Croma's privacy notice is well drafted, hosted in India and unusually honest about backups. Its defining feature is how far the data travels: Croma may share it with "Tata Sons Private Limited, and its subsidiaries, affiliates, associate companies and joint venture companies with whom we have a contractual arrangement", and with other participating entities on the "Tata Consumer Platform operated by Tata Digital Limited".
We read croma.com/privacy-policy first-party on 8 October 2026, logged out, with nothing purchased and no account created. Below: that group-wide sharing and the safeguards attached to it, the collection categories that reach past electronics, what deletion actually achieves, the 30-day free request route and its refusal clause, the amendment rule that binds you on your next visit, and the several provisions this notice handles better than the market norm. This reports a published notice and expresses no view on whether any part of it complies with any law; nothing here is legal advice.
Verbatim, from Croma's own Privacy Notice
Read 8 October 2026 on croma.com/privacy-policy
"Even if we delete your Data ... it may persist on backup or archival media for audit, legal, tax or regulatory purposes"
📅 Update log:
8 October 2026 — First publication. Croma's Privacy Notice read in full from croma.com/privacy-policy: the definitions of Cookie, Data, Data Protection Laws, Partners, Service Providers, IRL and Tata Group Entities, the named operating entity and its Mumbai registered office, the categories of contact, financial, technical, transaction, product and service, personal, review and loyalty information collected, the in-store and attempted-transaction collection clauses, the automatic collection of IP address, operating system, browsing, device and language details, the email open and click confirmation, information received from other websites and from Tata Group Entities, the full list of purposes including financial product offers and behavioural insight generation, the treatment of inferences as personal or sensitive personal information, the minors clause, the sharing provisions covering Partners, Tata Group Entities, the Tata Consumer Platform operated by Tata Digital Limited, Service Providers and legal disclosures, the business-transfer clause, the differing-practices warning, the security and retention clauses, the backup-persistence sentence, the India hosting statement, the rights list, the no-fee and 30-day response commitments, the refusal-with-reasons clause, the severability clause and the amendment and deemed-acceptance clause. Notice verified 8 October 2026.
The data does not stop at Croma
The defining feature of Croma's privacy notice is not what it collects but how far that collection reaches. The notice defines its sharing circle up front, and the circle is a conglomerate:
"Tata Sons Private Limited, and its subsidiaries, affiliates, associate companies and joint venture companies with whom we have a contractual arrangement" — the notice's own definition of Tata Group Entities. Croma is operated by IRL, "a company incorporated in India whose registered office is at Unit No. 701 & 702, Wing A, 7th Floor, Kaledonia, Sahar Road, Andheri (East), Mumbai 400069".
The sharing clauses then run outward. Croma "may make available to you products, services and/or applications of Tata Group Entities, to assist them to reach out to you in relation to their programs or campaigns", and accordingly "may share your Data with Tata Group Entities". Separately: "Your Data may be shared with Tata Group Entities and other participating entities on the Tata Consumer Platform operated by Tata Digital Limited" for enrolment and for offering products, services and benefits.
The practical reading is that an electronics purchase is an entry point to a group-wide customer record, not a transaction with one shop. The uses clause says so directly: data may be used to "enable Tata Group Entities and Partners to offer their products and/or services and communicate with you about such products and/or services".
Sharing data within a corporate group under contractual arrangements is lawful and extremely common, and no wrongdoing is alleged. The notice also attaches safeguards — it says appropriate written contracts are in place and that service providers must process data only on instruction. One caveat is the notice's own: "Tata Group Entities and Partners may have privacy practices that differ from those of IRL. The use of your Data will be governed by their privacy statements when you provide Data on their websites."
Ethnicity, religion, marital status and travel history
The categories of data listed under "Personal information" are broader than an electronics retailer's business obviously requires, and the notice lists them plainly:
"Age, sex, date of birth, marital status, nationality, details of government identification documents provided, occupation, ethnicity, religion, travel history or any other personal information provided in responses to surveys or questionnaires."
