PRIVACY POLICY
Website: rishi.friendsssc.com
Business Name: Rishi Fashions
Business Activity: Men’s Fashion Wear / Online Retail
Effective Date: 15 August 2026
Last Updated: 15 August 2026
Email: andalurisrikanth3@gmail.com
Business Address:
#21-10-10, 3rd Line, SRWA-373,
Srinagar Colony, Sathyanarayana Puram,
Vijayawada, Andhra Pradesh, India
1. Introduction
Rishi Fashions (“Rishi Fashions”, “we”, “us”, or “our”) respects your privacy and is committed to protecting personal information entrusted to us.
This Privacy Policy explains how we collect, use, disclose, store, protect and otherwise process personal data when you:
- Visit rishi.friendsssc.com.
- Browse our products.
- Create an account, if account functionality is available.
- Place an order.
- Contact customer support.
- Request a return, refund or exchange.
- Subscribe to communications or marketing.
- Submit a review, enquiry or other information.
- Otherwise interact with our Website or services.
This Privacy Policy is intended to provide clear and transparent information about our data practices.
Where applicable, this Policy is designed to address requirements of the EU General Data Protection Regulation (GDPR) and applicable Indian data-protection and privacy laws.
The GDPR requires organisations to process personal data lawfully, fairly and transparently, collect it for specified purposes, minimise collection, maintain accuracy, limit retention and implement appropriate security measures.
For customers in India, the Digital Personal Data Protection Act, 2023 (DPDP Act) provides a framework governing processing of digital personal data and includes provisions concerning notice, consent, access, correction/erasure and grievance redressal.
2. Who Is Responsible for Your Personal Data?
For purposes of applicable data-protection laws, Rishi Fashions is responsible for the personal data processed through its Website to the extent applicable.
Data Controller
Where the GDPR applies, Rishi Fashions may act as the Data Controller for personal data collected through the Website.
Data Fiduciary
Where Indian data-protection law applies, Rishi Fashions may act as the relevant Data Fiduciary for personal data processed for its business purposes.
Contact Details
Rishi Fashions
Email: andalurisrikanth3@gmail.com
Address:
#21-10-10, 3rd Line, SRWA-373,
Srinagar Colony, Sathyanarayana Puram,
Vijayawada, Andhra Pradesh, India
At present, this Privacy Policy does not designate a separate Data Protection Officer because Rishi Fashions should appoint one only where required by applicable law or where the business determines that one is appropriate.
If a Data Protection Officer or designated privacy contact is appointed in the future, the relevant contact details will be added to this Policy.
3. Scope of This Privacy Policy
This Privacy Policy applies to personal data collected through:
- rishi.friendsssc.com
- Online orders.
- Customer-service communications.
- Return and refund requests.
- Contact forms.
- Account-registration facilities, where available.
- Marketing subscriptions.
- Website interactions.
- Other digital services operated by Rishi Fashions that expressly link to this Privacy Policy.
This Policy does not automatically apply to websites or services operated independently by third parties, even if links to those services appear on our Website.
4. What Is Personal Data?
“Personal data” generally means information that identifies, relates to, describes, or can reasonably be associated with an identifiable individual.
Depending on how you use our Website, this may include:
- Name.
- Email address.
- Telephone/mobile number.
- Billing address.
- Delivery address.
- Account information.
- Order information.
- Product preferences.
- Return/refund information.
- Customer-service correspondence.
- Payment-related information.
- IP address.
- Browser information.
- Device information.
- Website usage information.
- Cookie identifiers.
- Information contained in messages or enquiries.
- Reviews or other content you voluntarily submit.
We aim to collect only information reasonably necessary for the relevant purpose.
This reflects the GDPR principle of data minimisation, under which organisations should process only personal data necessary for their purposes.
5. Personal Data We May Collect
5.1 Information You Provide Directly
You may provide information when you:
- Place an order.
- Create an account.
- Contact us.
- Request a return or refund.
- Subscribe to marketing.
