Madhu's Jewellery

Legal

Privacy Policy

Effective date:
18 August 2026
Last updated:
18 August 2026
Version:
PRIVACY-2026-08-18-v2.0

This notice explains what personal data we collect when you use Madhu's Jewellery, why, who else sees it, how long we keep it, and what you can ask us to do about it. It describes what this website actually does - where something is not yet required by law, or is something we do not do, it says so.

1. Who we are

Madhu's Jewellery Pvt. Ltd., registered office 30-7-11, gollala street, suryanarayana puram, Kakinada, Andhra Pradesh 533001, India, is responsible for the personal data described here. We sell imitation and fashion jewellery online across India.

2. What we collect

Information you give us

  • Name, email address and mobile number - to create your account, sign you in, and contact you about an order.
  • Delivery address, including pincode, and map coordinates if you use address search.
  • Order details - what you bought, quantities and prices.
  • Messages you send us, and the contents of any complaint.

Information created when you use the site

  • A session token in a cookie, which keeps you signed in. It contains no personal data itself.
  • One-time passcodes you request to sign in. Stored hashed, expiring quickly, and limited in number.
  • A record of your cookie and policy choices- date and time, the version of the document you saw, your IP address and your browser’s user-agent string. This exists to evidence what you agreed to and when.
  • Payment transaction records - see section 4.

Information from third parties

  • Payment outcome data from Razorpay - see section 4.
  • Delivery status from couriers, where a shipment has been booked.

What we do not collect

We do not collect Aadhaar numbers, PAN, date of birth, gender, biometric data, health data, precise location, or card or bank account numbers. There is no social sign-in, and no analytics or advertising technology anywhere on this site - see our Cookie Policy.

We do not currently operate a WhatsApp integration. Where our policies mention WhatsApp, that is a message sent by hand by a member of staff, not an automated system.

3. Why we process it, and on what basis

The Digital Personal Data Protection Act, 2023 allows processing on the basis of consent, or of a “legitimate use” listed in section 7 of that Act. It does notcontain a general “performance of a contract” basis, so we do not claim one.

PurposeData usedBasis
Creating and operating your accountName, email, mobiles.7(a) - data you gave us voluntarily for that purpose
Taking and delivering your orderName, contact, address, order detailss.7(a)
Taking payment and reconciling itTransaction records (section 4)s.7(a); legal obligation for tax records
Answering questions and complaintsContact details, order reference, your messages.7(a)
Keeping accounts secure, preventing misuseSession and passcode data, IP addresss.7(a); legitimate security interest
Evidencing what you agreed toConsent records, policy version, IP, user-agents.7(a); needed to show the terms of your purchase
Meeting tax, accounting and legal obligationsOrder and payment recordsLegal obligation
Sending you promotional messagesEmail address, mobileYour consent - separate, optional, withdrawable

Only the last row rests on consent. Everything above it is what we need to run the shop you asked us to run, and agreeing to our Terms is not the same as consenting to marketing.

The relevant DPDP obligations commence in May 2027. We describe our processing in these terms now so nothing has to change then.

4. Orders and payments - exactly what we hold

This section is deliberately precise, because vague wording here is how privacy notices become inaccurate.

We never receive or store your card number, UPI ID, CVV, PIN or bank account details. Those are entered inside Razorpay’s own payment window and never reach our servers.

We do store payment transaction records:the Razorpay order identifier, the payment identifier, the payment signature we use to verify the payment is genuine, the amount, the payment status and the time it was paid. That is transaction metadata, not payment credentials - but it is not nothing, and we would rather say so than claim we “hold no payment information”.

Razorpay processes your payment as an independent provider under its own privacy policy. We make no claim about Razorpay’s certifications, and we claim none of our own.

5. Delivery

To deliver your order we give the courier the recipient’s name, delivery address, pincode and a contact number, with an order reference. We receive back a tracking number and delivery status.

Your tracking is visible only when you are signed in to the account that placed the order. There is no public lookup by tracking number.

6. Support, complaints and damage claims

When you contact us or file a complaint we hold your name, contact details, the order concerned, and what you told us.

Transit-damage claims.Our Cancellation & Refund Policy requires a video of the parcel being opened. We do not currently have a way for you to upload that video to this website. Videos reach us by email or messaging app and are held in that mailbox or account, not in a customer upload system. We are telling you this rather than describing a facility that does not exist. Such a video may show your face, your voice or your home - please record only what is needed to show the damage.

7. Marketing

Promotional email or SMS is sent only if you separately opt in - at sign-up, or from your account. You can withdraw at any time through the same controls, and withdrawing has no effect on your orders or your account.

Transactional messages are different. Order confirmations, payment receipts, dispatch and delivery updates and replies to your questions are part of the service you asked for.

8. Cookies

We use a small number of necessary technologies and two optional ones. There is no analytics or advertising technology on this site. The full inventory and your controls are in our Cookie Policy.

9. Who else sees your data

RecipientWhat they getWhy
RazorpayPayment amount, order reference, and details you enter in their windowTo take payment
Courier / logistics partnerRecipient name, address, pincode, phone, order referenceTo deliver your parcel
MSG91Your mobile number and a one-time passcodeTo send sign-in codes by SMS
Our email providerYour email address and the message contentTo send order and account email
CloudinaryProduct images onlyImage hosting - no customer personal data
Our hosting providerWhatever passes through the site in the ordinary courseTo run the website and database

We do not sell personal data for monetary consideration. That is a statement about one thing only; the table above is the real answer to who sees your data.

