Privacy Policy
Last updated: 1 September 2026
What we collect, what we deliberately do not, who else sees it, and how long we keep it.
The short version: we collect what an order needs and little else. There is no advertising or analytics tracking on this site, and we never hold your card details — there is no payment field here to give them to.
01Who we are
Diecast Punch is operated by [registered business name], registered at [registered address]. We decide what personal data this store collects and why, and this policy explains both.
It sits alongside our Terms & Conditions and Shipping Policy.
02What we collect
Only what running your account and your orders actually needs.
When you create an account: your name, email address, and a password, which we store only as a one-way hash — we cannot read it, recover it, or tell you what it is.
Optionally, on your profile: a phone number, gender, and a second email address for receipt copies. These are blank unless you fill them in, and you can clear them.
When you order: the delivery name, address, city, postcode, country and phone number you give us, what you ordered, what you paid, the currency you were browsing in, and the order’s progress. Saved addresses stay on your account until you delete them.
As you use the site: your cart and wishlist while signed in, so they follow you between devices.
Automatically: your IP address, used to rate-limit sign-in and sign-up attempts so the site cannot be brute-forced. It is a short-lived counter, not a profile.
03What we deliberately do not collect
No card or bank details. There is no payment field on this site and no payment gateway behind it — payment is arranged separately, so we never hold a card number, UPI ID, CVV or OTP. Nobody from Diecast Punch will ever ask you for one.
No third-party analytics, advertising or tracking. The site loads no Google Analytics, no advertising or social pixel, no session-replay tool and no heatmap script. We do not build advertising profiles, we do not track you across other sites, and there is nothing here for a data broker to receive.
No selling or renting of your data. Not to advertisers, not to other retailers, not in aggregate.
04How we use it
- To take, fulfil, ship and support your orders, including pre-order balances.
- To run your account — signing you in, and keeping your cart, wishlist and saved addresses.
- To email you about an order: confirmation, dispatch, a balance request, a delay.
- To quote shipping to your pincode.
- To keep the site secure and prevent fraud and abuse.
- To keep the books and meet tax and accounting obligations.
We do this to perform our contract with you, to meet legal obligations, and for the narrow legitimate interest of keeping the store secure. We do not send marketing email unless you have asked for it, and any we do send has an unsubscribe link that works.
05Cookies and browser storage
We use no advertising or analytics cookies, so there is no consent banner to dismiss. What the site does store is either necessary to sign you in or a convenience that never leaves your browser.
Cookies. A session cookie that keeps you signed in, and the security cookies our sign-in system needs to prevent request forgery. Blocking them means you cannot sign in.
Local storage, on your device only. We never read these on the server:
- your cart, and a marker for whose cart it is
- your currency choice
- your light or dark preference
- models you recently viewed
- which announcements you have already seen
Clearing site data in your browser removes all of it. Your cart will also be restored from your account next time you sign in, because that copy is stored server-side so it survives changing device.
07How we protect it
Traffic is encrypted in transit. Passwords are stored as one-way hashes and never in a readable form. Sign-in and sign-up are rate-limited against brute force. Administrative access is restricted and re-checked on every request rather than trusted from a session. No system is perfectly secure, and we do not claim otherwise — but the most sensitive thing a store usually holds, your card details, is data we never have in the first place.
08How long we keep it
Account details stay until you ask us to close the account. Cart, wishlist and recently-viewed data is transient and goes with the account.
Order records are kept for as long as tax and accounting law requires, and we cannot delete those on request — an invoice is a statutory record. Where an account is closed with orders still on file, we keep the order and detach what is not needed to support it.
Security counters such as rate-limit records expire within minutes.
09Your rights
You can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything wrong — you can edit most of it yourself on your account;
- delete your account and the data we are not legally required to keep;
- stop sending you marketing, at any time.
Write to [support email] from the email address on the account. We may need to confirm it is you before acting, and we will respond within the period the law allows.
10Children
This store is not intended for children, and accounts are for people old enough to enter a binding contract where they live. We do not knowingly collect data from a child. If you believe a child has given us personal data, tell us and we will delete it.
11Grievance officer
If you are unhappy with how we have handled your data, raise it with our grievance officer, who is required to acknowledge and address complaints within the timelines set by Indian law:
[grievance officer name]
[grievance officer email]
[registered address]
If you are still not satisfied, you may escalate to the relevant data protection authority.
12Changes to this policy
We may update this policy. The date at the top is when it last changed, and a change that materially affects how we handle your data will be brought to your attention rather than made quietly.
13Contact
Anything about this policy or your data: [support email].