- Submit a review.
- Participate in an offer or promotion.
- Complete a form.
- Communicate with customer support.
This may include your name, email address, phone number, address and other information needed to provide the requested service.
5.2 Order Information
When you purchase products, we may process:
- Order number.
- Products purchased.
- Quantity.
- Size and colour selected.
- Price.
- Billing information.
- Delivery address.
- Order date.
- Delivery status.
- Return/refund information.
- Customer communications relating to the order.
5.3 Payment Information
Payments may be processed through third-party payment providers.
Where a third-party payment provider processes your payment, Rishi Fashions may receive limited payment-related information necessary to identify and reconcile the transaction.
We do not intend to collect or store complete payment-card numbers, CVV/security codes or banking credentials on our own systems unless our actual payment infrastructure specifically requires this and applicable security and legal requirements are satisfied.
Customers should never send passwords, card PINs, CVV numbers, OTPs or banking credentials to Rishi Fashions by email or through customer-support messages.
6. Automatically Collected Information
When you visit our Website, certain information may be collected automatically by the Website, hosting provider, analytics tools, security systems, cookies or similar technologies.
Depending on the technologies actually implemented, this may include:
- IP address.
- Browser type.
- Operating system.
- Device type.
- Approximate geographic location derived from IP address.
- Referring website.
- Pages visited.
- Time spent on pages.
- Date and time of access.
- Links clicked.
- Website interactions.
- Error information.
- Security and fraud-detection information.
We will not intentionally use automatically collected information to identify you personally unless reasonably necessary for a legitimate purpose.
7. Cookies and Similar Technologies
Our Website may use cookies and similar technologies.
Cookies may be used for purposes such as:
Essential Cookies
These may be necessary for:
- Website functionality.
- Shopping-cart functionality.
- Login/session management.
- Security.
- Fraud prevention.
- Order processing.
Preference Cookies
These may remember:
- Language preferences.
- Website preferences.
- Other selected settings.
Analytics Cookies
Where implemented, analytics cookies may help us understand:
- How visitors use the Website.
- Which pages are visited.
- Website performance.
- Technical errors.
- General traffic patterns.
Marketing Cookies
Where implemented and where legally required, marketing cookies may be used to support advertising or marketing measurement.
Non-essential cookies should only be activated where the applicable legal requirements for consent or another valid legal basis have been satisfied.
Where GDPR consent is required, users should be provided with a clear choice to accept, reject or manage non-essential cookies.
8. How We Use Personal Data
We may use personal data for the following purposes:
- Processing and fulfilling orders.
- Delivering purchased products.
- Processing payments through applicable payment providers.
- Managing customer accounts.
- Providing customer support.
- Processing returns, refunds and exchanges.
- Communicating about orders.
- Responding to enquiries.
- Preventing fraud and abuse.
- Maintaining Website security.
- Improving Website functionality.
- Understanding Website usage.
- Managing customer reviews.
- Providing requested services.
- Sending marketing communications where legally permitted.
- Managing promotions and offers.
- Maintaining business and financial records.
- Complying with legal obligations.
- Establishing, exercising or defending legal claims.
- Protecting the rights, property and safety of Rishi Fashions, customers and others.
We will not use personal data for materially incompatible purposes without an appropriate legal basis or other lawful justification.
9. Legal Bases for Processing Under the GDPR
Where the GDPR applies, Rishi Fashions will process personal data only where a lawful basis exists.
Depending on the circumstances, the legal basis may include:
9.1 Contract
Processing may be necessary to:
- Process an order.
- Deliver products.
- Process payment.
- Provide requested services.
- Manage returns/refunds.
- Communicate about contractual transactions.
9.2 Legal Obligation
Processing may be necessary to comply with applicable legal obligations, such as:
- Accounting requirements.
- Tax requirements.
- Consumer-protection obligations.
- Fraud-prevention requirements.
- Court orders or lawful government requests.