Two things should be said about that list immediately. First, the sentence ends by tying the category to information "provided in responses to surveys or questionnaires" — so the natural reading is a catalogue of what a customer might volunteer rather than a list of what is demanded at checkout. Second, this is a Tata Group notice template used across businesses, which plausibly explains categories like travel history and loyalty programme "frequent flyer or travel partner programme affiliation" appearing on an electronics site. Nothing here suggests Croma asks any customer for their religion or ethnicity to sell them a washing machine, and no such allegation is made.
The financial category is the one most directly tied to shopping: "payment instrument information, transactions, transaction history, preferences, method, mode and manner of payment, spending pattern or trends, and other similar data." Spending pattern or trends is an inference rather than a fact you hand over, and the notice addresses that too: "We treat these inferences as personal information (or sensitive personal information, as the case may be), where required under applicable law" — which is the right treatment and worth crediting.
The stated purposes include generating "aggregated data to prepare insights to enable us to understand customer behaviour, patterns and trends with a view to learning more about your preferences or other characteristics" and providing "offers (including for financial products and/or services), personalized services and recommendations".
What "delete" means here
The rights section is reasonably generous on paper. Depending on the applicable law you may "access your Data, rectify it, restrict or object to its processing, or request its deletion or anonymization", opt out of cookies and marketing, receive your data to transmit elsewhere, withdraw consent and lodge a complaint with a supervisory authority. Requests are free: "We will not charge you for any request", answered "within 30 days".
Two sentences qualify it. The first is about refusal: "Where we are legally permitted to do so, we may refuse your request. If we refuse your request, we will tell you the reasons why." Giving reasons for a refusal is good practice and not every notice commits to it.
The second is about what deletion actually achieves: "Even if we delete your Data, including on account of exercise of your right under Clause 12 below, it may persist on backup or archival media for audit, legal, tax or regulatory purposes."
That is an honest sentence and a technically accurate one. Backups are written to be immutable, and tax and audit rules require retailers to keep transaction records for years regardless of what a customer asks. Most privacy notices leave this implied; this one states it. The retention clause is equally candid: "Because these needs can vary for different data types and purposes, actual retention periods can vary significantly." There is no number anywhere in the notice.
Data location is specified and is in the customer's favour: "Data collected under this Privacy Notice is hosted on servers located in India."
| What the notice covers | What Croma's Privacy Notice states | Effect |
|---|
| Who you are sharing with | Tata Sons and its subsidiaries, affiliates, associates and JVs | Group-wide |
| The Tata Consumer Platform | data may be shared with participating entities on it | Operated by Tata Digital |
| Their privacy practices | Group entities and partners "may have privacy practices that differ" | Differ |
| Personal categories | includes ethnicity, religion, marital status, travel history | From surveys |
| Financial categories | includes "spending pattern or trends" | Inferred |
| Inferences | treated as personal or sensitive personal information where law requires | Correct treatment |
| Deleting your data | "may persist on backup or archival media" | Not erased |
| Retention period | no figure given; "can vary significantly" | No number |
| Refusing a request | "we may refuse your request" but will give reasons | With reasons |
| Cost and speed | no charge; answered "within 30 days" | Free, 30 days |
| Where data is hosted | "servers located in India" | In India |
| If the business is sold | data "may be transferred as part of such transaction" | Transferable |
| Changes to the notice | "deemed to have accepted ... on your first use" after a change | Deemed consent |
| Under-18 users | only "with the involvement of a parent or guardian" | Supervised |
The notice can change and bind you on your next visit
The amendment clause does not promise notice before a change takes effect: "Our business changes constantly and our Privacy Notice will change also. We may e-mail periodic reminders of our notices and conditions, unless you have instructed us not to, but you should check our website and mobile application frequently to see recent changes. The updated version will be effective as soon as it is accessible. Any changes will be immediately posted on our website and mobile application and you are deemed to have accepted the terms of the updated Privacy Notice on your first use of our website or mobile application or first purchase of the products and/or services following the alterations."
