
Last updated 6 September 2026
Draft. This policy has been prepared against the applicable Indian rules but has not yet been reviewed by legal counsel. It must be reviewed before this store accepts live payments.
This notice explains how GHUMR handles your personal data. It is published under Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011, and is written to align with the Digital Personal Data Protection Act 2023 as its rules come into force.
We collect only what an order needs:
We do not collect or store your card number, CVV or expiry date. Payment details are entered inside Razorpay’s own secure window and never reach our servers, our logs, or our analytics.
Data you give us to process an order is used to process that order. We will not use it to market to you unless you separately opted in — which is a distinct checkbox at checkout, unticked by default, and recorded separately. You can withdraw that consent at any time by replying to any message or emailing us.
You can ask us to show you the data we hold about you, correct it, or erase it. Because we do not use accounts, we verify such requests using your order number and a one-time code sent to the phone or email on that order. Write to support@ghumr.in.
We keep what tax law requires us to keep — invoices and order records — for as long as it requires. Everything else is deleted once its purpose is served.
We share your name, phone number and address with the sourcing partner who dispatches your order, and with the courier who delivers it. They receive only what delivery needs. We do not sell your data to anyone, ever.
The site runs over HTTPS. Access to order data is restricted and logged. If a security incident affects your data we will notify the relevant authorities within the timelines required of us, and tell you.
Laxmi, Grievance Officer — support@ghumr.in, 8458970094.