Farmer In Mumbai — A M Enterprise

1. Introduction

Farmer In Mumbai (operated by A M Enterprise) is committed to protecting your personal information and your right to privacy. This Privacy Policy explains what information we collect, how we use it, and what rights you have in relation to it when you visit www.farmerinmumbai.co.in or engage with our services. This policy is drafted to comply with the Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 (India), and, to the extent applicable, the EU General Data Protection Regulation (GDPR).

Under DPDP, A M Enterprise acts as the Data Fiduciary; under GDPR (where applicable), we act as the Data Controller. You are referred to as the Data Principal (DPDP) or Data Subject (GDPR).

GDPR applies to us only where we offer goods/services to, or monitor the behaviour of, individuals located in the EU/EEA. If our user base is India-only, the GDPR-specific provisions below are included as a precaution and are not currently operative.

2. Information We Collect

2.1 Information You Provide Directly

  • Name, email address, phone number, and postal address when you contact us, enquire about services, or fill out a form.
  • Business details when engaging with corporate gifting or farmhouse services.
  • Payment-related information when processing service bookings (processed securely via third-party gateways — we do not store full card/payment credentials ourselves).

2.2 Information Collected Automatically

  • IP address, browser type, and operating system.
  • Pages visited, time spent on pages, and referring URLs.
  • Cookies and similar tracking technologies (see Section 6).

2.3 Information from Third-Party Platforms

If you arrive via affiliate links from Amazon, Flipkart, or Meesho, those platforms may share aggregated or anonymised referral data with us. We do not receive your personal purchase details from these platforms; any data you provide to them for a purchase is governed by their own privacy policies as independent Data Fiduciaries/Controllers.

3. How We Use Your Information, and Our Lawful Basis for Processing

We use the information we collect to:

  • Respond to your enquiries and provide requested services.
  • Process service bookings and send confirmations, updates, and invoices.
  • Send you relevant communications, newsletters, or promotional offers (only with your consent).
  • Improve our website, content, and service offerings.
  • Comply with legal obligations.
  • Detect and prevent fraud or misuse of our services.
Purpose DPDP Basis GDPR Basis (if applicable)
Responding to enquiries, processing bookings Consent Contract performance
Sending confirmations, updates, invoices Consent Contract performance
Newsletters / promotional communications Consent (opt-in) Consent
Website analytics and service improvement Consent (via cookie notice) Consent / legitimate interest
Fraud detection / legal compliance Legal obligation Legal obligation / legitimate interest

Under DPDP, we process your personal data primarily on the basis of your consent, obtained through a clear, itemised notice at the point of collection (e.g., on our contact/booking forms), stating what data is collected and for what purpose, in English and, where feasible, other Indian languages you may prefer. Consent can be withdrawn at any time, as set out in Section 7.

4. Sharing of Your Information

We do not sell, trade, or rent your personal information to third parties. We may share your information with:

  • Service providers who assist us in operating our website and delivering services (e.g., hosting, email, payment processing), under strict confidentiality agreements and, where applicable, a written data processing agreement consistent with the DPDP Rules’ requirements for Data Fiduciary–Data Processor contracts.
  • Legal authorities when required by law or to protect our rights.
  • Business partners only with your explicit consent.

We do not transfer your personal data to any third party for their own independent marketing use without your explicit, separate consent.

5. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes outlined in this policy, or as required by applicable law. Once data is no longer needed, it is securely deleted and purged permanently. Specifically:

  • Enquiry and booking data is retained for the duration of the service relationship, plus a reasonable period thereafter for record-keeping, warranty, or dispute-resolution purposes.
  • Where the DPDP Rules prescribe a minimum retention period (e.g., for grievance, investigation, or audit purposes), we retain the relevant data for that period even after the original purpose has been served.
  • Where DPDP requires prior notice before erasure of certain retained data, we will notify you at least 48 hours in advance where applicable.

