This page is a practical website-policy draft for Crest Automotive Care. It is not formal legal advice. Replace bracketed business details and have a qualified attorney review it before relying on it.
1. Who we are
This policy applies to [insert full legal entity name] (“Crest Automotive Care”, “Crest”, “we”, “us” or “our”), located at [insert registered office address]. Our privacy contact is [insert privacy email] and our grievance contact is [insert grievance email].
This draft is structured with India’s Digital Personal Data Protection Act, 2023 in mind. It should be updated for the final operating model, vendors and legal identity before publication. Read the official Act at the Ministry of Electronics and Information Technology.
2. The information we may collect
- Contact information: name, phone number, email address and preferred communication channel.
- Vehicle and service information: vehicle model, category, community, selected treatment, add-ons, Rodim PPF choice and booking preferences.
- Enquiry content: details you include in a message, including vehicle condition, requested work or special instructions.
- Payment and invoice information: only if you proceed with a live booking or payment flow. Payment-card credentials should be handled by the authorised payment provider, not stored by Crest unless expressly stated.
- Technical information: browser, device, approximate location, referral source, cookies and usage events if analytics or similar tools are enabled.
In the current frontend-only demo, the contact form is not connected to a backend and does not transmit an enquiry. When a live endpoint, email service, CRM, analytics tool or payment service is connected, this notice must be updated to identify it accurately.
3. How we use personal data
We may use personal data to respond to enquiries, prepare and confirm estimates, schedule and deliver vehicle-care services, communicate changes, issue invoices, provide aftercare, handle complaints, protect the website, prevent misuse, comply with law, and improve the service experience.
We should rely on a lawful basis appropriate to the activity, such as consent, performance of a requested service or booking, compliance with a legal obligation, or another basis recognised by applicable law. Marketing messages should be sent only where the required consent or other lawful permission has been obtained, with a practical opt-out.
4. Notice and consent
Where consent is required, we will request it in a clear and specific way and will not treat silence or pre-ticked optional boxes as consent. You may withdraw consent by contacting us, although withdrawal may not affect processing already completed lawfully or prevent us from retaining information needed for a transaction, safety, accounting or legal purpose.
5. Sharing and processors
We may share information with personnel and service providers who help us operate the website or fulfil a requested service, such as hosting, email delivery, CRM, appointment management, payments, analytics, customer support, insurance or repair partners. They should process information only for documented purposes, maintain appropriate security and follow applicable data-protection obligations.
We may disclose information where required by law, court order, regulatory request, fraud-prevention process, emergency or protection of rights. We do not sell personal information as a standalone data product.
6. Retention
We retain information only for as long as reasonably necessary for the purpose collected, the customer relationship, accounting and tax records, dispute resolution, safety, fraud prevention or legal obligations. Insert the final retention schedule before launch: [insert enquiry retention period], [insert booking and invoice retention period], and [insert marketing consent retention period].
7. Security
We will use reasonable technical and organisational safeguards appropriate to the information and risk, including access control, secure transmission, vendor review, backups and incident handling. No internet transmission or storage method can be guaranteed absolutely secure. If a live system is compromised, Crest will follow the notification and response requirements that apply to the incident.
8. Your rights and requests
Subject to applicable law, you may request information about processing, correction of inaccurate data, deletion where appropriate, withdrawal of consent, access to available information, or a response to a grievance. Send a request to [insert privacy email] with enough information for us to verify and respond safely. We may ask for additional information to prevent unauthorised disclosure.
9. Cookies and third-party tools
Necessary technologies may support security, navigation, preferences and form functionality. Optional analytics, advertising or embedded third-party technologies should be disclosed and enabled according to the consent controls required in the relevant jurisdiction. See our Cookie Policy.
10. Children and sensitive information
The website is intended for adults arranging vehicle services. Do not submit another person’s personal data or sensitive information unless you are authorised to do so. If you believe a child has submitted personal information, contact us so we can review and delete it where appropriate.
11. International transfers
If a hosting, analytics, communications or payment provider processes information outside India, identify the provider and destination where required, and apply the safeguards required by applicable law. Insert the production vendor list before launch: [insert vendors and processing locations].
12. Changes and contact
We may revise this policy when our services, vendors or legal obligations change. We will publish the effective date at the top of this page. For privacy questions, contact [insert privacy email]. For complaints that are not resolved, follow the Grievance Redressal process.