Effective on posting, accepted on your next visit. The burden to check is placed on the reader, in the notice's own words — "you should check our website and mobile application frequently". This is why every quotation on this page carries the date it was read, 8 October 2026, and a reader checking later may find different text.
The business-transfer clause is brief: "As we continue to develop our business, we might sell or buy subsidiaries or business units. Your Data (including in relation to loyalty programs) may be transferred as part of such transaction." Unlike Amazon's equivalent clause, which carries forward "the promises made in any pre-existing Privacy Notice", this one attaches no such condition in its own words.
In-store collection is covered too, which is easy to miss on a chain with physical shops: data is collected "through our stores, website (including sub-domains and microsites) and mobile applications" and "when you conduct a transaction with us or attempt a transaction at our stores". An attempted transaction is enough.
What the notice does well
It would be a poor reading of this document to present it as uniformly customer-unfriendly, because several provisions are better than the market norm and deserve saying so.
Servers in India. Inferences treated as personal or sensitive personal information where law requires. No charge for a data request, answered within 30 days, with reasons given for any refusal. An explicit statement that deletion does not clear backups, where most notices stay silent and let the customer assume otherwise. A named operating entity with a full registered address. And an unusually specific undertaking on third parties: service providers "will be required to only process Data in accordance with express instructions" and to implement "appropriate technical and organizational security measures and confidentiality obligations binding employees accessing Data."
The automatic-collection section is also specific rather than vague: web servers and analytics affiliates "collect IP addresses, operating system details, browsing details, device details and language settings", aggregated to measure visits, time on site and pages viewed.
The honest summary is that this is a well-drafted conglomerate privacy notice whose single most important feature is the size of the circle it shares with — and that the circle is disclosed clearly rather than buried, which is the thing a reader can actually act on.
How to use this page
Four practical points, none of them legal advice. One: understand that a Croma purchase can feed a group-wide record, since the notice provides for sharing with Tata Group entities and the Tata Consumer Platform — if cross-brand marketing is unwelcome, the marketing opt-outs are the lever, and the notice says you may "opt out of some collection or uses of your Data". Two: do not treat deletion as erasure — the notice says data may persist on backup and archival media for audit, legal, tax and regulatory purposes, which is normal and worth knowing in advance. Three: a data request is free and answered in 30 days, and a refusal must come with reasons, so it costs nothing to ask. Four: volunteer less in surveys — the broadest categories in the collection list are tied to survey and questionnaire responses, which is the part a customer controls entirely. Everything above is Croma's published notice as it stood on 8 October 2026 and it can change at any time. This page describes a published privacy notice and expresses no view on whether any part of it complies with any law; nothing here is legal advice.
Frequently Asked Questions
Who does Croma share customer data with?
Its own notice defines the circle as the Tata Group. Tata Group Entities means "Tata Sons Private Limited, and its subsidiaries, affiliates, associate companies and joint venture companies with whom we have a contractual arrangement", and Croma "may share your Data with Tata Group Entities" so they can reach out about their programmes or campaigns. Separately, "Your Data may be shared with Tata Group Entities and other participating entities on the Tata Consumer Platform operated by Tata Digital Limited". The notice also warns that those entities "may have privacy practices that differ from those of IRL". Sharing within a corporate group under contractual arrangements is lawful and common, and no wrongdoing is alleged.
Does Croma collect my religion or ethnicity?
Those words appear in the collection list, with important context. The notice lists under personal information: "Age, sex, date of birth, marital status, nationality, details of government identification documents provided, occupation, ethnicity, religion, travel history or any other personal information provided in responses to surveys or questionnaires." The sentence ends by tying the category to what a customer provides in surveys and questionnaires, so the natural reading is a catalogue of what might be volunteered rather than what is demanded at checkout — and this appears to be a Tata Group template used across businesses, which also explains "travel history" on an electronics site. Nothing here suggests Croma asks any customer for their religion or ethnicity in order to sell them an appliance, and no such allegation is made.
If I ask Croma to delete my data, is it gone?