9.3 Consent
We may rely on consent where required, including potentially for:
- Certain marketing communications.
- Certain non-essential cookies.
- Certain optional data processing activities.
Where processing is based on consent, you may withdraw your consent at any time.
Withdrawal of consent does not affect the lawfulness of processing that occurred before withdrawal.
Under India’s DPDP framework, consent is intended to be free, specific, informed, unconditional and unambiguous with clear affirmative action, and withdrawal should be as easy as giving consent.
9.4 Legitimate Interests
Where permitted by applicable law, we may process personal data where necessary for legitimate interests pursued by Rishi Fashions or a third party, provided those interests are not overridden by the individual’s fundamental rights and freedoms.
Potential legitimate interests may include:
- Website security.
- Fraud prevention.
- Improving services.
- Managing customer relationships.
- Defending legal claims.
- Direct marketing where legally permitted.
- Protecting business assets.
Where legitimate interests are relied upon under the GDPR, we will consider the relevant balancing requirements.
10. Marketing Communications
We may send promotional communications where permitted by applicable law.
Marketing communications may include:
- New product announcements.
- Discounts.
- Seasonal offers.
- Fashion promotions.
- Special campaigns.
Where consent is required, we will obtain appropriate consent before sending marketing communications.
You may unsubscribe from marketing emails by:
- Using the unsubscribe mechanism provided in the email; or
- Contacting us at andalurisrikanth3@gmail.com.
Unsubscribing from marketing communications does not normally stop essential transactional communications, such as order confirmations, shipping updates, refunds or customer-service messages.
11. Sharing Personal Data
We do not sell personal data to third parties for their own unrelated purposes.
We may share necessary personal data with selected third parties where reasonably required to operate our business.
These may include:
Payment Providers
To process payments, refunds and transaction verification.
Delivery and Logistics Providers
To deliver orders and process returns.
Website and Hosting Providers
To host and maintain the Website.
Technology Providers
To provide necessary software, security, communication or technical services.
Analytics Providers
Where implemented, to understand Website usage and performance.
Professional Advisers
Such as accountants, lawyers, auditors or other professional advisers where necessary.
Government and Law-Enforcement Authorities
Where disclosure is required by applicable law, legal process or lawful governmental request.
Business Transfers
If Rishi Fashions undergoes a merger, restructuring, sale, acquisition or transfer of assets, personal data may be transferred as part of that transaction, subject to applicable legal requirements.
Third-party recipients should only receive information reasonably necessary for the relevant purpose.
12. Third-Party Service Providers
Third-party providers may process personal data on our behalf.
Where applicable, we will seek to use providers that implement appropriate privacy and security measures.
Where a provider processes personal data as a processor under the GDPR, Rishi Fashions should maintain an appropriate contractual arrangement governing that processing.
Customers should understand that third-party services may also have their own privacy policies and terms.
13. International Data Transfers
Some service providers may process data outside India or outside the European Economic Area (EEA).
Where personal data protected by the GDPR is transferred outside the EEA, Rishi Fashions will use an appropriate lawful transfer mechanism where required, such as:
- An adequacy decision;
- Standard Contractual Clauses;
- Another legally recognised transfer mechanism; or
- Another lawful safeguard available under applicable law.
The GDPR specifically requires transparency regarding transfers to recipients outside the EU and the safeguards used for such transfers.
Because the actual service providers used by rishi.friendsssc.com may change, this Policy does not claim that any particular provider or transfer mechanism is currently being used unless separately identified.
14. Data Retention
We will retain personal data only for as long as reasonably necessary for the purposes for which it was collected, unless a longer period is required or permitted by law.
Retention periods may depend on:
- The purpose for which information was collected.
- Whether you have an active customer relationship.
- Accounting and tax obligations.
- Consumer-protection requirements.
- Legal claims.
- Fraud-prevention requirements.
- Dispute-resolution requirements.
- Security requirements.
