Privacy Policy
Last updated: 30 September 2026
Abdul Rahim AlMasi ("we", "us", "our") sells ittars, attars and fragrances through this website. This policy explains what personal data we collect when you browse, create an account or place an order, why we collect it, and the choices you have. By using this site you agree to the collection and use of information as described here.
1. Information we collect
- Account details — your name and email address, plus an optional mobile number, whether you sign in with a password or with your Google account.
- Delivery addresses — full name, phone number, address, city, state, PIN code and country for anyone you ship an order to.
- Order & payment information — items purchased, order value and status, and a payment reference from our payment partner. We never see or store your full card number, CVV or UPI PIN — those are entered directly on our payment partner's secure page.
- Guest checkout — if you check out as a guest, we keep only the order and the delivery details you enter for that order; no account is created and no password is set.
- Your password — stored only as a one-way bcrypt hash. We never store, and cannot read, your actual password.
- Email confirmation & password reset links — these carry a signed token that expires on its own (24 hours and 2 hours respectively). Nothing extra is stored, and a reset link stops working the moment it is used.
- Communications — messages you send us by email or WhatsApp, and any replies.
- Technical data — standard web request data (IP address, browser/device type, pages visited) collected automatically by our server logs, and a session cookie used to keep you signed in and remember your cart.
2. How we use your information
- To create and manage your account, and to verify it's really you when you sign in.
- To process, pack, ship and deliver your orders, and to keep you updated on their status.
- To process payments and refunds through our payment partner, and to prevent fraud.
- To respond to your questions, and to send order-related emails or WhatsApp messages (such as confirmations, shipping updates, or replies to a chat you started).
- To improve the site and troubleshoot errors.
- To meet our legal, tax and accounting obligations.
We do not sell your personal data to anyone, and we do not use it for third-party advertising.
3. Who we share it with
We share only what each service needs to do its job:
- Razorpay — our payment gateway, to process card, UPI, netbanking and wallet payments, and refunds.
- Google — if you choose "Sign in with Google", to verify your identity; also for Google Fonts and Search Console on this site.
- Our email provider — to deliver account emails (confirmation and password-reset links) and order updates.
- WhatsApp — only if you tap our WhatsApp button to start a chat with us; that conversation is then subject to WhatsApp's own privacy policy.
- Courier/logistics partners — your name, phone number and delivery address, solely to deliver your order.
- Law enforcement or regulators — only where required by law.
4. Cookies
We use a small number of strictly necessary cookies — to keep you signed in, remember the items in your cart, and protect the site against cross-site request forgery. We do not currently use advertising or cross-site tracking cookies.
5. Data retention
We keep order records for as long as needed to handle warranty, tax, accounting and legal requirements. Confirmation and password-reset links expire on their own within hours. If you ask us to delete your account, we'll remove your personal profile data, but we may retain order records where we're legally required to.
6. Your rights & choices
- You can review and update your name, email and saved addresses any time from My Account.
- You can ask us to access, correct or delete your personal data, or to stop marketing messages, by contacting us (details below).
- Guest checkout customers can make the same request by contacting us with their order number.
7. Security
Passwords are stored only as a one-way bcrypt hash, never in readable form, and password-reset links expire within two hours and can be used only once. Payment details are handled directly by our PCI-DSS compliant payment partner and never touch our servers. We use industry-standard measures to protect the data we do hold, but no method of transmission or storage is 100% secure.
8. Children's privacy
This site is intended for adults. We do not knowingly collect data from children.
9. Changes to this policy
We may update this policy from time to time; the "Last updated" date above will change when we do. Continued use of the site after an update means you accept the revised policy.
10. Contact us
For any privacy question, or to exercise your rights above, contact us at the email address listed on our contact details .