YOUR INFORMATION
Privacy policy
Template — owner review required before launch. This draft describes the website’s current code. The owner must confirm the privacy contact, retention periods, provider arrangements and any applicable requirements. It is not a statement that a compliance review has been completed.
Who operates this store
Aurosa Handcraft, 31, Ghondli Village, Krishna Nagar, Delhi – 110051, India. For a privacy question or request, use our contact page or call +91 8851912062. Owner to confirm: the person responsible for handling privacy requests and a dedicated privacy contact if needed.
Information you provide
Checkout asks for your name, phone, email and delivery address, including an optional landmark. We keep the order items, totals, delivery details, payment method, status and payment references to handle the request and show its progress. A WhatsApp request still needs confirmation from the store.
If you sign in with ChatGPT, we receive your authenticated account identifier, email and display name. You may edit your profile name and phone or save delivery addresses. We do not collect or store your ChatGPT password. There is no newsletter subscription or website contact-message form.
Browsing and essential storage
The first-party lc_session cookie links your browser to its cart, wishlist, recently viewed product IDs and order requests. It is HttpOnly, SameSite=Lax and Secure on HTTPS, and lasts up to one year. Those store records are held in the database. A separate aurosa_submission cookie lasts ten minutes and lets the thank-you page find your recent order; it does not contain your name or address.
We store your analytics preference in browser local storage under aurosa_cookie_consent_v1 for up to six months. This remembers your choice. You can reopen “Cookie settings” at the bottom of the website.
Google Analytics
Analytics is currently disabled because a real Measurement ID has not been configured. Once enabled, Google Analytics 4 will load only after you choose “Accept analytics”, including for visitors in the EU, UK and Switzerland. Rejecting analytics does not prevent shopping.
With consent, analytics can measure public page visits and completed live order-request thank-you views, using Google’s browser identifiers and technical device/visit information. The application does not deliberately send names, emails, phone numbers, addresses or URL query strings. Account, cart, checkout, order-detail and admin pages are excluded. Advertising consent and Google signals remain disabled.
GA cookies, such as _ga and _ga_…, are configured for up to six months. Withdrawal disables measurement, clears accessible first-party GA cookies and reloads the page. Owner to confirm before activation: disable enhanced form-interaction and site-search measurement, choose an appropriate GA data-retention setting and review Google’s processing arrangements. Cookie lifetime is not the same as Google’s stored-data retention.
Other services
- Sites / Cloudflare: provide hosting, database and uploaded-image storage. They process technical requests needed to serve and protect the website. A live response also set Cloudflare’s
__cf_bmbot-management cookie with a 30-minute expiry. Platform logging, other provider cookies and retention must be checked with the host. - ChatGPT: provides the optional hosted sign-in flow. Its own sign-in storage and policies also apply.
- Razorpay: the current integration is restricted to Test Mode. If you initiate an online test payment, Razorpay receives the order reference, amount, name, email and phone. Payment details entered in its checkout are handled by Razorpay; this application does not store card details. Live payments are not enabled by this privacy page.
- WhatsApp: opens only when you follow a WhatsApp link. An order message includes the contact and delivery information shown in your order so you can send it to the store.
- Google Maps and Instagram: external directions/profile links open those services when selected. Maps is not embedded, and Instagram appears only if the store configures a profile link.
These services have their own privacy terms. Owner to confirm: relevant provider agreements, processing locations and any cross-border transfer arrangements.
Security and abuse prevention
Forms are checked on the server and use a hidden spam-trap field and request limits. Network rate counters use a hash of the connecting IP supplied by the host, where available; raw IP addresses are not saved in that rate-limit table. Inactive network counters are cleaned after 24 hours when subsequent traffic runs cleanup. Session/account rate counters are also used. No CAPTCHA is currently loaded.
Owner-only forms manage products, uploaded photos, stock, orders, coupons and store settings. Account and order access checks limit access to the relevant customer or authorised store owner.
Retention and requests
The current application has no automatic expiry for customer profiles, saved addresses, order records, carts, wishlists or recently viewed records. Owner action required: set appropriate retention periods and a deletion process before launch, including any records that must be retained. Customers can remove saved addresses and wishlist entries through the available controls; for other access, correction or deletion requests, contact the store.
We will need to verify that a request relates to your account or order. Owner to confirm: response procedures, applicable rights and any record-retention exceptions. This template does not invent deadlines or promise deletion that the current application cannot automatically perform.
Changes
Review and update this policy when the forms, analytics, payment setup or providers change. Draft prepared on 7 October 2026.
Contact Aurosa Handcraft about privacy