As a general approach:
| Type of Information | Indicative Retention |
|---|---|
| Order and transaction records | As required for accounting, tax, legal and business purposes |
| Customer-service communications | As reasonably necessary to resolve and document the matter |
| Return/refund records | As reasonably necessary for transaction and legal records |
| Marketing preferences | Until withdrawn or otherwise no longer required |
| Account information | While the account remains active and for a reasonable period thereafter where necessary |
| Security/log information | For a period reasonably necessary for security and operational purposes |
| Consent records | For as long as reasonably necessary to demonstrate and manage consent |
Actual retention periods may vary depending on the circumstances and applicable law.
The GDPR’s storage-limitation principle requires personal data not to be kept longer than necessary for the purposes for which it is processed.
15. Data Security
Rishi Fashions takes reasonable technical and organisational measures designed to protect personal data against:
- Unauthorised access.
- Unauthorised disclosure.
- Accidental loss.
- Destruction.
- Alteration.
- Misuse.
- Unlawful processing.
Depending on the Website’s actual technical environment, security measures may include:
- Access controls.
- Password protection.
- Secure administrative access.
- HTTPS/TLS encryption where available.
- Limited access to personal data.
- Software and security updates.
- Backup procedures.
- Malware and security monitoring.
- Fraud-prevention measures.
- Secure payment processing through appropriate providers.
- Staff or service-provider confidentiality obligations.
However, no internet transmission or electronic storage system can be guaranteed to be completely secure.
Accordingly, while we take reasonable precautions, we cannot guarantee absolute security.
16. Data Breaches
If Rishi Fashions becomes aware of a personal-data breach, we will assess the incident and take reasonable steps to contain, investigate and remediate it.
Where applicable law requires notification to affected individuals, regulators, authorities or other parties, we will make the required notifications within the applicable legal timeframe.
The GDPR contains specific obligations concerning certain personal-data breaches, including notification requirements in applicable circumstances.
17. Your GDPR Rights
If the GDPR applies to you, you may have the following rights, subject to applicable limitations and exceptions:
17.1 Right to Be Informed
You have the right to receive clear information about how your personal data is processed.
17.2 Right of Access
You may request confirmation of whether we process your personal data and, where applicable, obtain a copy of that data.
17.3 Right to Rectification
You may ask us to correct inaccurate or incomplete personal data.
17.4 Right to Erasure
You may request deletion of your personal data in certain circumstances.
This right is not absolute. We may retain information where legally required or where another lawful ground permits retention.
17.5 Right to Restriction of Processing
You may request restriction of processing in certain circumstances.
17.6 Right to Data Portability
Where applicable, you may request personal data you provided to us in a structured, commonly used and machine-readable format and request transmission to another controller where the GDPR requirements are satisfied.
17.7 Right to Object
You may object to certain processing based on legitimate interests.
You may also object to direct marketing at any time.
17.8 Right to Withdraw Consent
Where processing relies on consent, you may withdraw your consent at any time.
Withdrawal does not affect processing that was lawful before withdrawal.
17.9 Rights Regarding Automated Decision-Making
Where applicable, you may have rights concerning decisions based solely on automated processing that produce legal or similarly significant effects.
Rishi Fashions does not intend to use solely automated decision-making to make decisions producing legal or similarly significant effects on customers unless expressly disclosed and legally permitted.
The GDPR requires transparency concerning applicable automated decision-making and related logic/consequences.
18. Rights Under Indian Data-Protection Law
Where applicable, individuals may have rights under India’s Digital Personal Data Protection Act, 2023 and associated rules, including rights concerning:
- Access to information about personal data.
- Correction of inaccurate personal data.
- Erasure of personal data where applicable.
- Grievance redressal.
- Withdrawal or management of consent where consent is the basis of processing.
- Other rights provided by applicable law.
The DPDP Act expressly provides for rights relating to access, correction/erasure and grievance redressal.
The exact availability and timing of particular rights will depend on the law and provisions applicable to the relevant processing activity.
