Back to Store

Privacy Policy

Last Updated: 24 June 2025

Effective Date: 24 June 2025


1. Introduction

This Privacy Policy (“Policy”) describes how Hallmark Food Products LLP, operating under the brand Sea Harvest Premium Seafoods(“Company,” “we,” “us,” or “our”), collects, uses, stores, and protects your personal data when you use our website and services (the “Platform”).

This Policy is published in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (DPDPA) of India. Where our Platform is accessed by users in the European Union or California, the relevant provisions of the GDPR and CCPA are additionally addressed.

By using the Platform, you consent to the collection and use of your information as described herein. Please read this Policy in conjunction with our Terms & Conditions.


2. Data We Collect

2.1 Information You Provide Directly

Data PointContextRequired?
Full NameOrder form, Contact formYes
Phone NumberOrder form (required), Contact form (optional)Conditional
Email AddressOrder form (optional), Contact form (optional)No
Message / Order NotesOrder form, Contact formConditional
Preferred Contact MethodOrder form (Phone / WhatsApp / Email)Yes
Product Selections & QuantitiesOrder formYes (for orders)

2.2 Information Collected Automatically

Data PointPurposeStorage
IP AddressRate limiting, security audit logging, fraud preventionServer-side audit logs
User Agent StringSecurity monitoring, debuggingServer-side audit logs
TimestampsOrder tracking, audit trailDatabase records
Page InteractionsProduct browsing (category filters, product views)Server logs (ISR cache)

2.3 What We Do NOT Collect

  • No user accounts or passwords — Our Platform does not require customer registration.
  • No payment or financial data — We do not process online payments. No credit card numbers, bank details, or UPI IDs are collected through the Platform.
  • No cookies for tracking or advertising — We do not use third-party analytics (Google Analytics, Facebook Pixel) or advertising cookies.
  • No biometric data or sensitive personal data as defined under DPDPA Section 3.

3. How We Collect Data

  • Direct Submission: When you voluntarily fill out and submit our Order form or Contact form.
  • Automated Server Logging: Your IP address and request metadata are logged by our server infrastructure for security, rate limiting, and operational purposes.
  • URL Parameters: Category filter selections are passed via URL query parameters for product browsing functionality.

We do not use hidden trackers, pixel tags, third-party analytics SDKs, social media widgets, or fingerprinting techniques.


4. Purpose of Processing

We process your personal data for the following specific, lawful purposes:

PurposeLegal Basis (DPDPA / GDPR)
Fulfilling order enquiries and communicating with youConsent / Contractual necessity
Responding to contact form submissionsConsent
Rate limiting and abuse preventionLegitimate interest / Legal obligation
Security audit logging (IP, user agent)Legitimate interest
Internal business analytics (order volumes, popular products)Legitimate interest
Legal compliance and dispute resolutionLegal obligation

We do not process your data for profiling, automated decision-making, or targeted advertising.


5. Third-Party Data Sharing

We share personal data only with the following categories of service providers, strictly for operational purposes:

Service ProviderPurposeData Shared
Neon (neon.tech)Database hosting (PostgreSQL)All form-submitted data (encrypted at rest and in transit)
Cloudinary (cloudinary.com)Product image hostingProduct images only — no customer personal data
Hosting InfrastructureApplication hosting and CDNIP addresses, request headers (standard HTTP logs)

We do NOT:

  • Sell your personal data to any third party.
  • Share your data with advertisers or marketing platforms.
  • Transfer your data to data brokers or aggregators.
  • Use your contact information for unsolicited marketing without your explicit consent.

5.1 Cross-Border Data Transfers

Our database and hosting infrastructure may be located outside India (e.g., AWS regions). Where such transfers occur, they are protected by appropriate safeguards including encryption in transit (TLS 1.2+), encryption at rest, and the service provider’s compliance with applicable data protection standards.


