THIS PRIVACY POLICY DESCRIBES HOW THEME STUDIO COLLECTS, USES, STORES, DISCLOSES, AND PROTECTS YOUR PERSONAL DATA. PLEASE READ THIS POLICY CAREFULLY BEFORE USING THE PLATFORM. BY REGISTERING, MAKING AN ENQUIRY, PURCHASING A SERVICE OR COURSE, OR OTHERWISE USING THE PLATFORM, YOU CONSENT TO THE PRACTICES DESCRIBED IN THIS POLICY.
1. INTRODUCTION AND IDENTITY OF DATA FIDUCIARY
This Privacy Policy ("Policy") applies to the website, registration pages, community panel, online courses, and all associated digital services operating under the name Theme Studio, accessible at www.themestudio.in (collectively, the "Platform").
1.2 The Platform is owned, operated, and managed by Theme Studio ("Operator", "We", "Us", or "Our"). Theme Studio is an e-commerce design and development agency that (a) provides Shopify store design, development, migration, and related services ("Agency Services"), and (b) offers or may in future offer online courses, training, workshops, and educational content ("Courses"). The Operator is the Data Fiduciary as defined under the Digital Personal Data Protection Act, 2023 ("DPDPA"), and is responsible for determining the purposes and means of processing personal data collected through the Platform.
1.3 This Policy governs all personal data collected from clients, prospective clients, course learners, community members, visitors to the Platform, and any other individuals whose personal data is processed by the Operator in connection with the Platform's operations (collectively, "Users", "You", or "Your").
1.4 This Policy is to be read in conjunction with, and forms an integral part of, the Terms and Conditions ("Terms") available at https://themestudio.in/terms-and-conditions. In the event of any conflict between this Policy and the Terms on a matter of data protection, this Policy shall prevail to the extent of such conflict.
2. DEFINITIONS
In this Policy, unless the context otherwise requires:
"Personal Data" means any data about an individual who is identifiable by or in relation to such data, as defined under the Digital Personal Data Protection Act, 2023, and includes Sensitive Personal Data.
"Sensitive Personal Data or Information" (SPDI) means data as defined under Rule 3 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, including passwords, financial information such as bank account and payment card details, and health-related data.
"Data Fiduciary" has the meaning assigned to it under the Digital Personal Data Protection Act, 2023, and refers to the Operator in the context of this Policy.
"Data Principal" has the meaning assigned to it under the Digital Personal Data Protection Act, 2023, and refers to the individual whose personal data is being processed.
"Data Processor" means any person who processes personal data on behalf of the Data Fiduciary.
"Processing" means any operation performed upon personal data, including collection, recording, storage, retrieval, use, disclosure, transmission, erasure, or destruction.
"Consent" means a free, specific, informed, unconditional, and unambiguous indication of the Data Principal's agreement to the processing of their personal data for a specified purpose, as required under the DPDPA.
"Cookies" means small text files placed on a device by a website or application to store and retrieve information about the user's browsing activity.
"Client" means any person who enquires about, registers for a consultation regarding, or purchases Agency Services.
"Learner" means any person who enrols in, purchases, or accesses a Course or educational content on the Platform.
"Platform", "Operator", "Terms", and other defined terms have the meanings assigned to them in the Terms and Conditions.
3. PERSONAL DATA WE COLLECT
3.1 Data Provided Directly by You
When You register, enquire, enrol, purchase, or otherwise interact with the Platform, You voluntarily provide us with the following categories of personal data:
Identity Data: Full name, username or display name, and photograph (if uploaded as a profile picture).
Contact Data: Email address, mobile number (including WhatsApp number), and postal address (where required for billing or correspondence).
Account Credentials: Password (stored in encrypted form; we do not have access to Your plain-text password).
Business and Project Data (Clients): Business name, nature of business, product category, number of products, existing website or social media links, budget range, project timeline, project requirements, brand assets, and any other information You share with us through registration forms, questionnaires, consultations, or project communication for the purpose of receiving Agency Services.
