Legal

Privacy Policy

Effective: 1 May 2026 Last updated: 23 May 2026 Governed by DPDP Act 2023
Contents
This Privacy Policy applies to myalankarini.com and all related services operated by MyAlankarini. By using our website, you agree to the collection and use of information as described here. This policy complies with India's Digital Personal Data Protection (DPDP) Act 2023.
01

Information We Collect

Account information: When you create an account, we collect your name, email address, and phone number (optional). You may sign in using Google, in which case we receive your name and email from Google.

Order & delivery information: When you place an order, we collect your delivery address, contact number, and payment details. Payment details are processed securely by Razorpay — we do not store card numbers or UPI IDs.

Usage data: We collect information about how you use our website — pages visited, products viewed, searches performed, and features used. This helps us improve your experience.

Device & technical data: IP address, browser type, device type, and operating system — collected automatically when you visit our site.

Communications: If you contact our support team, we retain the conversation for quality and training purposes.

02

How We Use Your Information

We use the information we collect to:

  • Process and fulfil your orders, and send order confirmations and updates
  • Manage your account, wallet, and wishlist
  • Provide customer support and respond to your queries
  • Send transactional emails (order placed, dispatched, delivered)
  • Send promotional communications — only if you have opted in
  • Improve our website, products, and services through analytics
  • Detect and prevent fraud, abuse, or unauthorised access
  • Comply with legal obligations under Indian law

We will never sell your personal data to third parties for their marketing purposes.

03

Virtual Try-On & AI Features

Your photos: When you use our Virtual Try-On feature, you upload or capture a photo of yourself. This image is sent to Google's Gemini AI API to generate the try-on result. We do not permanently store your selfie photos on our servers. The generated result image may be stored temporarily in your session and, if you choose to save it to My Looks, in your account.

BYOK (Bring Your Own Key): If you use the free tier by providing your own Gemini API key, your key is stored only in your browser's local storage. It is never sent to or stored on our servers.

AI Support (Aara): Conversations with our AI support assistant Aara are processed by Google Gemini. We store only summary analytics (not full conversation transcripts) for quality improvement. Your recent order data is shared with Aara only within the session to help resolve your query.

Gossip Wall photos: Images you post to the Gossip Wall are stored in Firebase Storage and are publicly visible. You may request deletion of your post by contacting us.

04

Data Sharing & Third Parties

We share your data with the following service providers, solely to operate our services:

  • Google Firebase & Firestore — secure database, authentication, and file storage (servers in Mumbai / asia-south1)
  • Google Gemini AI — powers Virtual Try-On and AI support; your data is subject to Google's AI data use policy
  • Razorpay — payment processing; governed by Razorpay's privacy policy
  • Shiprocket — order fulfilment and shipping; your name, address, and phone number are shared to create shipments
  • Zoho Mail — sending transactional emails; your email address is used solely for delivery
  • Google Analytics (GA4) — anonymous usage analytics; no personally identifiable information is shared

We may disclose your information if required by law, court order, or government authority in India.

05

Data Storage & Security

All data is stored on Google Firebase infrastructure located in Mumbai (asia-south1), within India. We implement industry-standard security measures including:

  • HTTPS encryption for all data in transit
  • Firebase Security Rules controlling data access at the database level
  • Admin access protected by Firebase Authentication and PIN verification
  • Payment secrets stored in Google Cloud Secret Manager — never in code
  • Return evidence (photos/videos) automatically deleted 10 days after resolution

No method of transmission over the Internet is 100% secure. While we take all reasonable precautions, we cannot guarantee absolute security.

Retention: We retain your account data for as long as your account is active. Order data is retained for 7 years for tax and legal compliance. You may request deletion of your account at any time (subject to legal retention requirements).

06

Cookies & Analytics

We use the following types of cookies and tracking technologies:

  • Essential cookies: Required for authentication and session management. Cannot be disabled.
  • Analytics cookies (GA4): Help us understand how visitors use our site. Only set after you accept cookies via our consent banner.
  • Push notification tokens (FCM): If you enable push notifications, we store a device token in your account to send order updates.

You can manage your cookie preferences at any time via the cookie consent banner on our website. Refusing analytics cookies will not affect your ability to use any features of the site.

07

Your Rights (DPDP Act 2023)

Under India's Digital Personal Data Protection Act 2023, you have the following rights:

  • Right to access: Request a copy of the personal data we hold about you
  • Right to correction: Update or correct inaccurate personal data
  • Right to erasure: Request deletion of your personal data (subject to legal retention requirements)
  • Right to grievance redressal: Raise a complaint with our data protection officer
  • Right to nominate: Nominate another person to exercise your rights in the event of your death or incapacity
  • Right to withdraw consent: Withdraw consent to marketing communications at any time via the unsubscribe link in any email

To exercise any of these rights, email us at privacy@myalankarini.com. We will respond within 30 days.

08

Children's Privacy

MyAlankarini is not intended for use by children under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal information, please contact us immediately and we will delete it.

09

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by displaying a prominent notice on our website. Your continued use of the site after any changes constitutes your acceptance of the updated policy.

The date of the most recent revision is shown at the top of this page.

10

Contact Us

For privacy-related queries, data requests, or to raise a grievance:

Data Protection Officer — MyAlankarini
🏠 MyAlankarini, India
We respond to all privacy requests within 30 days as required by the DPDP Act 2023.