Legal
Privacy Policy
Your privacy matters to us. This policy explains what data we collect, how we use it, and the simple promise we make: we never sell your data.
Last updated: May 2025
Who We Are
Riga Silver is a silver jewellery brand based in New Delhi, India. We operate the website at riga-silver.vercel.app (and any future domains we operate under), through which we sell 925 sterling silver jewellery directly to customers across India.
This Privacy Policy explains what personal information we collect when you visit our website or place an order, how we use it, who we share it with, and what rights you have over it.
We are committed to handling your personal information with care, transparency, and respect — in accordance with the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023 (DPDPA), and all other applicable Indian data protection laws.
Information We Collect
A. Information You Give Us
- Name, email address, and phone number when you create an account or place an order
- Delivery address (house/flat number, street, city, state, PIN code)
- Order history and product preferences
- Messages or queries you send us via WhatsApp, email, or our contact form
- Feedback, reviews, or comments you submit
B. Information We Collect Automatically
- IP address, browser type, and device information
- Pages visited, time spent on pages, and referring URLs
- Cookies and similar tracking technologies (see Section 7)
C. Payment Information
We do not store your credit/debit card numbers, UPI IDs, or net banking credentials on our servers. All payment transactions are processed through Razorpay, a secure, PCI-DSS compliant payment gateway. We only receive a confirmation of successful payment — no card or banking data is stored on our servers. Please refer to Razorpay's Privacy Policy for details on how they handle your payment data.
How We Use Your Information
We use your personal information only for the following purposes:
- Processing & fulfilling orders — to confirm your purchase, pack your jewellery, and arrange delivery to your address.
- Communicating with you — to send order confirmations, shipping updates, delivery notifications, and respond to your queries.
- Account management — to create and maintain your account, manage your wishlist, and display your order history.
- Improving our website — to understand how customers use our site and make it better, faster, and easier to navigate.
- Legal compliance — to meet our obligations under applicable Indian laws, including consumer protection and tax regulations.
- Preventing fraud — to detect and prevent fraudulent orders, chargebacks, and misuse of our platform.
No Marketing Communications
We do not use your contact information for promotional or marketing communications. All messages sent to you are strictly transactional — order confirmations, shipping updates, and direct responses to your queries.
We Do Not Sell Your Data
We do not sell, rent, trade, or lease your personal information to any third party — ever.
Your data is yours. We collect it solely to provide you with a smooth shopping experience. We have no business model that involves monetising your personal information, and we never will.
We do not share your information with advertisers, data brokers, marketing agencies, or any other commercial third parties for their own use.
Who We Share Your Data With
We share your personal information only where it is strictly necessary to fulfil your order or comply with the law. This is limited to the following categories:
Delivery & Logistics Partners
To deliver your order, we share the following information with our courier and logistics partners:
- Your full name
- Delivery address (including PIN code)
- Phone number (for delivery coordination and OTP confirmations)
- Order ID and package details
Our delivery partners are contractually obligated to use your information solely for completing your delivery and are not permitted to use it for any other purpose.
Payment Gateway Providers
When you make a payment, you are redirected to our payment gateway provider ( Razorpay ). They process your payment securely and in compliance with PCI-DSS standards. We share only the order amount and order reference — no additional personal data. Please refer to their privacy policy for details on how they handle your payment data.
Law Enforcement & Legal Authorities
We may disclose your personal information if required to do so by law, court order, or government authority — for example, to comply with tax regulations, respond to a legal process, or protect the rights and safety of Riga Silver and its customers.
Data Retention
We retain your personal information for as long as necessary to fulfil the purposes described in this Policy, or as required by applicable law.
- Order and transaction records are retained for 7 years to comply with Indian tax and accounting laws.
- Account information is retained for as long as your account is active. If you delete your account, we will erase your personal data within 30 days, except where retention is required by law.
- Customer support communications are retained for up to 2 years.
Cookies
We use cookies and similar technologies to enhance your experience on our website. Cookies are small text files stored on your device that help us remember your preferences and understand how you use our site.
Essential Cookies
Required for the website to function correctly — e.g., maintaining your shopping cart and login session. These cannot be disabled.
Analytical Cookies
Currently, no third-party analytics cookies are in use on our website. If we add tools such as Google Analytics or similar in the future, we will update this Policy before activating them and notify you accordingly.
Preference Cookies
Remember your choices such as language, currency, or display preferences.
You can control cookie settings through your browser. Note that disabling essential cookies may affect the functionality of our website.
Data Security
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These include:
- HTTPS encryption across the entire website
- Encrypted storage of sensitive data at rest
- Access controls limiting who within our team can access customer data
- Secure, PCI-DSS compliant payment processing — we never store card details
While we take reasonable precautions, no method of transmission over the internet or electronic storage is 100% secure. In the unlikely event of a data breach that affects your rights or freedoms, we will notify you and the relevant authorities as required by law.
Your Rights
Under the Digital Personal Data Protection Act, 2023 (DPDPA) and other applicable Indian laws, you have the following rights regarding your personal data:
Right to Access
You can request a copy of the personal data we hold about you.
Right to Correction
You can ask us to correct any inaccurate or incomplete personal data.
Right to Erasure
You can request deletion of your personal data, subject to our legal retention obligations.
Right to Withdraw Consent
Where processing is based on consent, you can withdraw it at any time.
Right to Grievance Redressal
You can raise a complaint with us and we are obligated to address it in a timely manner.
Right to Nominate
You may nominate another individual to exercise your data rights in the event of your incapacity.
To exercise any of these rights, please contact us via WhatsApp or email. We will respond within 30 days of receiving your request.
Children's Privacy
Our website and Services are not directed to children under the age of 18 years. We do not knowingly collect personal information from minors. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately and we will delete such information from our systems.
Links to Third-Party Websites
Our website may contain links to third-party websites (such as Instagram, Facebook, or our payment gateway). These third-party sites have their own privacy policies, and we do not accept any responsibility or liability for their practices. We encourage you to review the privacy policies of any third-party sites you visit.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the “Last Updated” date at the top of this page.
We encourage you to review this Policy periodically. Your continued use of our website after any changes constitutes your acceptance of the updated Policy.
Grievance Officer
In accordance with the Information Technology Act, 2000 (and Rules made thereunder, including Rule 5(9) of the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011) and the Digital Personal Data Protection Act, 2023, the details of the Grievance Officer are published below.
If you have any concerns about how your personal data is being processed, you may contact the Grievance Officer. All grievances will be acknowledged within 72 hours and resolved within 30 days of receipt.
Grievance Officer Details
Under the DPDPA 2023, you have the right to raise a complaint with us as the Data Fiduciary. If you are not satisfied with our response, you may approach the concerned authority.
© 2026 Riga Silver. All rights reserved.
