COOKIE POLICY
1. What are Cookies? (Types in E-commerce) Cookies are small text files stored in a user's browser. In e-commerce, they generally fall into 4 main categories: Strictly Necessary Cookies: Essential for the website to function. They handle core features like login sessions, shopping cart retention, and payment gateway interactions. Performance / Analytics Cookies: Collect information on how visitors interact with the site (e.g., page views, bounce rates via tools like Google Analytics) to improve site performance. Functional Cookies: Remember user choices and preferences, such as preferred language, region, or customized dashboard settings. Targeting / Advertising Cookies: Track browsing habits to deliver personalized ads and remarketing campaigns (e.g., Meta Pixel, Google Ads). 2. India's DPDP Act Compliance & Legal Framework Under India's Digital Personal Data Protection (DPDP) Act, e-commerce platforms must adhere to strict guidelines regarding personal data collection via cookies: Explicit Consent (Opt-in): Implied consent (e.g., "By continuing to use this site, you accept cookies") is no longer sufficient. Users must take an affirmative action (such as clicking an "Accept" button) before non-essential cookies are loaded. No Pre-Ticked Boxes: Consent mechanisms cannot use pre-selected options or opt-out defaults. Clear & Noticeable Banner: Websites must present a clear cookie notice explaining what data is being collected and for what purpose. Easy Withdrawal (Opt-out): Users must have an equally simple way to withdraw their consent or change their cookie preferences at any given time. Multi-Language Notice: Under section 5(3) of the DPDP Act, data principals should be given the option to access the notice/consent forms in English as well as languages specified in the Eighth Schedule to the Constitution of India. 3. Key Components of an E-commerce Cookie Policy Page Your dedicated Cookie Policy document should explicitly cover the following: Types of Cookies Used: A full breakdown of 1st-party (set by your domain) and 3rd-party cookies (set by external services). Purpose of Data Collection: Clear statements detailing why data is stored (e.g., processing orders, fraud prevention, ad targeting). Third-Party Services: Explicit disclosure of any external tools integrated into the platform (e.g., payment processors, analytics, social media pixels). User Control & Preference Management: Step-by-step instructions on how users can manage, block, or clear cookies via browser settings or through a dedicated consent management tool on your site. 4. Best Practices for E-commerce Implementation Consent Management Platform (CMP): Implement a banner that allows users to accept all, reject non-essential, or customize preference categories. Avoid Dark Patterns: Do not use deceptive UI designs that trick users into accepting advertising or tracking cookies unintentionally. Audit Cookies Regularly: Keep an updated inventory of all active cookies on your store to ensure full legal compliance.