Legal
Privacy Policy
Your trust is the most precious thing we hold. Here's exactly what we collect, why, and how we keep it safe.
Last updated · 13 August 2026
Who we are
This store is operated by [[TODO-LEGAL — registered legal entity name — not supplied]], registered at [[TODO-LEGAL — registered office address — not supplied]], GSTIN [[TODO-LEGAL — GSTIN — not supplied]]. Where this policy says "we" or "DIYAM", that is who it means.
This policy covers diyamhouseofsilver.com and everything you send us through it. It is written under the Digital Personal Data Protection Act, 2023, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
What we collect
When you shop with DIYAM, browse our collections, or reach out to us, we may collect the following:
- Contact details — name, email address, phone number, and shipping/billing address.
- Sign-in details — your email address, and the sign-in codes we email you. If you sign in with Google instead, the name, email address and profile picture Google passes us.
- Order information — the pieces you buy, sizes, gift messages, and delivery preferences.
- Delivery location — if you move the pin on the checkout map, the coordinates you leave it on. Whatever you leave it on is what the person carrying the parcel navigates to.
- Payment information — handled entirely inside Razorpay’s own payment window. Card numbers, UPI IDs and net-banking credentials never reach our servers, and we never store them.
- Technical logs — our host records the IP address, browser and requested page for each request, as every web server does, and we use it to keep the site up and to investigate abuse.
We do not run analytics on this site. There is no Google Analytics, no Tag Manager, no advertising pixel, and nothing that follows you to other sites. We do not build a profile of what you browse. The cookie page lists every last thing kept in your browser.
How we use it
We use your information to process and deliver your orders, offer support, send order updates and invoices, and — only if you opt in — share news of new collections and offers.
We never sell your personal data, and we do not share it for anyone else’s marketing.
Who else sees it
Running a shop means using other companies to do parts of it. Each one below receives only what its job needs, and none of them are permitted to use your data for their own purposes. This is the whole list:
- Razorpay — payments. Receives the order amount, our order reference and your email address, plus whatever you enter in its payment window. Razorpay is also who tells us an order was paid.
- Google Maps Platform — addresses. Receives the delivery address you type or the pin you drop, because we only deliver within a radius of our Bengaluru store and an order is refused unless we can place it on the map. There is no version of checkout that skips this.
- Google Sign-In — accounts, and only if you choose it. If you sign in with Google rather than with an emailed code, Google tells us your name, email address and profile picture, and knows that you signed in to this store. Sign in with a code instead and Google is not involved.
- Resend — email. Receives your name, email address and order details so we can send your confirmation and invoice, receives your email address when we send you a sign-in code, and receives whatever you write in the contact, callback, gifting or newsletter forms so it reaches our inbox.
- Neon — our database. Stores the order itself: your name, email, phone, delivery address and coordinates, the items, the amounts and the payment reference.
- Cloudflare — storage and delivery. Serves our product images, and holds your invoice in a private bucket that is not publicly readable.
- Netlify — hosting. Serves the site and runs the checkout code, and so sees each request and its IP address.
Several of these providers operate outside India, so some of your data is processed abroad under contracts that require them to protect it.
We will also disclose data where the law requires it — a court order, a tax assessment, or a lawful request from an authority.
How long we keep it
We do not keep personal data indefinitely. Concretely:
- Orders, invoices and payment records — six years from the end of the financial year in which you ordered. Section 36 of the CGST Act, 2017 requires a registered business to keep its books for 72 months, and an order is part of those books. We cannot delete these earlier, even on request.
- Your account — for as long as you keep it. Ask us to close it and we remove it, apart from the order records above.
- Contact, callback, gifting and newsletter messages — [[TODO-LEGAL — retention period for enquiry and marketing data — not supplied]].
- Server and access logs — [[TODO-LEGAL — retention period for server logs — not supplied]].
When a retention period ends, the data is deleted or irreversibly anonymised.
Your rights
Under the Digital Personal Data Protection Act, 2023 you may ask us to tell you what personal data we hold about you and who we have shared it with, correct anything inaccurate or incomplete, erase data we no longer need, withdraw a consent you gave us, and nominate someone to exercise these rights if you die or become incapacitated.
Write to our grievance officer, below, and we will respond within the timeframes the Act requires. We may need to confirm who you are before we act, so that nobody else can make a request in your name.
If you are not satisfied with how we handle your complaint, you may take it to the Data Protection Board of India.
You can unsubscribe from marketing emails at any time via the link in every message.
Grievance officer
Rule 5(9) of the Information Technology Rules, 2011 and section 13 of the Digital Personal Data Protection Act, 2023 both require us to name a person you can bring a complaint to. That is:
- Name — [[TODO-LEGAL — grievance officer name — not supplied]]
- Designation — [[TODO-LEGAL — grievance officer designation — not supplied]]
- Email — [[TODO-LEGAL — grievance officer email address — not supplied]]
- Phone — [[TODO-LEGAL — grievance officer phone number — not supplied]]
- Postal address — [[TODO-LEGAL — grievance officer postal address — not supplied]]
We acknowledge every complaint within 24 hours and resolve it within 15 days, as the IT Rules require.
Cookies and browser storage
We set one cookie, and it is the one that keeps you signed in. We use no analytics or advertising cookies, so there is nothing to opt out of and we do not show you a preferences panel that would change nothing. That cookie, and everything else we keep in your browser — your bag, your wishlist, your currency — is listed name by name on our cookie page, along with what our payment and mapping partners set at checkout.
You can clear or block all of it through your browser’s site settings at any time. The cookie page explains what stops working when you do.
Data security
Traffic to this site is encrypted in transit. Payment credentials are entered inside Razorpay’s window and never pass through our systems. Access to customer data is limited to the people who need it to serve you, and invoices are kept in private storage rather than on a public URL.
No system is perfect. If a breach ever affects your data, we will notify you and the Data Protection Board of India as the Act requires.
Children
This store is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, write to our grievance officer and we will remove it.
Changes to this policy
If we change how we handle your data we will update this page and move the date at the top. Material changes will be flagged to you directly where we can reach you.
Questions about your privacy? Write to us at hello@diyamhouseofsilver.com and we'll respond within two working days.