Privacy policy
Privacy Policy for Beauty Product Usage at YesMadam Technologies Private Limited
Effective Date: 18th June 2026
About this Privacy Policy
YesMadam Technologies Private Limited (formerly Notion Online Solution Private Limited) (“YesMadam”, “we”, “us” or “our”) owns and operates the SOKORA brand and the website www.sokora.com, through which we offer beauty and personal-care products and related services. In respect of the personal data we collect from you, we act as a Data Fiduciary.
At YesMadam Technologies Private Limited, we are committed to protecting your privacy and ensuring that your personal information is handled with care. This Privacy Policy outlines the types of information we collect, how we use, store, and share that information, and the measures we take to protect your data. We also explain your rights regarding your personal data and how you can control it.
This Privacy Policy is framed to comply with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), and is designed to give you transparency and control over your personal data.
Please read this Policy together with the notice we present to you when we seek your consent.
Key Terms
• Data Principal: the individual to whom the personal data relates — that is, you.
• Data Fiduciary: the person who, alone or with others, determines the purpose and means of processing personal data — that is, YesMadam.
• Data Processor: a person who processes personal data on behalf of a Data Fiduciary.
• Personal Data: any data about an individual who is identifiable by or in relation to such data.
• Processing: any operation performed on personal data, whether automated or not, such as collection, storage, use, sharing, or erasure.
• Consent Manager: a person registered with the Data Protection Board of India who enables a Data Principal to give, manage, review, and withdraw consent through an accessible and interoperable platform.
• Board: the Data Protection Board of India established under the DPDP Act.
1. Personal Data We Collect
We collect only the personal data that is necessary for the purposes described in this Policy. Depending on how you interact with us, this may include:
• Identity and contact details: your name, billing and delivery address, email address, and phone number — to create and manage your account, process and deliver your orders, and communicate with you.
• Account credentials: your username, password, and saved preferences.
• Transaction and payment data: details of the products you purchase and payment-related information. Card and other sensitive payment details are collected and processed directly by our third-party payment gateways; we do not store full card details on our servers.
• Demographic and preference data: information such as age, gender, and product preferences, where you choose to provide it, to offer you relevant recommendations and offers.
• Technical and usage data: your IP address, device type, browser type, operating system, and information about how you use our website, such as pages visited, time spent, and click patterns.
• Cookies and similar technologies: we use cookies to operate the website, remember your preferences, analyse usage, and improve your experience. You can manage cookies through your browser settings, though some features may not function correctly if cookies are disabled.
2. Purposes for Which We Process Your Personal Data
We process your personal data for the following specified purposes:
• Order processing and fulfilment: to process, fulfil, ship, and manage your orders, including billing, returns, refunds, and exchanges.
• Customer support: to respond to your queries, resolve issues, and provide support.
• Personalisation: to tailor product recommendations, offers, and content to your preferences and purchase history.
• Marketing and promotions: to send you promotional communications, discounts, special offers, and loyalty programme updates, where you have consented to receive them.
• Fraud prevention and security: to detect, prevent, and investigate fraud, misuse, and unauthorised activity, and to keep your account and our services secure.
• Legal and regulatory compliance: to comply with applicable laws, including taxation, accounting, and financial-reporting obligations, and to respond to lawful requests from authorities.
3. The Basis on Which We Process Your Personal Data
We process your personal data on the basis of your consent or for the legitimate uses permitted under the DPDP Act.
4. Withdrawal of Consent
You may withdraw your consent at any time, and doing so is as easy as giving it. You can withdraw consent by using the controls in your account, by writing to our Grievance Officer (see Section 15), or through a Consent Manager registered with the Board.
On withdrawal, we will stop processing your personal data for the relevant purpose within a reasonable time and will require our Data Processors to do the same, unless we are permitted or required to continue processing under applicable law. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal and may mean we are unable to provide certain services to you.
6. Data Retention and Erasure
We retain your personal data only for as long as it is necessary for the purposes for which it was collected, or for as long as required to comply with applicable law (including for taxation, accounting, and record-keeping).
We will erase your personal data once the purpose for which it was collected is no longer being served — for example, when you withdraw your consent, or when the purpose has otherwise been fulfilled unless retention is required under applicable law. Where the retention thresholds prescribed under the DPDP Rules apply to us, we will additionally erase your personal data after the prescribed period of your inactivity. Certain technical logs and traffic data may be retained for the minimum period required by law before erasure.