Client Account Access Data (Clients): Where required to deliver Agency Services, access credentials or collaborator permissions for third-party platforms such as Shopify, domain registrars, or app accounts. Such access is used solely for delivering the agreed services and is revoked or returned upon project completion.
Payment and Financial Data: Transaction reference numbers, payment method type (e.g., credit card, UPI, net banking), and billing address. Full payment card details are processed solely by the Payment Gateway and are not stored on our servers.
Educational and Interaction Data (Learners): Course enrolment history, progress records, quiz responses, assignments submitted, completion status, and certificates issued.
Communications Data: Messages, queries, feedback, reviews, comments, testimonials, and any other content You submit through the Platform's communication features, community panel, email, phone, or WhatsApp.
Identity Verification Data: Government-issued identification documents or other KYC documentation, where required to be collected under Applicable Laws.
3.2 Data Collected Automatically
When You access or use the Platform, we may automatically collect the following data through cookies, pixels, web beacons, log files, and similar technologies:
Device and Technical Data: IP address, browser type and version, operating system, device type, device identifier, time zone setting, and screen resolution.
Usage Data: Pages visited, content accessed, videos played, duration of viewing sessions, clickstream data, forms started or submitted, and navigation paths.
Advertising Data: Information collected through advertising technologies such as the Meta (Facebook) Pixel and Google Ads tags, including the pages You visit, the actions You take on the Platform (such as submitting a registration form), and identifiers used to measure and deliver advertising (see Clause 6).
Log Data: Server logs recording access times, error reports, and actions performed on the Platform.
Location Data: Approximate geographic location derived from IP address (country and city level only), unless You grant explicit permission for precise location access.
3.3 Data Received from Third Parties
We may receive personal data about You from third parties in the following circumstances:
Payment Gateway Providers: Transaction confirmation details, transaction identifiers, and payment status updates.
Social Login Providers: If You choose to register or log in using a third-party service (such as Google), we receive the data You have authorised that service to share with us, typically Your name, email address, and profile picture.
Advertising Platforms: Where You interact with our advertisements or lead forms on platforms such as Meta (Facebook and Instagram) or Google, we receive the information You submit through those platforms (such as name, email, and phone number) and aggregated performance data about our advertising campaigns.
Analytics Providers: Aggregated and pseudonymised analytical data about how users interact with the Platform.
3.4 Data You Are Not Required to Provide
Certain fields on the Platform are optional. Where fields are mandatory, they will be clearly marked. You may choose not to provide optional data, though this may limit certain features or the quality of Your experience on the Platform.
4. PURPOSES FOR WHICH WE PROCESS YOUR PERSONAL DATA
We process Your personal data only for specific, lawful purposes. The table below sets out the categories of data we may collect and the corresponding purposes for which each is processed:
Category of Data
Purpose of Processing
Identity Data & Contact Data
Account registration; identity verification; contacting You via WhatsApp, phone, or email to schedule and conduct consultations; communicating with You regarding Your enquiry, project, enrolment, account, or queries; sending administrative notices and service updates.
Business and Project Data
Understanding Your requirements; preparing store plans, proposals, and quotes; delivering and managing Agency Services; providing post-launch support.
Client Account Access Data
Performing agreed design, development, migration, and configuration work on Your third-party platforms.
Account Credentials
Authentication and secure access to Your account; password recovery.
Payment and Financial Data
Processing service fees, course fees, and subscription payments; issuing invoices and receipts; complying with GST obligations; fraud prevention; record-keeping under the Income Tax Act, 1961.
Educational and Interaction Data
Delivering Course content; tracking and displaying Your progress; issuing certificates; improving Course quality; analysing learning outcomes.
Communications Data
Responding to Your queries; moderating community discussions; improving the Platform; addressing complaints and grievances; displaying testimonials with Your consent.
Device, Technical, and Usage Data
Maintaining platform security; diagnosing technical issues; improving platform performance and user experience; analysing engagement trends.
Advertising Data
Measuring the effectiveness of our advertising campaigns; showing You relevant advertisements on third-party platforms; building audiences for advertising (including retargeting and lookalike audiences).
