Jeffi Stores Logo
Jeffi Stores
Hardware & Tools
HomeProductsCategoriesAbout UsSupport
Login
Jeffi StoresJeffi Stores
HomeProductsCategoriesAbout UsSupport
CartWishlist
LoginSign Up
Theme
Legal & Policies

Privacy Policy

What we collect, why we collect it, how long we keep it, and your rights over your data.

Last updated: 14 Jun 2026

Download PDF

1. The short version

  • We collect what we need to run your account, fulfil your orders, file GST, and keep our platform secure — nothing more.
  • We do not sell your data. Ever.
  • Third parties only see what they need to do their job (Razorpay sees payment context; Delhivery sees the shipping label; AWS hosts the data; Google sign-in sees your email if you choose it).
  • You can ask us to export, correct, or delete your data anytime by writing to support@jeffistores.in.

2. Who we are

Jeffi Stores is operated from Raipur, Chhattisgarh, India. When this policy says "we", "us", or "Jeffi Stores", we mean the entity running jeffistores.in (and the business.jeffistores.in / admin.jeffistores.in subdomains). The data controller is Jeffi Stores; the GSTIN, registered address and grievance officer details are listed in the Grievance Redressal page.

3. Information you give us directly

  • Account: name, email, phone (mobile OTP is the primary auth), avatar (optional), and password if you set one.
  • For business accounts: company name, GSTIN, business address, industry, and the contact person.
  • Orders: shipping and billing addresses (with PIN code), GSTIN if you want a tax invoice, and any notes you add to the order.
  • Support: anything you type in the chatbox, send by email, or share on a phone call (which we do not record by default).
  • Reviews: the rating, photos, and text you submit alongside a review form.

4. Information we collect automatically

  • Cart and browsing: products you view, items in your cart, search queries, and category filters — used to keep your session, recover an abandoned cart, and personalise recommendations.
  • Device and connection: IP address, user-agent, approximate location (city-level), referrer, and the time of each visit — used for security and fraud detection.
  • Cookies and similar: a session cookie for sign-in, a session id cookie for guest carts, and a theme preference. We do not run advertising trackers.
  • Analytics: aggregated page views, conversion events, and click events via Google Analytics 4 / Google Tag Manager. We do not use Analytics for cross-site advertising.
  • AI assistant: the prompt you type, the products our model retrieves to answer it, and a thumbs-up / thumbs-down rating if you give one. We do not link these prompts to your name in our analytics dashboards.

5. Why we use it

  • To run your account: sign you in, persist your cart, send transactional emails (OTP, order, invoice, RFQ updates).
  • To fulfil orders: print invoices and packing slips, generate Delhivery shipping labels, and track delivery status.
  • To comply with Indian tax law: store invoice copies and GST data per the GST rules (typically 8 financial years).
  • To prevent fraud and abuse: rate-limit suspicious sign-in attempts, flag risky payment patterns, log admin activity.
  • To improve the product: aggregate, anonymised analytics. We never act on individual records here.
  • To communicate, when you ask: order confirmations and shipping updates are mandatory. Marketing emails are opt-in (and there is an unsubscribe link in every email we send).
  • To deliver business-customer features: discount tiers, RFQ negotiations, and credit-limit decisions for approved business accounts.

6. How long we keep it

  • Account profile: while your account is active, plus 30 days after you close it (a window for account-recovery requests).
  • Order history and invoices: 8 financial years from the order date — required by GST law.
  • Payment metadata (Razorpay reference IDs, last 4 of card): 18 months for chargeback handling.
  • Failed sign-in logs: 90 days, then aggregated and deleted.
  • Anonymised analytics: indefinitely. These do not identify you.
  • Backups: rolling 7-day window. Backups age out automatically.

7. Who we share it with

  • Razorpay (payments): order amount, your name, email, phone, and the order id. Razorpay is PCI-DSS Level 1 — they store your card data, not us.
  • Delhivery (shipping): the recipient name, full shipping address, phone, and weight/dimensions of the package.
  • Amazon Web Services (hosting): all of our application data sits in AWS RDS, S3, and EC2 in their us-east-1 region. AWS is bound by their Data Processing Addendum.
  • Google (sign-in, Maps autocomplete, Analytics): your email and Google id when you choose Google sign-in; address autocomplete queries when you type in an address field.
  • OpenAI / our self-hosted models (AI assistant): the prompt you type. We do not send your account email or phone to the model.
  • SES (email): the recipient address and the email body. Standard email delivery.
  • Tax authorities: invoice and GSTIN data when filing GSTR-1 / GSTR-3B / e-invoicing.
  • Law enforcement: only when compelled by valid Indian legal process. We will tell you if we are required to share and the law lets us.

8. Where it is stored

Right now, in AWS US-East-1 (Northern Virginia). India does not currently require local hosting for ecommerce data, but we monitor the DPDP Act rules and will move to in-region hosting if and when required. Any cross-border transfer relies on the AWS Data Processing Addendum and the Indian Data Protection rules.

9. Your rights

  • Access — request a copy of your data.
  • Correction — fix anything wrong in your profile or address book directly, or write to us for changes outside the UI.
  • Deletion — close your account and ask us to delete data older than the legal retention windows above.
  • Withdraw marketing consent — every marketing email has an unsubscribe link, and your account preferences page lets you opt out.
  • Portability — get a JSON export of your orders and addresses.
  • Complain — you can write to our grievance officer (see Grievance Redressal) or, in India, escalate to the relevant data protection regulator.

10. Cookies

We use only first-party functional cookies (session, cart, theme) plus Google Analytics. We do not run advertising or cross-site cookies. You can clear cookies in your browser; some features (sign-in, cart) will need to be re-set.

11. Children

The platform is intended for users aged 18 and above. We do not knowingly collect data from minors. If you believe a child has created an account, write to support@jeffistores.in and we will close it.

12. Updates to this policy

When we change this policy, we update the version and date at the top, and ask you to re-accept the next time you sign in or open the site. Material changes (new third-party data sharing, new categories of data we collect) will additionally be emailed to you.

13. Contact

Privacy questions: support@jeffistores.in. Grievance officer: see the Grievance Redressal policy. Postal: Jeffi Stores, Raipur, Chhattisgarh.

Have questions about our policies?

Contact Support