Privacy Policy
1. Introduction
This Privacy Policy ('Policy') outlines the practices of Capital Bolts & Hardwares ('CBH', 'we', 'our', or 'us') regarding the collection, use, storage, disclosure, and protection of personal and business-related data. CBH is committed to ensuring the privacy and protection of information collected from users of our websit [https://cbh.store], our digital platform CBH.Store, and associated services offered through web, mobile, and dealer-based applications.
By accessing or using our services, you consent to the terms set forth in this Privacy Policy. This Policy is designed under applicable data protection regulations, including but not limited to the Information Technology Act, 2000 (India), the General Data Protection Regulation (EU) 2016/679 ("GDPR"), and any other jurisdiction-specific rules where CBH operates.
If you do not agree with the terms of this Privacy Policy, please refrain from using our services or accessing our platforms.
2. Definitions
For the purposes of this Privacy Policy, the following terms shall have the meanings ascribed to them below:
2.1 'Personal Data' refers to any information that identifies or can reasonably be used to identify an individual, including but not limited to name, email address, telephone number, billing or shipping address, payment details, and identification numbers.
2.2 'User' means any individual or legal entity who accesses, browses, registers with, or conducts transactions through our Platforms, including customers, channel partners, dealers, vendors, and authorized representatives.
2.3 'Dealer' refers to any authorized distribution partner, reseller, or entity enrolled in CBH's barcode-integrated dealership network or registered on our proprietary digital platform for procurement and sales.
2.4 'Platform(s)' collectively refers to all websites, mobile applications, digital interfaces, APIs, and web-based systems operated or maintained by CBH, including but not limited to our official website (https://cbh.store) and our online store.
2.5 'Services' means all products, digital tools, support features, and functionalities made available by CBH through its Platforms, including access to product catalogs, real-time stock data, account dashboards, online procurement, and inventory management tools.
2.6 'Third Party' refers to any individual or entity other than the User and CBH, including but not limited to logistics providers, IT service vendors, payment gateways, legal advisors, and regulatory authorities.
2.7 'Processing' means any operation or set of operations performed on Personal Data, whether or not by automated means, including but not limited to collection, recording, organization, structuring, storage, alteration, retrieval, consultation, use, disclosure, dissemination, or deletion.
3. Information We Collect
CBH may collect and process the following categories of information from Users, either directly or indirectly, when they interact with our Platforms, engage in commercial transactions, or otherwise utilize our Services:
3.1 Personal Identifiable Information (PII)
Information provided voluntarily by the User or Dealer, including:
-
Full name
-
Email address
-
Mobile or telephone number
-
Postal or billing address
-
Company name and designation
-
GSTIN/VAT or other business registration identifiers
-
Government-issued identification, where required for KYC compliance
3.2 Account and Authentication Data
-
Username and password associated with platform accounts
-
Dealer code or channel partner ID
-
Login timestamps and session data
-
Two-factor authentication credentials (if applicable)
3.3 Transactional and Commercial Data
-
Purchase history, invoices, and order fulfillment records
-
Payment gateway transaction references (no card or bank details are stored by CBH directly)
-
Product preferences, SKU-level procurement behavior, and quotations
3.4 Device and Technical Usage Data
Automatically collected through user interaction with our Platforms:
-
IP address, browser type, device type, and operating system
-
Referring URL and clickstream behavior
-
Time spent on pages, navigation paths, and search queries
-
Mobile App usage logs and push notification interactions
3.5 Communication and Support Records
-
Emails, messages, or customer service tickets submitted via contact forms or support channels
-
Call recordings (where applicable and lawfully disclosed)
-
Feedback, reviews, or participation in surveys and testimonials
3.6 Location and Logistics Data
-
Geolocation data (where enabled, e.g., in mobile apps for delivery tracking)
-
Warehouse dispatch, logistics partner integrations, and delivery confirmation records
3.7 Cookies and Tracking Technologies
-
Browser cookies and tracking pixels for analytics, security, and session management
-
Preferences selected via cookie consent banners
4. Purpose and Use of Collected Information
CBH processes the information collected from Users for one or more of the following lawful and legitimate purposes:
4.1 To Fulfill Orders and Provide Core Services
-
Processing, confirming, and executing online and offline transactions.
