Privacy Policy
Last updated: 6 October 2026
ONEWOOZ PRIVACY POLICY
Operated by: The Artless (brand: OneWooz)
Website: https://OneWooz.com
Effective date: 07/10/2026
Version: 1.0
This Privacy Policy explains how The Artless, operating the brand OneWooz ("OneWooz", "we", "us"), handles digital personal data in connection with https://OneWooz.com, the OneWooz commerce platform, and related services (the "Platform").
This Policy is oriented to the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), as applicable, and other Indian law where relevant. It is not a substitute for independent legal advice and is not a claim of court-proof or 100% compliance.
We do not invent operational data practices in this Policy. Where a fact depends on product configuration or has not been confirmed, we use [TO BE PROVIDED]. Please read this Policy together with our Terms of Service and Platform Buying Agreement.
Contact details for privacy requests, notices, and grievance redressal appear in Section 16 at the end of this Policy.
1. Who We Are
1.1 Legal entity: The Artless (brand: OneWooz).
1.2 Full postal address, phone, email, and website for privacy contacts are listed in Section 16.
1.3 Data protection / Grievance Officer contact: Shemanshi Charan- Grievance Officer: +918506060601, Email grievance@onewooz.com.
2. Scope of This Policy
2.1 This Policy covers Personal Data processed in connection with:
(a) Visitors to OneWooz marketing and informational websites;
(b) Merchants / Account Holders who register for, purchase, or use OneWooz Plans and Platform tools; and
(c) End Customers of Merchant stores, to the limited extent OneWooz processes their Personal Data when providing the Platform (see Section 4 on roles).
2.2 "Personal Data" means digital personal data as defined under the DPDP Act, as applicable.
2.3 This Policy does not replace a Merchant's own privacy notice to End Customers. Merchants remain responsible for notices and compliance for processing they control in their selling relationship.
2.4 Related documents: Terms of Service; Platform Buying Agreement (commercial Plan terms, including sales-data export limits); any Data Processing Addendum ("DPA") if offered — [TO BE PROVIDED — DPA availability / URL].
3. Roles Under the DPDP Act (Fiduciary / Processor)
3.1 Orientation (subject to confirmation). Without inventing practices beyond this SaaS model:
(a) For Personal Data of Merchants and their authorised users collected to create accounts, authenticate access, bill Plans, provide support, secure the Platform, and meet legal obligations, OneWooz / The Artless typically acts as a Data Fiduciary determining purposes and means of that processing.
(b) For End Customer Personal Data processed because a Merchant uses the Platform to operate a Store (for example, checkout, orders, shipping details, or storefront messaging instructed by the Merchant), the Merchant typically acts as Data Fiduciary for that sales relationship, and OneWooz typically acts as Data Processor processing on the Merchant's instructions — to the extent that matches actual operations.
3.2 Role matrix confirmation: [TO BE PROVIDED — fiduciary / processor matrix by data category and processing activity]. Until confirmed and reflected here or in a DPA, the descriptions in Section 3.1 are an orientation only.
3.3 Where OneWooz is Data Processor, Merchants are responsible for ensuring they have a valid ground under the DPDP Act to collect and instruct processing of End Customer Personal Data, and for providing required notices to End Customers.
4. Personal Data We May Process
We process only what is needed for stated purposes, subject to product design. Categories below are typical for a SaaS ecommerce platform and/or marked for confirmation. We do not claim we collect every item listed unless confirmed.
4.1 Merchants / Account Holders / Visitors (OneWooz as Fiduciary — typical)
[TO BE PROVIDED — confirm which of the following are actually collected:]
(a) Identity and contact: name, email, phone, business name, billing address;
(b) Account credentials and authentication data;
(c) Plan, billing, payment-method references, invoices, and transaction records for Platform fees (card/UPI/bank details are typically handled by payment providers — [TO BE PROVIDED — what payment fields OneWooz stores vs tokenised by PG]);
(d) Store configuration, domain connection metadata, and support communications;
(e) Usage / log / device / IP / approximate location data generated by use of the Platform — [TO BE PROVIDED — analytics and log details];
(f) Marketing preferences and communication consents where collected — [TO BE PROVIDED — consent records].
4.2 End Customers (Merchant as Fiduciary; OneWooz as Processor — typical)
When a Merchant's Store processes an order or related interaction, Personal Data may include, as configured by the Merchant:
[TO BE PROVIDED — confirm fields actually supported/stored:]
(a) Name, email, phone, delivery address;
(b) Order contents, amounts, payment status references, COD preferences;
(c) Shipping / tracking references;
(d) Messages or reviews if enabled by the Merchant;
(e) Other fields the Merchant adds via forms or integrations — [TO BE PROVIDED].
