Legal
Privacy Policy
Last updated: March 2026
We collect only what we need, we protect it carefully, and we never sell it. This policy explains exactly what we do with your data.
1. Overview
Rivarna ("we", "our", "us") is committed to protecting your personal information. This Privacy Policy explains what data we collect, why we collect it, how we use it, and your rights in relation to it.
We collect only what we need. We do not sell your data. We do not share it with third parties except where necessary to fulfil your order or comply with legal obligations.
This policy applies to all personal data collected through our website (rivarna.com), including during account creation, checkout, commission requests, and newsletter sign-ups.
2. Data We Collect
We collect the following categories of personal data:
Account & Identity: Name, email address, and phone number when you create an account or check out as a guest.
Order & Transaction Data: Shipping address, order history, payment method type (we do not store full card numbers — payment processing is handled by our payment provider), and order correspondence.
Commission Data: Any information you provide when requesting a bespoke piece, including design preferences, measurements, and reference images.
Communication Data: Messages you send us via email, WhatsApp, or our contact form.
Technical Data: IP address, browser type, device type, pages visited, and time spent on pages. This is collected automatically via our analytics tools and is used in aggregate, anonymised form.
Newsletter Data: Email address if you subscribe to our newsletter. You can unsubscribe at any time.
3. How We Use Your Data
We use your personal data for the following purposes:
Order Fulfilment: To process and deliver your orders, send order confirmations and shipping updates, and handle returns or exchanges.
Account Management: To maintain your account, save your addresses, and provide order history.
Customer Support: To respond to your enquiries and resolve issues.
Commission Management: To manage bespoke commission requests from initial brief through to delivery.
Marketing: To send you our newsletter if you have subscribed. We will never send marketing emails without your explicit consent. Each email includes an unsubscribe link.
Legal Compliance: To comply with applicable laws, including tax obligations and fraud prevention.
We do not use your data for automated decision-making or profiling.
4. Data Sharing
We share your personal data only where necessary:
Delivery Partners: Your name and shipping address are shared with our courier partners to fulfil your order.
Payment Processors: Payment data is handled by our payment provider. We receive only a transaction reference and the last four digits of your card — never your full card details.
Email Service Provider: We use a third-party email service to send transactional and marketing emails. Your email address is shared with this provider for this purpose only.
Analytics: We use anonymised, aggregated analytics data. No personally identifiable information is shared with analytics providers.
Legal Requirements: We may disclose your data if required to do so by law or in response to a valid legal request.
We do not sell, rent, or trade your personal data to any third party for their own marketing purposes.
5. Data Retention
We retain your personal data for as long as necessary to fulfil the purposes for which it was collected:
Order data is retained for 7 years to comply with Indian tax and accounting regulations.
Account data is retained for as long as your account is active. If you delete your account, your personal data will be removed within 30 days, except where retention is required by law.
Newsletter subscriptions are retained until you unsubscribe.
Commission correspondence is retained for 3 years after the commission is completed.
6. Security
We take the security of your personal data seriously. We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, or disclosure.
These measures include encrypted data transmission (HTTPS), secure database storage, access controls limiting who within our team can access personal data, and regular security reviews.
No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. If you believe your data has been compromised, please contact us immediately at security@rivarna.com.
8. Your Rights
Under applicable data protection law, you have the following rights:
Access: You can request a copy of the personal data we hold about you.
Correction: You can ask us to correct inaccurate or incomplete data.
Deletion: You can request that we delete your personal data, subject to legal retention requirements.
Portability: You can request your data in a structured, machine-readable format.
Objection: You can object to our processing of your data for marketing purposes at any time.
To exercise any of these rights, contact us at privacy@rivarna.com. We will respond within 30 days.
9. Children's Privacy
Our website is not directed at children under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we will notify registered customers by email.
Continued use of our website after any changes constitutes acceptance of the updated policy.
11. Contact
For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us at privacy@rivarna.com or through our Contact page. We aim to respond to all privacy enquiries within 5 business days.
Also see our Terms of Service and Returns & Exchanges Policy.