Privacy policy
QYROVIA FABRICS PRIVATE LIMITED · Last reviewed 23 August 2026
Who is responsible for your data
QYROVIA FABRICS PRIVATE LIMITED, at 3rd Floor, North Block, ANo-312, Astra Towers, 2C/1, Rajarhat, New Town, North 24 Parganas, West Bengal 700161, India, is the Data Fiduciary for the personal data described here. Contact us at info@qyroviafab.com.
This policy explains our practices under the Digital Personal Data Protection Act, 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
What we collect
You give us: name, email, mobile number, delivery and billing address, GSTIN if you ask for a business invoice, order and return history, reviews and photographs you upload, and messages you send us.
We generate: order numbers, invoice numbers, loyalty of purchase patterns, and support ticket history.
We collect automatically: IP address, device and browser type, pages viewed, referring URL, and cookie identifiers. See the Cookie Policy for detail.
We do not collect your full card number, CVV, UPI PIN or net-banking password. Those are entered on the payment gateway's own page and never reach our servers.
We do not knowingly collect data from children under 18. If you believe a child has given us data, write to info@qyroviafab.com and we will erase it.
Why we use it, and on what basis
| Purpose | What we use | Basis |
|---|---|---|
| Fulfilling your order, invoicing, delivery | Name, contact, address, GSTIN | Performance of the contract |
| Payment processing and fraud checks | Order value, transaction reference, IP | Contract and legitimate use |
| Customer support and returns | Order history, correspondence | Contract |
| Statutory records — GST, income tax, company law | Invoice data | Legal obligation |
| Marketing emails and messages | Email, mobile, purchase history | Your consent, withdrawable at any time |
| Improving the site and catalogue | Aggregated, de-identified usage data | Legitimate use |
We do not sell your personal data. We do not use it to make solely automated decisions that have a legal effect on you.
Who we share it with
Only with parties who need it to deliver your order, and only to that extent:
- Payment gateways — Razorpay, PhonePe, Cashfree or Stripe, depending on how you pay
- Courier and logistics partners — your name, address and phone, so they can deliver
- Cloud hosting and storage providers, under contractual confidentiality
- Communication providers for transactional email and SMS
- Analytics providers, where you have consented to analytics cookies
- Professional advisers, auditors and authorities, where the law requires it
Every processor is bound by a written agreement to use the data only on our instructions and to keep it secure.
Where it is stored, and for how long
Data is stored on servers in India, or in a country not restricted by the Central Government under section 16 of the DPDP Act. Payment gateway data may be processed under the gateway's own arrangements.
- Order and invoice records: 8 years from the end of the relevant financial year, as required under GST and company law
- Account data: while your account is open, then 12 months
- Support correspondence: 3 years
- Marketing consent records: until withdrawn, plus 2 years to evidence the withdrawal
- Server and access logs: 180 days
After these periods the data is deleted or irreversibly anonymised.
Your rights
Under the DPDP Act you may:
- Access a summary of the personal data we hold about you and how it is processed
- Correct data that is inaccurate, and complete or update data that is incomplete
- Erase data we no longer need for the purpose it was collected, subject to our statutory retention duties
- Withdraw consent at any time, for anything we do on the basis of consent
- Nominate another person to exercise these rights if you die or become incapacitated
- Complain to us, and then to the Data Protection Board of India
Write to info@qyroviafab.com with "DPDP request" in the subject line. We respond within 30 days. We may ask you to verify your identity first — that is a protection for you, not an obstacle.
Marketing
We send marketing only if you opt in. Every message carries a one-click unsubscribe, and you can also reply STOP to a WhatsApp or SMS message. Transactional messages about an order you placed — dispatch, delivery, refund — are not marketing and continue regardless.
How we protect it
Transport encryption (TLS) across the whole site; passwords stored only as bcrypt hashes; payment credentials encrypted at rest with AES-256-GCM; role-based access so staff see only what their job needs; audit logging of administrative actions; and periodic review of access rights.
No system is perfectly secure. If a breach occurs that is likely to affect you, we will notify you and the Data Protection Board as the DPDP Act requires, and tell you plainly what happened and what to do.
Cookies
See the Cookie Policy. You can reject non-essential cookies without losing the ability to shop.
Changes
We will post any update here and change the review date. If a change is material we will tell you by email or a notice on the site before it takes effect.
Grievance Officer
Complaints about how we handle your data go to our Grievance Officer, appointed under the IT Rules, 2021 — see the Grievance Redressal Policy for the name, email and response timeline.
Not covered here?
Write to info@qyroviafab.com or WhatsApp +91 9975399914. We answer during monday to saturday, 10:00–18:30 ist.