4.3 Sensitive or children's data. We do not intentionally design the Platform for OneWooz to seek children's Personal Data as a Fiduciary for marketing to children. Merchant Stores may involve children's data in limited cases (for example, delivery to a family address). Practices and age-gating: [TO BE PROVIDED — children's data / verifiable consent practices]. Special category / sensitive handling if any: [TO BE PROVIDED].
4.4 Data we do not intentionally collect as Fiduciary unless you provide it: [TO BE PROVIDED — any explicit "we do not collect" list once confirmed].
5. Purposes of Processing
5.1 As Data Fiduciary (Merchant / account / Platform administration), purposes typically include:
(a) Providing, operating, securing, and improving the Platform;
(b) Account registration, authentication, and customer support;
(c) Plan purchase, billing, invoicing, collection of Platform fees (including ₹1 entry Plan and other Plans), and related tax records;
(d) Communicating service, security, and (where permitted) product messages;
(e) Preventing fraud, abuse, and illegal use;
(f) Complying with law and enforcing Terms / Buying Agreement;
(g) Analytics to understand Platform performance — [TO BE PROVIDED — analytics tools and whether aggregated only].
5.2 As Data Processor (End Customer data on Merchant instructions), purposes are those instructed by the Merchant to operate the Store — typically order fulfilment, customer communication, and related store operations. OneWooz does not decide End Customer marketing purposes for the Merchant.
5.3 We will not process Personal Data for purposes that are incompatible with those disclosed, except as permitted by law.
6. Grounds for Processing (DPDP)
6.1 Under the DPDP Act, processing generally requires consent of the Data Principal or another ground recognised by law (including certain legitimate uses specified in the DPDP Act, where applicable).
6.2 Where consent is required, we (as Fiduciary) or the Merchant (as Fiduciary for End Customers) will seek consent in the manner described in product flows. Consent UX, withdrawal mechanism, and record-keeping: [TO BE PROVIDED — consent UX and retention of consent artefacts].
6.3 Where processing is based on a legitimate use or other non-consent ground permitted by the DPDP Act (for example, for employment-related or other specified uses, if ever applicable, or other statutory grounds), we will identify that ground in updated notices — [TO BE PROVIDED — mapping of processing activities to consent vs other permitted grounds]. We do not assert a specific statutory ground for every activity until that mapping is confirmed.
6.4 You may withdraw consent where processing is consent-based, subject to consequences such as inability to provide certain Services, and subject to law.
7. How We Share Personal Data
7.1 We do not sell Personal Data.
7.2 We may share Personal Data with:
(a) Service providers / Data Processors engaged to host, secure, message, analyse, or support the Platform — [TO BE PROVIDED — subprocessor list / categories and locations];
(b) Payment gateways and financial partners for Platform fee payments and, where integrated for Store checkout, as needed to process payments — under their terms;
(c) Logistics / courier partners when a Merchant enables shipping integrations and instructs related data sharing;
(d) Professional advisers (legal, accounting) under confidentiality where needed;
(e) Authorities, courts, or regulators where required by law or to protect rights, safety, and security;
(f) A successor entity in connection with a merger, acquisition, or reorganisation, subject to appropriate safeguards and notice where required.
7.3 Merchants may export or connect Store data to third-party tools they choose. Those tools are outside OneWooz's control once data leaves the Platform under the Merchant's instruction.
8. Cookies and Similar Technologies
8.1 We may use cookies, pixels, local storage, or similar technologies on OneWooz websites and the Platform for functionality, security, preferences, and analytics.
8.2 Cookie inventory, purposes, duration, and consent banners (if any): [TO BE PROVIDED — cookie policy / table].
8.3 You can control cookies through browser settings; some features may not work if cookies are disabled. Merchant Stores may set additional cookies under the Merchant's responsibility — [TO BE PROVIDED — whether Platform injects storefront cookies and which].
9. Rights of Data Principals
9.1 Subject to the DPDP Act and applicable exceptions, Data Principals may have rights including:
(a) Right to access information about Personal Data and processing;
(b) Right to correction and erasure;
(c) Right to data portability where applicable under law;
(d) Right to withdraw consent where processing is based on consent;
(e) Right to grievance redressal;
(f) Right to nominate another person in case of death or incapacity, where provided by law — [TO BE PROVIDED — nomination process if offered].
9.2 How to exercise rights:
(a) For OneWooz account / billing / Platform Fiduciary processing: contact the email in Section 16 (and Grievance Officer when appointed).