Location Data (approximate)
Fraud prevention; compliance with regional access restrictions; tailoring content or pricing where applicable.
Identity Verification Data
Compliance with KYC and anti-money laundering requirements under Applicable Laws.
4.1 The Operator processes Your personal data on the following legal bases, as applicable:
Contractual Necessity: Processing necessary to perform Our obligations to You under the Terms (e.g., delivering Agency Services, delivering Courses, processing payments).
Consent: Where You have provided free, specific, informed, and unambiguous consent, particularly for WhatsApp communication, marketing communications, advertising and retargeting, the display of testimonials, and the use of non-essential cookies.
Legal Obligation: Processing required to comply with Applicable Laws, including tax laws, anti-money laundering regulations, and court or regulatory orders.
Legitimate Interest: Processing for Our legitimate business interests, such as maintaining platform security, preventing fraud, and improving the Platform, where such interests are not overridden by Your rights and interests.
4.2 We shall not use Your personal data for any purpose that is incompatible with the purposes for which it was originally collected, without Your prior consent.
5. MARKETING COMMUNICATIONS
5.1 WhatsApp and Phone Communication By submitting Your mobile number on the Platform — including through consultation registration forms, lead forms on advertising platforms, or course enrolment — You expressly consent to being contacted by the Operator on WhatsApp, by phone call, and by SMS regarding Your enquiry, consultation, project, enrolment, or account. WhatsApp communications are transmitted through WhatsApp (owned by Meta Platforms, Inc.) and are subject to WhatsApp's own privacy policy and encryption practices. You may withdraw Your consent to WhatsApp communication at any time by informing us on WhatsApp or by writing to support@themestudio.in.
5.2 Marketing Communications We may send You promotional communications about our services, new Courses, offers, educational content, and Platform updates via email, WhatsApp, or SMS. We will do so only where You have provided Your prior consent, or where permitted under Applicable Laws (such as the Telecom Commercial Communications Customer Preference Regulations, 2018, and the National Do Not Call Registry framework).
5.3 Opting Out You may opt out of receiving marketing communications at any time by using the unsubscribe link in our emails, replying "STOP" on WhatsApp, or writing to us at support@themestudio.in.
5.4 Transactional Communications Opting out of marketing communications will not affect the delivery of transactional or administrative communications relating to Your enquiry, project, enrolment, or account (e.g., consultation scheduling, project updates, invoices, receipts, security alerts, or service updates), which We are required to send as part of our obligations to You.
6. COOKIES AND TRACKING TECHNOLOGIES
6.1 Types of Cookies Used
We use the following categories of cookies and similar tracking technologies on the Platform:
Strictly Necessary Cookies: Essential for the Platform to function correctly, including session management, authentication, and security. These cannot be disabled without affecting core functionality.
Functional Cookies: Enable enhanced features such as remembering Your preferences, language settings, and viewing history.
Analytics Cookies: Help Us understand how Users use the Platform, including which pages are visited most frequently and how users navigate through content. We may use third-party analytics services (e.g., Google Analytics) for this purpose. Data collected is aggregated and pseudonymised wherever possible.
Advertising and Marketing Cookies: Placed by Us or our advertising partners to deliver advertisements relevant to You, measure the effectiveness of advertising campaigns, and limit the number of times You see an advertisement.
Payment and Security Cookies: Placed by the Payment Gateway and security providers to prevent fraud and facilitate secure transactions.
6.2 Advertising Pixels and Retargeting
We use advertising technologies including the Meta Pixel (Facebook/Instagram) and Google Ads conversion tracking on the Platform. These tools collect information about Your device and Your activity on the Platform (such as pages viewed and forms submitted) and share it with Meta Platforms, Inc. and Google LLC respectively. This enables Us to:
Measure the performance of our advertising campaigns;
Show You advertisements for our services and Courses on Facebook, Instagram, Google, and partner websites after You have visited the Platform (retargeting); and
Build audiences of users with similar characteristics for advertising purposes.
Meta and Google process this data in accordance with their own privacy policies and may combine it with other data they hold about You. You may control the advertisements You see through Your Facebook Ad Preferences (www.facebook.com/adpreferences) and Google Ad Settings (adssettings.google.com), and by adjusting Your browser or device settings.