6. Cookies

Our website uses cookies to enhance your browsing experience. Cookies are small data files stored on your device. We use:

  • Essential cookies — required for the website to function properly.
  • Analytics cookies — to understand how visitors use our website (e.g., Google Analytics).
  • Marketing cookies — to track the effectiveness of our promotions (used only with consent).

Non-essential cookies (analytics and marketing) are set only after you provide consent via our cookie banner/notice. You can control or disable cookies at any time through your browser settings or the cookie preference tool on our website. Please note that disabling certain cookies may affect website functionality.

7. Your Rights

Under the DPDP Act, 2023, as a Data Principal you have the right to:

  • Obtain a summary of the personal data we hold about you and the processing activities we carry out.
  • Request correction, completion, or updating of inaccurate or incomplete personal data.
  • Request erasure of your personal data once it is no longer needed for the purpose it was collected, subject to any legal retention requirements.
  • Withdraw consent at any time, as easily as you gave it. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, but we may not be able to continue providing certain services as a result.
  • Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
  • Register a grievance with our Grievance Officer (Section 11), and if unresolved within our stated timeline, escalate the complaint to the Data Protection Board of India.

Under GDPR (where applicable), you additionally have the right to:

  • Data portability — receive your data in a structured, commonly used, machine-readable format.
  • Object to processing based on legitimate interests, including for direct marketing.
  • Restrict processing in certain circumstances.
  • Lodge a complaint with your local EU/EEA supervisory authority.

To exercise any of these rights, contact us at info@farmerinmumbai.co.in. We will acknowledge your request and respond within the timeframe prescribed under applicable law.

8. Data Security

We implement appropriate technical and organisational measures — including access controls, encryption in transit where applicable, and restricted internal access — to protect your personal information from unauthorised access, disclosure, alteration, or destruction. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

Breach notification: In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as required under the DPDP Rules, and, where GDPR applies, the relevant EU supervisory authority and affected individuals within the legally required timeframe.

9. Children’s Privacy

Our services are not directed at children. Under the DPDP Act, a “child” is any individual under 18 years of age, and we do not knowingly process a child’s personal data without verifiable consent from a parent or lawful guardian, except where processing relates to essential services such as healthcare or education as permitted under the Rules. Where a person with a disability cannot provide consent independently, we require consent from their lawful guardian, verified as required by law. (Where GDPR applies, the relevant age of consent is 16, or as low as 13 depending on the EU member state.) If you believe a child has provided us with personal data without appropriate consent, please contact us immediately and we will delete it.

10. Cross-Border Data Transfers

Where personal data is processed or stored outside India (for example, via cloud-based hosting or email providers), we do so consistently with the DPDP Act’s transfer framework. Where GDPR applies, any transfer of EU/EEA personal data outside the EEA is carried out using an appropriate safeguard, such as the EU Standard Contractual Clauses.

11. Grievance Redressal / Data Protection Officer

Grievance Officer

Name: Akhilesh Maurya

Email: info@farmerinmumbai.co.in

Tel: +91-9967915689

If you have concerns about how we handle your personal data, please contact our Grievance Officer first. We will acknowledge and address grievances within the timeframe prescribed under the DPDP Rules. If unresolved, you may escalate the matter to the Data Protection Board of India, or, for GDPR-related matters, your local EU/EEA data protection authority.

12. Changes to This Policy

We may update this Privacy Policy from time to time, including as the DPDP Rules’ phased provisions come into effect through 2026–2027. The revised policy will be posted on this page with an updated “Last updated” date. We encourage you to review this policy periodically. Material changes will be notified via the website or, where appropriate, directly to you.

13. Contact Us

For any privacy-related queries or to exercise your rights, please contact:

Farmer In Mumbai — A M Enterprise

Email: info@farmerinmumbai.co.in

Email: farmerinmumbai@gmail.com

Tel: +91-9967915689

Website: www.farmerinmumbai.co.in