19. How to Exercise Your Privacy Rights
To exercise a privacy right, send an email to:
Please use the subject:
“Privacy Rights Request – Rishi Fashions”
Your request should include:
- Your full name.
- Email address associated with your account/order, if applicable.
- Description of the request.
- Relevant order/account number, if applicable.
- Any information reasonably necessary to identify the relevant personal data.
We may request reasonable information to verify your identity before completing certain requests.
This is intended to protect personal data from being disclosed to someone who is not authorised to receive it.
We will not require unnecessary information merely to exercise a privacy right.
20. Response to Privacy Requests
We aim to respond to valid privacy requests within the timeframe required by applicable law.
Where the GDPR applies, requests concerning Articles 15–22 generally must be addressed without undue delay and, in principle, within one month of receipt. The period may be extended by up to two additional months where legally permitted because of complexity or number of requests, in which case the individual should be informed.
Where applicable Indian law establishes different timelines or procedures, those requirements will apply.
21. Fees for Privacy Requests
Privacy requests will generally be handled without charge where required by applicable law.
However, where permitted by law, we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive, particularly where repeated requests create disproportionate administrative costs.
Any such action will be taken only where permitted by applicable law.
22. Identity Verification
For certain requests, particularly requests involving access, deletion, correction or portability, we may need to verify your identity.
Verification may involve asking for limited information already associated with your account or transaction.
We will not request sensitive authentication information such as passwords, PINs, OTPs or complete payment-card security information.
23. Children and Minors
Our Website is intended for general consumers and is not specifically directed at children.
We do not knowingly seek to collect personal data from children where such collection is prohibited by applicable law.
If you believe a child has provided personal data to us in circumstances where collection was not appropriate, please contact:
We will assess the situation and take appropriate action where required by law.
Where Indian law imposes specific requirements concerning children’s personal data, Rishi Fashions will comply with the requirements applicable to its processing activities.
24. User-Generated Content
If customers submit:
- Reviews.
- Comments.
- Photographs.
- Testimonials.
- Questions.
- Other publicly visible content.
the information submitted may become visible to other Website visitors depending on the functionality involved.
Customers should not submit personal information about themselves or others that they do not wish to make publicly available.
Rishi Fashions may moderate or remove content in accordance with applicable Website policies and law.
25. Links to Other Websites
Our Website may contain links to third-party websites or services.
We are not responsible for the privacy practices, content or security of third-party websites.
Before providing personal data to another website, you should review its privacy policy.
26. Payment Security
Payments may be handled by third-party payment processors.
Where a payment processor is used, payment information may be processed directly by that provider in accordance with its own privacy and security practices.
Rishi Fashions does not request customers to send:
- ATM PINs.
- UPI PINs.
- OTPs.
- CVV numbers.
- Passwords.
by email, phone, social media or customer-support messages.
If someone claiming to represent Rishi Fashions requests such information, do not provide it.
27. Fraud Prevention and Security Monitoring
We may process certain information to detect, investigate and prevent:
- Fraudulent orders.
- Payment abuse.
- Account abuse.
- Return/refund fraud.
- Security attacks.
- Unauthorised access.
- Other unlawful activity.
This may include technical information, transaction information, account information and information concerning suspicious activity.
Where applicable under GDPR, such processing may rely on legitimate interests or another lawful basis.
28. Accuracy of Personal Data
We aim to keep personal data accurate and up to date.
You should notify us if your personal information changes.
You may request correction of inaccurate or incomplete personal data by contacting:
The GDPR includes accuracy as one of its core data-protection principles.
29. Data Minimisation
Rishi Fashions seeks to collect only information reasonably necessary for the purpose for which it is processed.
We do not intend to collect sensitive personal data merely because it may be technically available.
If information is not necessary for providing a requested service, customers should not be required to provide it.
30. No Sale of Personal Data
Rishi Fashions does not intend to sell customers’ personal data as a standalone commercial asset.
Where third-party service providers process personal data, they should use it only for authorised purposes and according to the applicable contractual and legal arrangements.
