SONYCAR BAZAAR
PRIVACY & DATA

Privacy Policy

Version 2026-07-26-v1Effective 26 July 2026Last updated 26 July 2026

At Sony Car Bazaar, we respect your privacy and aim to handle personal information responsibly. This policy explains what the current website collects, why it is used, how it may be shared, how it is protected, how long it is retained and the choices available to you.

Privacy at a Glance

1. Information we collect

Contact and enquiry information

Website forms collect your name, Indian mobile number, optional email address, preferred contact channel and optional message. A vehicle enquiry also identifies the selected published vehicle. Test-drive requests collect a preferred date and time window.

Sell or exchange information

When you ask to sell or exchange a vehicle, the form collects make, model and year, with optional kilometres driven, fuel type, expected price and location. The current public form does not upload images or documents.

Communication and support information

Staff may maintain the enquiry status, follow-up time and internal notes. If you choose phone, WhatsApp or email, those communications are also handled through the relevant channel and its provider.

Technical and administration information

The lead service uses a SHA-256 hash of the request source address for abuse controls and a hashed duplicate fingerprint. It records a correlation identifier and audit event. Restricted staff accounts store username, email, display name, a BCrypt password hash, roles, login/security state, refresh-session data and audit events. The application does not request exact GPS location.

2. How information is collected

Information is collected directly when you submit a general, vehicle, test-drive, or sell/exchange form; when you contact the showroom by phone or WhatsApp; and during staff follow-up. Google Maps loads from Google when the map section enters view. The website does not claim access to government vehicle databases.

3. Why we use information

Personal-data purposes
Information or activityPurpose
General or vehicle enquiryRespond, discuss available vehicles and provide the requested assistance
Test-drive requestContact you about a preferred date and time; submission is not a confirmation
Sell or exchange requestDiscuss the vehicle details, expected price and possible next steps
Contact and preference detailsUse your chosen channel for service-related follow-up
Lead history and internal notesCoordinate follow-up and maintain an operational customer-service record
Hashed source address and duplicate fingerprintLimit spam, repeated submissions and misuse without storing the raw address in the lead record
Admin authentication and audit dataProtect restricted administration features and investigate security or operational events

We do not use the submitted enquiry as consent for unrelated marketing. There is currently no promotional mailing-list feature.

5. WhatsApp, phone and external services

WhatsApp links open a pre-addressed conversation only after you choose them; website form data is not silently sent to WhatsApp. WhatsApp, Google Maps, Instagram, Facebook and YouTube operate under their own privacy practices. Avoid sending unnecessary sensitive documents in ordinary chat messages.

6. Cookies and browser storage

Public browsing does not set a Sony Car Bazaar analytics or advertising cookie. The protected admin system uses one strictly necessary scb_refresh HttpOnly, SameSite=Strict refresh cookie. Its CSRF token is held in session storage, while the access token remains in application memory. Google Maps and linked external services may use their own cookies or storage under their policies.

Because no optional analytics or advertising trackers are installed, the current public website does not show a non-essential cookie banner.

7. When information may be shared

Information may be accessible to authorised showroom staff and the infrastructure providers required to operate the website and database. If you choose an external communication or map service, that provider receives information needed for the interaction. Information may also be disclosed where required by a verified lawful process, or to advisers and transaction participants where reasonably necessary for a requested service.

The website does not establish an affiliation with an RTO, Parivahan/VAHAN, an insurer, bank or finance company. Production hosting and processor locations must be confirmed before launch; therefore this policy does not claim that all data stays in India.

8. Vehicle listings and document privacy

Public pages expose only explicitly published vehicle records and approved vehicle images. Draft and archived vehicles are excluded by backend queries. Public vehicle-image uploads are restricted to authorised staff and are decoded, dimension/size checked, re-encoded as JPEG or PNG, assigned generated keys and stripped of EXIF/GPS metadata.

The current system has no customer identity-document upload workflow. Do not submit Aadhaar, PAN, a full RC scan, signatures, banking credentials or other sensitive documents through an enquiry form. If a later offline transaction reasonably requires Aadhaar, ask whether a masked copy is sufficient; UIDAI describes Masked Aadhaar as hiding the first eight digits and showing only the last four.

9. Data security

Implemented safeguards include backend role permissions, BCrypt password hashing, signed and expiring JWTs, refresh-token rotation/revocation, an HttpOnly SameSite refresh cookie, CSRF protection for refresh operations, exact-origin CORS, restrictive security headers, login and lead rate limits, honeypot/timing/duplicate controls, audit events, secret and dependency scanning in CI, and validated/re-encoded vehicle images.

Production deployment requires HTTPS, separate credentials, backups and monitoring; those operational controls must be verified for the chosen host before launch. No internet transmission or storage system can be guaranteed completely secure.

Suspected incidents

Suspected unauthorised access should be investigated, contained and documented, with remedial action and notices to affected people or authorities where applicable law requires them. No arbitrary notification deadline is promised here.

10. Data retention

Current retention position
Data categoryPurposeCurrent position
Enquiries, follow-up details and internal notesCustomer service and requested transaction discussionsNo automatic fixed deletion period is currently configured. Records must be reviewed and removed or anonymised when no longer needed, subject to lawful business-record requirements.
Consent recordEvidence of the requested contact permissionStored with the enquiry, including policy version and submission time.
Hashed anti-abuse dataRate limiting and duplicate preventionStored with the enquiry; in-memory rate counters expire after one hour.
Admin sessions and audit eventsAccount security, access control and investigationSession expiry is enforced; a formal audit-record deletion period is not yet configured.
Public vehicle images and inventory recordsShowroom inventory and transaction recordsRetained while operationally required. Unpublishing removes a vehicle and its media from authorised public queries.

The absence of a configured deletion schedule is a production-readiness gap, not permission to retain information indefinitely. The business, accountant and legal reviewer must approve exact periods before production launch.

11. Your privacy choices and rights

Subject to applicable law and the provisions in force, you may ask about processing, request access to an appropriate summary, correct or update inaccurate details, request erasure where applicable, withdraw consent, opt out of promotional communications and raise a grievance. We may preserve information where lawfully required or needed for an existing dispute or transaction.

As of this policy date, India’s DPDP Act and Rules have phased commencement dates. The principal operational notice, consent, processing, safeguard and data-principal-right provisions are scheduled for later commencement. We nevertheless use clear notices and data-minimising practices now. See the official India Code DPDP Act record and MeitY DPDP Rules record.

12. Children’s privacy

The website and vehicle-dealing services are intended for adults. We do not knowingly seek personal data directly from children for vehicle transactions or target children with behavioural advertising.