6.3 Third-Party Cookies
Certain third-party service providers integrated into the Platform (such as payment processors, analytics providers, advertising platforms, and video hosting services) may place their own cookies on Your device. These are subject to the respective third party's privacy and cookie policies, over which We have no control.
6.4 How to Manage Cookies
You may control and delete cookies through Your browser settings. Please note that disabling certain cookies may impair the functionality of the Platform.
7. SHARING AND DISCLOSURE OF PERSONAL DATA
7.1 No Sale, Rent or Trade of Data
The Operator does not sell, rent, or trade Your personal data to third parties for their independent marketing or commercial purposes.
7.2 Service Providers and Data Processors
We engage third-party service providers who process personal data on Our behalf and strictly under Our instructions, for the following purposes:
Platform Provider: The Platform, including its registration pages, community panel, and Course delivery, is hosted on TagMango, which processes the personal data You enter on the Platform as a service provider to the Operator.
Payment Gateway Providers: Payments are processed by Razorpay and/or other payment gateways integrated through the Platform, to process service fees, course fees, and subscription payments securely.
Cloud Hosting and Infrastructure Providers: To host, store, and deliver the Platform and its content.
Email, Messaging, and Communication Service Providers: To deliver transactional emails, WhatsApp messages, notifications, and support communications.
Video Streaming and Content Delivery Services: To host and stream Course videos and other video content.
Analytics Providers: To provide aggregated analytical reports about Platform usage.
Advertising Platforms: Meta Platforms, Inc. (Facebook, Instagram, WhatsApp) and Google LLC, for advertising measurement, delivery, and audience building as described in Clause 6.
Project and Business Tools: Design, development, project management, and file-sharing tools used to deliver Agency Services.
Customer Support Tools: To manage and respond to User queries and grievances.
All such service providers maintain appropriate technical and organisational security measures and to process personal data only for the specified purposes.
7.3 Third-Party Platforms Used in Delivering Agency Services
In the course of delivering Agency Services, We may access or share Your business information with third-party platforms necessary to complete Your project — such as Shopify, domain registrars, app providers, and payment gateways configured on Your store. Such sharing is limited to what is necessary to deliver the agreed services.
7.4 Legal and Regulatory Disclosure
We may disclose Your personal data without Your consent where required or permitted by Applicable Laws, including:
In response to a valid court order, summons, or direction issued by a competent court, tribunal, or judicial authority;
In response to a lawful demand or requisition by a government department, law enforcement agency, tax authority, or regulatory body;
To comply with Our obligations under the Information Technology Act, 2000, the Prevention of Money Laundering Act, 2002, the Income Tax Act, 1961, or any other Applicable Laws; or
Where disclosure is necessary to prevent, detect, or investigate an offence, fraud, or breach of the Terms.
7.5 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or a substantial portion of the Operator's business or assets, personal data held by the Operator may be transferred to the successor entity. In such circumstances, We shall notify You via the email address registered with us and shall ensure that the successor entity is bound by a privacy policy that affords a standard of protection at least equivalent to this Policy.
7.6 No Disclosure to Advertisers
With Your consent, We may display Your business name, store link, logo, screenshots of work completed for You, and testimonials You provide on the Platform, on our social media, and in our marketing materials. You may withdraw this consent at any time by writing to support@themestudio.in, following which We shall remove such material within a reasonable period.
8. CROSS-BORDER TRANSFER OF PERSONAL DATA
8.1 The Platform's servers and data storage infrastructure are primarily located in India. Some of Our third-party service providers (including cloud infrastructure, video hosting, analytics, communication, and advertising providers such as Meta and Google) may be located in, or may process data in, countries outside India.
8.2 Where personal data is transferred outside India, We take reasonable steps to ensure it is protected in accordance with this Policy and Applicable Laws, including the DPDPA and any restrictions notified by the Central Government thereunder.
8.3 By using the Platform and providing Your personal data, You acknowledge and consent to the transfer of Your data as described in this Clause.
