ROLLEX

Privacy Policy

Last updated: 22 August 2026

This policy explains what we collect when you pre-book a phone, why we collect it, who it is shared with, how long we keep it, and the choices you have. It applies to this website and to any support conversation you have with us.

Who is responsible for your data

Rollex International is a trading name operated by Nebha Sarman Bhutiya, a sole proprietorship (individual business) registered on the Udyam (MSME) portal (UDYAM-XX-00-0000000). It is not a private limited company, public limited company, or limited liability partnership (LLP).

We decide why and how your personal data is processed, which makes us the data fiduciary for it. Questions, requests or complaints about privacy go to nebhabhutiya85@gmail.com.

What we collect

We only collect what a pre-booking actually needs. We do not ask for your date of birth, gender, government ID, or any financial instrument details.

  • Account: your name, email address and phone number.
  • Booking: the phone, colour and storage option you reserved, quantity, deposit and balance amounts, and your booking status.
  • Payment reference: the UPI transaction reference (UTR) you enter, and the payment method you used, so we can match your deposit against a bank entry.
  • Delivery: the address and contact number you give us when your order is ready to ship.
  • Technical: your session cookie, and standard server logs (IP address, browser, timestamps) kept by our hosting and database providers.

Payment information

We do not run a payment gateway and we never see or store your card number, UPI PIN, bank credentials or OTP. Payment happens entirely inside your own UPI or banking app.

The payment QR code shown at checkout is generated on this website itself. Your payment details are not sent to any third-party QR or payment service.

What we do store is the UTR you submit, so we can confirm the money arrived. A UTR identifies a transaction; it cannot be used to take money from you.

Why we use it

  • To verify your deposit and hold the unit you reserved.
  • To contact you about balance payment, dispatch, delivery, refunds or a change to your ship date.
  • To meet our obligations as a seller, including tax and accounting records.
  • To detect duplicate or fraudulent booking attempts and keep the site secure.

We do not use your data for advertising, profiling, or automated decisions that affect you. We do not sell it, and we do not share it for anyone else’s marketing.

Cookies and sessions

When you sign in, Supabase Auth sets secure HTTP-only session cookies so you stay logged in across pages. These are strictly necessary for your account, your bookings and admin access.

If you arrive through a promoter link we store a single cookie holding that promoter’s code for 30 days, so the referral can be credited. It contains no personal information about you.

We do not use advertising, analytics or tracking cookies. Session cookies refresh as you navigate and are cleared when you sign out.

Who we share it with

We share data only with the providers that run this store, and only as far as they need it:

  • Supabase — database, authentication and image storage.
  • Vercel — website hosting and server logs.
  • Our bank and UPI provider — to receive and reconcile your payment.
  • A courier partner — your name, address and phone number, once your order ships.

We may also disclose data where the law requires it, or to establish or defend a legal claim. We do not transfer your data to anyone else.

Where your data is stored

Our database and file storage are hosted in the Asia Pacific (Mumbai) region. Some providers may process limited technical data, such as server logs, outside India as part of running their global infrastructure.

How long we keep it

  • Booking and payment records, including your UTR: retained for 8 years, as commercial and tax records require.
  • Account details: kept while your account is open, and deleted within 90 days of you closing it, except where a booking record must be retained above.
  • Cancelled or expired bookings that never received a payment: deleted after 12 months.
  • Promoter referral cookie: 30 days.

Your choices

You can ask us to show you the data we hold about you, correct anything wrong, delete your account, or stop contacting you. You can also withdraw consent for anything that is not needed to complete a booking you already made.

Write to nebhabhutiya85@gmail.com from the email address on your account and we will respond within 30 days. If a request would require us to break a legal retention rule above, we will tell you which records we must keep and why.

Keeping it secure

Access to customer data is restricted to the proprietor. The database enforces row-level security so a signed-in customer can only ever read their own bookings, and every change to a booking or the catalogue is recorded in an audit log.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority without undue delay.

Children

This store is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.

Changes to this policy

If we change this policy we will update the date at the top of this page. Where a change materially affects how we use data you already gave us, we will email you before it takes effect.

Contact and grievances

Privacy questions: nebhabhutiya85@gmail.com · +91 6354 275 141.

Grievance Officer: Nebha Sarman Bhutiya — nebhabhutiya85@gmail.com · +91 6354 275 141. We acknowledge grievances within 48 hours and resolve them within 30 days.

Registered address: Ahmedabad, Gujarat, India.