Privacyin plain words
What we collect when you shop with us, why we need it, who else can see it, and how to make us delete it. No clauses designed to be skipped.
Before this goes live: have your legal counsel review this policy, and replace the company name, address, phone and grievance officer in src/data/site.ts with the registered details. This describes what the website actually does, but it is not legal advice.
This policy explains how Verrah Fine Jewellery Pvt. Ltd. (“verrah”, “we”, “us”) handles personal data when you browse verrah.com, buy from us, book an appointment or write to us. It is written to meet India's Digital Personal Data Protection Act, 2023, and applies to everyone who uses the site.
1. What we collect
Information you give us
- Account — your name, email address, phone number and password. The password is never stored: we keep only a bcrypt hash of it, which cannot be reversed.
- Orders — delivery address, contact number, the pieces you bought and what you paid.
- Appointments — your name, contact details, preferred date and time, and anything you tell us about what you would like to see.
- Enquiries — whatever you write in the contact form, so we can answer it.
Information we collect automatically
- Session — a signed cookie that keeps you logged in. It holds your user ID and role, nothing else.
- Live viewer counts — an anonymous, random per-tab identifier so the “people viewing this piece” number is accurate. It is not linked to your account and expires within a minute of you leaving.
- Security — your IP address, briefly, to rate-limit sign-in attempts and form submissions so the site cannot be attacked or spammed.
What we never collect
We do not ask for or store card numbers, CVVs, UPI PINs or bank credentials. Those are entered on Razorpay's own secure form and never reach our servers. We also do not buy personal data from third parties.
2. How we use it
- To take, fulfil and deliver your order, and to show you its progress.
- To create and secure your account, and to let you reset your password.
- To arrange and confirm boutique appointments.
- To answer your enquiries and provide after-sales service.
- To send transactional email — order confirmations, appointment confirmations, password resets. These are not marketing and you cannot unsubscribe from them while you have an active order.
- To detect and prevent fraud, abuse and automated attacks.
- To understand which pieces sell, in aggregate, so we make more of what people want.
We do not sell your personal data. We do not share it with advertisers. We do not use it to build profiles for third parties.
3. Why we're allowed to
Under the DPDP Act we process personal data either with your consent or for a legitimate use permitted by the Act:
- To perform our contract with you — everything needed to take payment, make and deliver a piece.
- With your consent — when you voluntarily give details for an appointment or an enquiry. You may withdraw consent at any time; see your rights.
- To comply with law — tax invoices, GST records and hallmarking documentation we are required to keep.
4. Payments
Payments are processed by Razorpay Software Private Limited, an RBI-authorised payment aggregator. When you pay, you are handed to Razorpay's own checkout. Your card, UPI or netbanking details are entered there and are covered by Razorpay's PCI-DSS certified systems and their own privacy policy.
We receive back only a payment reference, the amount, the method used (“UPI”, “card”) and whether it succeeded. We store those against your order because we are legally required to, and because you would reasonably expect a receipt.
7. How long we keep it
- Account data — until you ask us to delete it.
- Orders and invoices — eight years, as tax law requires. We cannot delete these earlier even on request.
- Appointments — two years, so we know your history when you next visit.
- Enquiries — kept in our email inbox, not in the database, and cleared on our normal mail retention schedule.
- Security logs and rate-limit counters — hours, not days.
8. Your rights
Under the DPDP Act you may ask us to:
- Show you the personal data we hold about you, and who we have shared it with.
- Correct anything inaccurate, incomplete or out of date. Most of it you can edit yourself from your account page.
- Erase your data, where we are not required by law to keep it.
- Withdraw consent you previously gave, as easily as you gave it.
- Nominate someone to exercise these rights on your behalf if you die or become incapacitated.
- Complain to the Data Protection Board of India if we have not resolved your grievance.
Write to [email protected] and we will respond within thirty days. There is no charge.
9. How we protect it
- The whole site is served over HTTPS; nothing travels in the clear.
- Passwords are hashed with bcrypt at cost 12, and are never stored or logged in readable form.
- Admin access is checked on the server for every single action, not merely hidden in the interface, and each staff member holds only the permissions their role needs.
- Sign-in, registration, password reset and public forms are rate limited against brute-force and spam.
- Database access is restricted to the application, over an encrypted connection.
No system is perfectly secure. If a breach ever affects your data, we will notify you and the Data Protection Board as the law requires.
10. Children
This site is not intended for anyone under 18, and we do not knowingly create accounts for children. If you believe a child has given us personal data, write to us and we will delete it.
11. Changes to this policy
When we change anything material we update the date at the top of this page and, where the change affects how we use data you have already given us, we tell you by email. Continuing to use the site after a change means you accept it.
12. Contact & grievances
For anything about this policy or your data, contact our Grievance Officer:
- The Grievance Officer, Verrah Fine Jewellery Pvt. Ltd.
- [email protected]
- +91 98200 44521
- Verrah Atelier, 12 Altamount Road, Cumballa Hill, Mumbai 400026, India
We answer every request within thirty days. If you are not satisfied, you may escalate to the Data Protection Board of India.
