← Adonai Reserve

Privacy Policy

What this shop collects about you, why it needs it, which companies receive it, how long it is kept and how to get it deleted. Every field named here is one that genuinely exists. This page is written from the database, not from a template.

In effect from

Governed by the laws of India

01

The short version

  • We collect what an order needs and almost nothing else: your name, email, phone, delivery address and what you bought.
  • We run no analytics and no advertising trackers. There is no Google Analytics, no Meta pixel and no session recorder on this site, and nothing here follows you around the web. The only cookie we set keeps you signed in; the only other one you will meet is Razorpay’s, during payment, and clause 5 covers both. Nobody is building a profile of you here.
  • We never see your payment details. Card numbers, UPI IDs and bank credentials go straight to Razorpay and never touch our servers.
  • Your address goes to the people who make and deliver the piece, because that is the only way it can reach you.
  • You can have your account and your personal data deleted by writing to adonai.reserve@gmail.com.

02

What we collect, and why

Account
Your name, email address and phone number, and a password you set. The password is stored only as a bcrypt hash, a one-way scramble. We cannot read it, recover it or tell you what it is, and neither can anyone who obtains the database.
Addresses
The billing and delivery addresses you save or enter at checkout: name, street, city, state, postcode, country and phone. Needed to quote shipping and to get the parcel to you.
Orders
What you bought, in which size, what it cost, which delivery service you chose, the delivery address for that order, its status, and any tracking number and carrier. Kept as the record of the sale.
Payment references
The identifiers Razorpay gives an order and a payment, whether it succeeded, and when. These are references to a transaction, not a means of making one.
Inner Circle
Only if you join from the footer: your email address, when you joined, and when you left. Used for Inner Circle mail and nothing else. Every message carries a link to leave, and leaving takes effect at once.
Sessions
For each device you sign in on: the IP address and browser user-agent at sign-in, when it was created, when it was last used and when it expires. This is what expires a stale sign-in on its own, what lets changing your password sign out every other device, and what makes a stolen session detectable.

That is the whole of it. We do not ask for a date of birth, a gender, an occupation or any of the other fields a shop collects because a form template had a slot for them.

03

What we do not collect

No card details, ever

When you pay, Razorpay’s own hosted form opens over this site. Your card number, CVV, UPI PIN and bank credentials are entered there and are transmitted to Razorpay, not to us. They are never sent to this server and never stored in our database. What we receive back is a payment reference and a cryptographic signature confirming the payment was genuine.

We also do not run behavioural analytics, advertising pixels, heat-mapping or session replay, and we do not buy, sell, rent or enrich customer data. This site sets no third-party cookie of any kind.

04

Who else receives it

Three companies are involved in getting a piece to you, and each receives the part of your data its job requires. They are named rather than described as “trusted partners”, because you are entitled to know who holds your home address:

Printify
Recipient name, delivery address, phone number, and the items ordered. Printify passes these to the print provider that makes the piece and to the carrier that delivers it.Printify privacy policy ↗
Razorpay
Billing name, email address, phone number, and the order amount. Card, UPI and bank details are entered on Razorpay's own hosted form and are never transmitted to or stored by us.Razorpay privacy policy ↗
Render
Everything stored by the shop, as the infrastructure it runs on. Account records, order records and session records sit in a managed database operated by Render.Render privacy policy ↗
Google
Your email address and the emails we send you: order confirmations, and Inner Circle mail if you joined it. Sent through Google's Gmail service.Google privacy policy ↗

Beyond these, we disclose data only where the law requires it (a court order, a tax authority, or a lawful request we are obliged to answer) and to professional advisers bound by confidentiality. If the business is ever sold or transferred, customer records may pass to the buyer, who would be bound by this policy.

05

Cookies

This site uses cookies for one purpose: keeping you signed in. There is no cookie banner because there is nothing here that a banner would need to ask you about. No tracking, no profiling, no advertising.

adonai_rt
The sign-in cookie. It holds a refresh token that lets your browser get a new access token without making you log in again on every visit. It is HTTP-only, so no script on the page can read it, and it is marked Secure in production so it only travels over HTTPS. It lasts 30 days, and signing out deletes it.
Razorpay's cookies
Set by Razorpay’s payment form during checkout, under their own domain and their own policy, for fraud prevention and to keep the payment session working. We cannot read them. Razorpay privacy policy ↗

Your browser can block or clear either. Blocking the sign-in cookie means you cannot stay signed in, and so cannot check out.

06

Where your data is held

The shop’s database and servers are operated by Render. Our production partner and our payment provider process data in their own locations, and the business itself is established in India.

In practice this means that if you order from the United States, your delivery details cross borders: to the business in India, and to whichever print facility and carrier is closest to you. That is inherent in buying from abroad, and we mention it because a policy that quietly omits it is hiding the obvious.

07

How long it is kept

Account data
For as long as your account exists. Ask us to delete it and it goes, subject to the order records below.
Order records
Kept after an account is deleted, for as long as tax and accounting law requires a seller to be able to evidence a sale. These are the record of a transaction that happened; they are not something either of us can simply erase.
Inner Circle
Kept while you are in it. When you leave, the address stays only as a record that you left, so you are never mailed again. Ask and we will delete it outright.
Sessions
Expire on their own, and are removed when they do or when you sign out or revoke the device.

08

Your rights

Wherever you live, and whatever framework applies to you, we will honour the following. Write to adonai.reserve@gmail.com from the email address on the account and we will answer within 2 business days.

  • See it. A copy of everything held about you.
  • Correct it. Most of it you can edit yourself in your profile; anything you cannot, we will.
  • Delete it. Your account and its personal data, except the order records clause 7 explains we must keep.
  • Take it with you. Your data in a machine-readable file.
  • Object. Tell us to stop processing it, or to stop sending you anything you signed up for. Note that this does not stop the order confirmation we send when you pay, or the despatch notification our production partner sends when a parcel you have ordered is handed to the carrier. Those are part of fulfilling the order, not marketing: they are the record of what you bought and where your parcel is.

California residents: we do not sell or share personal information as those terms are defined under the CCPA, and we do not offer financial incentives in exchange for personal information. The rights above cover the access and deletion rights that statute provides.

09

Security

Concretely, and only what is actually true of this system:

  • Everything moves over HTTPS. There is no unencrypted route into the shop.
  • Passwords are stored as bcrypt hashes at a deliberately slow cost factor, never as text and never reversibly encrypted.
  • Sign-in uses short-lived access tokens with rotating refresh tokens, so a token captured once cannot be replayed indefinitely, and reuse of an old one is detectable.
  • The sign-in cookie is HTTP-only and, in production, Secure. It cannot be read by a script and will not travel over plain HTTP.
  • No payment credential is stored, because none is ever received.

No system is perfect, and a policy that claimed otherwise would be the least trustworthy sentence on this page. If we ever discover a breach affecting your data, we will tell you and the relevant authority as the law requires.

10

Children

This shop is not directed at children. We do not knowingly collect data from anyone under 16, and an account may only be created by someone 18 or over. If you believe a child has given us data, write to adonai.reserve@gmail.com and we will delete it.

11

Changes, and how to reach us

If this policy changes, the revised version appears here with a new effective date at the top of the page. The date is what tells you whether it has moved since you last read it, which is why it is set by hand rather than by the build. It marks a change in the text, not a deploy.

Questions, requests and complaints about privacy all go to the same place: adonai.reserve@gmail.com. Full contact details are on the Contact Us page.