This Privacy Policy explains what personal information we collect when you visit our storefront, place an order, sign up for an account or contact our support team, what we do with that information, and the choices you have. This policy applies to our website, mobile experiences, email communications and our walk-in studio.
Information we collect
We collect information you give us directly, information that is generated when you use the storefront, and a small amount of information from third parties (such as payment processors).
Information you give us
- Account details — first name, last name, email address and mobile number when you create an account, sign in via OTP, or place an order as a guest.
- Order information — billing and shipping addresses, the items you bought, payment mode, GSTIN if you ask for a GST invoice, and any messages you add to a gift order.
- Communications — the content of any email, WhatsApp message, contact-form submission or call recording you exchange with our support team.
- Reviews and submissions — anything you publicly post such as product reviews, ratings or photos.
Information generated automatically
- Device and log data — IP address, browser type and version, operating system, referring URL, the pages you visit on our storefront and the timestamps of those visits.
- Cookies and similar technologies — small files placed on your device that help us keep you signed in, remember your bag, measure the performance of the storefront and (with your consent) personalise the experience and measure marketing performance.
- Inferred preferences — categories, sizes and price bands you browse, used to surface relevant products on the storefront.
Information from third parties
- Payment processors share the status of a transaction (success, failure, refund), masked card or UPI identifiers and any fraud signals tied to the payment. We do not receive or store full card numbers, CVVs or UPI PINs.
- Logistics partners share delivery scans and exception events for your shipment so we can keep tracking accurate.
- OTP and verification providers share delivery receipts and basic device-risk signals to help us prevent abuse of the OTP login flow.
How we use your information
- Fulfil your order — process payment, allocate stock, generate invoices, ship to your address, handle returns and issue refunds.
- Operate your account — sign you in via OTP, save your addresses and preferences, show your order history, store credit and any active offers.
- Provide customer support — respond to your queries, investigate issues with orders or deliveries, escalate disputes with payment or logistics partners.
- Keep the storefront safe — detect and prevent fraud, abuse, automated scraping and unauthorised access. This is the basis on which we may decline a Cash on Delivery order or trigger an additional verification step.
- Improve the storefront — understand which pages, products and journeys work, fix bugs, run controlled experiments on the layout and merchandising.
- Send transactional notifications — order confirmations, dispatch alerts, delivery updates, return status emails and security messages. These are operational and cannot be opted out of while your order is in flight.
- Send marketing — drop announcements, capsule launches and editorial newsletters, only where you have opted in. Every marketing email and SMS includes a one-tap unsubscribe.
Cookies and tracking technologies
We use a small set of first-party cookies to keep you signed in, remember your bag and remember a chosen language or region. We use a separate set of third-party cookies for analytics and, where you have given consent, for marketing measurement.
You can control cookies in your browser settings. Disabling strictly-necessary cookies will break the storefront experience (you will not be able to stay signed in or check out). Disabling analytics or marketing cookies will not affect your ability to shop.
Sharing and disclosure
We do not sell your personal information. We share it only with the categories of recipients listed below, and only to the extent needed for them to perform their function.
- Payment gateways (such as Razorpay, PayU and Cashfree) — to process payments and refunds.
- Logistics partners (such as Delhivery, Shiprocket, Blue Dart and partners they assign to your pin code) — to deliver your order and collect returns.
- OTP and notification providers (such as MSG91 and Resend) — to send authentication codes, transactional SMS and email.
- Cloud and infrastructure providers — to host the storefront, store backups and run analytics.
- Professional advisers — auditors, lawyers, accountants and insurers, where their engagement reasonably requires it.
- Authorities — when a request is legally compelling and properly served, or when sharing is necessary to protect the safety of our customers or staff.
Data retention
We retain personal information only for as long as we need it for the purposes explained above. As a guideline:
- Account profile data — for the life of your account, plus 12 months after your last sign-in or order.
- Order, invoice and tax records — for at least 8 financial years, as required by Indian tax law.
- Support conversations — for 36 months after the case is closed.
- Marketing consents and unsubscribes — indefinitely, so we honour your choice.
- Cookies and analytics data — see the cookie banner for category-by-category retention.
Your rights
You can exercise the following rights at any time by emailing privacy@riseeagle.in from the address registered on your account, or by writing to our studio.
- Access — ask for a copy of the personal information we hold about you.
- Correction — ask us to correct anything that is wrong or out of date.
- Erasure — ask us to delete your personal information. We will honour the request subject to legal retention obligations (for example, tax invoices we are required to keep).
- Restriction and objection — ask us to pause certain processing while a query is being resolved.
- Withdraw consent — for anything we process on the basis of your consent, including marketing.
- Grievance — escalate any concern that we do not resolve to your satisfaction.
We respond to verifiable rights requests within 30 days. If we need longer, we will tell you why and when to expect a response.
Children
The storefront is intended for adults (18 years and over). We do not knowingly collect personal information from children. If you believe a child has shared personal information with us, please contact us and we will delete it.
Security
We protect your information with administrative, technical and physical safeguards proportionate to its sensitivity. Highlights include encrypted transport (HTTPS) on every page, hashed passwords (we never store passwords in clear text — and for customer logins we do not store passwords at all, since we use OTP), least-privilege access for our staff, audit logs on every administrative action, and regular reviews of our supplier security posture.
No system is perfectly secure. If we ever discover a breach affecting your personal information we will notify you and the relevant authorities without undue delay.
Cross-border transfers
Some of our infrastructure suppliers may process information in regions outside India. Where this happens we ensure that the supplier provides an adequate level of protection through contractual safeguards.
Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top of this page reflects when the latest version came into force. If we make material changes we will notify you by email or via a notice on the storefront before the change takes effect.
Contact us
For any privacy question or to exercise the rights listed above, write to our Data Protection contact at privacy@riseeagle.in or to our registered address: 92 Hauz Khas Village, New Delhi 110016, India.