Legal
Privacy
Last updated . If we change anything that matters, we will change this date and say what changed at the foot of the page.
The short version
We collect what an order requires and almost nothing else. We do not sell your data — not to anyone, not in aggregate, not “with trusted partners”. We use analytics and advertising technologies to understand what is working on the site and to measure how our advertising performs; any contact detail is scrambled before it leaves us, and you can limit them through your browser and ad settings. If you want your data out, email us and we will do it.
Who we are
The Bath Aura, a business registered in India. Under the Digital Personal Data Protection Act, 2023 we are the Data Fiduciary for the personal data described here. We decide why and how it is processed, and we are the ones answerable for it. You are the Data Principal.
What we collect, and why
- To send you a parcel: name, delivery address, pin code, email, phone number. There is no version of shipping a bar of soap that does not require these.
- To take payment: we do not collect card details. Cashfree handles payment and we never see your card number. What comes back to us is a transaction reference, the amount, and whether it succeeded.
- To invoice you: your name and address, and your GSTIN if you gave us one. This is a statutory record, not a marketing asset.
- If you write to us: whatever is in the message and the address it came from.
- If you subscribe to the letter: your email address. Nothing else. It is six emails a year and there is an unsubscribe link in every one of them that actually works.
- If you make a trade enquiry: the business details on the form, including your GSTIN.
- Automatically: basic server logs — IP address, browser, pages requested — kept briefly, for security and to find out which of our pages is broken.
We do not collect your date of birth, your gender, your income bracket or your skin type unless you volunteer it in a message. None of those help us send you soap.
What we do not do
- We do not sell or rent your data. No caveat follows this sentence.
- We do not let our analytics tools identify you to anyone else. We use analytics and advertising technologies — Google, Meta and Microsoft — to see what is working and to measure how our ads perform, but any contact detail is scrambled before it leaves us, and none of them may use your data for their own purposes. You can limit them any time (see Cookies, below).
- No dark patterns. Under the CCPA Guidelines for Prevention and Regulation of Dark Patterns, 2023, basket sneaking, false urgency, drip pricing and confirm-shaming are prohibited. We do not use them — not because we are being watched, but because they are the opposite of what this brand is.
- We never ask for an OTP, a bank detail or an advance cash payment. The notice at the foot of every page is the whole policy. Anyone who asks you for these in our name is not us.
Who else touches it
A short list, and we would rather name them than say “service providers”:
- Cashfree — payments. They see the payment; we do not see the card.
- Delhivery, Blue Dart, India Post — they get the name, address and phone number, because a parcel does not arrive without them.
- Our email provider — order confirmations, dispatch notices, and the letter if you asked for it.
- WhatsApp (Meta) — only if you message us, or if you opted in to order updates there. Their privacy policy is theirs, and it is not a short read.
- Google, Meta and Microsoft — analytics and ads. Google Analytics and Microsoft Clarity show us what is working; the Meta pixel lets us measure our advertising and reach people like you. We send the least that makes them useful, and any contact detail is scrambled before it leaves us. You can limit them through your browser and your Meta and Google ad settings.
Each gets the minimum required to do the job and nothing beyond it. None of them may use it for their own purposes.
How long we keep it
- Order and invoice records: as long as tax and company law require us to — currently several years. This is not our choice and we cannot delete these on request.
- Marketing consent and the mailing list: until you unsubscribe, and then we keep the fact that you unsubscribed, so we do not accidentally add you back.
- Enquiry forms and support email: around two years, then deleted.
- Server logs: a matter of weeks.
Your rights under the DPDP Act
You can ask us for all of these, at thebathaura@gmail.com, and we will act inside thirty days. You do not need a reason and you do not need to be polite about it.
- Access — a summary of what we hold about you and who we have shared it with.
- Correction — fix anything wrong, complete anything missing.
- Erasure — delete it, except where a law makes us keep it (see invoices, above).
- Withdraw consent — as easily as you gave it. Withdrawing marketing consent takes one click and does not affect an order in flight.
- Nominate — the DPDP Act lets you nominate someone to exercise these rights if you cannot. Write to us and we will set it up.
- Grievance redressal — if we handle any of the above badly, our Grievance Officer is the next step, and the Data Protection Board of India is the step after that.
If you are reading this from outside India
We ship only within India, so this is mostly theoretical. If you are in the EU or UK, the rights above map closely onto the GDPR ones and we will honour them under either name. If you are in California: we do not sell or share personal information as the CCPA defines those terms, so there is nothing to opt out of. You can still ask us for access or deletion, and we will not treat you differently for asking.
Cookies
Two kinds. The first make the cart work and keep it from emptying when you refresh — those are essential, they identify nobody, and need no permission. The second are analytics and advertising technologies: Google Analytics, the Meta pixel and Microsoft Clarity. We use them to see what is working on the site and to measure how our advertising performs. We send the least that makes them useful, and any contact detail is scrambled before it leaves us. You can limit or block these any time through your browser’s cookie controls and through your ad-preference settings with Meta and Google. We name every tool we use on this page, and we always will before adding a new one.
Security
HTTPS everywhere, access to order data limited to the people who pack the orders, and no card numbers on our side to lose. We are a small company and we are not going to claim a certification we do not hold. If we ever have a breach that affects you, you will hear it from us. Quickly, in plain English, with what was taken and what to do about it.
Children
The site is not intended for under-18s and we do not knowingly collect their data. India’s threshold is higher than most of the world’s and requires verifiable parental consent. If you believe we hold a child’s data, tell us and we will delete it.
Contact
Privacy questions and any of the rights above: thebathaura@gmail.com. Everything else: the usual channels.
Grievance Officer: to be named before launch, with a postal address and a response timeline, as the law requires. This placeholder is here deliberately, so it cannot quietly ship unfilled.
This page is written to be understood rather than to be unfalsifiable. If something here is unclear, or if you think it contradicts what we actually do, that is a bug — tell us and we will fix the page or the behaviour, whichever is wrong.
