cloudflare DDoS protection and Web Application Firewall (WAF)
  • Razorpay PCI DSS compliance for payment data
  • Two-factor authentication for administrative accounts

7.3 Data Breach Response. In the event of a data breach that poses risk to your rights, we will notify affected users within 72 hours of becoming aware of the breach, in accordance with applicable data protection regulations. We will notify you via the email address associated with your account.

⚠ Your Responsibility
The security of your account also depends on you. Do not share your OtakuIsland password with anyone. Use a strong, unique password and enable two-factor authentication if available. OtakuIsland will never ask for your password via email, phone, or chat.
8

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this policy or as required by law.

Data TypeRetention PeriodReason
Order & transaction records7 yearsGST / tax compliance (Income Tax Act)
Account data (active users)Duration of account + 2 years after deletionLegal and support purposes
Support communications3 yearsDispute resolution
Marketing consent recordsUntil consent withdrawn + 1 yearProof of consent
Server & access logs90 daysSecurity and debugging
Analytics data26 months (Google Analytics default)Performance analysis
Cookie dataPer cookie type (see Section 6)Session / preference management

After the applicable retention period, your data is either permanently deleted or anonymized so that it can no longer be linked to you as an individual.

9

Your Privacy Rights

Under Indian data protection law and our own commitment to transparency, you have the following rights regarding your personal data:

πŸ‘
Right to Access
Request a copy of all personal data we hold about you
✏️
Right to Correction
Update or correct inaccurate data in your account
πŸ—‘οΈ
Right to Erasure
Request deletion of your account and associated data
πŸ“€
Right to Portability
Receive your data in a machine-readable format
🚫
Right to Object
Opt out of marketing communications at any time
⏸️
Right to Restrict
Ask us to limit how we process your data in certain cases

9.1 How to Exercise Your Rights. To exercise any of the rights above, email us at privacy@otakuisland.in with the subject line "Privacy Rights Request" and include your registered email address and the nature of your request. We will respond within 30 days.

9.2 Identity Verification. To protect your data, we may ask you to verify your identity before processing any access, correction, or deletion request. We will not process requests where we cannot verify the requestor's identity with reasonable confidence.

9.3 Limitations. Certain data cannot be deleted if its retention is required by law (e.g., financial records for tax purposes). In such cases, we will inform you of the specific legal obligation that prevents deletion.

10

Children's Privacy

OtakuIsland's services are not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we discover that a child under 13 has provided us with personal information without parental consent, we will promptly delete that information from our systems.

If you are a parent or guardian and believe your child under 13 has provided us with personal data, please contact us immediately at privacy@otakuisland.in.

Users between 13 and 18 years of age may use the website only with verifiable parental consent and under parental supervision. By allowing your minor child to use our website, you as a parent or guardian agree to this Privacy Policy on their behalf.

11

Third-Party Links & Services

Our website may contain links to third-party websites, social media platforms, and partner services. These links are provided for your convenience and information. OtakuIsland has no control over the content or privacy practices of such third-party sites and does not accept any responsibility for them.

Visiting a third-party site from a link on our website means you are subject to that site's own privacy policy and terms of service. We encourage you to read the privacy policies of every website you visit.

Social media sharing buttons (Instagram, YouTube, etc.) may also set cookies and track your activity even if you do not click them β€” this is governed by the respective platform's privacy policies, not ours.

12

Marketing Communications

12.1 Opt-In. We will only send you marketing emails, SMS, or WhatsApp messages if you have explicitly opted in during registration or checkout, or if you have previously purchased from us (in which case we may send you relevant product updates under legitimate interest).

12.2 Opt-Out. You can unsubscribe from marketing communications at any time by:

  • Clicking the "Unsubscribe" link in any marketing email
  • Replying "STOP" to any marketing SMS
  • Contacting us at support@otakuisland.in with the subject "Unsubscribe"
  • Updating your preferences in your OtakuIsland account settings

12.3 Transactional Communications. Even if you unsubscribe from marketing, you will continue to receive essential transactional communications such as order confirmations, shipping notifications, and account security alerts. These cannot be opted out of as they are necessary for your use of our services.

13

Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make significant changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Display a notice on our website homepage for at least 7 days
  • Send an email notification to registered users for material changes

Your continued use of OtakuIsland after the effective date of any changes constitutes your acceptance of the updated policy. If you disagree with the changes, you should discontinue use of the website and request deletion of your account.

14

Contact & Grievance Officer

In accordance with the Information Technology Act, 2000 and the IT (Intermediary Guidelines) Rules, 2021, OtakuIsland has appointed a Grievance Officer to address privacy-related complaints and concerns.

If you have any questions about this Privacy Policy, wish to exercise your rights, or wish to file a complaint about how we handle your data, please contact:

Grievance Officer – OtakuIsland

Officer [Grievance Officer Name] – OtakuIsland
Address Coimbatore, Tamil Nadu, India – 641001
Response Within 30 days of receipt of your complaint
β„Ή Escalation
If you are not satisfied with our response to your privacy complaint, you may escalate to India's Data Protection Board (once constituted under the Digital Personal Data Protection Act, 2023) or approach a court of competent jurisdiction in Coimbatore, Tamil Nadu.

βœ“ Simple Summary
We collect your name, address, phone, and email to process orders. We don't sell your data. We use cookies to improve your experience. You can delete your account any time. We keep financial records for 7 years as required by Indian tax law. Questions? Write to privacy@otakuisland.in.