The whole policy in one paragraph
AimsCraft collects only what it needs to take your order, deliver it and answer you afterwards: your name, delivery address, phone, email, order history and the technical basics your browser sends. We never sell or rent personal data, we never store full card numbers, and the only third party that sees your address is the courier carrying your parcel. You can ask for a copy of everything we hold, or ask us to delete it, by writing to privacy@aimscraft.com — we answer within 30 days.
At a glance
DPDP Act 2023 · GDPR- Data controller
- AimsCraft Pvt. Ltd., Watergam, Rafiabad, Baramulla, Jammu & Kashmir 193303, India
- Data protection officer
- privacy@aimscraft.com
- Governing law
- Digital Personal Data Protection Act 2023 (India); UK/EU GDPR for those customers
- Data sold or rented
- Never — to anyone, for any price
- Card numbers stored
- None. Payments are tokenised by our RBI-licensed gateway
- Where data lives
- AWS Mumbai (ap-south-1), India
- Standard retention
- 8 years for invoices (tax law), 24 months for browsing data
- Rights request turnaround
- 30 days, free of charge, once per quarter
1Who we are, and what this policy covers
AimsCraft Pvt. Ltd. is the data controller for aimscraft.com, and this policy covers every piece of personal data the website, the mobile experience and our three Kashmir stores collect from you.
We are a private limited company registered in Jammu & Kashmir, India, trading as AimsCraft from Watergam, Rafiabad, Baramulla, Jammu & Kashmir 193303. “We”, “us” and “AimsCraft” in this document always mean that company.
This policy applies when you browse the site, place an order, create an account, subscribe to the newsletter, write a review, use the WhatsApp support line, or walk into one of our shops and give us an address for a delivery. It does not apply to sites we link to — a courier tracking page, for example, has its own policy and its own controller.
It sits alongside three other documents you may want open: the Cookie Policy, which itemises every cookie and browser-storage key we set; the Terms & Conditions, which govern the sale itself; and the Returns Policy, which explains what happens to the data attached to a refund.
2What we collect
We collect four things: what you tell us, what your order generates, what your browser sends, and what you choose to publish in a review. We do not buy data about you from anyone else.
Nothing in the table below is optional trickery: every field marked required at checkout is required because a parcel cannot physically reach you without it. Fields we do not need are not asked for — we have never asked a customer for a date of birth, a gender or an income bracket.
| Category | Examples | Where it comes from |
|---|---|---|
| Identity | Name, the name a gift is addressed to | You, at checkout or on your profile |
| Contact | Delivery address, billing address, pincode, mobile number, email | You, at checkout |
| Order | Items and sizes bought, any alteration measurements, price paid, coupon used, GSTIN on a business invoice, AWB number | Generated by the order |
| Payment | Method, last four digits, card network, gateway transaction id, refund reference | Our payment gateway — never the full card number |
| Account | Password hash, saved addresses, wishlist, compare list, loyalty tier, wallet balance | You, when you create an account |
| Technical | IP address, user agent, screen size, referring page, pages viewed, search terms typed on-site | Your browser, automatically |
| Support | Emails, WhatsApp messages, call notes, return reasons, photographs of a damaged parcel | You, when you contact us |
| Published | Review text, star rating, display name, review photographs | You — and visible to everyone by design |
We do not knowingly collect special-category data: no religion, no health, no biometrics, no political opinion. If you volunteer something sensitive in a support message — a medical reason for an altered fit, say, or a bereavement behind a gift order — we use it only to answer you and delete it with the ticket.
3Why we use it, and our legal basis
Every use of your data falls under one of four legal bases: performing your contract, complying with Indian tax and consumer law, our legitimate interest in running a shop that works, or your explicit consent.
