Privacy Policy
AlifQurbani.com
Effective Date: 20 May 2026
Last Revised: May 2026
Company Information
- HikmatPrime Global Private Limited
- CIN: U69100DL2025PTC460252
- Registered Address: 753-754, Y block Mangolpuri, New Delhi, 110083, India
- Email: alifqurbanisupport@gmail.com
This Privacy Policy is issued in compliance with the Digital Personal Data Protection Act, 2023 ('DPDP Act'), the Digital Personal Data Protection Rules, 2025 ('DPDP Rules'), the Information Technology Act, 2000 ('IT Act'), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ('SPDI Rules'), and Razorpay's merchant compliance requirements.
HikmatPrime Global Private Limited ('Data Fiduciary', 'Company', 'We', 'Us', 'Our'), operating alifqurbani.com, processes your personal data for the purposes described in this Policy. You are the 'Data Principal' under the DPDP Act. By using the Website or placing an order, you consent to the practices described herein.
1. DATA FIDUCIARY IDENTITY & CONTACT
Data Fiduciary:
HikmatPrime Global Private Limited
CIN: U69100DL2025PTC460252
Registered Address:
753-754, Y block Mangolpuri,
New Delhi, 110083, India
Data Protection / Privacy Officer
(as per DPDP Act 2023):
Mr. Imran Khan
Email: srkjanpath@gmail.com
Address: 753-754, Y block Mangolpuri,
New Delhi, 110083, India
Grievance Officer (as per IT Rules 2021 & E-Commerce Rules 2020):
Email: srkjanpath@gmail.com
Acknowledgement: Within 48 hours | Resolution: Within 5 Business Days
2. SCOPE OF THIS POLICY
2.1 This Policy applies to all personal data collected by the Company through: the Website (www.alifqurbani.com); mobile applications (if any); email, phone, and WhatsApp communications; and any offline interactions related to orders placed online.
2.2 This Policy does NOT apply to: third-party websites linked from the Website; Razorpay's processing of your payment data (governed by Razorpay's own Privacy Policy and Buyer Privacy Notice at razorpay.com); or Meta/WhatsApp's processing of your messaging data.
2.3 This Policy is to be read alongside our Terms of Service. All capitalised terms not defined here have the meaning given in the Terms of Service.
3. PERSONAL DATA WE COLLECT
3.1 Data You Provide Directly
- Identity Data: Full name, names of persons on whose behalf Qurbani/Aqeeqah is performed (including names of deceased persons for posthumous services).
- Contact Data: Email address, mobile number, WhatsApp number.
- Address Data: Full postal address, city, state, PIN code (for delivery and distribution coordination).
- Transaction Data: Order details, package selected, add-ons, order history.
- Communication Data: Queries, complaints, feedback, and messages sent to us via any channel.
- Consent Records: Records of your consent to marketing communications and these policies.
3.2 Data Collected Automatically
- Technical Data: IP address, browser type and version, operating system, device type and identifiers, time zone setting, screen resolution.
- Usage Data: Pages visited, time spent on pages, clickstream data, referral URL, exit pages, search queries on the Website.
- Cookie Data: See Section 8 (Cookies Policy).
- Transaction Metadata: Order ID, timestamp, payment method type (not payment credentials), transaction reference number, and payment status received from Razorpay.
3.3 Data Received from Third Parties
- Payment Status from Razorpay: Transaction reference, payment status (success/failure), payment method category (card/UPI/netbanking not the credentials themselves).
- Delivery Updates: From logistics/courier partners tracking status, delivery confirmation.
- Social Login (if enabled): Name, email, and profile picture from Google or Facebook if you choose to log in using these.
3.4 Sensitive Personal Data / Information (SPDI) What We Do NOT Collect
In accordance with the SPDI Rules 2011 and the DPDP Act 2023, the Company does NOT collect, store, or process:
- Payment card numbers, CVV codes, net banking credentials, or UPI PINs (these are processed exclusively by Razorpay);
- Biometric data;
- Medical or health information;
- Sexual orientation;
- Passwords in plain text (all passwords, if applicable, are stored in encrypted/hashed form).
4. LEGAL BASIS FOR PROCESSING (DPDP ACT 2023)
Under the Digital Personal Data Protection Act, 2023, we process your personal data on the following lawful bases:
- Consent (Section 6, DPDP Act): For marketing communications, cookies (non-essential), and processing data for purposes beyond contractual necessity. You may withdraw consent at any time (see Section 10).
