Legal
Privacy policy.
Last updated · April 2026
We treat your data like we treat ingredients: minimum necessary, no proprietary blends, every claim sourced. This page is the unfussy version. The full GDPR / DPDP-act compliant text is available on request.
What we collect
Account information. Email, name, phone (if you provide one), and a bcrypt-hashed password. Never your raw password.
Order data. Shipping address, items, totals, payment provider reference (we never see your card). Stored with your account as long as you have one; required by Indian tax law for seven years after.
Cart cookie. A 32-byte token on sprimx_cart. Lets you keep your cart between visits. Essential — you can't opt out without losing the cart.
Analytics. Only with consent. We use Google Analytics 4 to understand which blends people read about before buying. No marketing cookies, no ad networks, no data sales.
What we don't collect
- Your card numbers — those go directly to Razorpay or Stripe.
- Health data. Even when you take the quiz; concerns aren't medical.
- Location beyond what your shipping address tells us.
- Cross-site tracking. We don't buy data from anyone, ever.
Who sees it
Our hosting provider (Vercel), database (Neon), payments (Razorpay, Stripe), email (Resend), and analytics (Google) process data on our behalf under data-processing agreements. Nobody else.
Your rights
Email us at care@sprimx.example to: export your data, delete your account, opt out of marketing email, or correct anything that's wrong. We respond within seven days.
Cookies
On first visit you see a banner. Choose “Essential only” to keep just the cart cookie. Choose “Accept all” to also enable GA4. You can change your choice anytime by clearing your browser's storage for sprimx.com.
Questions? care@sprimx.example. A real person reads it.