Indian Culture
Back to shop

Privacy Policy

As of: March 2026

Legal note: The legally binding version of our Privacy Policy is the German version available at /datenschutz. The English translation below is provided for information purposes only.

1. Controller

Controller within the meaning of the General Data Protection Regulation (GDPR):

Savin Kumar Kapoor
Indian Culture
Altländer Straße 32
21614 Buxtehude
Germany

Email: info@indian-culture.de

2. Overview of Processing

We process personal data only insofar as this is necessary to provide a functional online shop, our content, and services. Personal data is generally processed only with user consent or where processing is permitted by law.

3. Data Collected

The following personal data is collected when using our shop:

3.1 During registration: First and last name, email address, password (encrypted), phone number (optional), delivery address (street, ZIP, city, country)

3.2 When placing an order: Order data (products, quantities, prices), payment information (processed directly by Stripe, we do not store credit card data), delivery address, IP address

3.3 When visiting the website: IP address, browser type and version, operating system, screen resolution, referrer URL, pages visited, date and time of access, time spent, click behavior

Legal basis: Art. 6 para. 1 lit. b GDPR (contract performance), Art. 6 para. 1 lit. f GDPR (legitimate interest), Art. 6 para. 1 lit. a GDPR (consent).

4. Purpose of Data Processing

We process your data for the following purposes:

  • Execution and processing of orders and deliveries
  • Creation and management of your customer account
  • Communication regarding your orders (order confirmation, shipping notification)
  • Sending newsletters and discount codes (only with your express consent)
  • Analysis and improvement of our website and offerings
  • Prevention of abuse and fraud
  • Fulfillment of statutory retention obligations

5. Hosting and Infrastructure

5.1 Vercel (Hosting): Our website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Vercel processes access data (IP address, time of access) to provide the website. Legal basis: Art. 6 para. 1 lit. f GDPR. Vercel is certified under the EU-US Data Privacy Framework.

5.2 Cloudflare (CDN/DNS): We use Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, as a Content Delivery Network and DNS service. Cloudflare processes access data to provide and protect our website. Legal basis: Art. 6 para. 1 lit. f GDPR.

5.3 Supabase (Database): Our customer and order data is stored with Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992. Data is transmitted and stored encrypted. Legal basis: Art. 6 para. 1 lit. b GDPR.

6. Payment Service Provider

Stripe: For payment processing, we use Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. When you make a payment, your payment data is transmitted directly to Stripe. We do not receive or store complete credit card numbers or bank details. Stripe processes your data for fraud prevention purposes, among others.

Legal basis: Art. 6 para. 1 lit. b GDPR (contract performance). Stripe's privacy policy: https://stripe.com/privacy

7. Cookies

Our website uses cookies. Cookies are small text files stored on your device.

7.1 Necessary cookies: These cookies are required for the operation of the website (e.g., shopping cart, login session). They cannot be disabled. Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest).

7.2 Analytics cookies: We use our own tracking technologies to analyze user behavior on our website (page views, time spent, click behavior, device information). This data is anonymized and used solely to improve our offerings. Legal basis: Art. 6 para. 1 lit. a GDPR (consent via cookie banner).

7.3 Cookie settings: When you first visit our website, you will be informed about the use of cookies via a cookie banner and asked for your consent. You can revoke your consent at any time.

8. Website Tracking and Analysis

We use a self-hosted tracking system to analyze user behavior. The following data is collected: pages visited, time spent, click behavior, scroll depth, device information (device type, browser, operating system, screen resolution), referrer/traffic sources.

Data is stored on our own servers and not shared with third parties. We do not use external tracking services (such as Google Analytics).

Legal basis: Art. 6 para. 1 lit. a GDPR (consent) or Art. 6 para. 1 lit. f GDPR (legitimate interest in optimizing our offerings).

9. Newsletter

With your consent, we can send you our newsletter with information about new products, recipes, and special offers. For sending, we use the service Resend (Resend, Inc., USA). Your email address is stored at Resend as long as you are subscribed to the newsletter.

You can revoke your consent at any time by sending us an email to info@indian-culture.de. Legal basis: Art. 6 para. 1 lit. a GDPR (consent).

10. Sharing Data with Third Parties

Your data is shared with third parties only in the following cases:

  • With the shipping provider (Hermes) for delivery of your order (name, address)
  • With the payment service provider (Stripe) for payment processing
  • With the email service provider (Resend) for sending transactional emails and newsletters
  • When we are legally obligated to do so (e.g., to tax authorities)

Apart from this, we do not share your data with third parties unless you have expressly consented.

11. Retention Period

Personal data is stored only for as long as necessary for the respective purpose or for statutory retention periods:

  • Customer account data: Until deletion of the account by the customer
  • Order data: 10 years (commercial and tax law retention obligations under §§ 147 AO, 257 HGB)
  • Invoice data: 10 years
  • Tracking data: 12 months, then automatic deletion
  • Newsletter data: Until revocation of consent

12. Your Rights

You have the following rights regarding your personal data:

  • Access (Art. 15 GDPR): You can request information about the data we have stored about you.
  • Rectification (Art. 16 GDPR): You can request the correction of inaccurate data.
  • Erasure (Art. 17 GDPR): You can request the deletion of your data, provided no statutory retention obligations conflict.
  • Restriction (Art. 18 GDPR): You can request the restriction of processing.
  • Data portability (Art. 20 GDPR): You can receive your data in a structured format.
  • Objection (Art. 21 GDPR): You can object to the processing of your data.
  • Revocation (Art. 7 para. 3 GDPR): You can revoke consent given at any time.

To exercise your rights, please contact: info@indian-culture.de

13. Right to Lodge a Complaint with a Supervisory Authority

If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a data protection supervisory authority.

Responsible supervisory authority:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5, 30159 Hannover, Germany
www.lfd.niedersachsen.de

14. SSL/TLS Encryption

For security reasons and to protect the transmission of confidential content, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the browser address line changing from "http://" to "https://" and the lock symbol in your browser bar.

15. Changes to This Privacy Policy

We reserve the right to adapt this Privacy Policy to always meet current legal requirements or to implement changes to our services. For your renewed visit, the current version applies.