Legal

Privacy Policy

Last updated: April 2026

1. Information We Collect

We collect information you provide directly (name, email, phone, shipping address) when you place an order, create an account, submit a consultation request, or contact us. We also collect browsing data (pages visited, time on site) via PostHog analytics and error data via Sentry.

2. How We Use Your Information

  • To process and fulfil your orders.
  • To send order confirmation, shipping, and delivery notifications via email.
  • To respond to your customer service enquiries.
  • To improve our products and website experience.
  • To send you marketing communications (only if you have opted in).

3. Data Sharing

We do not sell your personal data. We share data only with service providers necessary to operate our business: Supabase (database), Resend (email), Stripe/Razorpay (payments), Cloudinary (images), Sentry (error monitoring), and PostHog (analytics). All providers are bound by data processing agreements.

4. Data Retention

We retain order data for 7 years as required by Indian GST regulations. Account data is retained until you request deletion. Analytics data is retained for 12 months.

5. Your Rights

You have the right to access, correct, or delete your personal data. To exercise these rights, email us at hello@smilvin.com. We will respond within 30 days.

6. Cookies

We use strictly necessary cookies (session management) and analytics cookies (PostHog). You can disable analytics cookies in your browser settings at any time.

7. Security

We use HTTPS/TLS encryption for all data in transit. Payment data is processed directly by Stripe/Razorpay — we never store card numbers. Our database is hosted on Supabase with row-level security enabled.

8. Contact

For privacy questions, contact our data officer at hello@smilvin.com.