the small print
privacy
last updated 9 August 2026
The short version: we collect what we need to send you a parcel and nothing we don't. We don't sell your data to anyone, ever.
this page isn't finished
Still needed: registered business name, registered address, contact phone number. Fill these in at lib/site.ts and this notice disappears. Have the wording checked by someone qualified before you rely on it.
Who we are
This site is run by [registered business name — not filled in yet], at [registered address — not filled in yet]. For anything about your data, write to business@shethriftss.com.
What we collect
To send you an order: your name, email, phone number and delivery address.
If you make an account: the same, plus a password we store only as a one-way hash — we can't read it, and neither can anyone who obtains our database.
If you book a donation pickup: your name, phone, address and how many pieces you're giving.
If you join the mailing list: just your email address.
We never see your card details. Payments go directly to Razorpay; we receive only a payment reference and the amount.
What we do with it
Take payment, get a parcel to you, keep you updated about that parcel, run the She Coins wallet, and answer you when you write in. If you joined the mailing list, tell you about new pieces — and stop the moment you ask.
We don't run advertising trackers or sell anything to data brokers.
Who else touches it
Only the services needed to run a shop, and only the part each one needs:
Razorpay — payments and refunds. Shiprocket — your name, phone and address, so a courier can find you. Resend — your email address, to send order and account emails. Neon and Vercel — the database and hosting the site runs on.
Our database is hosted in Singapore. Order data may therefore be stored outside India, protected by the same safeguards described here.
How long we keep it
The DPDP Act says personal data should not be kept once the purpose it was collected for is finished. So we put actual numbers on it rather than “as long as necessary”:
- Orders and invoices — 6 years. Income-tax and GST rules require it. These we cannot delete on request.
- Your account — until you delete it. There is a button on your account page.
- Saved addresses — deleted with your account, immediately.
- Checkouts that were never paid for — 30 days, then deleted automatically.
- Password reset links — deleted as soon as they expire or are used.
- Mailing list — until you unsubscribe, then 90 days so we don’t mail you again by accident.
- Consent records — kept while your account exists, because they are the proof of what you agreed to.
A scheduled job actually enforces these — they are not aspirations we would have to remember to act on.
Your rights
Under the Digital Personal Data Protection Act, 2023 you have the following rights. Two of them are buttons on your account page, because a right you have to write a letter to use is not much of a right.
- To see what we hold. “Download my data” gives you every row we have about you, as a file.
- To have it erased. “Delete my account” erases your details, addresses and subscription at once.
- To correct it. Edit your details on your account page, or write to us.
- To withdraw consent. As easily as you gave it — unsubscribing is one click, and it never affects an order.
- To nominate someone. You may nominate a person to exercise these rights if you die or become incapacitated. Write to us and we will record it.
- To complain. To our Grievance Officer below, and after that to the Data Protection Board of India.
What erasure cannot remove: orders. They are our tax records, the law requires six years of them, and the Act allows us to keep what another law compels. Everything that identifies you as an account holder goes; the invoice stays. Deleting also closes your She Coins balance, so spend those first.
Grievance Officer
If anything about your data isn’t right, this is the person responsible for putting it right — named, as the Act requires.
[Grievance Officer — name to be published — not filled in yet]
business@shethriftss.com
We acknowledge within 7 working days and aim to resolve within 30. If we don’t, you can escalate to the Data Protection Board of India.
How we ask for consent
We ask separately for the things that are genuinely separate. Processing your order is not optional — we cannot post a parcel without an address, and we don’t pretend that is a choice. Marketing is optional, is never pre-ticked, and is never a condition of buying.
Every answer is recorded with its date and the exact wording you were shown, so neither of us has to rely on memory. The version of this notice in force is 2026-08-09.
Cookies
We use a small number of cookies to keep you signed in and to remember your bag and wishlist between visits. No advertising cookies, no cross-site tracking.
Keeping it safe
Everything travels over HTTPS, with HSTS so a browser will not fall back. Passwords are hashed and cannot be read by us or by anyone who obtains the database. Payment details never reach our servers at all — they go straight to Razorpay. Admin pages answer 404 to anyone not signed in, sign-in and checkout are rate limited, and the database is backed up daily to separate storage.
If there is ever a breach: the Act requires us to notify the Data Protection Board and every affected person. We will tell you what happened, what data was involved and what to do about it — promptly, in plain words, and without waiting to be asked.
questions about any of this?
Write to business@shethriftss.com and a person will answer — or see the contact page.