- Performance of Contract: To process and fulfil your orders, including procurement, slaughter, distribution, delivery, and issuing proofs and certificates.
- Legitimate Interests: For fraud prevention, security, analytics, and improving our services where such interests are not overridden by your rights and freedoms.
- Legal Obligation: To comply with Indian law including GST/tax obligations, PMLA requirements, RBI regulations, court orders, and government directives.
In accordance with the DPDP Act, consent obtained from you is: freely given, specific, informed, unambiguous, and revocable. We do not use consent obtained through deception or coercion.
5. HOW WE USE YOUR PERSONAL DATA
We use your personal data strictly for the following purposes:
- Order Processing: Confirming, fulfilling, and managing your orders; issuing Order IDs; procuring animals; arranging slaughter; distributing meat; delivering physical products.
- Communication: Sending Order confirmations, proof of service (photos/videos), Qurbani certificates, delivery updates, and customer support responses via email, SMS, and WhatsApp.
- Payment Processing: Transmitting necessary data to Razorpay for payment collection, refund processing (where applicable), and fraud screening.
- Identity Verification & Fraud Prevention: Verifying your identity; detecting and preventing fraud, unauthorized transactions, and illegal activity, including PMLA compliance.
- Website Improvement: Analysing usage patterns (using anonymised/aggregated data) to improve the Website, user experience, and service offerings.
- Marketing Communications: Sending promotional messages about new services, seasonal offerings (Eid, Ramadan), and Islamic lifestyle products only with your consent.
- Legal Compliance: Maintaining records for GST compliance, responding to legal notices, complying with court orders, and fulfilling obligations under Applicable Law.
- Dispute Resolution: Maintaining records to resolve disputes, respond to chargebacks, and enforce our Terms of Service.
We will NOT use your personal data for automated decision-making (including profiling) that produces legal or similarly significant effects on you without your knowledge and explicit consent, as required under the DPDP Act, 2023.
6. DATA SHARING, DISCLOSURE & TRANSFERS
6.1 The Company does NOT sell, rent, lease, or trade your personal data to any third party for commercial or marketing purposes. This is an absolute commitment.
6.2 We may share your data with the following categories of recipients, strictly on a need-to-know basis:
- Razorpay Software Pvt. Ltd. for payment processing, fraud detection, RBI compliance, and chargeback management. Razorpay processes your data as per its own Privacy Policy and Buyer Privacy Notice (razorpay.com/buyer-privacy-notice). Razorpay is a separate and independent data fiduciary for data it processes.
- Animal Vendors / Slaughterhouse Operators limited to: order reference number, type of animal/service, and date; NO personal contact information is shared.
- Logistics / Courier Partners limited to: recipient name, delivery address, PIN code, phone number, and order reference; strictly for delivery fulfilment.
- Cloud Hosting & IT Infrastructure Providers hosting your data on servers located in India; bound by data processing agreements with confidentiality and security obligations.
- SMS / Email / WhatsApp Communication Platforms limited to mobile number and/or email for sending transactional and (with consent) marketing messages.
- Legal & Regulatory Authorities RBI, SEBI, FIU-IND, Income Tax Department, GST authorities, law enforcement agencies, courts when required by law, court order, or valid legal process.
- Professional Advisors lawyers, auditors, consultants under strict professional confidentiality obligations.
6.3 In the event of a merger, acquisition, restructuring, or sale of all or part of the Company's business, your personal data may be transferred to the successor entity, subject to a commitment from the acquirer to comply with this Privacy Policy.
6.4 Aggregate / Anonymised Data: We may share aggregated, de-identified statistical data that does not identify you as an individual (e.g., '70% of our customers are from outside India') with partners, investors, or for public reporting.
7. DATA LOCALIZATION & RBI COMPLIANCE
7.1 In compliance with the Reserve Bank of India's circular on Storage of Payment System Data (RBI/2017-18/153, dated April 6, 2018), all payment system data including end-to-end transaction data collected by Razorpay for processing your payments is stored exclusively on systems located within India.
7.2 Your personal data collected by the Company is stored on cloud infrastructure located within India.
7.3 Where any data is processed or accessed outside India (e.g., by a cloud provider with global operations), the Company ensures that: (a) such data is deleted from foreign systems within the timeframes mandated by the RBI; and (b) appropriate contractual safeguards are in place. By using the Website, you consent to such processing as permitted under the DPDP Act, 2023.