31. Do Not Track and Similar Signals
Different browsers and devices may provide privacy or “Do Not Track” signals.
Because technical standards and legal requirements regarding such signals may vary, our treatment of these signals will depend on the technologies actually implemented on the Website and applicable law.
32. Social Media
If Rishi Fashions operates or links to social-media accounts, interactions with those platforms may be subject to the privacy policies of the relevant social-media provider.
Rishi Fashions does not control how independent social-media platforms collect or process information through their own services.
33. Legal Disclosure
We may disclose personal data where reasonably necessary to:
- Comply with applicable law.
- Respond to lawful government requests.
- Comply with court orders.
- Protect legal rights.
- Investigate fraud.
- Prevent security threats.
- Establish, exercise or defend legal claims.
We will seek to limit such disclosure to what is reasonably necessary and legally permitted.
34. Business Transfers
If Rishi Fashions is sold, merged, reorganised, acquired, or transfers substantially all or part of its business or assets, customer information may form part of the transferred business assets where legally permitted.
Any successor entity may be required to continue protecting personal data according to applicable law and the commitments applicable to that information.
35. Changes to This Privacy Policy
We may update this Privacy Policy periodically.
Changes may be made to reflect:
- New Website features.
- New products or services.
- Changes to technology.
- Changes in third-party service providers.
- Changes in data-processing practices.
- Changes in applicable law.
- Improvements to privacy practices.
The updated version will be posted on:
rishi.friendsssc.com
The “Last Updated” date at the top of this Policy will also be changed.
Where required by law, we will provide additional notice or obtain consent before implementing material changes.
36. Complaints
If you have concerns about how Rishi Fashions handles your personal data, please contact us first.
Privacy Contact
Rishi Fashions
Email: andalurisrikanth3@gmail.com
Address:
#21-10-10, 3rd Line, SRWA-373,
Srinagar Colony, Sathyanarayana Puram,
Vijayawada, Andhra Pradesh, India
Please describe:
- The nature of your concern.
- Relevant account/order information.
- The data-processing activity involved.
- The remedy you are seeking.
We will investigate and respond in accordance with applicable law.
37. Right to Lodge a GDPR Complaint
If you are located in the European Economic Area and believe that your personal data has been processed in violation of the GDPR, you have the right to lodge a complaint with the competent supervisory authority in your country of residence, place of work, or the place of the alleged infringement, as applicable.
You may also contact the relevant data-protection authority for guidance regarding your rights.
Rishi Fashions encourages customers to contact us first so that we have an opportunity to resolve the issue directly, but this does not restrict your legal right to complain to a supervisory authority.
The GDPR expressly provides individuals with a right to lodge a complaint with a Data Protection Authority.
38. Indian Grievance Redressal
For customers in India, privacy-related complaints should first be submitted to:
Rishi Fashions
Email: andalurisrikanth3@gmail.com
We will provide a grievance-redressal mechanism appropriate to the legal requirements applicable to our processing activities.
Where applicable, individuals may pursue further statutory remedies available under Indian data-protection law.
The DPDP Act contains provisions establishing rights of Data Principals and a grievance-redressal framework.
39. Consent
Where consent is required for processing, we will seek consent through an appropriate affirmative action.
Consent requests should be presented clearly and separately from unrelated information where required by applicable law.
Where processing is based on consent:
- Consent should be informed.
- Consent should be specific.
- Consent should be freely given.
- Consent should involve a clear affirmative action.
- Consent may be withdrawn where applicable.
- Withdrawal should be reasonably easy.
The Indian DPDP framework similarly provides that consent should be free, specific, informed, unconditional and unambiguous with clear affirmative action.
40. Privacy by Design and Data Protection
Rishi Fashions aims to incorporate reasonable privacy and security considerations into the design and operation of its Website.
This may include:
- Collecting only necessary information.
- Restricting access to personal data.
- Using appropriate security controls.
- Reviewing third-party service providers.
