Marching Sheep — Privacy Policy
Effective date: 1 st April 2025·
Last updated: 14 July 2026
1. Who we are
Marching Sheep (including its brands and verticals 21 Marching and She Marches, together “Marching Sheep”, “we”, “us”, “our”) is an HR and diversity, equity & inclusion (DEI) consulting firm. Our activities include B2B consulting, inclusive hiring (recruitment), the She Marches direct-to-consumer (D2C) brand for women, and workplace-compliance tools such as the POSH Research Assistant, emodules.
- Legal entity & registered address: Marching Sheep, 108, Sector A. pocket c , vasant Kunj ND 110070
- Websites / apps covered: https://www.marchingsheep.com and related sub-brand sites, stores, and mobile applications
- Grievance / Data Protection Officer: alok@marchingsheep.com
2. Scope
This policy covers all personal data we process across: (a) our websites and online stores; (b) B2B consulting engagements; (c) recruitment and inclusive-hiring services; (d) the She Marches D2C brand (purchases, accounts, communications); (e) the POSH Research Assistant app; and (f) our social and messaging channels (e.g. Instagram, Facebook, YouTube, LinkedIn, WhatsApp). Where a service has its own notice (e.g. the candidate Privacy & Application Notice), that notice adds to and, where more specific, prevails over this policy.
By using our websites, stores, apps, or services, or by providing your data, you acknowledge this policy. Where the law requires consent, we ask for it separately and you may withdraw it (see §14).
3. Data we collect
We collect only what we need for the purposes in §5. Categories:
- Identity & contact: name, email, phone, postal/shipping address, and details you provide in forms, comments, or messages.
- Account: username, authentication data (e.g. OTP), preferences, and, for apps, device/installation identifiers.
- Transaction & financial: orders, subscriptions, purchase history, and billing status. We do not store full card numbers; payments are handled by payment processors (§10).
- Professional (recruitment): work history, skills, CV, and role preferences.
- Diversity data (sensitive, optional): self-identification, pronouns, and accommodation needs, collected only with separate consent (see §9.2).
- Technical & usage: IP address, browser/user-agent, device data, pages viewed, referring URLs, and cookie/pixel identifiers (§7).
- Communications: your messages to us across email, forms, chat, WhatsApp, and social channels.
- User-generated content: comments, reviews, ratings, and media you submit.
- Location: only as inferred from IP or provided by you; we ask you to avoid uploading images with embedded GPS (EXIF) data.
We do not knowingly collect more sensitive categories than described, and ask you not to submit unnecessary personal data (for example, in POSH queries, see §9.4).
4. How we collect it
Directly from you; automatically as you use our sites/apps (cookies, pixels, logs); and from third parties such as our service providers, employers/partners, payment processors, social and advertising platforms, and publicly available sources, consistent with their terms and applicable law.
5. Why we use your data (purposes)
To provide, operate, and improve our websites, stores, apps, and services; create and manage accounts; process orders, subscriptions, and payments; deliver products and fulfil D2C orders; assess candidates and present them to employers; respond to enquiries and provide support; send service and, where permitted, marketing communications; personalise content and offers; run analytics and measure and improve marketing; ensure security, prevent fraud and abuse; comply with law and enforce our terms; and for aggregated, anonymised reporting (§19).
6. Lawful basis
We rely on your consent under the DPDPA and, where applicable, other lawful/legitimate uses recognised by law (for example, responding to a request you initiate, or complying with legal obligations).
7. Cookies, pixels & tracking
We and our partners use cookies and similar technologies (including analytics and advertising pixels such as, without limitation, Google Analytics, Google Ads, and the Meta/Facebook Pixel) to run the site, remember preferences, measure performance, and deliver and measure advertising, including retargeting on platforms such as Google, Meta (Facebook/Instagram), and LinkedIn. Essential cookies are always active; non-essential cookies are used based on your choices. You can manage cookies via our your browser settings.
8. Marketing communications & opt-out
With your consent (or as otherwise permitted by law), we may send offers, updates, and content by email, SMS, WhatsApp, or push notification. You can opt out any time via the unsubscribe link, by replying STOP where offered, or by contacting us (§26). Transactional and service messages (e.g. order or application updates) are not marketing and may still be sent. We honour applicable Do-Not-Disturb/registry rules.
9. Service-specific notices
9.1 Website & general (incl. WordPress)
- Comments: we collect the comments-form data plus IP and user-agent for spam detection; an anonymised email hash may go to Gravatar (https://automattic.com/privacy/) to check usage; after approval your profile picture shows with your comment.