8. COOKIES & TRACKING TECHNOLOGIES
8.1 The Website uses cookies, web beacons, pixels, and similar tracking technologies. By using the Website with your browser set to accept cookies, you consent to our use of cookies as described below.
8.2 Types of cookies and tracking technologies we use:
- Essential / Strictly Necessary Cookies: Required for the Website to function (session management, login state, shopping cart, Order ID tracking). Cannot be disabled without breaking the Website.
- Analytics Cookies: Google Analytics (anonymised) to understand traffic patterns, popular pages, and user behaviour. Data is anonymised and aggregated. IP addresses are anonymised.
- Marketing / Advertising Pixels: Meta Pixel (Facebook/Instagram) and Google Ads Conversion Tracking to measure the effectiveness of our advertising and serve relevant ads to users who have visited our Website. These may track your behaviour across other websites. These are enabled only with your consent.
- Razorpay Embedded Scripts: Razorpay sets cookies on the payment page for fraud detection, session management, and payment processing. These are governed by Razorpay's Cookie Policy and are necessary for payment security.
- WhatsApp Business Plugin (if used): May set cookies for chat widget functionality.
8.3 Cookie Control: You may manage cookie preferences through your browser settings or, where provided, through our Cookie Consent Manager. Disabling non-essential cookies will not affect your ability to place orders.
8.4 Do Not Track: The Website currently does not respond to browser 'Do Not Track' signals. We will update this Policy if our practices change.
9. DATA SECURITY
9.1 The Company implements the following technical and organizational security measures:
- SSL/TLS encryption for all data transmission between your browser and the Website (HTTPS).
- Encrypted storage of sensitive data.
- Access controls personal data is accessible only to authorized personnel on a need-to-know basis.
- Regular security reviews and penetration testing.
- Secure data processing agreements with all third-party data processors.
9.2 Payment Security: The Website integrates Razorpay's PCI DSS v4.0.1 compliant payment infrastructure. No raw card data, CVV, or UPI credentials ever pass through or are stored on the Company's servers. Razorpay uses bank-grade encryption and tokenization for all payment instrument data.
9.3 Limitation: No method of transmission over the internet or electronic storage is 100% secure. While the Company takes all reasonable measures, it cannot guarantee absolute security. The Company shall not be liable for any data breach caused by factors beyond its reasonable control (cyberattacks, state-sponsored attacks, zero-day exploits, etc.), provided the Company has implemented reasonable security practices.
9.4 Data Breach Notification: In the event of a personal data breach that is likely to result in high risk to your rights and freedoms, the Company will notify the Data Protection Board of India (DPBI) and affected Data Principals as required under the DPDP Act, 2023 and DPDP Rules, 2025.
10. YOUR RIGHTS AS DATA PRINCIPAL (DPDP ACT 2023)
Under the Digital Personal Data Protection Act, 2023 and applicable Indian law, you have the following rights:
- Right to Access (Section 11, DPDP Act): Request a summary of personal data we hold about you and how it is being used.
- Right to Correction and Erasure (Section 12, DPDP Act): Request correction of inaccurate or incomplete data; request erasure of data that is no longer necessary for the purpose for which it was collected, subject to legal retention requirements.
- Right to Grievance Redressal (Section 13, DPDP Act): File a complaint with our Grievance Officer (srkjanpath@gmail.com) if you believe we have violated your data rights.
- Right to Nominate (Section 14, DPDP Act): Nominate another individual to exercise your data rights in the event of your death or incapacity.
- Right to Withdraw Consent: Withdraw your consent for marketing communications or non-essential cookie processing at any time, without affecting the lawfulness of prior processing.
- Right to Approach DPBI: If your complaint is not resolved to your satisfaction, approach the Data Protection Board of India (once operational) under Section 28 of the DPDP Act.
To exercise any of these rights, email alifqurbanisupport@gmail.com. We will acknowledge within 48 hours and respond within 30 days. Note: Certain rights are subject to legal retention obligations (e.g., we cannot delete transaction records required for GST compliance for 7 years).
11. DATA RETENTION
- Order & Transaction Data: Retained for 7 years minimum from the date of the transaction required for GST compliance, income tax records, and potential dispute resolution.
- Customer Account Data: Retained for the duration of the account's existence, and for 3 years after account closure or last interaction for fraud prevention and legal claims.
- Marketing Consent Records: Retained for the period of the marketing relationship plus 3 years after withdrawal of consent for TRAI and DPDP Act compliance.
- Support / Communication Records: Retained for 3 years after the closure of the support ticket.
