We collect only what we need to send you your order and to let you sign in.
We never see your card number, CVV or UPI PIN — those go straight to the payment gateway.
We do not sell your data, and we do not share it for advertising.
Write to us and we will show you, correct, or delete what we hold about you.
The detail is below, in plain language.
1. What we collect
You give us
Account details — your name, email address, phone number and password.
The password is stored only as a one-way hash; nobody at our studio can read it.
Delivery details — recipient name, phone, address, city, state, pincode, country and any
order note you add.
Order history — what you bought, when, for how much, and its status.
What you write — product reviews, wishlist items and any message you send us.
Collected automatically
A session cookie so the site remembers that you are signed in, what is in your bag, which
currency you chose to view, and any coupon you applied.
A "remember this device" cookie (valid up to 180 days) if you verify a device, so you are not
asked for an OTP every single time. It holds a random token, not your details, and it is stored on our
side only as a hash.
Standard server logs kept by our hosting provider — IP address, browser type, page requested,
time — used for security and to debug errors.
Two small entries in your browser's own storage: one that remembers you dismissed the
"install the app" banner, and one that stops the intro animation replaying on every page.
These never leave your device.
What we never collect
Card numbers, expiry dates, CVV, UPI PIN, netbanking passwords and OTPs. These are entered on the
payment gateway's own secure page. We only receive a payment reference and whether the payment
succeeded.
2. Why we use it
To fulfil your order
Confirming it, packing it, handing your address to the courier, and handling returns or refunds.
To run your account
Signing you in, sending the one-time code that verifies your email, keeping your saved address and order history.
To talk to you about an order
Order confirmation, dispatch and delivery updates, and replies to your questions.
To keep the site safe
Detecting fraud, abuse of coupons and attempts to break in.
To meet the law
Keeping invoice and tax records for as long as Indian law requires.
We do not send marketing email unless you ask us to. If we ever start a newsletter it will be opt-in,
with an unsubscribe link in every message.
3. Who else sees it
Only those who need it in order for your order to reach you:
Payment gateway — receives the order amount and reference so it can take the payment, and it
handles your card or UPI details under its own privacy policy and PCI-DSS obligations.
Courier partner — receives the recipient name, address and phone number needed to deliver.
Our hosting and email provider — stores the site, its database and sends transactional email
on our behalf.
Fonts and script libraries loaded from third-party content networks (Google Fonts, cdnjs,
unpkg). Your browser fetches these directly, so those networks can see your IP address. They receive
no order or account information.
Authorities, if we are legally required to disclose something.
We do not sell, rent or trade your personal data, and we do not share it with advertisers or data brokers.
4. How long we keep it
Order and invoice records — as long as tax and accounting law requires.
Account details — until you ask us to delete the account.
One-time codes — a few minutes; they expire and are then discarded.
Device tokens — up to 180 days, or until you sign out of that device or clear cookies.
When we delete an account we remove or anonymise the personal details, but we must keep the minimum
invoice record that the law requires.
5. How we protect it
The site is served over HTTPS, so traffic between your browser and us is encrypted.
Passwords are stored as bcrypt hashes; one-time codes and device tokens are stored hashed too.
Database queries use prepared statements, which is what keeps SQL injection out.
Forms are protected against cross-site request forgery, and admin pages need an admin sign-in.
No system is perfect. If we ever discover a breach that affects you, we will tell you and the relevant
authority without delay.
6. Your choices and rights
You can ask us to:
show you a copy of the data we hold about you;
correct anything that is wrong — or edit it yourself in
My account;
delete your account and personal details;
stop using your details for anything beyond completing an order you have already placed.
Email contact@houseofsharvi.com from the address on your
account and we will respond within 30 days.
You can also delete the cookies this site has set at any time, from your browser settings — you will
simply have to sign in again.
7. Children
This site is not intended for children under 18, and we do not knowingly collect their data. If you
believe a child has given us personal information, tell us and we will remove it.
8. Links to other sites
Our pages link out to WhatsApp, Instagram, Pinterest and the payment gateway. Once you leave this site
you are covered by their privacy policies, not ours.
9. Changes, and who to contact
If we change this policy in any meaningful way we will update this page, and the date at the top of it.