9. DATA RETENTION
9.1 We retain Your personal data only for as long as is necessary for the purposes for which it was collected, or as required by Applicable Laws, whichever is longer.
9.2 As a general guide:
In response to a valid court order, summons, or direction issued by a competent court, tribunal, or judicial authority;
In response to a lawful demand or requisition by a government department, law enforcement agency, tax authority, or regulatory body;
To comply with Our obligations under the Information Technology Act, 2000, the Prevention of Money Laundering Act, 2002, the Income Tax Act, 1961, or any other Applicable Laws; or
Where disclosure is necessary to prevent, detect, or investigate an offence, fraud, or breach of the Terms.
9.3 Upon expiry of the applicable retention period, personal data shall be securely deleted or anonymised in a manner that renders it irretrievable, in accordance with the Operator's internal data destruction procedures and the requirements of Applicable Laws.
9.4 Notwithstanding the above, We may retain personal data for a longer period where necessary to comply with a legal obligation, to defend or exercise legal claims, or pursuant to a direction from a competent authority.
10. DATA SECURITY
10.1 The Operator implements appropriate technical and organisational measures to protect Your personal data against unauthorised access, disclosure, alteration, loss, or destruction, in accordance with:
The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011; and
Industry-standard security practices as applicable to an online educational platform of comparable nature and scale.
10.2 The security measures we employ include, without limitation:
Transmission of data over encrypted channels using SSL/TLS protocols;
Storage of passwords using one-way cryptographic hashing with salting;
Restricted access controls ensuring that personal data is accessible only to authorised personnel or systems on a need-to-know basis;
Secure handling and prompt revocation of Client platform access upon project completion;
Regular security assessments of the Platform’s infrastructure; and
Data minimisation practices, collecting only the personal data necessary for the stated purposes.
10.3 While We take all reasonable measures to secure Your personal data, no method of transmission over the internet or electronic storage is completely secure. The Operator cannot guarantee absolute security. You are responsible for maintaining the confidentiality of Your account credentials.
10.4 Personal Data Breach. In the event of a personal data breach that is likely to result in a risk to the rights of Data Principals, the Operator shall:
Take immediate steps to contain and mitigate the breach;
Notify the Data Protection Board of India as required under the DPDPA and rules thereunder; and
Notify affected Users at their registered email address or mobile number, where required by the DPDPA or where the breach poses a high risk to the User's rights and interests, providing details of the nature of the breach and recommended protective measures.
11. YOUR RIGHTS AS A DATA PRINCIPAL
11.1 Under the Digital Personal Data Protection Act, 2023, and other Applicable Laws, You, as a Data Principal, have the following rights with respect to Your personal data:
Right to Access: To obtain a summary of the personal data We hold about You, the processing activities undertaken, and the identities of Data Processors with whom Your data has been shared.
Right to Correction and Erasure: To request correction of inaccurate or incomplete personal data, updating of Your data, and erasure of personal data that is no longer necessary for the purpose for which it was collected, subject to legal retention requirements.
Right to Withdraw Consent: To withdraw Your consent at any time for processing based on consent (including WhatsApp communication, marketing, advertising, and testimonials), without affecting the lawfulness of processing carried out before withdrawal.
Right to Grievance Redressal: To raise a grievance regarding the processing of Your personal data with Our Grievance Officer, and, if unresolved, to approach the Data Protection Board of India.
Right to Nominate: To nominate another individual to exercise Your rights in the event of Your death or incapacity.
11.2 To exercise any of these rights, please submit a written request to the Operator at support@themestudio.in with the subject line "Data Rights Request". We shall acknowledge Your request within 48 hours and endeavour to respond substantively within 30 days, subject to any verification requirements and limitations under Applicable Laws.
11.3 The Operator may request verification of Your identity before processing a rights request to protect against unauthorised access to or deletion of Your personal data.
12. CHILDREN’S PERSONAL DATA
12.1 The Platform is directed at business owners, professionals, and learners aged 18 years and above. We do not knowingly collect personal data from individuals below the age of 18 without the verifiable consent of a parent or legal guardian.
