Privacy policy
This policy summarizes the information used by the Al Azhari Perfumes storefront, customer account, and order workflows. The legal operator details, retention schedule, and formal privacy-request process still require business and legal approval.
Draft for business and legal reviewWho operates this site
The site is presented as Al Azhari Perfumes. The legal name and business form of the operator, its full postal address, and the person responsible for privacy requests have not been supplied. They must be added before this draft is published as the final policy.
Business contact: alazhariperfumes07@gmail.com; +91 93283 36696; +91 98798 82433. These details do not replace the legal identity, registered or principal address, or any formally appointed grievance contact that must be supplied.
What this policy covers
This policy covers browsing, customer accounts, product discovery, wishlist, address book, order placement, order history, notifications, and contact enquiries. Read it with the Cookie Policy, Terms of Service, Shipping & Delivery, and Returns pages.
Orders are recorded in the store database with payment pending until an administrator verifies manual payment. The website does not process card payments.
Information used by the site
If you create an account, the authentication provider processes your email address, password, and session. The store keeps your profile name and phone number. Session tokens are held in HTTP-only cookies. The browser bag stores product slugs, selected size IDs, and quantities in local storage; it is refreshed against the published catalog before checkout.
If you save an address, the store stores its recipient, phone, street, city, state, postal code, country, and default-selection state. Wishlist entries, notification preferences, and notification read status are stored with your customer record.
When you place an order, the store records the order number, items, quantities, catalog prices, product subtotal, delivery charge if set, total, delivery-address snapshot, payment status, and fulfillment/tracking details. No card number, security code, or online payment credential is collected. Contact enquiries may include the name, email address, and message you submit; the configured email service forwards them to the store inbox. Telephone and email links let you contact the business directly. Please do not send passwords or payment-card details through ordinary email.
When a page is requested, the browser and website host exchange technical information needed to deliver it. The production hosting provider, technical log fields, access controls, storage location, and retention period have not been confirmed and must be documented before launch.
Purposes for using information
Information is used to authenticate customers, maintain profiles and addresses, provide wishlist and order history, reserve inventory, confirm manual payments, fulfil and track orders, send order-status notifications, answer enquiries, and protect the service from misuse.
If the site later adds accounts, checkout, payments, delivery, analytics, advertising, chat, or other tools, this policy must be updated before those functions collect or share personal information. The business must document each purpose and the information actually needed for it.
Cookies and similar storage
The shopping bag uses browser local storage. Authentication sessions use HTTP-only cookies. The current application code does not intentionally load advertising pixels or analytics scripts. The Cookie Policy describes this storage in more detail.
The final hosting, security, and delivery services have not been confirmed. They may use strictly necessary cookies or similar technologies. The business must identify those technologies, purposes, providers, and lifetimes after the production setup is selected.
Service providers and disclosures
The application is configured to use Supabase for authentication, database access, and product-image storage, and Resend for contact enquiry email delivery. Hosting and delivery providers depend on deployment and fulfilment choices. No payment processor is enabled. The business should identify the production hosting, database, email, and delivery providers and describe their data access before launch.
The business must document any disclosure required to protect the site, respond to a valid legal request, handle a dispute, or complete a customer-requested transaction. This draft does not claim that a particular disclosure has occurred.
Storage location and transfers
Profile, saved address, wishlist, and order information are stored server-side with the store database. The shopping bag remains in local browser storage until changed or cleared. Actual hosting region, provider access locations, and any cross-border processing must be verified against the deployed project settings.
Before launch, the operator should record the countries in which its providers store or access personal information and review the safeguards and legal requirements that apply to those arrangements.
Retention and deletion
You can remove saved addresses and wishlist entries through your account. Account deletion is available online only when the store has configured the required secure administration credential; otherwise contact the store to request deletion. Order records may be de-identified and retained where business or legal recordkeeping requires. A complete retention schedule still needs business approval.
The business must set retention periods for support enquiries, technical logs, customer records, orders, payment references, and any legal or accounting records before enabling transactions. It should delete or de-identify information when the applicable purpose and retention requirement have ended.
Security
The business should protect personal information with safeguards appropriate to the information and systems involved, restrict access to people who need it, and maintain a process for investigating suspected security incidents. No policy statement can guarantee that transmission or storage will be completely secure.
The application limits customer account records to authenticated customer workflows and checks that account data belongs to the signed-in customer. Administrator routes require an active administrator role. Deployment access controls, backups, incident contacts, and incident-notification procedures still require operational confirmation.
Your questions and privacy requests
For a privacy question or a request relating to information you sent directly to the business, email alazhariperfumes07@gmail.com. Include enough detail for the business to understand the request, but do not include passwords or full payment credentials.
The business must approve an identity-check process, request-handling owner, response workflow, and any notices required by applicable law. Rights and time limits depend on the law in force and the person’s circumstances; this draft does not promise a legal outcome or deadline.
Children
The business has not provided an age policy or a process for information relating to children. Before adding accounts, targeted content, or a feature likely to collect children’s personal information, the operator must obtain legal advice and set appropriate age, consent, and safety controls.
Changes and approval
The business may need to revise this policy when its practices, technology, providers, or applicable requirements change. The final published version should show an accurate effective date and a way to identify material changes.
This document is a development draft for business and qualified legal review. The full operator identity, hosting and vendor details, data-retention schedule, privacy-request process, and production data flows must be confirmed before launch.
