Legal
Privacy Policy
- Effective date:
- 18 August 2026
- Last updated:
- 18 August 2026
- Version:
- PRIVACY-2026-08-18-v2.0
This notice explains what personal data we collect when you use Madhu's Jewellery, why, who else sees it, how long we keep it, and what you can ask us to do about it. It describes what this website actually does - where something is not yet required by law, or is something we do not do, it says so.
1. Who we are
Madhu's Jewellery Pvt. Ltd., registered office 30-7-11, gollala street, suryanarayana puram, Kakinada, Andhra Pradesh 533001, India, is responsible for the personal data described here. We sell imitation and fashion jewellery online across India.
2. What we collect
Information you give us
- Name, email address and mobile number - to create your account, sign you in, and contact you about an order.
- Delivery address, including pincode, and map coordinates if you use address search.
- Order details - what you bought, quantities and prices.
- Messages you send us, and the contents of any complaint.
Information created when you use the site
- A session token in a cookie, which keeps you signed in. It contains no personal data itself.
- One-time passcodes you request to sign in. Stored hashed, expiring quickly, and limited in number.
- A record of your cookie and policy choices- date and time, the version of the document you saw, your IP address and your browser’s user-agent string. This exists to evidence what you agreed to and when.
- Payment transaction records - see section 4.
Information from third parties
- Payment outcome data from Razorpay - see section 4.
- Delivery status from couriers, where a shipment has been booked.
What we do not collect
We do not collect Aadhaar numbers, PAN, date of birth, gender, biometric data, health data, precise location, or card or bank account numbers. There is no social sign-in, and no analytics or advertising technology anywhere on this site - see our Cookie Policy.
We do not currently operate a WhatsApp integration. Where our policies mention WhatsApp, that is a message sent by hand by a member of staff, not an automated system.
3. Why we process it, and on what basis
The Digital Personal Data Protection Act, 2023 allows processing on the basis of consent, or of a “legitimate use” listed in section 7 of that Act. It does notcontain a general “performance of a contract” basis, so we do not claim one.
| Purpose | Data used | Basis |
|---|---|---|
| Creating and operating your account | Name, email, mobile | s.7(a) - data you gave us voluntarily for that purpose |
| Taking and delivering your order | Name, contact, address, order details | s.7(a) |
| Taking payment and reconciling it | Transaction records (section 4) | s.7(a); legal obligation for tax records |
| Answering questions and complaints | Contact details, order reference, your message | s.7(a) |
| Keeping accounts secure, preventing misuse | Session and passcode data, IP address | s.7(a); legitimate security interest |
| Evidencing what you agreed to | Consent records, policy version, IP, user-agent | s.7(a); needed to show the terms of your purchase |
| Meeting tax, accounting and legal obligations | Order and payment records | Legal obligation |
| Sending you promotional messages | Email address, mobile | Your consent - separate, optional, withdrawable |
Only the last row rests on consent. Everything above it is what we need to run the shop you asked us to run, and agreeing to our Terms is not the same as consenting to marketing.
The relevant DPDP obligations commence in May 2027. We describe our processing in these terms now so nothing has to change then.
4. Orders and payments - exactly what we hold
This section is deliberately precise, because vague wording here is how privacy notices become inaccurate.
We never receive or store your card number, UPI ID, CVV, PIN or bank account details. Those are entered inside Razorpay’s own payment window and never reach our servers.
We do store payment transaction records:the Razorpay order identifier, the payment identifier, the payment signature we use to verify the payment is genuine, the amount, the payment status and the time it was paid. That is transaction metadata, not payment credentials - but it is not nothing, and we would rather say so than claim we “hold no payment information”.
Razorpay processes your payment as an independent provider under its own privacy policy. We make no claim about Razorpay’s certifications, and we claim none of our own.
5. Delivery
To deliver your order we give the courier the recipient’s name, delivery address, pincode and a contact number, with an order reference. We receive back a tracking number and delivery status.
Your tracking is visible only when you are signed in to the account that placed the order. There is no public lookup by tracking number.
6. Support, complaints and damage claims
When you contact us or file a complaint we hold your name, contact details, the order concerned, and what you told us.
Transit-damage claims.Our Cancellation & Refund Policy requires a video of the parcel being opened. We do not currently have a way for you to upload that video to this website. Videos reach us by email or messaging app and are held in that mailbox or account, not in a customer upload system. We are telling you this rather than describing a facility that does not exist. Such a video may show your face, your voice or your home - please record only what is needed to show the damage.
7. Marketing
Promotional email or SMS is sent only if you separately opt in - at sign-up, or from your account. You can withdraw at any time through the same controls, and withdrawing has no effect on your orders or your account.
Transactional messages are different. Order confirmations, payment receipts, dispatch and delivery updates and replies to your questions are part of the service you asked for.
8. Cookies
We use a small number of necessary technologies and two optional ones. There is no analytics or advertising technology on this site. The full inventory and your controls are in our Cookie Policy.
