Data Protection & Trust
Privacy Policy
At Himflora, your trust is as precious as the botanicals we preserve. This policy outlines how we collect, safeguard, and respect your personal information.
Our Strict Privacy Promise
We never sell, rent, or trade your personal data to third-party marketing companies. Your information is used exclusively to fulfill your orders, provide dedicated customer service, and ensure seamless delivery of your botanical artworks.
1. Introduction & Scope
Himflora (“we,” “us,” or “our”) operates the website and online boutique at himflora.com. This Privacy Policy governs your use of our website and explains how personal data is handled when you browse, place orders, or communicate with our studio.
By accessing or using our platform, you acknowledge that you have read and agreed to the terms of this policy in adherence to the Information Technology Act, 2000, and the Digital Personal Data Protection Act (DPDPA).
2. Information We Collect
We only gather details necessary to process orders and provide exceptional support:
Contact & Delivery Details
Your name, shipping address, billing address, phone number (for courier dispatch and SMS tracking), and email address for order invoices and updates.
Customization Information
Any personal floral notes, custom inscription requests, or photos shared with us when ordering bespoke pieces.
Technical & Usage Data
Anonymized browser type, IP address, general geographic region, and pages visited to maintain speed, responsiveness, and site performance.
3. How We Use Your Data
- Order Fulfillment: Crafting, packing, invoicing, and delivering your artworks via logistics couriers.
- Customer Support: Responding to order questions, custom commissions, or transit inquiries via email or WhatsApp.
- Order Notifications: Sending automated email or SMS notifications regarding dispatch status and tracking links.
- Platform Security: Monitoring for fraudulent transactions and ensuring system stability.
4. Payment Processing & Security
Zero Storage of Sensitive Card Credentials
All monetary transactions on Himflora are routed through PCI-DSS Level 1 compliant, RBI-approved payment gateways (such as Razorpay or Stripe). Himflora servers never view, record, or store your credit/debit card numbers, CVVs, UPI PINs, or net banking passwords.
Connections are protected with industry-standard 256-bit Secure Socket Layer (SSL) encryption.
5. Third-Party Sharing & Logistics
We only share essential customer details with trusted operational service providers who are strictly bound by confidentiality agreements:
- Delivery & Logistics Partners: (e.g., Delhivery, Blue Dart, DTDC, India Post) receive your name, address, and contact number strictly for package drop-off.
- Payment Gateways: Encrypted transaction handoff for processing payment clearance.
- Legal Requirements: If compelled by applicable Indian law or government authorities in connection with legal proceedings or fraud prevention.
7. Data Storage & Protection
We implement technical and organizational safeguards against unauthorized access, alteration, disclosure, or destruction of your personal data. We retain order records for as long as required to comply with statutory tax, accounting, and warranty obligations under Indian law.
8. Your Privacy Rights
You have full autonomy over your personal information:
- Request a copy of the personal data we hold about you.
- Request correction or updating of inaccurate information.
- Request deletion of your profile or contact records (subject to statutory order retention requirements).
- Opt out of any marketing or promotional communication at any time.
9. Grievance Redressal & Contact
For any privacy inquiries, data deletion requests, or grievances under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules:
Himflora Privacy & Grievance Team
Email: contact.himflora@gmail.com
Location: Mussoorie, Uttarakhand, India
