At Aurealm Crystals, we treat your personal information with the same reverence we offer our stones. This policy explains what we collect, why, and the rights you hold over your data — written in compliance with India's IT Act 2000, the DPDP Act 2023, and the IT Rules 2011.
SECTION I.
Information we collect
We collect information that helps us serve you better — nothing more, nothing extracted without purpose. The categories of personal data we may collect include:
a) Personal Information you provide:
- Identity: Name, email address, phone number
- Address: Billing and shipping addresses with PIN code
- Account: Username, password (stored encrypted)
- Voluntary: Date of birth, gender (only if you choose to share)
- Communications: Messages, queries, reviews, and feedback
b) Information collected automatically:
- IP address, browser type, device information, operating system.
- Pages visited, time spent, click patterns, referring URLs.
- Cookies and similar tracking technologies (see Cookie section below).
c) Information from third parties:
- If you log in via Google/Facebook, we receive your name, email, and profile picture.
- Analytics services (Google Analytics, Meta Pixel) provide aggregated usage data.
SECTION II.
Purpose of Collection
We collect and process your data only for specific, lawful purposes including:
- Processing orders, payments, and deliveries.
- Creating and managing your account.
- Sending order confirmations, shipping updates, and customer support communications.
- Sending marketing emails/SMS (only with your consent; you can opt out anytime).
- Improving our products, services, and website experience.
- Preventing fraud and ensuring security.
- Complying with legal and regulatory obligations.
SECTION III.
Consent
By using our Website and providing your information, you consent to the collection and use of your data as described in this Policy. Under the DPDP Act, 2023, you have the right to withdraw your consent at any time by writing to us at info@aurealmcrystals.com.
SECTION IV.
Sharing of Information
We do not sell your personal data. We share information only with:
- Logistics partners (e.g., Delhivery, Bluedart, India Post) — for order delivery.
- Payment gateways (e.g., Razorpay, PayU, Cashfree) — for processing transactions.
- Marketing platforms (e.g., Mailchimp, WhatsApp Business) — only if you opt in.
- Government authorities — when required by law or court order.
- Professional advisors — lawyers, auditors, under confidentiality obligations.
SECTION V.
Data Retention
We retain your personal data only as long as necessary for the purposes for which it was collected, or as required by Indian law (e.g., GST records must be retained for 6 years; income tax records for 8 years). Once the retention period expires, your data will be securely deleted or anonymised.
SECTION VI.
Your Rights
As a Data Principal, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request erasure of your data (subject to legal retention requirements).
- Withdraw consent for processing at any time.
- Nominate another individual to exercise your rights in case of incapacity or death.
- File a grievance with our Grievance Officer (details below).
- Approach the Data Protection Board of India for unresolved grievances.
To exercise these rights, write to us at info@aurealmcrystals.com with proof of identity. We will respond within 30 days.
SECTION VII.
Cookies
We use cookies to enhance your experience. Types of cookies used:
- Essential cookies — required for website functionality (e.g., login, cart).
- Analytics cookies — help us understand site usage (Google Analytics).
- Marketing cookies — show relevant ads (Meta Pixel, Google Ads).
You can control cookies through your browser settings or our cookie consent banner. Disabling cookies may affect site functionality.
SECTION VIII.
Data Security
We implement reasonable security practices in line with ISO/IEC 27001 standards as prescribed under the IT Rules, 2011, including:
- SSL encryption for all data transmission.
- Restricted access to personal data on a need-to-know basis.
- Regular security audits.
- Use of PCI-DSS compliant payment gateways.
However, no system is 100% secure. In the unlikely event of a data breach, we will notify affected users and the Data Protection Board within 72 hours, as required by law.
SECTION IX.
Children’s Privacy
Our Website is not directed at children under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us data, please contact us at info@aurealmcrystals.com for immediate deletion.
SECTION X.
Third-Party Links
Our Website may contain links to third-party sites. This Privacy Policy does not apply to those sites. Please review their privacy policies independently.
SECTION XI.
International Data Transfers
Some of our service providers may be located outside India. Where data is transferred internationally, we ensure adequate safeguards are in place, in compliance with the DPDP Act, 2023.
SECTION XII.
Changes to Privacy Policy
We may update this Policy from time to time. The updated version will be posted on this page with a revised “Last Updated” date. Material changes will be notified via email or website notice.