6. Data Retention & Deletion

Data CategoryRetention Period
Order records3 years from order date (for tax/legal compliance)
Contact messages1 year from submission, unless ongoing business relationship
Audit logs (IP, actions)1 year, then anonymized or deleted
Deleted productsSoft-deleted (retained for order history integrity), purged after 1 year

6.1 How to Request Deletion

You may request deletion of your personal data at any time by contacting us at midhunprathap.in@gmail.comwith the subject line “Data Deletion Request.” We will:

  • Verify your identity using the phone number or email associated with your order/message.
  • Process your request within 30 days.
  • Confirm deletion or inform you if certain data must be retained for legal obligations (e.g., tax records).

7. Security Measures

We implement the following technical and organizational security measures:

  • Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS (HTTPS).
  • Encryption at Rest: Database hosted on Neon PostgreSQL with AES-256 encryption at rest.
  • Rate Limiting: API endpoints are rate-limited to prevent abuse (5-120 requests per window depending on endpoint sensitivity).
  • Input Validation: All user inputs are validated and sanitized using Zod schemas before processing.
  • Access Control: Administrative access is protected by secret-key authentication with constant-time comparison to prevent timing attacks.
  • Audit Logging: All administrative actions are logged with IP address and timestamp for accountability.
  • Minimal Data Collection: We follow data minimization principles — we only collect what is necessary for order fulfillment and communication.
  • No Plaintext Secrets: All server-side credentials are stored as environment variables, never in source code or client-side bundles.

While we implement reasonable security practices as prescribed under the IT (Reasonable Security Practices) Rules, 2011, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.


8. Your Rights

8.1 Under Indian Law (DPDPA 2023)

As a Data Principal, you have the right to:

  • Access: Request confirmation of whether we hold your personal data and obtain a summary.
  • Correction: Request correction of inaccurate or incomplete personal data.
  • Erasure: Request deletion of your personal data (subject to legal retention requirements).
  • Grievance Redressal: File a complaint with us or with the Data Protection Board of India.
  • Withdraw Consent: Withdraw your consent at any time (this does not affect the lawfulness of processing prior to withdrawal).
  • Nominate: Nominate another person to exercise your rights in case of death or incapacity.

8.2 Under GDPR (EU/EEA Users)

If you are located in the EU/EEA, you additionally have the right to:

  • Data Portability: Receive your personal data in a structured, machine-readable format.
  • Restriction of Processing: Request limitation of processing under certain circumstances.
  • Object: Object to processing based on legitimate interests.
  • Lodge a Complaint: With your local supervisory authority.

8.3 Under CCPA (California Residents)

If you are a California resident, you have the right to:

  • Know: Request disclosure of personal information collected, used, and shared.
  • Delete: Request deletion of personal information.
  • Non-Discrimination: Not receive discriminatory treatment for exercising your rights.
  • Opt-Out of Sale: We do not sell personal information. No opt-out is necessary.

8.4 How to Exercise Your Rights

To exercise any of the above rights, email us at midhunprathap.in@gmail.comwith the subject line “Privacy Rights Request” and include:

  • Your full name and contact details used on the Platform.
  • A description of the right you wish to exercise.
  • Any supporting information to help us locate your records.

We will respond within 30 days of receipt.


9. Children’s Privacy

The Platform is not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe a minor has submitted personal data through our Platform, please contact us immediately and we will take steps to delete such information.


10. Cookies & Local Storage

Our Platform uses sessionStorage (browser-only, tab-scoped) exclusively for administrative session management. This data is automatically cleared when the browser tab is closed and is not transmitted to our servers.

We do not use persistent cookies, tracking cookies, third-party cookies, or local storage for customer-facing functionality. No cookie consent banner is required as we do not deploy cookies for tracking or analytics.


11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Changes will be posted on this page with an updated “Last Updated” date. Material changes will be communicated via a notice on our Platform. Continued use after changes constitutes acceptance.


12. Grievance Officer

In accordance with the Information Technology Act, 2000 and the DPDPA 2023, the Grievance Officer for this Platform is:

  • Name: Midhun Prathap
  • Entity: Hallmark Food Products LLP
  • Email: midhunprathap.in@gmail.com
  • Phone: +91 9656200209
  • Response Time: Within 30 days of receipt of complaint.

13. Contact

For any privacy-related questions, concerns, or requests:

  • Email: midhunprathap.in@gmail.com
  • Phone: +91 9656200209
  • Address: Hallmark Food Products LLP, Kerala, India