Dr Rumika's
AboutContactSign in

Legal

Privacy Notice

What we collect, why we hold it, how long we keep it, and the rights you have over it.

Last updated 10 August 2026

The short version

We collect what we need to sell you something and get it to you, and very little else. We do not sell your personal data. We do not share it with advertisers. We run no advertising pixels on this site. If you want your data out of our systems, write to us and we will do it.

The rest of this notice is the detail behind that, written out properly because you are entitled to check.

1. Who is responsible for your data

Dr Rumika's is the data controller under the GDPR and the Data Fiduciary under India's Digital Personal Data Protection Act 2023. The operating company's registered name, corporate identity number and registered office are set out in section 18 of the Terms of Sale & Use.

Privacy contact
privacy@bearsystems.in
Grievance Officer
Grievance Officer — info@bearsystems.in
EU representative
TODO — EU Article 27 representative, if appointed
UK representative
TODO — UK representative, if appointed

2. What we collect

Order data
Name, delivery address, billing address, email, telephone, order contents and order history.
Payment data
Handled entirely by Shopify and our payment gateway. We receive a confirmation and the last four digits — never the full card number.
Account data
Only if you create an account: email, password hash, saved addresses.
Correspondence
Emails and messages you send us, and our replies.
Technical data
IP address, browser type and pages requested, in server logs kept for security and fraud prevention.
Marketing preferences
Whether you have subscribed, and whether you have withdrawn.

We do not ask for and do not want special category data — health, biometrics, religion, politics, sexual orientation, caste or tribe. If you volunteer something of that kind in a message to us, we use it only to answer you and delete it when the matter closes.

3. Why we hold it, and on what basis

Fulfilling your order
Performance of a contract (GDPR Art. 6(1)(b)). Under the DPDP Act, the legitimate use of data you gave us for that purpose.
Payment and fraud checks
Legal obligation and legitimate interests in preventing fraud (Art. 6(1)(c) and 6(1)(f)).
Customer service
Performance of a contract, and our legitimate interest in answering you properly.
Tax, accounting and customs records
Legal obligation under Indian tax law and the destination country's customs rules.
Marketing email
Your consent, withdrawable at any time (Art. 6(1)(a); DPDP consent). We do not email you unless you asked us to.
Security and abuse prevention
Legitimate interests in keeping the site and its customers safe.
Optional analytics
Your consent only, given through the cookie banner and withdrawable there. None runs unless you opt in.

4. The concierge

The chat at the foot of the page is answered by a language model, not a person. What you type is sent to our server and on to OpenRouter, which routes it to the model that generates the reply. It is sent so the question can be answered and for no other purpose.

  • No account, name, email or address is attached to a conversation.
  • Conversations are held in your browser for the length of the visit and are gone when the window closes.
  • We do not use conversations to build a profile of you, and we never will.
  • The concierge cannot see your basket, your orders, or anything else about you.
  • It can advise and link. It cannot buy, cancel, refund or change anything.

Please do not type payment details, passwords or anything you would not put in an email. If we ever begin keeping transcripts to learn what people ask for, the notice under the chat window will say so before you type — it is generated from the same setting, so it cannot tell you one thing while we do another.

Messages are limited to ten per half hour per visitor. To count them we hold your IP address in memory for that half hour and then discard it. It is never written to disk and never linked to an order.

5. Who else touches it

We use a small number of service providers, each bound by contract to process data only on our instructions, and none of them permitted to use it for their own purposes.

Shopify
Storefront data, cart, checkout and order records.
Payment gateway
Card authorisation and settlement. Named on the checkout page at the point you pay.
Carriers
Name, address and telephone, to deliver the parcel and to clear customs.
Hosting
Serving this site and its server logs.
Email
Transactional email, and marketing email if you subscribed.
OpenRouter
Routes concierge messages to a language model and returns the reply. Sees the conversation, nothing else.

We disclose data to law enforcement or a regulator only where we are legally obliged to, and we satisfy ourselves that the request is lawful before we do. We do not sell personal data, and we do not share it for cross-context behavioural advertising as the CPRA defines that term. We have never done either.

6. Sending data abroad

We are based in India and we ship worldwide, so data crosses borders. Where data leaves the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses, the UK Addendum where relevant, and a transfer risk assessment. Under the DPDP Act, transfers out of India are permitted except to countries the Central Government restricts, and we monitor that list.

7. How long we keep it

Order and tax records
Eight years from the end of the financial year, to meet Indian tax and company law retention requirements.
Account data
Until you close the account, then 90 days.
Correspondence
Three years from the last message, so we can pick up a thread and defend a claim.
Marketing list
Until you unsubscribe, then a permanent suppression record so we do not email you again by accident.
Server logs
90 days.
Cookie consent record
12 months, so we can show what you chose and when.

8. Your rights

Whichever law applies to you, we will honour the strongest version of these rights rather than argue about which regime you fall under.

  • Access — a copy of what we hold about you.
  • Correction — fix anything wrong or incomplete.
  • Erasure — delete it, unless we are legally required to keep it.
  • Portability — a machine-readable copy to take elsewhere.
  • Restriction and objection — stop or limit a particular use, including any based on legitimate interests.
  • Withdraw consent — at any time, without affecting what was lawful before you withdrew.
  • Nominate — under the DPDP Act, nominate someone to exercise your rights if you die or become incapacitated.
  • Opt out of sale or sharing — under the CPRA. Nothing to opt out of here, because we do neither, but the right stands.
  • Non-discrimination — we will not give you a worse price or service for exercising any of this.

Write to privacy@bearsystems.in. We reply within 30 days. If we need longer because a request is complex, we will tell you why before the 30 days are up. We do not charge for this.

If we get it wrong, you can complain to your supervisory authority: the Data Protection Board of India, your EU member state authority, or the UK Information Commissioner's Office. We would rather you told us first, but that is your choice, not a precondition.

9. Children

This site is not for children. We do not knowingly collect data from anyone under 18. The DPDP Act requires verifiable parental consent before processing a child's data and prohibits behavioural advertising directed at children — we avoid the question entirely by neither targeting nor knowingly serving them. If you believe we hold a child's data, tell us and we will delete it.

10. How we protect it

  • The whole site is served over HTTPS.
  • Payment card data never reaches our servers.
  • The cart cookie is httpOnly and same-site, so a script cannot read it and another site cannot send it.
  • Access to order data is limited to people who need it to do their job.
  • Credentials are held as environment secrets, never in the codebase.

If a breach happens that puts you at risk, we will tell you and the relevant regulator. The DPDP Act requires notification to the Data Protection Board and to affected Data Principals; the GDPR requires notification within 72 hours where the risk warrants it.

11. Changes to this notice

We date every version. If we change how we use data in a way that would surprise you, we will tell you directly rather than rely on you noticing a new date at the top of a page.