Loading the shop
Last updated 21 August 2026
This says what personal data we collect when you use this shop, why we collect it, how long we keep it, and what you can ask us to do with it. It is written to the Digital Personal Data Protection Act, 2023 and the Information Technology (Reasonable Security Practices) Rules, 2011.
We collect only what an order needs. Nothing on this list is optional decoration — if a field is not required to take, deliver or account for an order, it is not asked for.
We do not collect your card number, UPI PIN or bank credentials. Payments are handled by the payment gateway; those details go to them and never reach our servers.
Your basket is kept in your browser, not on our servers, until you place the order. So is your language choice, your PIN code and — if you are signed in — the token that keeps you signed in. Clearing your browser data clears all of it, and doing so signs you out.
We process your data on the consent you give when you place an order or create an account, and for the purposes named above. You can withdraw that consent at any time by writing to us — it is as easy to withdraw as it was to give. Withdrawing it does not undo anything lawfully done before, and we may still have to keep records the tax law requires us to keep.
Only the people who have to, and only the part they need:
We do not sell your data, and we do not share it for anybody else's advertising.
Order and invoice records are kept for as long as the GST and income-tax rules require — presently eight financial years. Your account, and the addresses saved in it, are kept until you ask us to close it. Delivery and return photographs are kept with the order they belong to. When a purpose ends and no law requires the record, it is deleted.
Under the Digital Personal Data Protection Act, 2023 you may ask us to:
You can delete your account yourself, on this website or in the app — here is how, and what is kept.
Write to the address on this page and we will answer. If you are not satisfied with how we handled it, you may complain to the Data Protection Board of India.
The site is served over HTTPS. Passwords are stored hashed, never in readable form, and one-time passwords are stored the same way and expire. Staff access to order data is limited by role, and every change a member of staff makes to an order, a price or a setting is written to an audit log with their name against it.
This shop is not intended for children under 18, and we do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will delete it.
If this policy changes we will update the date at the top of the page. Where a change materially affects how we use data you have already given, we will tell you before it takes effect.