-
Managing logistics, dispatch, delivery, and returns of purchased products.
-
Enabling procurement through CBH's online store and digital ordering systems.
4.2 To Facilitate Dealer and Partner Management
-
Creating, verifying, and managing dealer accounts within the barcode-integrated network.
-
Providing dashboard access for real-time inventory, pricing, and credit details.
-
Enabling seamless dealer communications and digital quote management.
4.3 To Improve User Experience and Platform Functionality
-
Analyzing website and app usage behavior to enhance product discoverability, catalog navigation, and UI performance.
-
Offering personalized product recommendations and procurement workflows based on historic usage data.
-
Implementing real-time stock visibility and alerts through ERP and mobile app integrations.
4.4 To Manage Legal, Financial, and Compliance Obligations
-
Maintaining statutory records for tax, GST, customs, and export/import documentation.
-
Ensuring compliance with applicable regulatory frameworks, including data protection laws, business registration verifications, and audit trails.
-
Preventing fraudulent activity, abuse, or unauthorized access to CBH systems.
4.5 To Provide Support and Communication
-
Responding to customer service requests, warranty claims, and product inquiries.
-
Sending legally required notifications, service announcements, and account-related communications.
-
Managing participation in surveys, testimonials, and feedback channels (subject to consent).
4.6 For Marketing and Promotional Purposes (Subject to Consent)
-
Sending promotional emails, newsletters, and product launch notifications to Users who have opted in.
-
Displaying targeted advertisements or retargeting Users based on anonymized usage patterns.
-
Conducting market research to enhance product offerings and customer engagement.
4.7 For Security and Risk Mitigation
-
Detecting, investigating, and preventing suspicious activities, unauthorized access, and system breaches.
-
Maintaining secure access through firewalls, authentication layers, and real-time monitoring.
4. Purpose and Use of Collected Information
CBH processes the information collected from Users for one or more of the following lawful and legitimate purposes:
4.1 To Fulfill Orders and Provide Core Services
-
Processing, confirming, and executing online and offline transactions.
-
Managing logistics, dispatch, delivery, and returns of purchased products.
-
Enabling procurement through CBH's online store and digital ordering systems.
4.2 To Facilitate Dealer and Partner Management
-
Creating, verifying, and managing dealer accounts within the barcode-integrated network.
-
Providing dashboard access for real-time inventory, pricing, and credit details.
-
Enabling seamless dealer communications and digital quote management.
4.3 To Improve User Experience and Platform Functionality
-
Analyzing website and app usage behavior to enhance product discoverability, catalog navigation, and UI performance.
-
Offering personalized product recommendations and procurement workflows based on historic usage data.
-
Implementing real-time stock visibility and alerts through ERP and mobile app integrations.
4.4 To Manage Legal, Financial, and Compliance Obligations
-
Maintaining statutory records for tax, GST, customs, and export/import documentation.
-
Ensuring compliance with applicable regulatory frameworks, including data protection laws, business registration verifications, and audit trails.
-
Preventing fraudulent activity, abuse, or unauthorized access to CBH systems.
4.5 To Provide Support and Communication
-
Responding to customer service requests, warranty claims, and product inquiries.
-
Sending legally required notifications, service announcements, and account-related communications.
-
Managing participation in surveys, testimonials, and feedback channels (subject to consent).
4.6 For Marketing and Promotional Purposes (Subject to Consent)
-
Sending promotional emails, newsletters, and product launch notifications to Users who have opted in.
-
Displaying targeted advertisements or retargeting Users based on anonymized usage patterns.
-
Conducting market research to enhance product offerings and customer engagement.
4.7 For Security and Risk Mitigation
-
Detecting, investigating, and preventing suspicious activities, unauthorized access, and system breaches.
-
Maintaining secure access through firewalls, authentication layers, and real-time monitoring.
