पाठशाला Pathshala · नियम Niyam, Law and compliance · Lesson 12 · Build

Terms of service and privacy policy that protect the company

Terms copied from another product describe another business. Terms that protect yours limit liability where the law allows, say how refunds and disputes work, and meet the IT Rules and the DPDP Act.

Pathshala, The Founder Library · 11 October 2026 · 7 min read

Seen from above a courier on a scooter carries parcels along a sunlit street.
Photograph: Thuan Pham · Pexels

The terms of service were copied from an American app at launch. They are governed by the law of California, promise refunds within fourteen days that the company has never given, say nothing about who in the company handles complaints, and describe a privacy policy that predates both the product’s payments feature and India’s data protection law. When the first angry customer writes in, the founder discovers the company has published a contract it cannot keep.

This lesson treats the terms and the privacy policy as working documents. It covers how to make the terms bind, which liability limits Indian law will respect, how to write refunds and disputes, what the IT Rules require of a platform that hosts users’ content, what the consumer e-commerce rules and the dark-patterns guidelines require of anyone selling online, and how the privacy policy changes under the DPDP Act. The figure shows which grievance clock applies and when it runs out.

Three documents, three readers

The terms of service are a contract with the user: what the service is, who may use it, what they may not do with it, what they pay, what happens when something goes wrong, and which law and court decide. The refund and cancellation policy answers the question most users will actually ask, in plain words, and it is worth keeping separate so that support staff can link to it. The privacy notice tells users what personal data is collected, why and what their rights are. Each has a different reader on a different day, and a single document that tries to be all three serves none of them.

Write all three for your business, not someone else’s. A clause promising something the company does not do is not harmless boilerplate. It is a promise a customer can hold you to, and a statement a regulator can read.

Making the terms bind

Section 10A of the Information Technology Act 2000 provides that a contract formed by electronic means is not unenforceable only because it was formed that way. Whether a particular user agreed to particular terms is still a question of fact, so design for proof. Show the terms, or a clear link to them, at the point of sign-up or purchase, and ask for a positive action, a button that says the user agrees, rather than relying on a footer link nobody clicks. Store the version of the terms accepted, the time and the account. When terms change, show the change and ask again for anything material; do not rely on a clause saying continued use means acceptance.

Name the contracting entity with its registered address and CIN, so that the user knows whom they are dealing with. Choose Indian law and courts in a city where the company has a lawyer, or arbitration with a named seat for business customers, as the [contracts lesson](/library/contracts-ten-clauses-that-decide-disputes) explains. California law in an Indian consumer product mostly signals that nobody read the document.

Liability limits that will survive

The Indian Contract Act 1872 sets the frame. Section 73 already excludes remote and indirect loss from compensation for breach, so an exclusion of indirect and consequential loss largely restates the law and is uncontroversial. A cap on direct liability, usually the fees the user paid in the twelve months before the claim, is the clause that does the work; for a free service, a modest fixed figure. Section 74 limits any sum named in a contract as payable on breach to reasonable compensation not exceeding it. And section 23 makes an agreement void where a court regards its object or consideration as opposed to public policy, which is where an attempt to exclude liability for fraud, for wilful misconduct or for death or injury caused by negligence is most exposed.

So write the limitation clause to be defensible rather than maximal: exclude indirect loss, cap direct loss at fees paid, carve out fraud and wilful misconduct expressly, and keep a separate, narrower clause for what the user indemnifies you against, typically misuse of the service and the content they upload. A clause that tries to exclude everything invites a court to strike it and leaves the company with no limit at all.

Write the clause a judge would enforce, not the one a frightened founder would like. The first protects the company; the second gets struck out.

Refunds, cancellations and dark patterns

A business selling to consumers online should assume the Consumer Protection (E-Commerce) Rules 2020 apply to it. As the consumer affairs ministry told the Lok Sabha, the rules require the entity to appoint a grievance officer, display the officer’s contact details prominently on the platform, acknowledge every consumer complaint within 48 hours and redress it within one month of receipt. The refund policy should therefore say who decides, in how many days, by what method money is returned, and what the customer must do: return the goods within a stated window, in a stated condition, or cancel before a stated cut-off.