Where a service provider is outside India, your data is processed outside India to that extent. We have not completed a full jurisdictional audit of every provider, so we do not claim that your data never leaves India.

We may also disclose personal data where legally required - to a court, a regulator or law enforcement - or where necessary to investigate fraud or establish or defend a legal claim. We disclose the minimum necessary.

10. How long we keep it

DataRetainedWhy
Account detailsWhile your account existsTo operate the account
Order, invoice and payment recordsAs required by applicable tax and accounting lawLegal obligation - the period is set by that law, not by us
Consent and policy-acceptance recordsWhile the related order or account exists, and while a dispute could still be raisedTheir only purpose is to evidence that transaction
Cookie preferences12 months, then we ask againOur own policy - no Indian statute sets a period
Marketing consent recordsKept after withdrawalThe record of a withdrawal is what proves we stopped
Complaint and claim recordsThrough handling and any escalationTo resolve the complaint and any follow-on
Sign-in passcodesMinutes - they expire and are supersededSecurity
Server and delivery logsShort operational periodsSecurity and troubleshooting

We have not invented a “7 years” or a “forever”. Where a period depends on tax or accounting law, we say so rather than guessing at a number.

11. Your rights

Under the DPDP Act, 2023 you may ask for access to your personal data, correction of inaccurate data, erasure, and to raise a grievance, and you may nominate someone to exercise these on your behalf. These provisions commence in May 2027; we are honouring them now, and the notes below describe what actually happens today.

  • Access. Signed in, you can download everything we hold about you immediately from your account. Anyone else can ask us.
  • Correction. Contact details can be corrected on request. The delivery address on an order already placed cannot be rewritten - it is the record of where that parcel was sent - but we correct anything used going forward.
  • Erasure. We remove your name, email address, mobile number and saved credentials, and end your sessions. We retain order and payment records, and the record of what you agreed to when placing them, because tax and accounting law requires the former and the latter is the evidence of a completed purchase. We tell you exactly what was removed and what was kept.
  • Grievance. See section 12.

We are not claiming rights Indian law does not currently give you. In particular this notice does not offer data portability, a right to object, or rights over automated decision-making - the first two because the DPDP Act does not provide them, and the last because we carry out no automated decision-making, profiling, personalisation or scoring at all.

12. How to exercise your rights, and how to complain

Email mj@madhusjewellery.com, or use the privacy request form in your account. We confirm your identity before disclosing or deleting anything - a request from a signed-in account is verified automatically, otherwise we verify on the details we already hold. We will not release your order history to someone who merely knows your email address.

Two separate routes, and they are not the same mechanism:

  • Privacy matters - anything in this notice. Contact us as above.
  • Consumer complaints about an order, delivery or refund go to our Grievance Officer under the Consumer Protection (E-Commerce) Rules, 2020 - acknowledgement within 48 hours, redressal within one month. Details on our Terms & Conditions page.

Once the Data Protection Board of India’s complaint process is operative for these provisions you will also be able to complain to it. We do not name a portal or address here, because we would be guessing.

13. Children

The DPDP Act treats anyone under 18 as a child and requires verifiable parental consent before processing a child’s personal data, with a prohibition on tracking, behavioural monitoring and targeted advertising directed at children. These provisions commence in May 2027.

Our Terms require purchasers to be 18 or over. We do not currently operate an age-verification mechanism, and we will not describe one that does not exist. We do not track or profile any user, child or adult, and run no advertising technology, so the tracking and targeting prohibitions are met by the fact that we do none of it. If you believe a child has created an account, contact us and we will remove it.

The age at which someone can enter a contract and the age used in data protection law are separate questions; we have not merged them.

14. Security

We use reasonable technical and organisational measures designed to protect personal data: sign-in without stored customer passwords, one-time passcodes stored hashed and expiring, rate limiting on code requests, administrator passwords stored as one-way hashes, customer records restricted to administrator accounts, session cookies marked httpOnly and Secure, and payment handled inside the provider’s own window.

We claim no certification, and we do not claim any system is completely secure - none is.

If a personal data breach occurs we will act in accordance with the obligations applying at the time. We do not promise a specific notification deadline here, because the DPDP breach-reporting provisions are not yet in force and we will not commit to a timescale we cannot yet be held to.

15. Third-party links

Pages here may link to other websites with their own policies. When you pay, you enter details inside Razorpay’s window and Razorpay’s policy governs what happens there - but that does not end our responsibility for the data we hold about your order.

16. Business transfers

If the business is sold or reorganised, personal data may transfer as part of it. Any transfer remains subject to applicable law and to the purposes described here; a buyer does not acquire the right to use your data for something else.

17. Changes

When this notice changes materially we publish a new version with a new version identifier and effective date. Previous versions are preserved, and the version that applied when you placed an order remains available.

18. Contact

Madhu's Jewellery Pvt. Ltd., 30-7-11, gollala street, suryanarayana puram, Kakinada, Andhra Pradesh 533001, India