7. Disclosure and Sharing of Your Personal Data
We do not sell your personal data. We share it only as described below and only to the extent necessary:
• Data Processors and service providers: we engage trusted service providers — such as payment gateways, logistics and courier partners, and IT, cloud-hosting, communications, and analytics providers — to process personal data on our behalf. They act under binding contracts that require them to protect your personal data and to process it only on our instructions.
• Other Data Fiduciaries: where you choose services that involve another Data Fiduciary, we may share the personal data necessary to provide those services.
• Legal and regulatory disclosures: we may disclose personal data where required by law, by a court or regulatory authority, or to establish, exercise, or defend legal claims, or to protect the rights, safety, or property of our users, the public, or us.
8. Transfer of Personal Data Outside India
We may process and store your personal data on servers, or with service providers, located outside India. The DPDP Act permits the transfer of personal data outside India except to such countries or territories as the Central Government may restrict by notification. We will comply with any such restrictions and will apply appropriate safeguards to personal data transferred outside India.
9. Your Rights as a Data Principal
Subject to the DPDP Act, you have the following rights in respect of your personal data:
• Right to access: to obtain a summary of the personal data we process about you and the related processing activities, together with the identities of the Data Fiduciaries and Data Processors with whom we have shared your personal data and a description of the data shared.
• Right to correction and erasure: to have inaccurate or misleading personal data corrected, incomplete data completed, data updated, and personal data erased where it is no longer necessary for the purpose for which it was processed, unless retention is required by law.
• Right of grievance redressal: to have your grievances addressed by us through the means described in Section 15.
• Right to nominate: to nominate another individual who may exercise your rights under the DPDP Act in the event of your death or incapacity.
To exercise any of these rights, please contact our Grievance Officer using the details in Section 15. We may need to verify your identity before acting on your request. We will respond within the timelines prescribed under the DPDP Rules, and in any event within 90 days for grievance redressal.
10. Your Responsibilities as a Data Principal
When exercising your rights or interacting with us, the DPDP Act requires that you do not impersonate another person, do not suppress any material information, do not raise false or frivolous grievances, and furnish only authentic and verifiably correct information.
11. Security Safeguards
We implement reasonable technical and organisational security safeguards to protect your personal data against unauthorised access, use, disclosure, alteration, loss, or destruction. These include:
• Encryption: encryption of sensitive data in storage and in transit using industry-standard protocols, with masking or tokenisation where appropriate.
• Access control and authentication: restricting access to authorised personnel only, and using secure authentication methods, including multi-factor authentication.
• Data minimisation: collecting only the personal data necessary to provide our services.
• Monitoring and logging: monitoring for unauthorised access and retaining logs for the period required by law.
• Regular security review: conducting periodic security reviews and audits to identify and address vulnerabilities.
We require our Data Processors to maintain comparable safeguards. While we take these measures seriously, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Personal Data Breach
In the event of a personal data breach, we will intimate each affected Data Principal without undue delay, describing the breach, its likely consequences, and the measures we are taking. We will also report the breach to the Data Protection Board of India, including a detailed report within 72 hours of becoming aware of it (or such longer period as the Board may allow), as required under the DPDP Act and DPDP Rules.
13. Changes to This Policy
We may update or modify this Policy from time to time to reflect changes in our practices or in the law. Any changes will be posted on this page with a revised “Effective Date”. We encourage you to review this Policy periodically to stay informed about how we protect your personal data.
14. Contact Us
If you have any questions or concerns about this Privacy Policy or how your data is handled, please contact us at:
YesMadam Technologies Private Limited
C-45, Sector no – 63, Noida, Uttar Pradesh
Email: support@sokora.com
Phone: 01204322953
Website: www.sokora.com
15. Grievance Redressal and Grievance Officer
We have appointed a Grievance Officer, who also serves as our point of contact for questions about the processing of your personal data. If you have any questions, concerns, grievances, or requests regarding your personal data or this Policy, please contact:
Name: Varun Bhutani
Email: ymlegal@yesmadam.com
Timings: Monday – Saturday (10:00 AM to 6:00 PM)
We will acknowledge and address your grievance within the period prescribed under the DPDP Rules.
16. Complaint to the Data Protection Board of India
If you are not satisfied with the manner in which we have addressed your grievance, or if you believe your rights under the DPDP Act have not been honoured, you may make a complaint to the Data Protection Board of India. You should ordinarily approach us and exhaust our grievance redressal mechanism before making a complaint to the Board.
