Legal & Regulatory References
Last updated: 8 October 2026
Official Indian legal references relevant to the Terms of Service, Privacy Policy and subscription payments of batterydealer.in, operated by RETAIL PAY. Source review date: 8 October 2026.
On this page
1. How to read these references
Each entry gives the Act, notification or circular number, relevant provisions and an official Government of India or RBI source. Applicability depends on the activity, transaction, information and legal role concerned. The official text, amendments and commencement notifications control where a summary differs.
The references explain the legal context of our policies. They are not government approval, a licence, or a certification that every legal or operational obligation has been satisfied. Payment-provider obligations and merchant obligations must be assessed separately.
2. Commencement and mandatory rights
The DPDP Act and final 2025 Rules have phased commencement. Entries below identify provisions that have not commenced as of the source review date. Existing privacy and security obligations continue to apply according to their own scope and commencement.
Our standard 48-hour subscription refund-request window is a RETAIL PAY policy, not a government-prescribed deadline. It does not restrict applicable remedies for failed or duplicate payments, an unprovided subscription, or any mandatory consumer or payment-system rights.
Government rules and official references
Reviewed on 8 October 2026. Read each reference with its scope, amendments and effective provisions. Official sources open in a separate tab.
Indian Contract Act, 1872
Act No. 9 of 1872; sections 10 and 11
Relevant to a valid subscription agreement, free consent and the capacity of an authorised adult to contract. Electronic acceptance remains subject to the usual requirements for a valid contract.
Information Technology Act, 2000
Act No. 21 of 2000; sections 10A, 43A, 70B and 72A
Section 10A recognises electronic contract formation. Sections 43A and 72A concern protection of information and unlawful disclosure; section 70B supports CERT-In directions. The omission of section 43A under DPDP Act section 44(2) is subject to the phased commencement notification below.
Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
G.S.R. 313(E), 11 April 2011; rules 4 to 8
Relevant to privacy notices, sensitive information, collection, disclosure, transfers and reasonable security practices, where applicable. The Government clarification distinguishes processing under a contract with a legal entity from collecting information directly from an individual; rules 5 and 6 are not applied identically to both situations.
Consumer Protection Act, 2019
Act No. 35 of 2019; section 2(7)
Consumer remedies depend on whether the purchaser qualifies as a consumer under the statutory definition. A business subscription is not automatically a consumer purchase; commercial-purpose exclusions and applicable exceptions must be assessed. Mandatory rights, where applicable, are preserved by our policies.
Consumer Protection (E-Commerce) Rules, 2020, as amended in 2021
G.S.R. 462(E), 23 July 2020; rules 4 and 7; amendment G.S.R. 328(E), 17 May 2021
Where applicable, these rules cover online service disclosures, affirmative consent, grievance handling and refunds. Rule 4(5) requires acknowledgement of consumer complaints within 48 hours and redress within one month. These complaint deadlines are separate from our voluntary 48-hour refund-request window. The 2021 amendment addresses the resident nodal officer requirement for the entity categories specified in rule 4(1).
Digital Personal Data Protection Act, 2023 and commencement notification
Act No. 22 of 2023; sections 3 to 8 and 11 to 14; G.S.R. 843(E), 13 November 2025
The Act provides the framework for lawful digital personal data processing, notice, consent, safeguards and individual rights. Commencement is phased: core processing duties and individual rights take effect eighteen months after publication of G.S.R. 843(E); specified consent-manager provisions take effect after one year. As of 8 October 2026, those later phases have not commenced. Their inclusion here describes the forthcoming framework, rather than treating all provisions as already enforceable.
Digital Personal Data Protection Rules, 2025 and corrigenda
G.S.R. 846(E), 13 November 2025; rule 1; corrigenda G.S.R. 892(E), 10 December 2025
Rule 1 brings rules 1, 2 and 17 to 21 into force on publication; rule 4 after one year; and rules 3, 5 to 16, 22 and 23 after eighteen months from publication in the Official Gazette. The later rules include notice, safeguards, breach reporting and rights procedures. As of 8 October 2026, the one-year and eighteen-month phases have not commenced. Read the notified rules with the official corrigenda.
Reserve Bank of India (Regulation of Payment Aggregators) Directions, 2025
RBI/DPSS/2025-26/141; CO.DPSS.POLC.No.S-633/02-14-008/2025-26, 15 September 2025; paragraphs 3, 8 and 9
These directions regulate payment aggregators and specified banks, including dispute management, merchant agreements and security. When online checkout is enabled, RETAIL PAY receives payment for its own software subscription as the merchant. Using a provider does not represent RETAIL PAY as an RBI-authorised payment aggregator. Relevant merchant requirements are handled through the selected provider and applicable agreements.
RBI framework for failed-payment reversals and customer compensation
RBI/2019-20/67; DPSS.CO.PD No.629/02.01.014/2019-20, 20 September 2019
This circular sets transaction-specific reversal deadlines and compensation requirements for operators and participants of authorised payment systems. A failed-payment reversal is distinct from a merchant-approved subscription refund. Applicable bank or payment-system remedies are not reduced by our 48-hour subscription refund-request window.
Central Goods and Services Tax Act and Rules, 2017
Act No. 12 of 2017; sections 31, 35 and 36; CGST Rules, 2017, rule 46
Relevant to tax invoices, books of account and statutory record retention for registered persons. Section 36 generally requires relevant records for 72 months from the due date of the annual return for the relevant year, with longer retention in specified proceedings. RETAIL PAY and subscribing stores remain responsible for their respective tax obligations. Deletion requests cannot require removal of records that must legally be retained; using the software does not itself establish GST compliance.
CERT-In directions on cyber incident reporting and security logs
No. 20(3)/2022-CERT-In, 28 April 2022; IT Act section 70B(6); directions (ii) to (iv)
Covered entities must report specified cyber incidents within six hours of noticing them or being informed, designate a CERT-In point of contact, and securely maintain ICT logs for a rolling 180 days within India. These are operational obligations for covered entities; an account-closure request does not override legally required retention. This reference does not certify that every operational requirement has been audited.
Contact RETAIL PAY
RETAIL PAY
GSTIN: 24ABAFR1564K1Z7
Email: care@batterydealer.in
Mobile: 8905656089