Who we are
Aliiss is a perfume house composed in Dubai, shipping across India. If you have a question about this policy, write to us at hello@aliiss.com.
What we collect
- Contact details you give us when you place an order: name, email, phone, shipping address.
- Order details: products, sizes, quantities, payment mode, and the contents of any notes you include.
- Authentication data: one-time passcodes (OTPs) sent to your email, hashed before storage.
- Usage data: pages visited, device type, approximate location (city/country), referrer — collected anonymously via Google Analytics.
- Technical logs: IP address and timestamps for security and fraud prevention.
What we do with it
- Fulfil your order — process payment, pack, ship, and keep you updated.
- Send order-related email: confirmation, shipping, delivery, and service notices.
- Reply to your questions when you write in.
- Improve the site, measure what works, and catch bugs.
What we don't do
- We do not sell your data. Ever.
- We do not share it with advertising networks or data brokers.
- We do not store card numbers or bank details on our servers.
Who processes it alongside us
- Courier partners (Delhivery, Blue Dart, DTDC, India Post, Shiprocket and similar) — receive your name, address, and phone only to deliver the parcel.
- Email delivery — we use a transactional SMTP provider to send receipts and updates.
- Google Analytics & reCAPTCHA — anonymised usage data and bot-protection signals, under Google's privacy policy.
- Google Places — when you use the address autocomplete on checkout, your typed query is sent to Google.
How long we keep it
Order and invoice records: retained as long as required under Indian tax and consumer law (currently up to 8 years). Authentication records (OTPs, login sessions): purged after 30 days. Analytics data: retained for 14 months by default.
Your rights
You can ask us to show you, correct, export, or delete any personal data we hold about you. Write to hello@aliiss.com from the email address on your account. We'll respond within 30 days. Deletion is honoured unless we're required by law to retain the record (for example, tax receipts).
Security
We use HTTPS for all traffic, hashed one-time passcodes, and keep production credentials off-device. No system is perfect — if you believe your account has been compromised, write to us and we will invalidate it.
Cookies
We set a session cookie to keep you signed in and remember your cart. Analytics and reCAPTCHA cookies come from Google. You can block cookies in your browser — the cart and checkout will still work, analytics and bot protection won't.
Changes
We'll update this page when our practices change. Material changes will be announced by email to account holders. The "Last updated" date at the top reflects the current version.