Privacy
Privacy Policy.
Last updated: 2026-05-02. We try to keep this readable. If something isn't clear, write to hello@sahipick.in.
1. Who we are
SahiPick (sahipick.com) is an India-focused affiliate review site. We earn a commission when you buy via our links; that's how we keep the site free. We're a sole-prop, currently based in India, and we comply with the Digital Personal Data Protection Act, 2023 (DPDP).
2. What we collect
- Page-view analytics — anonymous, aggregated. We use self-hosted Plausible (no cookies, no cross-site tracking).
- Click events — when you click an affiliate link, we log the bundle and offer ID so we know which picks people find useful. Stored against a session-scoped, non-personal ID — not your name, IP, or email.
- Email — if you sign up for price alerts or the weekly digest. Stored only as long as you want it. One-click unsubscribe in every email.
- WhatsApp number — if you opt into our WhatsApp recommendation chatbot. We store the number, your consent text verbatim, and the timestamp. Used only for the conversation you started, plus one optional 7-day follow-up.
- Search queries — when you use the on-site search, we may log the query (without your identity) to improve coverage.
3. What we do NOT collect
- No third-party advertising cookies. We don't run programmatic ads.
- No fingerprinting or cross-site tracking.
- No selling, renting, or trading of personal data — ever.
- No special-category data (Aadhaar, biometrics, financial IDs).
4. WhatsApp loop — DPDP specifics
You opt in via the page widget by ticking the consent box and submitting your number. We store:
- The exact consent text you saw, verbatim.
- The timestamp of consent.
- Your IP address at the time of consent (proof of consent only).
- Your phone number, hashed for matching incoming messages.
Reply STOP to any of our WhatsApp messages to revoke consent. We honour STOP within seconds and delete your number from future-message tables. The DPDP Act gives you the right to consent withdrawal, data correction, and erasure — write to privacy@sahipick.in.
5. Cookies
We use the minimum cookies the site needs to function:
sahipick_session— opaque session ID for click attribution. Lifetime: 30 days.- None for advertising. None for cross-site tracking.
6. Affiliate links — disclosure
Every product link on this site is an affiliate link. We earn a commission when you buy. This does NOT change the price you pay, and it does NOT change which products win our rankings — see our methodology page. Disclosure is shown above the fold on every page (the "Includes affiliate links" pill near the top).
7. Data retention
- Click events — 24 months, then deleted.
- Email subscribers — until you unsubscribe.
- WhatsApp consent + numbers — until you reply STOP, then 7 days for legal proof, then deleted.
- Server logs (web access) — 30 days.
8. Your DPDP rights
- Access — ask what data we have about you.
- Correction — fix anything that's wrong.
- Erasure — delete your data.
- Withdraw consent — for marketing emails / WhatsApp.
- Grievance — write to our Data Protection Officer at dpo@sahipick.in.
We respond within 30 days as required by the DPDP Act.
9. Where data lives
Our servers are in Hetzner Falkenstein (Germany). Day-to-day operations don't transfer Indian users' data outside India for anything beyond cloud hosting. We use the following sub-processors:
- Hetzner — server hosting (DE).
- Twilio — WhatsApp message delivery (US).
- Postmark — transactional email delivery (CA).
- Plausible (self-hosted) — analytics (DE, our box).
LLM providers (Google Gemini, Groq) process the recommendation conversation but don't receive your phone number or email — only the product text + your concern slug. No identity goes off our box.
10. Children
Per DPDP § 9, we do not knowingly process data of users under 18. If you believe a child has shared data with us, write to privacy@sahipick.in and we will delete it.
11. Changes to this policy
We may update this policy. Material changes will be notified via the site banner; the "Last updated" date at the top of this page tracks every revision.
12. Contact
General: hello@sahipick.in
Privacy: privacy@sahipick.in
DPO: dpo@sahipick.in