Under the Digital Personal Data Protection Act 2023 we process data for the specified lawful purposes below and no others. For customers in the UK and EU, the equivalent GDPR Article 6 basis is named in the same row.
| Purpose | Data used | Legal basis |
|---|---|---|
| Take payment and dispatch your order | Identity, contact, order, payment | Performance of a contract |
| Send order, dispatch and delivery notifications | Contact, order | Performance of a contract |
| Handle a return, exchange or refund | Order, payment, support | Performance of a contract; legal obligation |
| Issue a GST-compliant tax invoice | Identity, contact, order, GSTIN | Legal obligation (CGST Act 2017) |
| Detect card fraud and coupon abuse | Order, payment, technical | Legitimate interest |
| Improve the shop — which pages fail, which searches return nothing | Technical, aggregated | Legitimate interest |
| Send the newsletter and back-in-stock alerts | Contact | Consent — withdrawable in one click |
| Publish your review under your display name | Published | Consent |
Where the basis is legitimate interest we have written down the balancing test and will send it to you on request. Where the basis is consent you can withdraw it at any time without giving a reason, and withdrawing it never affects an order already in flight.
6Where your data is stored, and international transfers
All AimsCraft data is stored in India, in AWS’s Mumbai region, with encrypted backups held in the same country.
If you order from outside India, your data necessarily crosses a border to reach us. For customers in the UK and the European Economic Area those transfers are made under the European Commission Standard Contractual Clauses (2021/914) together with a transfer risk assessment that we will share on request.
International courier shipments also involve a transfer to the destination country’s customs authority: your name, address, the contents of the parcel and its declared value appear on the customs declaration, because they legally must.
7How long we keep it
We keep invoices for eight financial years because Indian tax law requires it, and delete almost everything else within two years of your last interaction.
| Data | Kept for | Why |
|---|---|---|
| Tax invoices and payment records | 8 financial years | Section 36, CGST Act 2017 |
| Order and delivery history | 5 years from delivery | Consumer Protection Act claims window |
| Account profile and saved addresses | Until you delete the account | You control it |
| Support tickets and WhatsApp threads | 24 months from closure | Complaint handling and training |
| Newsletter subscription | Until you unsubscribe, plus 30 days | Proof the unsubscribe was honoured |
| Server and analytics logs | 24 months, IP truncated after 30 days | Security and abuse investigation |
| Abandoned cart contents | 90 days | So a returning bag still works |
| CCTV in our retail stores | 30 days | Loss prevention |
When a period expires the record is deleted, not archived. Backups roll off on a 35-day cycle, so a deletion is fully flushed within five weeks even from cold storage.
8How we keep it safe
Everything moves over TLS 1.3, passwords are hashed with bcrypt and never stored in readable form, and access to customer records is limited to the eleven staff whose job needs it.
- HTTPS everywhere, with HSTS and a strict content security policy — the site loads no external scripts at all.
- Passwords hashed with bcrypt at cost factor 12. We cannot read your password and will never ask for it.
- Two-factor authentication available on your account, and mandatory for every member of staff.
- Role-based access: the packing desk sees an address label, not a payment record; the marketing desk sees neither.
- Encrypted backups, restored and tested quarterly.
- A documented breach procedure: the Data Protection Board of India within 72 hours, and you without undue delay if there is a real risk to you.
No system is perfect and we do not pretend otherwise. If you spot a vulnerability, write to security@aimscraft.com; we acknowledge within two working days and we do not take legal action against good-faith researchers.
9Your rights, and how to use them
You can ask for a copy of your data, correct it, delete it, restrict how we use it, take it elsewhere in a machine-readable file, or object to a use you disagree with — and we answer within 30 days at no charge.
- Access. A full export of your profile, addresses, orders, returns, reviews and support history.
- Correction. Fix a misspelt name or a wrong pincode yourself in your profile, or ask us to.
- Erasure. Delete the account and everything in it, except invoices the tax law obliges us to keep.
- Restriction. Freeze processing while a dispute about accuracy is resolved.
- Portability. A JSON or CSV export you can hand to another retailer.
- Objection. Object to any processing based on legitimate interest, including all profiling.
- Withdraw consent. One click in any newsletter, or one line in an email, with no effect on orders in progress.
- Nominate. Under the DPDP Act you may nominate someone to exercise these rights if you die or become incapacitated.
Write to privacy@aimscraft.com from the address on your account. We may ask one verification question — usually the value of your last order — before releasing anything, because handing your data to an impostor would be the worse failure.