- Media: avoid uploading images with EXIF GPS; visitors can extract location data from uploaded images.
- Contact forms: we collect what you submit to respond and, where relevant, follow up. These involve forms from and not limited to linkedin, meta, brevo, bigin, zoho recruit , wordpress.
- Cookies: comment opt-in cookies (1 year); a temporary cookie-check cookie (discarded on browser close); login cookies (2 days), screen-option cookies (1 year), “Remember Me” (2 weeks), removed on logout; an editor cookie storing a post ID (1 day).
- Embedded content: embedded media from other sites behaves as if you visited them; those sites may collect data, set cookies, and track you, including if you are logged in to them.
- Analytics: We may use abalytics services to analyze anonymized data.
9.2 Recruitment & inclusive hiring (job applicants)
Governed in full by the candidate Privacy & Application Notice shown at application. In summary:
- We collect contact details, work history, skills, CV; and, only with separate consent, diversity self-identification, pronouns, and accommodation needs.
- Lawful basis: your consent under the DPDPA.
- Sensitive data is optional, separately consented, restricted to your recruiter and the hiring employer, and never used by our screening assistant to score you.
- What we believe: your gender, disability, accommodation needs, pronouns, LGBTQ+ status, or a career break should never be the reason you don’t get a job. These characteristics are never used to screen you out, and a human recruiter makes the final decision. Because inclusive hiring is what we do, where you have consented we may also use this information to connect you with employers specifically seeking to hire diverse talent (for example, returning mothers or persons with disabilities).
- Retention: 60 months, then deleted or anonymised. Requests: pwd@marchingsheep.com.
9.3 She Marches D2C (customers)
For purchases and accounts on the She Marches store, we collect identity, contact, shipping, and order/subscription details, and process payments via third-party processors. We use this to fulfil and deliver orders, manage returns/refunds, provide support, prevent fraud, and, with consent, send marketing. Reviews and ratings you submit may be shown publicly with your display name. Referral or loyalty features, if used, process the data needed to run them.
9.4 POSH Research Assistant (app)
- We collect: email + phone (OTP) for authentication; purchase history via Google Play Billing (no card details stored); Firebase Installation IDs for functionality/security; and structured POSH reports/queries stored in Firestore. Enter only hypothetical or fully anonymised scenarios; do not enter personal data.
- AI (Google Gemini): queries are sent to Google for processing and may be used to train global models” . No PII from your reports is shared with the AI unless you include it in a query. AI can err or “hallucinate”; verify all citations and case law (Appendix A).
- Providers: Google Cloud/Firebase (auth, Firestore), Google Play Billing (payments), Google Gemini (AI), App Store.
- Deletion & retention: request full deletion via https://forms.gle/gfBD1D5nhhqFz3259; we remove Firebase Auth records and Firestore POSH reports within 30 days. Data is kept while your account is active and purged within 30 days of deletion, except anonymised analytics.
- Compliance: assists with POSH Act compliance; not legal advice; handled confidentially in line with the Indian IT (Reasonable Security Practices) Rules, 2011
10. Service providers & processors we may use
We use trusted third parties to run our services, and may add or change providers over time. These fall into categories including, without limitation:
- Cloud & hosting: e.g. Google Cloud / Firebase, and similar (potentially AWS, Microsoft Azure).
- Analytics & performance: e.g. Google Analytics, and similar (potentially Microsoft Clarity, Hotjar).
- Advertising & retargeting: e.g. Google Ads, Meta (Facebook/Instagram) Ads, LinkedIn Ads, and similar.
- Email, SMS & messaging: e.g. WhatsApp Business/Meta, and email/SMS providers (potentially Zoho Campaigns, Mailchimp, Klaviyo, Twilio, Gupshup).
- Payments: e.g. Google Play Billing, and payment gateways (potentially Razorpay, Stripe, PayU, Shopify Payments). We do not store full card details.
- E-commerce & CRM: e.g. the She Marches store platform, and Zoho products (Recruit, Bigin, CRM).
- AI providers: e.g. Google Gemini, and similar (potentially OpenAI, Anthropic), used as described per service.
- Social platforms: e.g. Meta (Facebook, Instagram), YouTube, LinkedIn, for pages, content, and advertising.
We require providers to process personal data only on our instructions and to protect it.
11. Who we share your data with
We share personal data only as needed: with prospective employers (recruitment, per your consent); with the service providers above; within our brands/affiliates for the purposes in this policy; with professional advisers, auditors, and insurers; with authorities, regulators, or courts where required by law or to protect our rights, users, or the public; and in connection with a business transfer (§20). We do not sell your personal data.
