This Privacy Policy explains how Embroo India (https://embroo.in) collects, uses, and protects your information. We follow the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the Digital Personal Data Protection Act, 2023.
1. Data we collect
- Order data: name, phone number, delivery address, design details, cart total.
- Payment data: the screenshot you upload of your UPI payment, plus any reference number you share. We do not see card or bank credentials.
- Communication: messages you send us on WhatsApp or email.
- Technical: standard server logs (IP, user-agent, timestamps) and basic Vercel Analytics aggregates. No third-party trackers.
- Cookies: a single cookie that remembers if you've dismissed the cookie banner. No advertising or cross-site tracking.
2. How we use it
- To produce, dispatch, and track your order.
- To verify your payment against our bank statement.
- To respond to your messages and resolve grievances.
- To comply with applicable Indian law.
We do not sell your data to third parties. We do not use it for retargeting ads.
3. Who we share data with
- Courier partners (Delhivery, Shiprocket) for delivery — name, phone, address only.
- Vercel (hosting) and Cloudinary (file storage, when used) — both are SOC2-compliant data processors.
- Banking partners as required to verify UPI inflows.
- Government authorities only when required by law.
4. How long we keep it
- Order records: 7 years (statutory requirement under Indian tax law).
- Payment screenshots: 90 days, then auto-deleted from private storage.
- WhatsApp chats: per Meta's WhatsApp data policy.
- Server logs: 30 days.
5. Security
We use HTTPS everywhere, signed access tokens for order pages, restricted file uploads, and rate-limited APIs. No system is perfectly secure; we follow industry-standard reasonable practices.
6. Your rights
You may, at any time, ask us to:
- show you the data we hold about you,
- correct anything inaccurate,
- delete your data (subject to statutory retention obligations),
- withdraw any consent (e.g., for using your design photo on Instagram).
Email pkexportpvtltd@gmail.com with the subject line “Data request” and we will respond within 15 business days.
7. Children
This site is not intended for users under 18. We do not knowingly collect data from minors.
8. International users
We currently ship only within India. If you visit this site from outside India, you do so at your own initiative; we make no representation that our products or content are appropriate or available in your jurisdiction.
9. Changes
We will post any updates to this policy on this page with a new “Last updated” date.
10. Contact
Privacy questions or grievances: pkexportpvtltd@gmail.com · Embroo India Support, Grievance Officer · Embroo Workshop, Sector 62, Noida, Uttar Pradesh 201309, India.
