Privacy Policy
Last updated: 26 April 2026
This Privacy Policy describes how The Elephant's Trunk Pvt. Ltd. (“we”, “us”, or “The Elephant's Trunk”) collects, uses, discloses, and protects your personal data when you use the website at theelephantstrunk.shop (the “Service”). We are based in India and comply with the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the Information Technology Act, 2000 and rules thereunder.
1. Data we collect
We collect the minimum personal data required to deliver and improve the Service:
1.1. You give us directly
- Account details — name, email, profile picture (if you sign in with Google).
- Order details — child's first name, age, gender, photo references, shipping address, contact phone number.
- Payment details — processed entirely by our payment partners (Stripe, Razorpay). We never see or store your full card number, UPI PIN, or netbanking credentials.
- Photos & images — reference photos you upload for personalised storybook illustrations. See §3 (Photos of children) for special protections.
1.2. Collected automatically
- Device & log data — IP address, browser, OS, pages visited, timestamps. Used for security, fraud prevention, and aggregated analytics only.
- Cookies & local storage — strictly necessary cookies for authentication and cart persistence. We do not use third-party advertising cookies.
1.3. Google Sign-In data (specific OAuth disclosure)
When you sign in with Google, we receive your name, email, and profile picture from Google's OAuth identity API. We use this only to create and identify your The Elephant's Trunk account. We do not access, store, or transmit any other Google data (Drive, Gmail, Calendar, Contacts, etc.). Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
2. How we use your data
- To create your storybook order and produce the personalised illustrations.
- To process payments, fulfilment, shipping, and tax invoicing.
- To send transactional emails (order confirmation, dispatch notice, delivery).
- To respond to your support requests at tanya@theelephantstrunk.shop.
- To detect, investigate, and prevent fraud, abuse, or violations of our Terms.
- To comply with applicable Indian law and respond to lawful government requests.
We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
3. Photos of children — extra protections
Our service generates personalised storybooks using reference photos provided by adults. We treat any photo of a minor with the highest care:
- You confirm you are the parent or legal guardian of any child whose photo you upload, or that you have explicit permission from such a parent/guardian.
- Reference photos are used only as inputs to generate the storybook illustrations for your specific order. They are never used to train AI models, never shown to other customers, never published, and never shared with any third party beyond the inference compute provider that processes them transiently for your order.
- Reference photos are deleted from active storage within 30 days of order delivery. Encrypted backups may retain them for up to 90 days for disaster-recovery purposes, after which they are permanently destroyed.
- You may request immediate deletion of any uploaded reference photo at any time by emailing tanya@theelephantstrunk.shop.
4. Data sharing
We share your data only with the following categories of processors, under contract:
- Payment processors (Stripe Inc., Razorpay Software Pvt. Ltd.) — to process your payment.
- Shipping carriers (e.g., Shiprocket, Quince) — to deliver the printed storybook to your address.
- Cloud infrastructure (Google Cloud Platform, region
asia-south1/ Mumbai) — for compute and storage. Reference photos are processed inasia-southeast1(Singapore) for GPU image generation; they are deleted from that region's memory after generation completes. - Email delivery (e.g., SendGrid, Google Workspace) — to send transactional notifications.
- AI model providers (e.g., OpenAI for text generation, Hugging Face for model weights) — for the AI components of the Service. Photo data is never sent to third-party AI providers; only text prompts and model weights are exchanged.
5. International transfers
Your data is processed primarily in India (Google Cloud Mumbai). Some transient processing occurs in Singapore (Google Cloud GPU region). These are jurisdictions notified by the Government of India under the DPDP Act for permitted cross-border transfers. Limited service-provider data (e.g., payment metadata, email delivery logs) may be processed in the United States by Stripe and SendGrid under their respective privacy programmes.
6. Data retention
| Data category | Retention period |
|---|---|
| Account profile (name, email) | Until you delete your account, then 30 days in soft-delete |
| Order records (invoices, shipping) | 7 years (statutory requirement for Indian tax records) |
| Reference photos of children | Active: 30 days post-delivery. Backups: 90 days. |
| Generated storybook PDFs | Available in your account for 2 years; longer on request |
| Server access logs | 30 days |
7. Your rights under the DPDP Act
You have the right to:
- Access a summary of personal data we hold about you and how we use it.
- Correct inaccurate or incomplete personal data.
- Erase your personal data, subject to retention obligations under Indian law (e.g., tax records).
- Withdraw consent for any processing that relies on your consent.
- Nominate another individual to exercise these rights on your behalf in case of death or incapacity.
- Grievance redressal — see §10.
To exercise any of these rights, email tanya@theelephantstrunk.shop from the email address associated with your account. We will respond within 30 days.
8. Security
We use TLS for all data in transit, AES-256 encryption for data at rest, private-IP-only connections to our database and cache (no public exposure), per-service IAM with least-privilege roles, and Google Secret Manager for credentials. We monitor for unauthorised access and follow the breach-notification timelines required by the DPDP Act.
9. Children's data
The Service is intended for purchase by adults. We do not knowingly create accounts for users under 18. Children's data appears in the Service only as reference photos and names provided by their parent or guardian for the purpose of generating a storybook for that specific child, and is processed under the protections in §3.
10. Grievance officer
In accordance with the IT Rules, 2011 and the DPDP Act, our Grievance Officer can be contacted at:
- Name: Tanya Sharma
- Email: tanya@theelephantstrunk.shop
- Address: The Elephant's Trunk Pvt. Ltd., India.
We will acknowledge complaints within 24 hours and resolve them within 15 days.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified via email and announced on this page at least 7 days before they take effect. The “Last updated” date at the top reflects the most recent revision.
12. Contact
For any privacy questions, contact us at tanya@theelephantstrunk.shop.