4.8 Legal Basis for Processing under the GDPR (Applicable to EU/EEA Residents)
Where the processing of Personal Data concerns individuals located in the European Union or European Economic Area (EEA), CBH processes such data lawfully in accordance with Article 6 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"). The legal bases include, without limitation:
-
Performance of a Contract: Where processing is necessary for fulfilling sales, logistics, or service obligations.
-
Legal Obligation: Where data must be processed to comply with tax, customs, export, or accounting laws.
-
Legitimate Interests: Where processing supports internal operations such as security, fraud detection, or analytics, and such interests do not override individual rights.
-
Consent: For optional communications, testimonials, or analytics, consent will be obtained and may be withdrawn at any time.
-
International Transfers: For transfers outside the EU/EEA, CBH adopts appropriate safeguards such as Standard Contractual Clauses (SCCs) in accordance with Chapter V of the GDPR.
5. Disclosure of Information to Third Parties
CBH may disclose Personal Data to third parties only where such disclosure is necessary, proportionate, and aligned with the purposes set out in Section 4 of this Policy. All such disclosures are made in accordance with applicable data protection laws and contractual safeguards.
5.1 Logistics and Fulfillment Partners
We may share relevant personal or business data (e.g., name, address, invoice details, product description) with authorized third-party logistics providers, freight forwarders, or shipping companies to enable the packing, dispatch, tracking, and delivery of orders.
5.2 Customs and Regulatory Authorities
In connection with international shipping and export compliance, CBH may be legally required to disclose transaction-related data, including personal or company identifiers, to:
-
Customs and border protection authorities,
-
Port operators and trade regulators,
-
Tax and export compliance bodies,
-
Local embassies or consulates involved in verification of goods or invoices.
5.3 Technology and Software Service Providers
CBH engages third-party vendors to operate and maintain its digital infrastructure. This may include:
-
Cloud hosting providers (e.g., for website and database storage),
-
ERP, CRM, or supply chain management platforms,
-
Payment processors for online transactions,
-
Mobile application developers and analytics services.
All such vendors are contractually obligated to process data solely under CBH's instructions and to implement industry-standard security and confidentiality measures.
5.4 Legal and Regulatory Disclosure
We may disclose data where legally required to:
-
Comply with a subpoena, court order, or applicable law,
-
Respond to lawful requests by public or government authorities,
-
Cooperate with tax audits or regulatory investigations,
-
Prevent, detect, or investigate potential fraud or misconduct.
5.5 Professional Advisors
CBH may share limited data with its auditors, legal counsel, tax consultants, or other professional advisors strictly for the purposes of obtaining advice or fulfilling statutory obligations, under appropriate non-disclosure agreements.
5.6 Affiliates and Group Entities
Where operationally necessary, CBH may share Personal Data with its affiliated companies, subsidiaries, or group entities for internal administrative purposes, provided such entities are subject to equivalent data protection standards.
6. Data Retention and Storage
CBH retains Personal Data only for as long as is reasonably necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by applicable law.
6.1 Retention Periods
Data may be retained based on the following criteria:
-
Transactional Records: Order history, invoices, shipping logs, and tax documentation are retained for a minimum of seven (7) years in compliance with applicable tax, export, and commercial laws.
-
Dealer and Business Accounts: Account information for channel partners, including inventory data, credentials, and ERP-linked records, shall be retained for th duration of the business relationship and for up to three (3) years thereafter for audit and reconciliation purposes.
-
Support and Communications: Customer service interactions, call records, and complaint resolutions are generally retained for up to two (2) years from the date of last interaction.
-
Marketing Consent Records: Records of consent for marketing communications are retained until consent is withdrawn, and for a limited period thereafter to document compliance with consent requirements.
6.2 Storage Location
Data may be stored on:
-
CBH-managed servers hosted within India,
-
Secure third-party cloud servers in jurisdictions that offer an adequate level of data protection,
-
GDPR-compliant environments for data originating from the EU/EEA, where required.
6.3 Archival and Deletion
Once the retention period expires, data shall be securely deleted or anonymized. Where deletion is not technically feasible (e.g., stored in backup archives), CBH shall isolate such data and prevent further processing until deletion becomes possible.