- Deleting information when no longer necessary.
- Maintaining reasonable organisational safeguards.
The specific measures used may change as the Website and its technology infrastructure develop.
41. Automated Decision-Making
Rishi Fashions does not intend to use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.
If such processing is introduced in the future and applicable law requires additional disclosure, safeguards or consent, this Privacy Policy will be updated accordingly.
42. International Visitors
Rishi Fashions is based in India.
If you access the Website from another country, including an EU/EEA country, your personal data may be processed in India and/or other countries where our service providers operate.
Where GDPR applies to the processing, we will implement appropriate safeguards for international transfers as required by applicable law.
43. Applicable Law
This Privacy Policy shall be interpreted consistently with applicable Indian law and, where applicable, the laws governing protection of personal data in the jurisdiction of the individual.
Where GDPR applies to a particular processing activity, applicable GDPR rights and obligations will not be excluded merely because Rishi Fashions is based in India.
Nothing in this Privacy Policy is intended to remove or restrict a mandatory statutory right.
44. Contact Information
For any privacy question, request or complaint, please contact:
Rishi Fashions
Website: rishi.friendsssc.com
Email: andalurisrikanth3@gmail.com
Business Address:
#21-10-10, 3rd Line, SRWA-373,
Srinagar Colony, Sathyanarayana Puram,
Vijayawada, Andhra Pradesh, India
Effective Date: 15 August 2026
Last Updated: 15 August 2026
45. QUICK PRIVACY SUMMARY
What information may we collect?
Information such as your name, email, phone number, delivery address, order information, customer-service communications and certain technical information.
Why do we use it?
Primarily to process orders, deliver products, provide customer service, process returns/refunds, secure the Website, comply with law and, where legally permitted, send marketing communications.
Do we sell your personal data?
No. Rishi Fashions does not intend to sell your personal data as a standalone commercial product.
Who may receive it?
Necessary service providers such as payment processors, delivery companies, hosting/technology providers, professional advisers and authorities where legally required.
How do we protect it?
We use reasonable technical and organisational safeguards appropriate to the nature of the information and risks involved.
How long do we keep it?
Only for as long as reasonably necessary for the relevant purpose, unless a longer period is required or permitted by law.
Can you request deletion?
Where applicable, yes. You may request deletion or erasure subject to legal exceptions.
Can you access your information?
Where applicable, yes. You may request access to personal data we hold about you.
Can you correct your information?
Yes, where applicable, you can request correction of inaccurate or incomplete information.
Can you withdraw consent?
Where processing is based on consent, yes, subject to applicable law. Withdrawal does not make earlier lawful processing unlawful.
How do you contact us?
IMPORTANT IMPLEMENTATION NOTICE
This Privacy Policy should be published only after it is matched to the actual technology and data practices of rishi.friendsssc.com.
In particular, before launch, Rishi Fashions should verify whether the Website actually uses:
- Google Analytics or another analytics platform.
- Google Ads/Meta Pixel or other advertising trackers.
- Google Fonts or other externally hosted resources.
- Contact-form plugins.
- Newsletter/email-marketing software.
- Payment gateways.
- Courier/shipping platforms.
- Hosting providers.
- Customer accounts.
- WhatsApp or other messaging services.
- Social-media plugins.
- CAPTCHA/security services.
- Cookies and local storage.
- Third-party APIs.
- Cloud storage or databases.
If any of these are used, their actual data processing, purposes, recipients, retention periods and international transfers should be reflected accurately in this Privacy Policy.
For GDPR compliance, merely placing a privacy policy on the Website is not enough. The underlying processing must also satisfy the GDPR’s principles of lawfulness, transparency, purpose limitation, data minimisation, storage limitation, accuracy, security and accountability.
Similarly, India’s DPDP framework requires a clear notice describing the personal data being processed and the specified purposes, along with mechanisms for consent management, rights and complaints where applicable.
© 2026 Rishi Fashions. All rights reserved.
