Skip to content
Offer of the Day Free Billing Software with Company Registration. Valid today only Claim on WhatsApp
TaxhintAdvisors
Legal documents · Website & app policies

Privacy Policy & Terms and Conditions Drafting

Every website or app that collects names, phone numbers or payments needs a privacy policy and terms of use that match how it actually works. Our privacy policy drafting covers both under Indian law: the IT Act and SPDI Rules today, and the Digital Personal Data Protection Act, 2023, whose main duties start on 13 May 2027.

Privacy policyTerms of useRefund & shipping policyDPDP-ready notices
5000+ businesses served10+ years of practice · Pan-India
Get a free consultationWe reply within one working day

What it is

A privacy policy tells visitors what personal data you collect, why, who you share it with and how they can ask questions or complain. Terms and conditions, or terms of use, set the rules for using your site or app: who may use it, how orders and payments work, refunds, liability and how disputes are settled.

Two sets of rules apply in India right now. Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 requires a body corporate to publish a privacy policy on its website. The Digital Personal Data Protection Rules, 2025, notified on 13 November 2025, bring stricter notice and consent duties under the DPDP Act from 13 May 2027, when Section 43A of the IT Act is also omitted.

Who it applies to

You sell online

Anyone selling goods or services online. The Consumer Protection (E-Commerce) Rules, 2020 add display and grievance duties on top of privacy law, alongside GST registration for selling online.

You run an app or SaaS product

Mobile apps, software platforms and portals that create user accounts, store customer data or process it for business clients.

Your website has an enquiry form

Think of a Faridabad coaching institute whose admission form collects students’ names, phone numbers and parents’ details. That is personal data, some of it about children.

Why it matters

Meets the law today and in 2027

SPDI Rule 4 requires a published privacy policy today. From 13 May 2027, the DPDP Rules require a clear notice before consent is taken.

Keeps large penalties away

Under the DPDP Act, failing to take reasonable security safeguards can attract a penalty of up to ₹250 crore, and failing to report a breach up to ₹200 crore. Rule 8(2) of the SPDI Rules names ISO 27001 certification as one standard for reasonable security practices.

Earns customer trust

A clear policy answers the first question a careful buyer asks: what happens to my phone number and card details?

Documents required

About your business

  • Legal name, registered address and contact details
  • Website or app URL
  • Name and contact of the grievance officer

About the data

  • Forms, sign-up fields and what each field collects
  • Payment gateway, analytics, CRM and hosting providers
  • Whether children use the service
  • Where data is stored and for how long

About your terms

  • Pricing, delivery, cancellation and refund practice
  • Subscription or auto-renewal terms
  • City you want disputes to be heard in

What the documents cover

DocumentKey contentsMain legal hook
Privacy policyData collected, purpose, sharing, security, retention, rights, grievance officerSPDI Rules 4 and 5; DPDP Act and Rules
Consent noticeItemised data, specific purpose, how to withdraw consent, how to complain to the BoardDPDP Rules, Rule 3
Terms of useEligibility, accounts, payments, IP, liability, termination, governing lawIndian Contract Act, 1872; IT Act, 2000
Refund and shipping policyReturn, refund, cancellation and delivery termsConsumer Protection (E-Commerce) Rules, 2020

How it works

1

Map every form and tool

Privacy policy drafting starts with your real data flow. We go through your site or app with you: every form, cookie, third-party tool and payment flow, and where the data ends up.

2

Get plain-English drafts

We draft the privacy policy, terms of use and refund policy in plain English, matched to what your business actually does.

3

Check them against your operations

You check the drafts against your operations, and we revise. Your developer then adds consent checkboxes where the law needs them.

4

Publish and keep them current

You publish the pages and link them in the footer and at sign-up. We update them when your features or the law change.

Timelines

In force now

SPDI Rule 4 privacy policy and a grievance officer under Rule 5(9), who must address grievances within one month.

13 November 2026

Registration of consent managers with the Data Protection Board begins under the DPDP Rules.

13 May 2027

Data fiduciary duties start: notice under Rule 3, consent, security safeguards, breach reporting and grievance replies within 90 days.