6.4 User Requests
Data subjects may request access to, correction of, or deletion of their data under applicable laws (refer to Section 8). CBH shall honor such requests within the legally mandated timeframe, subject to verification and exceptions prescribed by law.
7. Data Security Measures
CBH is committed to implementing and maintaining robust technical and organizational safeguards to ensure the confidentiality, integrity, and availability of all Personal Data in its custody.
7.1 Technical Safeguards
CBH employs a range of industry-standard security controls, including but not limited to:
-
Secure Socket Layer (SSL) encryption for all data transmitted via our Platforms.
-
Role-based access control (RBAC) to limit internal data access based on authorization levels.
-
Multi-factor authentication (MFA) for administrative and dealer accounts.
-
Firewalls and intrusion detection/prevention systems (IDS/IPS) to monitor unauthorized access attempts.
-
Real-time logging and audit trails of system activities.
7.2 Organizational Safeguards
CBH ensures that:
-
Employees and contractors with access to Personal Data are subject to confidentiality obligations.
-
Access to sensitive data is restricted to personnel with a legitimate operational need.
-
All third-party service providers handling data are contractually obligated to maintain appropriate security standards.
-
Internal policies governing data handling, classification, and breach response are enforced and regularly reviewed.
7.3 Data Breach Notification
In the event of a confirmed data breach involving Personal Data, CBH shall:
-
Notify affected users and/or relevant supervisory authorities within the timeframe mandated by applicable law (e.g., 72 hours under GDPR).
-
Investigate the breach, contain its impact, and implement corrective measures.
-
Maintain records of all such incidents in accordance with statutory obligations.
7.4 Physical Security
Where applicable, CBH's physical premises and server infrastructure are secured through access controls, CCTV surveillance, and restricted entry protocols, in accordance with ISO-standard physical security practices.
8. Data Subject Rights
CBH respects the rights of all individuals whose Personal Data it processes. Depending on the applicable data protection laws — including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (India), and the General Data Protection Regulation (GDPR) — you may exercise the following rights:
8.1 Right to Access
You have the right to request confirmation as to whether CBH holds Personal Data about you and, if so, to access such data along with details of its purpose, categories, source, and disclosures.
8.2 Right to Rectification
You have the right to request the correction or updating of inaccurate or incomplete Personal Data held by CBH.
8.3 Right to Erasure (Right to be Forgotten)
Subject to legal exceptions, you may request the deletion of your Personal Data where:
-
The data is no longer necessary for the purpose it was collected;
-
You have withdrawn consent;
-
The processing is unlawful;
-
The data must be erased to comply with a legal obligation.
8.4 Right to Restriction of Processing
You may request that CBH temporarily suspend processing of your data under specific circumstances, such as during the investigation of accuracy disputes or lawful objections.
8.5 Right to Data Portability
Where processing is based on consent or contract and carried out by automated means, you may request a copy of your Personal Data in a structured, machine-readable format and transmit it to another controller.
8.6 Right to Object
You may object, on legitimate grounds, to the processing of your Personal Data, particularly where it involves:
-
Direct marketing communications;
-
Processing based on CBH's legitimate interests.
8.7 Right to Withdraw Consent
Where CBH relies on your consent to process Personal Data, you may withdraw such consent at any time, without affecting the lawfulness of prior processing.
8.8 Exercising Your Rights
To exercise any of the above rights, you may contact CBH's Data Protection Officer (DPO) or designated representative using the contact details provided in Section 11. CBH reserves the right to verify your identity before processing any such request.
CBH shall respond to your request within a reasonable period and in accordance with the timeframe prescribed by applicable law. Certain requests may be denied where permitted by law, or where fulfilling the request would adversely affect the rights or freedoms of others.
9. Cookies and Tracking Technologies
CBH uses cookies and similar tracking technologies to enhance user experience, improve website functionality, analyze platform usage, and support targeted communications.
9.1 What Are Cookies?
Cookies are small text files that are placed on your device when you visit a website. They enable the website to recognize your browser and remember your preferences over time.