If we get it wrong, you can complain to the Data Protection Board of India, or, in the UK and EEA, to your national supervisory authority. We would rather you told us first: nearly every complaint we have had was a fixable mistake.
10Marketing, and how to stop it
We email roughly twice a month, only to people who ticked the box, and every message carries a one-click unsubscribe that works immediately rather than “within ten days”.
The newsletter covers what has come off the looms, the winter overcoat cut-off dates and the occasional sale. If you bought from us without subscribing you will get transactional messages about your order — confirmation, dispatch, delivery, refund — and nothing else. Those are not marketing and cannot be unsubscribed from while an order is live.
WhatsApp updates are opt-in separately and can be stopped by replying STOP. SMS is used only for OTP codes and delivery alerts. We do not run retargeting campaigns, so unsubscribing here means you genuinely stop hearing from us rather than seeing us follow you around the internet.
11Children
AimsCraft is not intended for anyone under 18, and we do not knowingly collect data from children.
Accounts and orders require you to be 18 or older, as set out in the Terms & Conditions. Under the DPDP Act, processing a child’s data would need verifiable parental consent, and behavioural advertising to children is banned outright — we run none for anyone.
If you believe a child has given us personal data, write to privacy@aimscraft.com and we will delete it within seven days.
12Changes to this policy
When this policy changes materially we email every account holder at least 14 days before the new version takes effect, and we keep the previous version available on request.
Version 4.2, dated 1 September 2026, replaced version 4.1 of 12 March 2026. The change added the DPDP Act nomination right and named AWS Mumbai explicitly as the storage location. Typographic corrections do not trigger a version bump; anything that changes what we collect, why, or who sees it always does.
13Contacting our Data Protection Officer
Every privacy question, rights request and complaint goes to privacy@aimscraft.com, which reaches our Data Protection Officer directly rather than the general support queue.
- Data Protection Officer
- privacy@aimscraft.com
- Grievance Officer (IT Rules 2021)
- grievance@aimscraft.com
- Postal address
- The Data Protection Officer, AimsCraft Pvt. Ltd., Watergam, Rafiabad, Baramulla, Jammu & Kashmir 193303, India
- Telephone
- +91 00000 00000, Monday to Saturday, 10am–7pm IST
- Acknowledgement
- Within 2 working days
- Full response
- Within 30 days
14Questions we get asked about privacy
Five questions that come in most often, answered without the legalese.
Do you sell my email address to anyone?
No. AimsCraft has never sold, rented or bartered a customer list, and this policy commits us not to. The only companies that receive your details are the ones needed to complete your order — the payment gateway, the courier and our email provider — and each is contractually barred from using that data for its own marketing.
Do you store my card number?
No. Card details are entered on our payment gateway, which is PCI DSS Level 1 certified, and we only ever receive a token plus the last four digits and card network so your invoice can say "Visa ending 4421". We could not charge your card again without you re-authorising it, even if we wanted to.
How do I get a copy of everything you hold about me?
Email privacy@aimscraft.com from the address on your account, or write from the phone number on it. We verify it is you, then send a machine-readable export of your profile, addresses, orders, returns, reviews and support tickets within 30 days. There is no charge for the first request in any quarter.
Can you delete my account and everything in it?
Yes, with one legal exception. We erase your profile, addresses, wishlist, cart and marketing record on request. Tax invoices must be kept for eight financial years under Indian GST rules, so those are retained in a locked archive that nobody in marketing or support can read or search.
Does this site track me across other websites?
No. There are no advertising pixels, no Meta or TikTok tags and no cross-site trackers on aimscraft.com. The single third-party request the site makes is a stylesheet from Google Fonts, which sees only your IP address and browser. Everything else — scripts, images, icons — is served from our own domain.
I am in the EU. Which law applies to me?
Both. Your order is governed by Indian law, but because we offer goods to people in the EU and the UK, GDPR rights apply to your personal data: access, rectification, erasure, restriction, portability and objection. Transfers to our Mumbai servers are made under the European Commission Standard Contractual Clauses.