Legal Notice
Privacy Policy
What we collect
When you use this website or book a reading, we collect the following categories of personal data:
- Identity and contact data: your full name, email address, and phone number.
- Birth data: date, time, and place of birth. For Kundli Match Making services, we also collect the same details for your partner, with that person's consent.
- Payment data: billing amounts and transaction reference numbers. Card numbers, CVV codes, and bank account details are handled exclusively by Razorpay and are never transmitted to or stored on our systems.
- Technical data: browser type and IP address at the moment of form submission. This data is used solely for fraud prevention and is deleted after 90 days.
- Calculator usage data: anonymised page-view and calculator-usage events, collected via a first-party event log with no personal data attached.
We do not collect data from minors. Our services are directed at persons aged 18 and above.
Why we collect it
- Chart computation: birth date, time, and place are essential inputs to compute a Vedic birth chart. Without them the service cannot be delivered.
- Service delivery: we use your contact details to send you your reading and to communicate about your booking.
- Billing: we use your name and email to issue a tax invoice and process payment via Razorpay.
- Tax compliance: invoices and related records are retained for six years as required by section 36 of the Central Goods and Services Tax Act, 2017 (CGST Act).
- Fraud prevention: IP address and browser type are logged at intake to detect and block fraudulent submissions.
How we use it
Your data is used only by Abhishek Soni to deliver and improve your reading. It is not shared with third parties for marketing, not sold to any data broker, and not used to train any artificial intelligence model.
We will not use your data for any purpose materially different from the one for which it was collected without obtaining fresh consent from you.
Where it goes — sub-processors
We engage the following sub-processors who may receive limited personal data as necessary to deliver the service:
- Frappe-hosted CRM at erp.astroabhisheksoni.com — receives your name, email, phone, and birth data to store your reading record and manage correspondence. Hosted on Indian servers.
- Razorpay Payments Private Limited — receives your name, email, phone, and the transaction amount to process payment and issue a payment receipt. Razorpay's own privacy policy governs their handling of payment data.
- Resend — receives your email address and reading content when we send a transactional email. Used as a fallback when WhatsApp delivery fails.
- WhatsApp Business API via frappe_whatsapp — receives your phone number and reading content to deliver your reading over WhatsApp, which is the primary delivery channel.
No data is transferred outside India except as strictly required by Resend's infrastructure. All processors are bound by data processing agreements.
How long we keep it
- Chart and reading data: retained for the lifetime of your relationship with us, and indefinitely unless you request erasure. Readings are not regeneratable identically across engine versions; deletion of the stored output would be permanent.
- Invoices and billing records: retained for six years from the date of the transaction, as required by the CGST Act, section 36.
- Technical data (IP, browser): deleted after 90 days.
- Marketing consent records: retained until you withdraw consent, then archived for three years to demonstrate compliance.
Your rights under the DPDP Act 2023
The Digital Personal Data Protection Act 2023 grants you the following rights in relation to your personal data held by us:
- Access: the right to obtain a summary of the personal data we hold about you and how it is being processed.
- Correction: the right to have inaccurate or incomplete personal data corrected or completed.
- Erasure: the right to have your personal data erased, subject to our legal retention obligations (see above).
- Grievance: the right to have your grievances heard and addressed within 30 days, per section 13 of the DPDP Act.
- Nomination: the right to nominate a person who may exercise your data rights in the event of your death or incapacity.
To exercise any of these rights, submit a request at /grievance/ or email mailme@astroabhisheksoni.com. We will verify your identity and respond within 30 days.
Cookies and tracking
We do not use cookies. We do not embed third-party analytics scripts, advertising pixels, or social media tracking beacons on this website.
We maintain a first-party event log that records page views and calculator usage events for internal product improvement. No personal data is attached to these events; they are keyed to an anonymous session identifier that is not linked back to your identity.
Consent
We collect your explicit consent at intake before processing your personal data. You may withdraw consent for marketing communications at any time by replying STOP to any WhatsApp message or email from us.
Withdrawal of marketing consent does not affect the lawfulness of processing that occurred before the withdrawal, nor does it affect processing carried out on other lawful grounds (such as billing or tax compliance).
To request erasure of your data, use the process described under Your Rights above.
Cross-border transfer of data
Our backend CRM and calculation engine are hosted on Indian virtual private servers. Personal data does not leave India, except where Resend's email infrastructure routes a transactional email through servers outside India. We are monitoring the DPDP Act's cross-border transfer rules (section 16) and will update this notice as those rules are notified by the Central Government.
Children
This website and its services are not directed at persons under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please notify us immediately at mailme@astroabhisheksoni.com and we will delete it promptly.
Data Protection Officer
For this scale of practice, Abhishek Soni serves as both Grievance Officer and the primary contact for data questions. We will appoint a separate Data Protection Officer if and when the practice meets the threshold for classification as a Significant Data Fiduciary under section 10(1) of the DPDP Act 2023.
Grievance Officer
As required by section 13 of the Digital Personal Data Protection Act 2023:
Grievance Officer
Name: Abhishek Soni
Address: Nagpur, Maharashtra, India
Email: mailme@astroabhisheksoni.com
Phone:
Response time: within 30 days of receipt of grievance
You may also file a grievance using the online form at /grievance/.
Changes to this notice
This privacy notice is versioned in our backend system. Material changes — those that affect your rights or the way we use your data — will be notified to you by email and by a banner on this website displayed for at least 30 days before the change takes effect.
Non-material changes (such as corrections of typographical errors or clarifications that do not affect substance) may be made without prior notice. The "Last updated" date at the top of this page always reflects the date of the most recent change.