Hands operate a small receipt printer on a wooden table.
A refund policy is read on the day something goes wrong. Write it for that customer. Photograph: Hook Tell · Pexels

The flow around the policy matters as much as its words. On 30 November 2023 the Central Consumer Protection Authority issued guidelines under section 18 of the Consumer Protection Act 2019 listing 13 specified dark patterns, among them drip pricing, disguised advertisement, bait and switch and false urgency. A refund policy that is generous on paper but sits behind a cancellation flow designed to wear the customer down is the kind of design the guidelines target. Show the full price at the start, make cancelling as easy as subscribing, and do not invent countdown timers.

If users post content: the IT Rules

A product where users post, message, review or upload is likely to be an intermediary for that content, and then the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 apply. As amended from 28 October 2022, rule 3(1)(a) requires the intermediary to publish prominently on its website or app its rules and regulations, privacy policy and user agreement, in English or a language of the Eighth Schedule of the user’s choice. Rule 3(1)(b) lists the kinds of content the rules must tell users not to host. Rule 3(1)(f) requires the intermediary to inform users periodically, and at least once a year, of its rules, privacy policy and user agreement and of any change to them.

Rule 3(2) requires a grievance officer whose name and contact details are published, who acknowledges a complaint within twenty-four hours and resolves it within fifteen days, with a shorter seventy-two hours for certain requests to remove content. Write the user agreement’s content rules to match rule 3(1)(b), publish the grievance officer’s details on the contact page and in the terms, and send the annual reminder from the same calendar as the rest of the company’s compliance.

The privacy policy after the DPDP Act

Until 13 May 2027 the older regime under section 43A of the IT Act and its 2011 rules on sensitive personal data continues to apply, and an intermediary must already publish a privacy policy under rule 3(1)(a). From that date, under the DPDP Rules, the document that matters is a notice that stands on its own, separate from the terms, with an itemised list of the personal data, the specified purposes and what each enables, and instructions for withdrawing consent, exercising rights and complaining to the Data Protection Board. Keep the long privacy policy for completeness, but build the notice into the screens where data is collected. The [DPDP lesson](/library/dpdp-act-what-it-requires-of-your-product) sets out the product work; the terms should simply point to the notice and never try to obtain consent to data processing by burying it in a general acceptance.

The annual terms review

Once a year, in the same month, and whenever the product adds payments, user content, a new country or a new category of data, run a review. Read the terms, the refund policy and the privacy notice against what the product actually does today, and delete every promise it does not keep. Check the liability cap, the carve-outs and the governing law. Walk the signup, purchase and cancellation flows against the thirteen dark patterns. Confirm that the grievance officer named on the site is still at the company and that complaint tickets are meeting the 24-hour, 48-hour and fifteen-day or one-month clocks that apply. Version the documents, show material changes to users and record fresh acceptance, and if the product hosts content, send the annual notice of rules the IT Rules require. One afternoon a year keeps the published contract and the real business the same thing.


Nothing here is legal or tax advice; confirm the current rule with a chartered accountant or lawyer before acting.

Sources

  1. The Information Technology Act 2000: section 10A, validity of contracts formed through electronic means, and section 43A, India Code (read 10 October 2026)
  2. The Indian Contract Act 1872: sections 23, 73 and 74, India Code
  3. PRS Legislative Research, IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 with the amendments of 28 October 2022: rules 3(1)(a), 3(1)(f) and 3(2)
  4. Lok Sabha Unstarred Question 2383, 21 December 2022, Ministry of Consumer Affairs: grievance officer, 48-hour acknowledgement and one-month redressal under the E-Commerce Rules 2020
  5. Lok Sabha Unstarred Question 2975, 20 December 2023: CCPA guidelines of 30 November 2023 listing 13 specified dark patterns
  6. Khaitan and Co, ERGO: Digital Personal Data Protection Rules, 15 November 2025: standalone notice and commencement on 13 May 2027