Last updated: January 2026
Your privacy matters to us. This policy explains what data we collect, why we collect it, and what we do with it. We comply with India's Digital Personal Data Protection Act, 2023.
WHAT WE COLLECT
When you place an order:
- Name, email, phone number
- Shipping and billing addresses
- Order history
- Payment information (handled by Razorpay — we never store card numbers)
When you create an account:
- Email and password (hashed, never stored in plain text)
- Optional: name, phone, preferences
When you browse our site:
- Pages you visit and time spent (via Google Analytics)
- Device type and browser
- IP address (for security and fraud prevention)
- Cookies (see Cookies section below)
HOW WE USE YOUR DATA
- To process and ship your orders (the primary reason we collect anything)
- To contact you about orders, returns, restocks (only if you opted in for marketing)
- To improve the site via analytics (which pages people use, where they drop off)
- To prevent fraud and protect against abuse
- To comply with law when legally required
WHO WE SHARE WITH
We share only the minimum needed with these third parties:
- Razorpay — to process payments
- Delhivery / Shiprocket / Blue Dart — to deliver your order
- Google Analytics — anonymous browsing data only
- Email service (Hostinger SMTP) — to send order confirmations
We do not sell your data. We don't share with marketing companies, data brokers, or anyone else not listed above.
COOKIES
We use cookies for:
- Essential cookies: keeping you logged in, remembering your cart (you can't turn these off without breaking the site)
- Analytics cookies: anonymous data via Google Analytics
You can disable cookies in your browser settings, but the cart and login will stop working.
YOUR RIGHTS UNDER DPDP ACT
You have the right to:
- Access the data we have on you
- Correct inaccurate data
- Delete your account and personal data
- Withdraw consent for marketing emails at any time
- File a complaint with the Data Protection Board of India
To exercise any of these, email hello@nikkamiaulaad.in with the subject "Data Request" and we'll respond within 30 days.
DATA RETENTION
- Order records: 7 years (for GST and tax compliance)
- Account data: until you ask us to delete it
- Marketing email lists: until you unsubscribe
- Analytics: 14 months (Google's default)
CHILDREN'S PRIVACY
We don't knowingly collect data from anyone under 18. If you believe a minor has shared data with us, email us and we'll delete it.
CHANGES TO THIS POLICY
We'll update this page if our practices change. Major changes will be announced via email to active users.
CONTACT
Questions about privacy? Email hello@nikkamiaulaad.in.