// privacy policy
YOUR DATA.
PLAINLY PUT.
Last updated — 16 August 2026
We collect what we need to print a tee and get it to your door, and not much else. We don't run advertising trackers, we don't build profiles on you, and we don't sell anything about you to anyone.
// we never see your card. we never sell your data.
// contents
Who we are
Archonic is a clothing brand operating as a sole proprietorship trading as “Archonic”, based in India. This policy covers everything you do on our website and every email we send you.
- Contact: archonicstore@gmail.com
- Address: your business address
For the purposes of India's Digital Personal Data Protection Act, 2023, Archonic is the Data Fiduciary for the personal data described below, and you are the Data Principal.
What we collect
When you create an account: your name, your email address, and a password. The password is stored only as a one-way hash — we cannot read it, recover it, or tell you what it is.
When you place an order: the delivery name, email address, phone number, street address, city, state, country and PIN/postal code you enter at checkout, plus what you ordered — product, size, colour and quantity.
When you pay: a reference number for the transaction. See the next section for what we don't get.
When you use a promo or referral code: the code, so we can apply your discount and credit the right person.
Automatically: a two-letter country code, derived from your connection and used only to decide whether to show you rupees or dollars. If you arrive through a referral link we record that the visit happened — a timestamp against that code, with nothing that identifies you. Our hosting provider keeps standard server logs, as any web host does.
When you contact us or subscribe: whatever you put in the email, and your email address if you sign up for drop announcements.
What we deliberately don't
Some of this is worth stating outright, because the absence is the point:
- We never see your card, UPI ID or bank details. Payments are handled entirely by our payment processor on their own systems. What comes back to us is a transaction ID and a yes or no — never a card number, never a CVV.
- No advertising or analytics trackers. There is no Google Analytics, no Meta pixel, no ad network, and no third-party tracking cookie anywhere on this site.
- No profiling, no automated decisions. We don't score you, segment you, or let software decide anything about you that has an effect on you.
- We never sell, rent or trade your personal data. Not to advertisers, not to data brokers, not to anyone.
Why we use it
- To fulfil your order — send your name, address and phone to our print and delivery partner, and to keep you updated on it
- To run your account — sign you in, show you your order history, let you cancel an eligible order and reset your password
- To take payment and to verify that a payment genuinely came from our payment processor
- To show the right currency and the right delivery options for your country
- To prevent abuse — rate limiting, and spotting fraudulent or repeatedly refused orders
- To meet legal obligations — keeping order and tax records for as long as the law requires
- To send you drops, but only if you asked us to
We rely on your consent for marketing, on the necessity of performing our contract with you for everything to do with your order and account, and on our legitimate interest in running a shop that isn't defrauded for the abuse-prevention parts.
Where your data lives
Our database is hosted in Mumbai, India. Our website is served from a global network, so a request may be handled by a server outside India, and our payment, fulfilment and email providers may process data on their own infrastructure, which for some of them is outside India.
Where data does leave India, it goes only to the providers listed above, only for the purposes listed above, and under the terms of our agreements with them.
How long we keep it
- Account details — until you ask us to delete the account.
- Orders, addresses and payment references — retained for up to 8 years, because Indian tax and accounting law requires us to keep transaction records. This is the one category we can't delete on request while the obligation lasts.
- Password reset links — stored as a hash, expire quickly, and are invalidated the moment they're used.
- Referral click records — kept indefinitely, but they contain no personal data.
- Newsletter subscriptions — until you unsubscribe.
Your rights
You can ask us to:
- Show you what personal data we hold about you and who we've shared it with
- Correct anything that's wrong or out of date
- Delete your account and personal data, subject to the retention obligation above
- Withdraw consent for marketing at any time, without affecting your orders
- Nominate someone to exercise these rights on your behalf if you die or become incapacitated, as the DPDP Act provides
- Complain — to us first, and then to the Data Protection Board of India if we haven't resolved it
Email archonicstore@gmail.com from the address on your account. We'll acknowledge within 2 working days and complete the request within 30 days. It's free — we won't charge you to see or delete your own data.
If you're ordering from outside India, you may have additional rights under your own local law, including data portability and objection. Ask and we'll honour them.
Marketing emails
We only email you about drops if you subscribed. Every one of those emails has an unsubscribe option, and you can also just reply and ask.
Transactional emails are separate — order confirmations, cancellations, shipping updates and password resets. Those aren't marketing and you can't opt out of them while you have an active order, because they're how we tell you what happened to your money.
How we protect it
- The whole site runs over HTTPS.
- Passwords are stored as one-way hashes, never in a readable form.
- Payment confirmations are cryptographically verified before an order is marked paid.
- Admin pages and APIs check your role on every request, on the server.
- Sensitive routes are rate limited, and reset links are single-use and short-lived.
That said, no website can promise perfect security, and we won't claim it. If a breach ever affects your personal data, we will notify you and the Data Protection Board of India as the law requires.
Children
Archonic isn't directed at children. If you are under 18, you may only use this site and place orders with the involvement of a parent or guardian, who is responsible for the order.
We don't knowingly collect personal data from anyone under 18 without verifiable guardian consent, and we don't advertise to children or track them. If you believe a child has given us personal data, email us and we'll delete it.
Changes to this policy
If we change how we handle your data, we'll update this page and move the “last updated” date at the top. For anything significant — a new category of data, a new partner receiving it — we'll tell account holders by email rather than expecting you to notice.
Contact & grievances
Privacy questions, data requests and complaints all go to the same place, and a person reads them:
- Email: archonicstore@gmail.com
- Grievance Officer: name of grievance officer
- Address: your business address
We acknowledge grievances within 48 hours and aim to resolve them within 30 days, as required by the Consumer Protection (E-Commerce) Rules, 2020 and the Information Technology Rules, 2021.