1. Information we collect
Contact and enquiry information
Website forms collect your name, Indian mobile number, optional email address, preferred contact channel and optional message. A vehicle enquiry also identifies the selected published vehicle. Test-drive requests collect a preferred date and time window.
Sell or exchange information
When you ask to sell or exchange a vehicle, the form collects make, model and year, with optional kilometres driven, fuel type, expected price and location. The current public form does not upload images or documents.
Communication and support information
Staff may maintain the enquiry status, follow-up time and internal notes. If you choose phone, WhatsApp or email, those communications are also handled through the relevant channel and its provider.
Technical and administration information
The lead service uses a SHA-256 hash of the request source address for abuse controls and a hashed duplicate fingerprint. It records a correlation identifier and audit event. Restricted staff accounts store username, email, display name, a BCrypt password hash, roles, login/security state, refresh-session data and audit events. The application does not request exact GPS location.
2. How information is collected
Information is collected directly when you submit a general, vehicle, test-drive, or sell/exchange form; when you contact the showroom by phone or WhatsApp; and during staff follow-up. Google Maps loads from Google when the map section enters view. The website does not claim access to government vehicle databases.
3. Why we use information
| Information or activity | Purpose |
|---|---|
| General or vehicle enquiry | Respond, discuss available vehicles and provide the requested assistance |
| Test-drive request | Contact you about a preferred date and time; submission is not a confirmation |
| Sell or exchange request | Discuss the vehicle details, expected price and possible next steps |
| Contact and preference details | Use your chosen channel for service-related follow-up |
| Lead history and internal notes | Coordinate follow-up and maintain an operational customer-service record |
| Hashed source address and duplicate fingerprint | Limit spam, repeated submissions and misuse without storing the raw address in the lead record |
| Admin authentication and audit data | Protect restricted administration features and investigate security or operational events |
We do not use the submitted enquiry as consent for unrelated marketing. There is currently no promotional mailing-list feature.
4. Consent and customer choice
Each public lead form requires a clear affirmative checkbox permitting Sony Car Bazaar to use the supplied details to respond to that request. Consent is stored with the policy version and submission time. The checkbox is not pre-selected and no marketing permission is bundled with it.
You may withdraw consent for future consent-based contact by using the privacy contact methods below. Withdrawal does not undo processing already required to respond to your request and may not require deletion where lawful records must be retained.
5. WhatsApp, phone and external services
WhatsApp links open a pre-addressed conversation only after you choose them; website form data is not silently sent to WhatsApp. WhatsApp, Google Maps, Instagram, Facebook and YouTube operate under their own privacy practices. Avoid sending unnecessary sensitive documents in ordinary chat messages.
6. Cookies and browser storage
Public browsing does not set a Sony Car Bazaar analytics or advertising cookie. The protected admin system uses one strictly necessary scb_refresh HttpOnly, SameSite=Strict refresh cookie. Its CSRF token is held in session storage, while the access token remains in application memory. Google Maps and linked external services may use their own cookies or storage under their policies.
Because no optional analytics or advertising trackers are installed, the current public website does not show a non-essential cookie banner.
7. When information may be shared
Information may be accessible to authorised showroom staff and the infrastructure providers required to operate the website and database. If you choose an external communication or map service, that provider receives information needed for the interaction. Information may also be disclosed where required by a verified lawful process, or to advisers and transaction participants where reasonably necessary for a requested service.
The website does not establish an affiliation with an RTO, Parivahan/VAHAN, an insurer, bank or finance company. Production hosting and processor locations must be confirmed before launch; therefore this policy does not claim that all data stays in India.
8. Vehicle listings and document privacy
Public pages expose only explicitly published vehicle records and approved vehicle images. Draft and archived vehicles are excluded by backend queries. Public vehicle-image uploads are restricted to authorised staff and are decoded, dimension/size checked, re-encoded as JPEG or PNG, assigned generated keys and stripped of EXIF/GPS metadata.
The current system has no customer identity-document upload workflow. Do not submit Aadhaar, PAN, a full RC scan, signatures, banking credentials or other sensitive documents through an enquiry form. If a later offline transaction reasonably requires Aadhaar, ask whether a masked copy is sufficient; UIDAI describes Masked Aadhaar as hiding the first eight digits and showing only the last four.
9. Data security
Implemented safeguards include backend role permissions, BCrypt password hashing, signed and expiring JWTs, refresh-token rotation/revocation, an HttpOnly SameSite refresh cookie, CSRF protection for refresh operations, exact-origin CORS, restrictive security headers, login and lead rate limits, honeypot/timing/duplicate controls, audit events, secret and dependency scanning in CI, and validated/re-encoded vehicle images.
Production deployment requires HTTPS, separate credentials, backups and monitoring; those operational controls must be verified for the chosen host before launch. No internet transmission or storage system can be guaranteed completely secure.
Suspected incidents
Suspected unauthorised access should be investigated, contained and documented, with remedial action and notices to affected people or authorities where applicable law requires them. No arbitrary notification deadline is promised here.
10. Data retention
| Data category | Purpose | Current position |
|---|---|---|
| Enquiries, follow-up details and internal notes | Customer service and requested transaction discussions | No automatic fixed deletion period is currently configured. Records must be reviewed and removed or anonymised when no longer needed, subject to lawful business-record requirements. |
| Consent record | Evidence of the requested contact permission | Stored with the enquiry, including policy version and submission time. |
| Hashed anti-abuse data | Rate limiting and duplicate prevention | Stored with the enquiry; in-memory rate counters expire after one hour. |
| Admin sessions and audit events | Account security, access control and investigation | Session expiry is enforced; a formal audit-record deletion period is not yet configured. |
| Public vehicle images and inventory records | Showroom inventory and transaction records | Retained while operationally required. Unpublishing removes a vehicle and its media from authorised public queries. |
The absence of a configured deletion schedule is a production-readiness gap, not permission to retain information indefinitely. The business, accountant and legal reviewer must approve exact periods before production launch.
11. Your privacy choices and rights
Subject to applicable law and the provisions in force, you may ask about processing, request access to an appropriate summary, correct or update inaccurate details, request erasure where applicable, withdraw consent, opt out of promotional communications and raise a grievance. We may preserve information where lawfully required or needed for an existing dispute or transaction.
As of this policy date, India’s DPDP Act and Rules have phased commencement dates. The principal operational notice, consent, processing, safeguard and data-principal-right provisions are scheduled for later commencement. We nevertheless use clear notices and data-minimising practices now. See the official India Code DPDP Act record and MeitY DPDP Rules record.
12. Children’s privacy
The website and vehicle-dealing services are intended for adults. We do not knowingly seek personal data directly from children for vehicle transactions or target children with behavioural advertising.
13. Legal requests and policy changes
We may preserve or disclose information where required by applicable law, a valid legal process or a verified request from an authorised public authority, and where reasonably necessary to investigate fraud, maintain security or protect legal rights.
This policy may be updated when the website, services, data practices or applicable law changes. The revised version and date will appear here. Material changes requiring a new notice or consent will be handled separately; continued browsing is not treated as blanket consent to every future use.