9.2 Types of Cookies Used
CBH may use the following categories of cookies:
-
Strictly Necessary Cookies: Required for the functioning of CBH's websites and digital services. These include authentication and session management cookies.
-
Performance and Analytics Cookies: Used to collect information about how visitors interact with our website, including page views, time spent, and navigation paths. These help us improve platform usability.
-
Functional Cookies: Enable enhanced features such as remembering login credentials, preferred language, or customized views.
-
Marketing and Retargeting Cookies: May be used for delivering personalized ads, remarketing campaigns, and product recommendations across third-party platforms. These cookies operate only with prior consent, where required by law.
9.3 Third-Party Tracking Technologies
CBH may permit trusted third-party services (such as Google Analytics or advertising networks) to place cookies or tracking pixels on our Platforms for analytics, campaign optimization, and reach measurement. These third parties are bound by their respective privacy policies and contractual agreements with CBH.
9.4 Cookie Consent and Control
-
For Users accessing the Platform from jurisdictions requiring explicit consent (e.g., EU), CBH provides a cookie consent banner on first visit.
-
You may adjust cookie preferences or withdraw consent at any time by accessing the cookie settings on our website or modifying your browser configuration.
-
Disabling certain types of cookies may impact website functionality and user experience.
9.5 Do Not Track Signals
CBH does not currently respond to browser "Do Not Track" signals. However, users may manage tracking preferences via browser settings and cookie management tools.
10. International Data Transfers
Given the global nature of CBH's operations and clientele, Personal Data collected through our Platforms may be transferred to, stored in, or processed in countries outside the jurisdiction in which the data was originally collected. These countries may have data protection laws that differ from those in the country of the data subject.
10.1 Cross-Border Transfers
CBH may transfer Personal Data to:
-
Group entities, affiliates, or business partners located outside India;
-
Cloud infrastructure and hosting services operating internationally;
-
Export compliance authorities, customs agencies, and international freight providers;
-
Third-party service providers that support CBH's international sales, logistics, customer service, or IT functions.
10.2 Safeguards for EU/EEA Transfers
Where Personal Data originates from the European Union or European Economic Area, CBH ensures that such transfers are conducted in compliance with Chapter V of the GDPR by relying on one or more of the following:
-
A decision by the European Commission confirming the receiving country offers an adequate level of data protection ("adequacy decision");
-
Standard Contractual Clauses (SCCs) or other contractual safeguards approved by the European Commission;
-
Explicit consent obtained from the data subject;
-
Transfers necessary for the performance of a contract with the data subject.
10.3 Security of Transferred Data
All international transfers of Personal Data are subject to CBH's internal data security measures as described in Section 7. In addition, CBH ensures that third-party recipients of the data are contractually bound to implement appropriate safeguards to maintain confidentiality, integrity, and lawful processing.
11. Contact Information and Complaints
CBH takes data privacy seriously and welcomes all inquiries, requests, and concerns regarding the processing of Personal Data. Data subjects may exercise their rights or submit complaints using the contact details below:
11.1 Data Protection Contact
If you wish to request access, correction, deletion, or clarification regarding your Personal Data, or if you have any questions about this Privacy Policy, you may contact:
Capital Bolts & Hardwares Email: sales@capitalbolts.co
Phone: +91 98880 21000
Address: Capital Towers, Gill Rd, opp. SBI, Miller Ganj, Ludhiana, Punjab 141003
11.2 Complaints to Supervisory Authorities
If you are a resident of the European Union, United Kingdom, or any jurisdiction that grants you the right to lodge complaints with a data protection authority, you have the right to submit a formal complaint to the relevant supervisory authority in your country of residence.
CBH encourages you to contact us first so we can address your concern promptly and in good faith.
12. Updates to This Privacy Policy
CBH reserves the right to amend or update this Privacy Policy from time to time in response to evolving legal, technical, or operational developments. When material changes are made, we will provide notice on our website or contact you directly where required by law.
All changes will take effect immediately upon being published on [https://cbh.store], unless otherwise specified.
We encourage all Users to review this Policy periodically to stay informed about how we protect their information