Teardown6 min read

Bombay Shaving Company's Privacy Policy vs the DPDP Act: A Template With the Seams Showing

A razor brand's privacy policy warns that your 'public activity' stays visible after account deletion. There is no public activity. It also has no retention clause at all.

Bombay Shaving Company sells razors and grooming kits. Its account deletion clause talks about "public activity on your Account" remaining visible to the public after you delete it.

There is no public activity on this account. No posts, no profile page, no feed. That line was written for a different kind of product and never got edited out, which tells you most of what you need to know about how the rest of the document was assembled.

Gap 1: There is no retention clause at all (Rule 8)

Not a weak one. Not a vague one. There is zero mention of how long any category of personal data is kept.

Most policies in this series at least attempt something, usually "as long as necessary", which Rule 8 rejects because it defers the decision indefinitely. This policy does not even do that. Rule 8 does not accept "we did not say" as an answer either. It expects a schedule per data category: a number, a trigger, or a deletion date that an auditor could verify.

Gap 2: Five distinct purposes, one blanket sentence (§6)

you are consenting to the collection, transfer, manipulation, storage, disclosure and other uses of your information
Source: Bombay Shaving Company privacy policy, consent clause

Five distinct actions, one blanket agreement, triggered simply by using the site. Under §6, each of those is a separate purpose, and each needs its own consent rather than a shared one buried in paragraph two. "Other uses" is doing especially heavy lifting there, since it covers purposes that have never been described to the user at all.

Gap 3: Consent does not survive an ownership change

The business transfer clause treats user data as a company asset. If Bombay Shaving Company is acquired or sold, your data transfers with it, and you "acknowledge" that this happens. You are not asked again.

That is not how consent under the DPDP Act survives a change of ownership. Consent was given to one Data Fiduciary, for one set of stated purposes. It does not automatically extend to whoever buys the company next, and an acknowledgement buried in a policy is not the same thing as consent to a new fiduciary. This is a live issue in Indian D2C, where acquisitions are frequent and the customer database is explicitly part of what is being valued.

Gap 4: The Act that is not there

The word DPDP does not appear anywhere in the document. The Grievance Officer is filed under the Information Technology Act, 2000. The statute governing consent, retention, and breach response from November is absent entirely.

Combined with the leftover "public activity" clause, the picture is clear: this policy was templated from somewhere else and never fully adapted to what the company actually does, let alone to the law that now applies to it.

What they get right

Ms. Charu Arora is named as Grievance Officer with a phone number, email, and full office address. Most D2C brands this size do not bother. This one did, and it satisfies the floor requirement under Rule 9 and Rule 14.

Why this matters more for D2C than founders expect

D2C brands run on repeat purchase data, browsing behaviour, and account history built over years. A grooming subscription knows more about someone's habits, and their household, than most people realise: what they buy, how often, when they stopped, and what they switched to.

A policy with no retention clause and a consent-by-usage model is not a gap that shows up in a demo or a funding round. It shows up the day a customer asks for their data to be deleted and the company has to explain why some of it cannot be, or the day an acquirer's diligence team asks which purposes the customer database was actually consented for.

If your policy was templated from another company, the fastest check is to search it for a feature you do not have. Then run our DPDP compliance checklist against what is left, or use the free Compliance Score below to see the gaps in 60 seconds.

Frequently asked questions

Does the DPDP Act require a retention period in a privacy policy?

Rule 8 requires Data Fiduciaries to erase personal data once the specified purpose is no longer served, which in practice means defining a retention period per data category. A policy with no retention clause at all gives a Data Principal no way to know when their data will be deleted, and gives an auditor nothing to verify.

What happens to my data consent if a company is acquired?

Consent under the DPDP Act is given to a specific Data Fiduciary for specific purposes. A clause stating that users "acknowledge" data will transfer in an acquisition is not the same as obtaining consent for processing by the new owner, particularly if the acquirer intends to use that data for different purposes.

Can one consent clause cover collection, storage, and disclosure?

No. §6 of the DPDP Act requires consent to be specific to each purpose. Collection, transfer, storage, disclosure, and any further use are distinct processing purposes, and bundling them into a single sentence, especially with an open-ended catch-all like "other uses", does not meet the standard.

Compliance Score

Where does your website stand against the DPDP Act?

Run a free Compliance Score: privacy policy, cookie consent, and retention posture, checked in 60 seconds. No signup.