9. Who else sees your data
| Recipient | What they get | Why |
|---|---|---|
| Razorpay | Payment amount, order reference, and details you enter in their window | To take payment |
| Courier / logistics partner | Recipient name, address, pincode, phone, order reference | To deliver your parcel |
| MSG91 | Your mobile number and a one-time passcode | To send sign-in codes by SMS |
| Our email provider | Your email address and the message content | To send order and account email |
| Cloudinary | Product images only | Image hosting - no customer personal data |
| Our hosting provider | Whatever passes through the site in the ordinary course | To run the website and database |
We do not sell personal data for monetary consideration. That is a statement about one thing only; the table above is the real answer to who sees your data.
Where a service provider is outside India, your data is processed outside India to that extent. We have not completed a full jurisdictional audit of every provider, so we do not claim that your data never leaves India.
We may also disclose personal data where legally required - to a court, a regulator or law enforcement - or where necessary to investigate fraud or establish or defend a legal claim. We disclose the minimum necessary.
10. How long we keep it
| Data | Retained | Why |
|---|---|---|
| Account details | While your account exists | To operate the account |
| Order, invoice and payment records | As required by applicable tax and accounting law | Legal obligation - the period is set by that law, not by us |
| Consent and policy-acceptance records | While the related order or account exists, and while a dispute could still be raised | Their only purpose is to evidence that transaction |
| Cookie preferences | 12 months, then we ask again | Our own policy - no Indian statute sets a period |
| Marketing consent records | Kept after withdrawal | The record of a withdrawal is what proves we stopped |
| Complaint and claim records | Through handling and any escalation | To resolve the complaint and any follow-on |
| Sign-in passcodes | Minutes - they expire and are superseded | Security |
| Server and delivery logs | Short operational periods | Security and troubleshooting |
We have not invented a “7 years” or a “forever”. Where a period depends on tax or accounting law, we say so rather than guessing at a number.
11. Your rights
Under the DPDP Act, 2023 you may ask for access to your personal data, correction of inaccurate data, erasure, and to raise a grievance, and you may nominate someone to exercise these on your behalf. These provisions commence in May 2027; we are honouring them now, and the notes below describe what actually happens today.
- Access. Signed in, you can download everything we hold about you immediately from your account. Anyone else can ask us.
- Correction. Contact details can be corrected on request. The delivery address on an order already placed cannot be rewritten - it is the record of where that parcel was sent - but we correct anything used going forward.
- Erasure. We remove your name, email address, mobile number and saved credentials, and end your sessions. We retain order and payment records, and the record of what you agreed to when placing them, because tax and accounting law requires the former and the latter is the evidence of a completed purchase. We tell you exactly what was removed and what was kept.
- Grievance. See section 12.
We are not claiming rights Indian law does not currently give you. In particular this notice does not offer data portability, a right to object, or rights over automated decision-making - the first two because the DPDP Act does not provide them, and the last because we carry out no automated decision-making, profiling, personalisation or scoring at all.
12. How to exercise your rights, and how to complain
Email mj@madhusjewellery.com, or use the privacy request form in your account. We confirm your identity before disclosing or deleting anything - a request from a signed-in account is verified automatically, otherwise we verify on the details we already hold. We will not release your order history to someone who merely knows your email address.
Two separate routes, and they are not the same mechanism:
- Privacy matters - anything in this notice. Contact us as above.
- Consumer complaints about an order, delivery or refund go to our Grievance Officer under the Consumer Protection (E-Commerce) Rules, 2020 - acknowledgement within 48 hours, redressal within one month. Details on our Terms & Conditions page.
Once the Data Protection Board of India’s complaint process is operative for these provisions you will also be able to complain to it. We do not name a portal or address here, because we would be guessing.
13. Children
The DPDP Act treats anyone under 18 as a child and requires verifiable parental consent before processing a child’s personal data, with a prohibition on tracking, behavioural monitoring and targeted advertising directed at children. These provisions commence in May 2027.
Our Terms require purchasers to be 18 or over. We do not currently operate an age-verification mechanism, and we will not describe one that does not exist. We do not track or profile any user, child or adult, and run no advertising technology, so the tracking and targeting prohibitions are met by the fact that we do none of it. If you believe a child has created an account, contact us and we will remove it.
The age at which someone can enter a contract and the age used in data protection law are separate questions; we have not merged them.
14. Security
We use reasonable technical and organisational measures designed to protect personal data: sign-in without stored customer passwords, one-time passcodes stored hashed and expiring, rate limiting on code requests, administrator passwords stored as one-way hashes, customer records restricted to administrator accounts, session cookies marked httpOnly and Secure, and payment handled inside the provider’s own window.
We claim no certification, and we do not claim any system is completely secure - none is.
If a personal data breach occurs we will act in accordance with the obligations applying at the time. We do not promise a specific notification deadline here, because the DPDP breach-reporting provisions are not yet in force and we will not commit to a timescale we cannot yet be held to.
15. Third-party links
Pages here may link to other websites with their own policies. When you pay, you enter details inside Razorpay’s window and Razorpay’s policy governs what happens there - but that does not end our responsibility for the data we hold about your order.
16. Business transfers
If the business is sold or reorganised, personal data may transfer as part of it. Any transfer remains subject to applicable law and to the purposes described here; a buyer does not acquire the right to use your data for something else.
17. Changes
When this notice changes materially we publish a new version with a new version identifier and effective date. Previous versions are preserved, and the version that applied when you placed an order remains available.