ZEN BLUE collects and processes personal information required to operate the website, process orders, provide customer support, deliver products, prevent fraud and comply with legal obligations. This policy explains what is collected and why.
What we collect
- Account details — your name, email address, phone number and password. Passwords are stored only as a one-way hash and cannot be read by us.
- Order details — shipping and billing addresses, order history and payment status.
- Usage data — pages viewed and actions taken on the site, through analytics tools.
- Communication — messages you send us through the contact form, email or WhatsApp.
What we do not collect
We never see or store your full card number, CVV, UPI PIN or netbanking credentials. Payments are handled entirely by our payment provider on their own infrastructure. We receive only a payment reference and a success or failure result.
Why we use it
- To process, pack, ship and invoice your orders
- To send transactional updates about your orders and returns
- To provide customer support
- To improve the store, our sizing and our product mix
- To send marketing messages, only where you have opted in
Sharing
We share data only with the parties needed to fulfil your order: our payment gateway, our courier partners, our email, SMS and WhatsApp providers, and our accountants for statutory filings. We do not sell your personal data.
Cookies
We use cookies to keep you signed in, remember your cart, and measure how the site is used. You can block cookies in your browser, but the cart and login will stop working.
Data retention
Order and invoice records are retained for the period required under applicable Indian tax law. Marketing consent records are kept until you withdraw them.
Your rights
Write to us using the details on the Contact page to request a copy of the data we hold about you, correct anything inaccurate, withdraw marketing consent, or ask us to delete your account, subject to the statutory retention above.
Security
The site runs entirely over HTTPS. Passwords are hashed. Access to customer data in our admin panel is restricted by role, protected by two-factor authentication, and every administrative action is written to an audit log.
Governing law
This policy is governed by applicable Indian data-protection law, including the Digital Personal Data Protection Act, 2023 and related rules.
This document should be reviewed by a qualified Indian legal professional before publication.
Last updated 27 August 2026