- Payment Metadata (non-SPDI): Retained for 7 years for financial reconciliation and PMLA compliance.
- Cookie / Analytics Data: Google Analytics data is retained for 26 months maximum; anonymised.
Upon valid erasure request (where no overriding legal obligation exists), the Company will anonymise or delete your personal data within 30 days of request verification.
12. CHILDREN'S PRIVACY (DPDP ACT COMPLIANCE)
12.1 The Website is intended for use by adults (18 years and above).
12.2 Under Section 9 of the DPDP Act, 2023, the Company shall not process personal data of children (below 18 years) without verifiable parental/guardian consent.
12.3 The Company does not knowingly collect personal data from anyone below the age of 18. If we become aware that a minor has submitted personal data without parental consent, we will delete such data promptly.
12.4 If you are a parent or guardian and believe your child has provided personal data to us without your consent, contact privacy@alifqurbani.com immediately.
13. INTERNATIONAL USERS
13.1 The Website accepts orders from users globally. If you are accessing the Website from outside India, please note that your personal data will be transferred to and processed in India.
13.2 Indian data protection law governs our data practices. By using the Website, you consent to the transfer, storage, and processing of your personal data in India under the laws of India.
13.3 Cross-border data transfer: Certain cloud infrastructure providers may process data in jurisdictions outside India. The Company ensures contractual safeguards consistent with the DPDP Act, 2023 and RBI localization requirements. Payment transaction data is stored exclusively in India per RBI mandate.
14. RAZORPAY BUYER PRIVACY NOTICE CROSS-REFERENCE
When you make a payment on alifqurbani.com through Razorpay, Razorpay processes your payment data as an independent data fiduciary. Razorpay's processing is governed by:
- Razorpay Privacy Policy: https://razorpay.com/privacy/
- Razorpay Buyer Privacy Notice (DPDP Act compliant): https://razorpay.com/buyer-privacy-notice/
- Razorpay Nodal Officer: nodal-officer@razorpay.com
The Company has no control over and assumes no liability for Razorpay's collection, use, disclosure, or storage of your personal data. All payment-data-related inquiries must be directed to Razorpay.
15. THIRD-PARTY PLATFORMS
15.1 Meta Pixel / Facebook Ads: The Website uses Meta's Pixel tracking tool to measure ad performance and enable retargeting. Meta may receive your IP address, device ID, and browsing behaviour on the Website. Meta's data practices are governed by Meta's Privacy Policy (facebook.com/privacy/policy/). You may opt out of Meta's ad targeting at facebook.com/ads/preferences/.
15.2 Google Analytics / Google Ads: We use Google Analytics with IP anonymisation enabled. Google's data practices are governed by Google's Privacy Policy. You may opt out at tools.google.com/dlpage/gaoptout.
15.3 WhatsApp Business: Order notifications and customer support are provided via WhatsApp Business API. WhatsApp's data practices are governed by WhatsApp's Privacy Policy. Communications on WhatsApp are subject to Meta's end-to-end encryption for individual chats.
15.4 Shipping Partners: Logistics partners receive your name, phone number, and delivery address strictly for delivery purposes and are bound by data processing agreements.
16. CHANGES TO THIS PRIVACY POLICY
16.1 The Company reserves the right to modify this Privacy Policy at any time to reflect changes in law, technology, business practices, or the DPDP Act regulations.
16.2 Material changes affecting your rights will be communicated via email or prominent Website notice at least 7 days before they take effect, wherever practicable.
16.3 The 'Last Revised' date at the top of this Policy indicates the most recent update. Your continued use of the Website after the effective date of changes constitutes your acceptance of the updated Policy.
17. CONTACT US
For all privacy, data protection, and personal data queries:
Data Protection / Privacy Officer
HikmatPrime Global Private Limited | AlifQurbani.com
Email: alifqurbanisupport@gmail.com
Grievance: srkjanpath@gmail.com
Phone: +91-6396082277
(Mon–Sat, 10:00 AM – 6:00 PM IST)
Address:
753-754, Y block
Mangolpuri, New Delhi,
110083, India
Escalation: If your complaint is not resolved within 30 days, you may approach the Data Protection Board of India (DPBI) under Section 28 of the Digital Personal Data Protection Act, 2023, once the DPBI is operationally active under the DPDP Rules, 2025.
© 2025–2026 HikmatPrime Global Private Limited. All Rights Reserved.
alifqurbani.com | New Delhi, Delhi 110001 India