(b) For End Customer data on a Merchant Store: contact the Merchant first. OneWooz will provide reasonable assistance as Processor where applicable, as described in any DPA / this Policy update — [TO BE PROVIDED — assistance SLA].
9.3 We may need to verify identity before fulfilling a request. We may refuse or limit requests as permitted by law (for example, legal retention duties or disproportionate requests).
10. Retention
10.1 We retain Personal Data only as long as needed for the purposes stated, for legal, tax, accounting, and dispute-resolution requirements, and as described below or in future retention schedules.
10.2 Merchant sales-data export. Consistent with the Platform Buying Agreement, Merchants may export sales data for the last three (3) years only (or shorter if less history exists). That export limit is an operational product rule; it does not by itself define every retention period for all Personal Data copies in backups or logs.
10.3 Retention periods by category: [TO BE PROVIDED — retention schedule for account data, billing records, logs, End Customer order data, backups, marketing consents].
10.4 After retention ends, we will delete or anonymise Personal Data as reasonably practicable, subject to technical limitations and legal holds.
11. Security
11.1 We implement reasonable security safeguards appropriate to the nature of Personal Data and processing risks, oriented to DPDP Act duties for Data Fiduciaries and to contractual Processor duties where we act as Processor.
11.2 Measures (high level; confirm actual controls): [TO BE PROVIDED — security overview: encryption in transit/at rest, access controls, logging, vulnerability management, employee access limits, etc.].
11.3 No method of transmission or storage is completely secure. Merchants must protect account credentials and any data they export.
11.4 Security contact for suspected account compromise: hello@onewooz.com (or [TO BE PROVIDED — security email]).
12. Children's Personal Data
12.1 The Platform's Merchant accounts are intended for persons competent to contract (generally 18+) or authorised representatives of entities.
12.2 We do not knowingly offer OneWooz Plans directed at children as Data Principals for account registration. If we learn we have collected Personal Data from a child in violation of applicable law, we will take appropriate steps to delete or secure it as required.
12.3 Merchants who process children's Personal Data through their Stores (if any) must comply with DPDP Act / DPDP Rules requirements, including verifiable consent where applicable. OneWooz-specific age-gating or parental consent tools: [TO BE PROVIDED — if any].
13. Cross-Border Transfers
13.1 Personal Data may be processed on servers or by service providers inside and/or outside India.
13.2 Cross-border transfer locations and mechanisms: [TO BE PROVIDED — countries / regions and transfer safeguards].
13.3 Transfers will be undertaken only as permitted under the DPDP Act and DPDP Rules, including any conditions or restricted territories notified by the Central Government. We will update this Policy when those details are confirmed.
14. Personal Data Breach
14.1 If a personal data breach occurs that requires intimation under the DPDP Act / DPDP Rules, the responsible Data Fiduciary will follow applicable notification duties to the Data Protection Board of India and/or affected Data Principals as required.
14.2 Where OneWooz acts as Processor, we will notify the Merchant (Fiduciary) without undue delay after becoming aware of a breach affecting Personal Data we process on their behalf, and will provide information reasonably available to assist the Merchant's compliance — details: [TO BE PROVIDED — breach notification timeline and template].
14.3 Breach reporting contact: [TO BE PROVIDED — breach contact email] or, until designated, hello@onewooz.com.
15. Updates to This Policy
15.1 We may update this Privacy Policy from time to time. The "Effective date" / Version will change when we do.
15.2 Material changes will be notified via email, dashboard notice, and/or website posting where reasonably practicable. Continued use of the Platform after the effective date constitutes acknowledgment of the updated Policy, except where mandatory law requires fresh consent.
16. Contact, Notices & Grievance Redressal
16.1 Provider contact (OneWooz / The Artless)
Legal entity: The Artless (brand: OneWooz)
Address: H.No. 866, Street No. 11, Mustafabad New, Delhi – 110094, India
Email: hello@onewooz.com
Phone: 8506066061
Website: https://OneWooz.com
16.2 Privacy requests and Data Principal rights (OneWooz Fiduciary processing): email hello@onewooz.com with the subject line "Privacy Request" and enough detail to identify your account and request type.
16.3 Grievance Officer / Data protection contact: Name, designation, and contact: [TO BE PROVIDED]
(To be appointed and published as required under applicable law, including the DPDP Act / DPDP Rules. Do not invent.)
16.4 End Customer requests about Store orders or Merchant marketing should be directed to the relevant Merchant. OneWooz is not the seller of Merchant Products.
16.5 Related policies: Terms of Service; Platform Buying Agreement (https://OneWooz.com/pricing/ for Plan commercial terms).
END OF ONEWOOZ PRIVACY POLICY