Privacy Policy

Privacy Summary - We collect **only data strictly required** to process orders and deliver products. - Checkout-related personal data is used **only for order fulfilment, invoicing, and legal compliance**. - Push notifications are **optional** and can be disabled anytime. - No ads, no behavioural analytics, no cross-site tracking. - We **do not sell** personal data. - Limited data may be shared with logistics or service providers **only to complete your order**. - You may request data access or deletion at any time, subject to legal retention requirements.

Effective Date: October 29, 2025
Last Updated: January 21, 2026

Sapna Shri Jewellers

Sapna Shri Jewellers (“we”, “us”, or “our”) is committed to protecting your privacy in accordance with the Digital Personal Data Protection Act, 2023 (India), the Information Technology Act, 2000, and applicable Consumer Protection (E-commerce) Rules, 2020.

This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use our website, Progressive Web App (PWA), or related digital services.


1. Scope & Consent

By using our website, placing an order, or submitting information, you provide free, specific, informed, and unambiguous consent for the limited data processing described in this policy.

You may withdraw consent at any time, subject to statutory obligations such as tax, accounting, or consumer protection laws.


2. Data We Collect

We follow a data minimisation approach and collect only what is necessary to operate our business and fulfil orders.


2.1 Order & Checkout Data (When You Place an Order)

Collected only when you proceed to checkout or place an order:

  • Full name
  • Mobile phone number
  • Email address
  • Billing address
  • Shipping address
  • Order details (products, quantity, price, order ID)
  • GST details (GSTIN, business name, billing address), only if you request a GST invoice

Purpose:

  • Order confirmation and fulfilment
  • Shipping and delivery coordination
  • Customer communication related to the order
  • Tax invoicing and statutory compliance

Legal Basis:

  • Performance of contract
  • Legal obligation (GST, consumer law)

Retention:

  • Order and invoice data is retained for statutory periods (currently up to 7 years) as required under Indian tax and accounting laws.

2.2 Payment Information

We do not store card, bank account, or UPI credentials.

Depending on the payment method you choose:

  • Payments may be completed via UPI apps (QR / collect request), or
  • Through third-party payment service providers.

We may store:

  • Payment reference number
  • Payment status (paid / pending / failed)
  • Order ID linked to payment

Purpose: Payment reconciliation and order processing
Legal Basis: Contractual necessity and legal compliance


2.3 Shipping & Logistics Data

To deliver your order, limited personal data is shared with logistics partners (such as courier or shipping aggregators):

  • Name
  • Phone number
  • Delivery address
  • Order reference
  • Package weight and dimensions

Purpose: Order shipment, delivery updates, and return handling
Legal Basis: Performance of contract

We share only the minimum information required to complete delivery.


2.4 Push Notification Data (Optional)

Collected only if you explicitly opt in:

  • Push service endpoint
  • Encrypted public keys (p256dh, auth)
  • Optional metadata (platform, timestamp)

Purpose: Deliver notifications you have requested (e.g., rate alerts, updates)
Legal Basis: Explicit consent
Retention: Until you unsubscribe or request deletion


2.5 Account-Related & Interaction Data (Limited)

Collected only when relevant features are used:

  • Google Sign-In identifier (used only to prevent duplicate ratings)
  • Product ratings or feedback submitted by you

Purpose: Platform integrity and feature operation
Legal Basis: Consent and legitimate use
Retention: Until deletion is requested or the feature is discontinued


3. Data We Do NOT Collect

We do not collect or process:

  • Unnecessary personal data beyond checkout requirements
  • Continuous or precise location tracking
  • Contact lists, photos, microphone, or camera access
  • Advertising identifiers
  • Behavioural profiling or cross-site tracking
  • Personal data for resale or marketing purposes

4. How We Use Personal Data

Your data is used only for:

  • Processing and fulfilling orders
  • Shipping and delivery coordination
  • Customer support and order communication
  • Issuing invoices and complying with tax laws
  • Preventing fraud or misuse of services
  • Legal and regulatory compliance

We do not use personal data for:

  • Advertising or remarketing
  • Sale, rental, or trade of personal data
  • Unrelated analytics or profiling

5. Cookies & Tracking

  • We do not use advertising or behavioural tracking cookies.
  • Limited technical cookies may be set automatically for session stability and security.
  • We do not track users across websites or applications.

6. Data Storage & Security

  • Website hosting: GitHub Pages
  • Application services: Cloudflare (Workers & KV)

We implement reasonable technical and organisational safeguards, including:

  • HTTPS encryption
  • Limited access controls
  • Data minimisation by design

No system is entirely risk-free; however, we actively minimise exposure and access.


7. Data Sharing & Disclosure

We do not sell personal data.

Data may be shared only when necessary with:

  • Logistics and courier partners (for delivery)
  • Payment service providers (for payment processing)
  • Government or regulatory authorities, when legally required

All third parties act as data processors and are permitted to use data only for the intended purpose.


8. Your Rights (DPDP Act, 2023)

You have the right to:

  • Access personal data we hold about you
  • Request correction of inaccurate data
  • Withdraw consent (subject to legal obligations)
  • Request deletion of data not required by law
  • Grievance redressal

Data Requests

📧 privacy@sapnashrijewellers.in
Subject: Privacy / Data Request

Requests are verified and fulfilled within 7–30 days as per applicable law.


9. Children’s Privacy

Our services are not intended for children under 13 years of age.
We do not knowingly collect children’s personal data.
If such data is identified, it will be deleted promptly.


10. Changes to This Policy

We may update this Privacy Policy periodically.
Material changes will be reflected by the “Last Updated” date above.


Data Fiduciary & Data Processor Roles

Under the Digital Personal Data Protection Act, 2023 (India):

  • Sapna Shri Jewellers acts as the Data Fiduciary, determining the purpose and means of processing personal data collected through the website, app, or order process.
  • Certain third-party service providers may act as Data Processors, processing personal data solely on our behalf and strictly in accordance with our instructions.

These Data Processors may include:

  • Website hosting and infrastructure providers
  • Logistics and courier partners for order delivery
  • Payment service providers, where applicable
  • Communication service providers for transactional notifications

Such third parties are contractually obligated to:

  • Process personal data only for authorised purposes
  • Maintain reasonable security safeguards
  • Not retain, sell, or use personal data for independent or commercial purposes

Sapna Shri Jewellers does not permit any Data Processor to use customer personal data for advertising, profiling, or resale.


11. Contact & Grievance Redressal

This contact serves as the grievance redressal mechanism under the DPDP Act, 2023.

Sapna Shri Jewellers
📞 Mobile: +91-8234042231
📧 Email: privacy@sapnashrijewellers.in

Requests are acknowledged and resolved within 7–30 days, in accordance with applicable law.

Mehtalogy LABS