OTTER

Privacy Policy

How OTTER handles personal information

Last updated: 2026-08-08

Privacy Policy

1. Who is responsible for your information

Yuhash India Private Limited, operating the OTTER brand, is responsible for the personal information described in this Policy in relation to OTTER's own activities. The registered office is Kazmi House, Near Masjid, Islampur, Asansol, West Bengal โ€“ 713301, India. Privacy questions may be sent to support@otter.net.in.

2. Information we may collect

Depending on how you use OTTER, we may collect account and contact information such as name, mobile number and email address; delivery and billing addresses; order and product information; payment references, amount, method and transaction status; shipment, AWB, courier and tracking information; return, refund and warranty information; customer-support communications; and technical or security information such as IP address, browser or device information, session information, login activity, timestamps and security logs.

We do not ask customers to send Aadhaar information, biometric data, medical information or other unrelated sensitive information for an ordinary retail purchase.

3. How information is collected

Information may be provided directly by you, generated when you use the website or customer account, created during an order or support workflow, or received from payment, logistics, communication and other service providers involved in your transaction.

4. How we use information

We may use information to create and administer customer accounts; authenticate access; maintain the cart and checkout; process and fulfil orders; verify payment status; prepare invoices; arrange shipment and tracking; manage cancellations, reverse pickups, returns, quality checks, refunds and warranty requests; communicate service information; answer enquiries and complaints; prevent fraud and protect the website; maintain accounting, tax and legal records; improve site operations; and send optional promotional communications where permitted and appropriately chosen.

5. Consent and other permitted processing

Where processing depends on consent, the request should be clear and connected to the stated purpose. Optional marketing consent should be separated from communications necessary for account security, an order, payment, delivery, cancellation, return, refund or warranty service. You may withdraw consent where applicable, although withdrawal does not invalidate prior lawful processing or prevent processing that remains necessary for an existing transaction or legal obligation.

6. Payments and Razorpay

OTTER may use Razorpay or another configured payment provider to facilitate online payments. Payment credentials such as a complete card number, CVV, UPI PIN, internet-banking password or payment OTP are processed through the applicable payment system and should not be sent to OTTER customer care. OTTER may receive transaction information such as payment reference, amount, method, status and refund status.

7. Shipping, Shiprocket and courier partners

To fulfil an order or return, OTTER may share information with Shiprocket, courier companies and logistics providers. This may include the recipient name, mobile number, delivery or pickup address, pincode, order and shipment details, package information, invoice information where required, AWB/tracking information and reverse-pickup information. Sharing is limited to information reasonably required for the relevant logistics service.

8. OTP, SMS and customer communications

OTTER may use communication providers such as MSG91 for OTPs and customer communications. Authentication, order, payment, shipment, delivery, cancellation, return, refund, warranty and security messages are service communications. Promotional communications are treated separately and are subject to applicable consent, preference and opt-out requirements.

9. Other service providers and disclosures

We may share information, as reasonably required, with website hosting and technology providers, payment processors, logistics providers, communication providers, fraud or security service providers, professional advisers such as accountants, auditors and lawyers, governmental or regulatory authorities where required by law, and a lawful successor in connection with a restructuring or transfer of the relevant business. OTTER does not sell or rent customer personal information as a business.

10. Cookies and similar technologies

OTTER may use cookies or similar technologies that are necessary for login sessions, cart contents, security, fraud prevention, preferences and ordinary website operation. If non-essential analytics, advertising or tracking technologies are introduced, OTTER will provide the disclosures and choices required for their actual use. Paid items or optional consent must not be activated through misleading or pre-selected choices.

11. Account closure and deletion requests

You may request closure of your OTTER account by contacting support@otter.net.in. OTTER may verify that the request relates to the account before acting on it. A verified account may be deactivated so it can no longer be used as an active account.

Account closure does not automatically erase every record associated with previous transactions. Order, invoice, payment, refund, shipping, return, warranty, complaint, fraud, security, accounting, tax and legal records may be retained where required or permitted. Information no longer required for a lawful or necessary purpose may subsequently be deleted or anonymised in accordance with OTTER's retention practices.

12. Retention

OTTER keeps personal information for as long as reasonably required for the purpose for which it was collected and for applicable legal, accounting, tax, fraud-prevention, security, dispute and record-keeping requirements. Different categories of records therefore have different retention periods. Information that is no longer required may be deleted or anonymised, subject to necessary backup and archival cycles.

13. Security

OTTER uses reasonable technical and organisational measures appropriate to the systems and information involved, which may include authentication controls, restricted administrative access, secure transmission where used, logging, monitoring, backups and service-provider controls. No website, communication channel or storage system can be guaranteed to be completely secure, and OTTER does not promise absolute security.

14. Security incidents and personal-data breaches

A security incident may come to OTTER's attention through system or access logs, suspicious activity, customer or employee reports, hosting or technology-provider alerts, or notifications from payment, logistics, communication or other providers. Where OTTER becomes aware of a personal-data breach, it will assess the incident, take reasonable containment and remediation steps, preserve relevant evidence and make notifications to authorities and/or affected individuals when applicable law requires them.

15. Your choices and requests

Subject to applicable law and reasonable identity verification, you may contact OTTER to request correction or updating of inaccurate information, information about your account or personal information, account closure, deletion of information that OTTER is no longer required or permitted to retain, withdrawal of consent where applicable, a change to promotional communication preferences, or assistance with a privacy concern or grievance.

16. Children and contractual eligibility

OTTER's customer accounts and online purchasing facilities are intended for persons who are 18 years of age or older or otherwise legally competent to enter into the relevant transaction. A person below 18 should not independently create an OTTER customer account or place an order; a parent or lawful guardian should complete the transaction on their behalf. OTTER does not claim that ordinary browsing currently uses independent age verification. If OTTER becomes aware of child data in circumstances requiring additional consent or protective measures, it may restrict the account, request appropriate verification, delete information where appropriate, or take other steps required by law.

17. Cross-border processing

Some service providers may process information using infrastructure in India or other jurisdictions. Where personal information is processed or transferred across borders, OTTER will comply with restrictions and safeguards applicable under Indian law. This Policy does not represent that every service provider stores all information exclusively in India.

18. Third-party links

The website may contain links to third-party websites or services. A third party's independent processing is governed by its own privacy practices. OTTER remains responsible for its own obligations but is not responsible for unrelated processing carried out independently by a third-party site you choose to visit.

19. Changes to this Policy

OTTER may update this Policy when its practices, technologies or legal obligations change. The revised page will show its updated effective date. Where law requires notice or fresh consent for a materially different use of personal information, OTTER will take the required step rather than relying solely on continued browsing.

20. Privacy and grievance contact

Privacy questions and requests may be sent to support@otter.net.in. Consumer or privacy grievances may also be escalated to the Grievance Officer shown on the Contact Us page. Consumer grievances are acknowledged within 48 hours and are sought to be redressed within one month in accordance with applicable e-commerce requirements.