Legal
Privacy Notice
What we collect, why we hold it, how long we keep it, and the rights you have over it.
Last updated 10 August 2026
The short version
We collect what we need to sell you something and get it to you, and very little else. We do not sell your personal data. We do not share it with advertisers. We run no advertising pixels on this site. If you want your data out of our systems, write to us and we will do it.
The rest of this notice is the detail behind that, written out properly because you are entitled to check.
1. Who is responsible for your data
Dr Rumika's is the data controller under the GDPR and the Data Fiduciary under India's Digital Personal Data Protection Act 2023. The operating company's registered name, corporate identity number and registered office are set out in section 18 of the Terms of Sale & Use.
- Privacy contact
- privacy@bearsystems.in
- Grievance Officer
- Grievance Officer — info@bearsystems.in
- EU representative
- TODO — EU Article 27 representative, if appointed
- UK representative
- TODO — UK representative, if appointed
2. What we collect
- Order data
- Name, delivery address, billing address, email, telephone, order contents and order history.
- Payment data
- Handled entirely by Shopify and our payment gateway. We receive a confirmation and the last four digits — never the full card number.
- Account data
- Only if you create an account: email, password hash, saved addresses.
- Correspondence
- Emails and messages you send us, and our replies.
- Technical data
- IP address, browser type and pages requested, in server logs kept for security and fraud prevention.
- Marketing preferences
- Whether you have subscribed, and whether you have withdrawn.
We do not ask for and do not want special category data — health, biometrics, religion, politics, sexual orientation, caste or tribe. If you volunteer something of that kind in a message to us, we use it only to answer you and delete it when the matter closes.
3. Why we hold it, and on what basis
- Fulfilling your order
- Performance of a contract (GDPR Art. 6(1)(b)). Under the DPDP Act, the legitimate use of data you gave us for that purpose.
- Payment and fraud checks
- Legal obligation and legitimate interests in preventing fraud (Art. 6(1)(c) and 6(1)(f)).
- Customer service
- Performance of a contract, and our legitimate interest in answering you properly.
- Tax, accounting and customs records
- Legal obligation under Indian tax law and the destination country's customs rules.
- Marketing email
- Your consent, withdrawable at any time (Art. 6(1)(a); DPDP consent). We do not email you unless you asked us to.
- Security and abuse prevention
- Legitimate interests in keeping the site and its customers safe.
- Optional analytics
- Your consent only, given through the cookie banner and withdrawable there. None runs unless you opt in.
4. The concierge
The chat at the foot of the page is answered by a language model, not a person. What you type is sent to our server and on to OpenRouter, which routes it to the model that generates the reply. It is sent so the question can be answered and for no other purpose.
- No account, name, email or address is attached to a conversation.
- Conversations are held in your browser for the length of the visit and are gone when the window closes.
- We do not use conversations to build a profile of you, and we never will.
- The concierge cannot see your basket, your orders, or anything else about you.
- It can advise and link. It cannot buy, cancel, refund or change anything.
Please do not type payment details, passwords or anything you would not put in an email. If we ever begin keeping transcripts to learn what people ask for, the notice under the chat window will say so before you type — it is generated from the same setting, so it cannot tell you one thing while we do another.
Messages are limited to ten per half hour per visitor. To count them we hold your IP address in memory for that half hour and then discard it. It is never written to disk and never linked to an order.
5. Who else touches it
We use a small number of service providers, each bound by contract to process data only on our instructions, and none of them permitted to use it for their own purposes.
- Shopify
- Storefront data, cart, checkout and order records.
- Payment gateway
- Card authorisation and settlement. Named on the checkout page at the point you pay.
- Carriers
- Name, address and telephone, to deliver the parcel and to clear customs.
- Hosting
- Serving this site and its server logs.
- Transactional email, and marketing email if you subscribed.
- OpenRouter
- Routes concierge messages to a language model and returns the reply. Sees the conversation, nothing else.
We disclose data to law enforcement or a regulator only where we are legally obliged to, and we satisfy ourselves that the request is lawful before we do. We do not sell personal data, and we do not share it for cross-context behavioural advertising as the CPRA defines that term. We have never done either.
6. Sending data abroad
We are based in India and we ship worldwide, so data crosses borders. Where data leaves the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses, the UK Addendum where relevant, and a transfer risk assessment. Under the DPDP Act, transfers out of India are permitted except to countries the Central Government restricts, and we monitor that list.
7. How long we keep it
- Order and tax records
- Eight years from the end of the financial year, to meet Indian tax and company law retention requirements.
- Account data
- Until you close the account, then 90 days.
- Correspondence
- Three years from the last message, so we can pick up a thread and defend a claim.
- Marketing list
- Until you unsubscribe, then a permanent suppression record so we do not email you again by accident.
- Server logs
- 90 days.
- Cookie consent record
- 12 months, so we can show what you chose and when.
8. Your rights
Whichever law applies to you, we will honour the strongest version of these rights rather than argue about which regime you fall under.
- Access — a copy of what we hold about you.
- Correction — fix anything wrong or incomplete.
- Erasure — delete it, unless we are legally required to keep it.
- Portability — a machine-readable copy to take elsewhere.
- Restriction and objection — stop or limit a particular use, including any based on legitimate interests.
- Withdraw consent — at any time, without affecting what was lawful before you withdrew.
- Nominate — under the DPDP Act, nominate someone to exercise your rights if you die or become incapacitated.
- Opt out of sale or sharing — under the CPRA. Nothing to opt out of here, because we do neither, but the right stands.
- Non-discrimination — we will not give you a worse price or service for exercising any of this.
Write to privacy@bearsystems.in. We reply within 30 days. If we need longer because a request is complex, we will tell you why before the 30 days are up. We do not charge for this.
If we get it wrong, you can complain to your supervisory authority: the Data Protection Board of India, your EU member state authority, or the UK Information Commissioner's Office. We would rather you told us first, but that is your choice, not a precondition.
9. Children
This site is not for children. We do not knowingly collect data from anyone under 18. The DPDP Act requires verifiable parental consent before processing a child's data and prohibits behavioural advertising directed at children — we avoid the question entirely by neither targeting nor knowingly serving them. If you believe we hold a child's data, tell us and we will delete it.
10. How we protect it
- The whole site is served over HTTPS.
- Payment card data never reaches our servers.
- The cart cookie is httpOnly and same-site, so a script cannot read it and another site cannot send it.
- Access to order data is limited to people who need it to do their job.
- Credentials are held as environment secrets, never in the codebase.
If a breach happens that puts you at risk, we will tell you and the relevant regulator. The DPDP Act requires notification to the Data Protection Board and to affected Data Principals; the GDPR requires notification within 72 hours where the risk warrants it.
11. Changes to this notice
We date every version. If we change how we use data in a way that would surprise you, we will tell you directly rather than rely on you noticing a new date at the top of a page.