Legal
Privacy Policy
Last updated: April 2026
1. Information We Collect
We collect information you provide directly (name, email, phone, shipping address) when you place an order, create an account, submit a consultation request, or contact us. We also collect browsing data (pages visited, time on site) via PostHog analytics and error data via Sentry.
2. How We Use Your Information
- To process and fulfil your orders.
- To send order confirmation, shipping, and delivery notifications via email.
- To respond to your customer service enquiries.
- To improve our products and website experience.
- To send you marketing communications (only if you have opted in).
3. Data Sharing
We do not sell your personal data. We share data only with service providers necessary to operate our business: Supabase (database), Resend (email), Stripe/Razorpay (payments), Cloudinary (images), Sentry (error monitoring), and PostHog (analytics). All providers are bound by data processing agreements.
4. Data Retention
We retain order data for 7 years as required by Indian GST regulations. Account data is retained until you request deletion. Analytics data is retained for 12 months.
5. Your Rights
You have the right to access, correct, or delete your personal data. To exercise these rights, email us at hello@smilvin.com. We will respond within 30 days.
6. Cookies
We use strictly necessary cookies (session management) and analytics cookies (PostHog). You can disable analytics cookies in your browser settings at any time.
7. Security
We use HTTPS/TLS encryption for all data in transit. Payment data is processed directly by Stripe/Razorpay — we never store card numbers. Our database is hosted on Supabase with row-level security enabled.
8. Contact
For privacy questions, contact our data officer at hello@smilvin.com.