12.2 If We become aware that We have inadvertently collected personal data from a child without appropriate parental consent, We will take prompt steps to delete such data. If You believe We have collected data from a child without proper consent, please contact Us immediately at support@themestudio.in.
13. THIRD-PARTY LINKS AND INTEGRATED SERVICES
13.1 The Platform may contain links to third-party websites, payment gateways, social media platforms (such as Instagram and YouTube), client stores showcased in our portfolio, or other external services. This Policy does not apply to such third-party services, and the Operator is not responsible for the privacy practices of any third party. We encourage You to review the privacy policies of any third-party services You access through the Platform.
13.2 Where We integrate third-party tools such as video hosting platforms, payment gateways, advertising pixels, messaging services, or single sign-on providers, Your use of the Platform may involve the transmission of personal data to those providers in accordance with their own terms of service and privacy policies.
14. APPLICABLE LAWS AND COMPLIANCE FRAMEWORK
14.1 The Operator processes personal data in compliance with the following laws, rules, and regulatory frameworks, as applicable:
The Digital Personal Data Protection Act, 2023, and rules notified thereunder;
The Information Technology Act, 2000;
The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011;
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021;
The Consumer Protection Act, 2019, and the Consumer Protection (E-Commerce) Rules, 2020;
The Telecom Commercial Communications Customer Preference Regulations, 2018; and
Any other Applicable Laws relating to data protection, privacy, and electronic communications in India.
14.2 The Operator shall update its data processing practices and this Policy as required to reflect changes in the above regulatory framework, including the progressive notification of the DPDPA's provisions and all other Applicable Laws.
15. GRIEVANCE OFFICER AND CONTACT INFORMATION
15.1 In accordance with the Information Technology Act, 2000, the IT-SPDI Rules, 2011, the DPDPA, and the Consumer Protection (E-Commerce) Rules, 2020, the Operator has designated a Grievance Officer to address complaints and grievances relating to the processing of personal data. The Grievance Officer's details are as follows:
Name: Rajat Tirkey
Designation: Owner
Email: support@themestudio.in
Postal Address: THEME STUDIO, GROUND FLOOR, HOUSE NO 268N, NEW SHANTIPUR, BAY PASS ROAD, DIBDIH, RANCHI, JHARKHAND, 834002
Contact Hours: Monday to Friday, 9:00 AM – 6:00 PM IST
15.2 For all other privacy-related queries, requests, or communications, including data rights requests under Clause 11, You may contact the Operator’s Privacy Point of Contact at:
Email: support@themestudio.in
Postal Address: THEME STUDIO, GROUND FLOOR, HOUSE NO 268N, NEW SHANTIPUR, BAY PASS ROAD, DIBDIH, RANCHI, JHARKHAND, 834002
15.3 All privacy grievances shall be acknowledged within 48 (forty-eight) hours of receipt and resolved within [30] days, unless additional time is required due to the complexity of the matter, in which case You will be informed of the revised timeline.
16. CHANGES TO THIS PRIVACY POLICY
16.1 The Operator reserves the right to update, modify, or revise this Policy at any time to reflect changes in Our data processing practices, applicable legal requirements, or Platform operations. The revised Policy shall be posted on the Platform with an updated "Last Updated" date.
16.2 For material changes to this Policy — including changes that significantly alter the purposes of processing, categories of data collected, sharing practices, or Your rights — We shall provide You with prior notice via email or WhatsApp to Your registered contact details, and shall seek fresh consent where required by Applicable Laws.
16.3 Your continued use of the Platform following the effective date of a revised Policy shall constitute Your acceptance of the revised terms, except where Your fresh consent is required, in which case continued use shall be conditional on such consent being provided.
17. GOVERNING LAW
17.1 This Privacy Policy shall be governed by and construed in accordance with the laws of India.
17.2 Any dispute arising out of or in connection with this Policy, including any question regarding its existence, validity, or termination, shall be subject to the jurisdiction of the courts at Ranchi, Jharkhand, India, and shall also be subject to the grievance redressal and dispute resolution mechanisms set out in the Terms and Conditions.