What happens if your policies are missing or wrong

Exposure under the IT Act

Until 13 May 2027, Section 43A lets a person claim compensation from a body corporate that is negligent with sensitive personal data and causes wrongful loss.

DPDP penalties from 2027

The Data Protection Board can impose penalties up to ₹250 crore for security failures, with other breaches carrying their own limits under the Schedule to the Act.

Weak ground in a dispute

Here is the catch: copied terms that do not match your refund practice or chosen city leave you with little to rely on when a customer complains.

Frequently asked questions

Is a privacy policy mandatory for a website in India?

Yes, if your business collects personal information. Rule 4 of the SPDI Rules, 2011 requires a body corporate to publish a privacy policy on its website, stating the type and purpose of information collected and the security practices followed. From 13 May 2027, the DPDP Rules also require a clear notice before consent. A short, accurate policy published now covers both. We check the dates against the Gazette notifications before we finalise the draft.

When does the DPDP Act actually apply to my business?

The main duties start on 13 May 2027. The DPDP Rules, 2025 were notified on 13 November 2025 and phased in. The Data Protection Board provisions started at once, consent manager registration starts on 13 November 2026, and notice, consent, security and grievance duties apply from 13 May 2027. Use the time to fix your forms and policies.

Can I copy a privacy policy from another website?

No, and you should not. Good privacy policy drafting starts from your own data, because a copied policy describes someone else’s data, tools and refund practice, and may infringe their copyright too. If your policy says one thing and your app does another, the policy becomes evidence against you. Under the DPDP Rules, a notice must list the specific personal data and purposes of your own processing. We draft from your actual forms and tools.

What must a DPDP consent notice contain?

Rule 3 of the DPDP Rules, 2025 requires the notice to stand on its own and be clear. It must give an itemised description of the personal data, the specified purpose and the goods or services it enables. It must also explain how to withdraw consent, as easily as it was given, how to exercise rights and how to complain to the Data Protection Board. We draft it in that order.

Do I need a grievance officer?

Yes, in most cases. Rule 5(9) of the SPDI Rules requires a grievance officer whose details are on the website, with grievances addressed within one month. E-commerce entities must also display the officer’s name, contact details and designation, and acknowledge complaints within 48 hours under Rule 4 of the E-Commerce Rules, 2020. Name one person and publish their email address.

Are click-to-accept terms and conditions legally valid?

Yes. Section 10A of the IT Act, 2000 says a contract is not unenforceable only because it was formed electronically. The usual tests of Section 10 of the Indian Contract Act still apply: free consent, lawful consideration and lawful object. Show the terms clearly and record the user’s acceptance with a checkbox, not just a footer link. That record is what you rely on if a dispute arises.

What extra rules apply to an online store?

The Consumer Protection (E-Commerce) Rules, 2020 apply. Rule 4 requires you to show your legal name, address, website and customer care details, appoint a grievance officer, acknowledge complaints within 48 hours and resolve them within one month. Spell out return, refund and cancellation terms plainly. We draft the terms and refund policy together so they never contradict each other.

Does my app need special terms if children use it?

Yes. Under the DPDP Act and Rules, you need verifiable consent of a parent before processing a child’s personal data. The Rules allow verification through reliable identity details or a Digital Locker service provider. Schools, coaching apps and gaming platforms must plan for this before 13 May 2027. We draft the notice and list the product changes your team will need.

How often should we update our policies?

Whenever your data use changes, and at least once a year. Say a Delhi clothing brand adds a WhatsApp marketing tool mid-year. Customer numbers now reach a new processor, so the policy must say so. The DPDP phase starting 13 May 2027 is a fixed date to plan around. We keep a version history and update the pages for you, so the live text always matches your product.

Pricing

What it costs

Our fee plus the government fee that applies to your case, quoted before you commit. Tell us the situation and we will price it exactly.

There is no government fee for publishing a privacy policy or terms of use.

Ready to begin?

Send us your website or app link, and we will draft a privacy policy and terms that match how your business really runs.