12. International / cross-border transfers
Some providers may process data outside India. Where they do, we take steps intended to protect your data consistent with this policy and applicable law, and, where required, obtain your consent.
13. Data retention
Context | Retention |
Website comments & metadata | Retained to auto-recognise follow-ups |
Registered website users | While the account exists; user-editable/erasable |
Contact-form enquiries | 24 months |
Recruitment applicant data | 60 months, then deleted/anonymised |
She Marches orders/accounts | While active + as required by tax/accounting law |
POSH Assistant account & reports | While active; purged within 30 days of deletion |
We keep data only as long as needed for the purposes above or as law requires, then delete or anonymise it.
14. Your rights & how to exercise them
You may request access, correction, and erasure, withdraw consent, and nominate in writing another person to exercise your rights in specified cases. Withdrawal does not affect processing already done. Some data may be retained where we are legally obliged to keep it. Registered users can view, edit, or delete their profile (except username). To exercise any right, or to raise a grievance, contact us at §26; we respond within the timelines required by law.
15. Children's data
Our services are intended for adults. We do not knowingly collect personal data of children (persons under 18) without verifiable parental/guardian consent as required by the DPDPA, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child has provided data, contact us and we will delete it.
16. How we protect your data
We use reasonable technical and organisational measures (such as access controls and encryption in transit) intended to protect personal data. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security; you provide data at your own risk and are responsible for keeping your credentials confidential.
17. Data breach procedures
We maintain a process to detect, assess, and respond to personal-data breaches and to notify affected persons and authorities where required.
18. Automated decision-making, AI & profiling
- Recruitment: an AI assistant scores role fit using only skills and experience; it never uses diversity attributes to screen you out, and a human recruiter makes the final decision.
- POSH Assistant: Gemini AI processes research queries; outputs are reference material, not decisions, and must be independently verified.
- Marketing: we may use analytics and platform tools to segment audiences and measure campaigns; we do not make decisions producing legal or similarly significant effects about you solely by automated means.
19. Aggregated & anonymised data
We may create and use aggregated or anonymised/de-identified data (which does not identify you) for any lawful purpose, including analytics, research, benchmarking, diversity reporting, and improving and marketing our services, and may share it with partners. This data is not personal data.
20. Business transfers
If we are involved in a merger, acquisition, financing, reorganisation, or sale of assets, personal data may be transferred as part of that transaction, subject to this policy or a successor policy with equivalent protections. [COUNSEL]
21. Third-party links & platforms
Our sites, apps, and channels may link to or embed third-party sites and platforms (including social media). We are not responsible for their content or privacy practices; their policies govern your use of them.
22. Disclaimers & limitation of liability
To the maximum extent permitted by law: our websites, stores, apps, and tools (including AI tools) are provided “as is” and “as available” without warranties of any kind; we do not warrant that they will be uninterrupted, error-free, or secure; and, except for liability that cannot be excluded by law, Marching Sheep and its officers, employees, and affiliates shall not be liable for any indirect, incidental, special, consequential, or exemplary damages, or for any loss arising from your reliance on outputs (including AI-generated content) or from unauthorised access to your data.
23. Indemnity
To the extent permitted by law, you agree to indemnify and hold Marching Sheep harmless from claims arising out of your misuse of our services, your breach of this policy or our terms, or content or data you submit unlawfully.
24. Changes to this policy
We may update this policy from time to time. Material changes will be indicated by updating the “Last updated” date and, where appropriate, by notice. Continued use after changes take effect means you accept the updated policy, to the extent permitted by law.
25. Governing law & jurisdiction
This policy is governed by the laws of India, and the courts at New Delhi have exclusive jurisdiction.
26. Contact & Grievance Officer
Questions, requests, or grievances: Alok Kohli alok@marchingsheep.com Recruitment-specific requests: pwd@marchingsheep.com.
Appendix A — POSH Research Assistant: Terms of Use
Terms of use (not privacy), reproduced for reference.
- Nature of the tool (not legal advice). The “POSH Research Agent” is an AI-powered research and reference assistant to help Internal Committees (ICs) and HR professionals navigate the Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013 and related jurisprudence. It is not a substitute for an attorney; use does not create an attorney-client relationship.
- Accuracy (AI limitations). The tool uses AI, which can produce errors or “hallucinations.” You must independently verify all citations and case laws.
- Limitation of liability. Marching Sheep shall not be liable for any legal penalties or adverse judgments resulting from reliance on the tool’s outputs.
- Data privacy. Do not enter personal data; all case scenarios must be hypothetical or fully anonymised.

