A house that publishes the wage it pays should be as exact about the data it holds. The notice below is written to be checked, with a clock on every answer we owe you and a named officer to hold to it.

What the order needs

Order processing uses your name, phone number, email, delivery address and payment status. Fulfilling the purchase you request requires those details, and that processing is covered by the legitimate-use provisions of the DPDP Act, 2023.

Marketing communication by email, WhatsApp or SMS happens only when you tick a consent box, and every message carries an unsubscribe path. At checkout the order-updates and letters boxes start ticked, say so on their labels, and are one tap to untick before you pay. Consent records are stored with timestamps and honoured immediately on withdrawal.

Who processes what

We share personal data only with the processors that operate the service, each under a data-processing agreement: Razorpay for payment, our courier partners for delivery, Resend and Meta (WhatsApp Business) for order and delivery messages, Klaviyo (only where you have explicitly opted in) for marketing email, and PostHog (only where you allow analytics) for first-party product analytics that set no advertising cookies. We sell personal data to no one.

Ad measurement, explained

Unless you switch off "Ad measurement" under Privacy choices, we send Meta Platforms a record of each confirmed purchase so we can measure our advertising: your mobile number, email, city and PIN code as SHA-256 hashes, together with the order value, the items purchased, and, where you reached us from a Meta advertisement, that advertisement’s click identifier.

The hashes are a join key rather than a veil: Meta uses them to match the purchase to an account it already holds. Where a parcel later comes back to us undelivered, we send Meta a matching correction. Switched off, none of this reaches Meta, and a refusal recorded on an earlier notice stands.

How long we keep it

Order records are kept for as long as tax and company law require them, because a purchase record is not ours to delete on request. A cart that was never checked out, an abandoned session and analytics data have far shorter lives, and marketing consent records are kept only while the consent stands plus the period needed to prove it was given.

Erasure of the data that is ours to erase is a right you can use at any time, and the paragraph below says how. Where a record has to be retained by law, we say which law rather than refusing without a reason.

What we do not do

We sell personal data to nobody, and there is no advertising cookie on this site. Nothing you do here is used to build a profile that follows you elsewhere. Measurement runs by default and stops the moment you untick it under Privacy choices, at the foot of every page.

Payment card details never reach us. Card and UPI credentials are entered on the payment provider’s own form and stay with them, so a breach of this site could not expose a card number we have never held.

Your rights and the clocks

To access, correct or erase your data, or to withdraw a consent at any time, email support@shwetheritage.in. We respond within 30 days, and breach notifications follow the 72-hour statutory requirement.

The officer

Grievance redressal under the DPDP Act, 2023 runs through a named officer: Vibha Mishra, one of our Founders & Directors. If a request to support@shwetheritage.in is not acknowledged within 48 hours or resolved within one month, write to her directly at vibha@safesociety.in with "Data grievance" in the subject line.