Not from backups, and the notice says so. "Even if we delete your Data, including on account of exercise of your right under Clause 12 below, it may persist on backup or archival media for audit, legal, tax or regulatory purposes." That is technically accurate and honest — backup media are written to be immutable, and tax and audit rules require transaction records to be retained regardless of a customer request. Most privacy notices leave this implied. The retention clause gives no figure either: "actual retention periods can vary significantly."
How long does Croma take to answer a data request, and can it refuse?
Thirty days, free, and yes it can refuse. "We will not charge you for any request. Where we are legally permitted to do so, we may refuse your request. If we refuse your request, we will tell you the reasons why." The response window is stated as "within 30 days". The rights listed, depending on which data protection laws apply to you, include access, rectification, restriction, objection, deletion or anonymisation, portability, withdrawal of consent and lodging a complaint with a supervisory authority. Committing to give reasons for a refusal is better practice than many notices manage, and since a request costs nothing it costs nothing to ask.
Can Croma change its privacy notice without telling me?
Changes take effect on posting and are deemed accepted on your next visit. "The updated version will be effective as soon as it is accessible. Any changes will be immediately posted on our website and mobile application and you are deemed to have accepted the terms of the updated Privacy Notice on your first use of our website or mobile application or first purchase of the products and/or services following the alterations." The notice puts the burden of checking on the reader — "you should check our website and mobile application frequently to see recent changes" — while saying it "may e-mail periodic reminders". This is why every quotation here is dated 8 October 2026.
Prices & codes last verified: October 8, 2026
Zoutons may earn a commission when you buy through links on this page. Every quoted sentence and detail here was read on 8 October 2026 from croma.com/privacy-policy, logged out, in India, with nothing purchased, no order placed, no account created, no data access or deletion request made, no store visited and customer service not contacted; quotations are reproduced verbatim from Croma's own page, including its own spelling, capitalisation and punctuation. A published notice can be amended at any time - this one states that changes are effective as soon as they are accessible - so the notice described here may already differ from the one that applies to you; the notice shown on croma.com prevails over anything on this page. This page describes a published privacy notice. It does not assess, and expresses no view on, whether that notice or any practice described in it complies with the Digital Personal Data Protection Act, the Information Technology Act and the rules made under it, or any other data protection law, which is a matter for the relevant authority or a court and not for a price page; nothing on this page is legal, contractual, tax or financial advice or a substitute for advice from a qualified lawyer. Reporting that a privacy notice describes collection of contact, financial, technical, transaction, personal and loyalty information, sharing with group companies, partners, a consumer platform and service providers, transfer of data in a corporate transaction, retention on backup or archival media, a right to refuse a request where legally permitted, or amendment with deemed acceptance is a description of published text; sharing data within a corporate group under written contracts, engaging service providers, retaining records for audit, legal, tax and regulatory purposes, generating aggregated behavioural insight and offering personalised services are ordinary and lawful practices, and no statement here alleges a data breach, unlawful processing, unlawful profiling, unfair trade practice, a dark pattern, deficiency in service or any breach of any law, rule or guideline by Infiniti Retail Limited, by Croma, by Tata Sons Private Limited, by Tata Digital Limited or by any other Tata Group entity, partner, officer or employee, and no wrongdoing is alleged or implied. In particular, nothing on this page asserts or implies that Croma requires, requests or has collected any customer's religion, ethnicity, caste, marital status or travel history in order to sell them anything, or that any such information has been used to differentiate between customers in any way; those words are quoted because they appear in a list the notice itself ties to information volunteered in surveys and questionnaires, and the list appears to follow a group-wide template used across businesses. Nothing here asserts that any personal data has in fact been shared, transferred, sold, lost or disclosed to any party, that any individual's data has been retained unlawfully, or that any data request has been refused. No product is assessed, tested, compared or recommended on this page, and no claim is made about the quality, price or performance of anything Croma sells. Product photographs are listings' own images, already held on our content delivery network from earlier price reads, and may be styled or retouched; the goods shown illustrate the kind of purchase this notice describes, are not offers, and their prices are not stated here. Prices change without notice; the figures shown at your own checkout prevail over anything here.