Hillcrest← Back to Home

Privacy Policy

Effective Date: 11th August, 2026  ·  Last Updated: 11th August, 2026

MG Cottons (“we”, “us”, or “our”) operates the website hillcrestwear.com and is committed to protecting the privacy of our customers in compliance with India’s Digital Personal Data Protection Act, 2023 (DPDP Act). This Privacy Policy explains what personal data we collect, why, who processes it on our behalf, and how long we keep it.


1. Information We Collect

  • Identity data: your full name and, if you create one, a username.
  • Contact data: email address, phone number, and optionally a WhatsApp number.
  • Delivery data: the recipient name, street address, apartment, city, state and PIN code of each address you save.
  • Account credentials: if you sign up with a password, we store a bcrypt hash of it. We never store your password itself. If you sign in with Google, we store only your Google account identifier — we do not store Google access or refresh tokens.
  • Order data: the products you buy, including size and colour, quantities, prices paid, order status, and your invoice number.
  • Payment references: the Razorpay order, payment and signature identifiers for each transaction. We never receive or store your card number, UPI ID or bank details — those are entered directly into Razorpay’s payment window.
  • Technical data: your IP address, recorded when you request a one-time passcode and when a rate limit is applied. We do not track pages visited or referring URLs.
  • Email delivery records: which emails we sent you, when, and whether they were delivered, bounced or reported as spam.
  • Wholesale enquiries: if you submit the wholesale form, the business name, contact name, email, phone and message you provide.

We collect this data when you create an account, verify your email, save an address, place an order, or contact us. We do not operate a newsletter and do not collect data for marketing lists.

2. How We Use Your Data

  • Order fulfilment: processing, invoicing and delivering your orders, and handling returns and refunds.
  • Account management: creating and maintaining your account, verifying your email address, and resetting your password.
  • Transactional email: order confirmations (with your GST invoice attached), payment and refund notices, dispatch and delivery updates, and security emails such as passcodes and password resets. These are necessary to perform your order and are not marketing.
  • Security and fraud prevention: rate limiting, bot protection, and checking proposed passwords against known breach corpora.
  • Analytics (only with your consent): understanding how visitors navigate the site. See section 4.
  • Legal compliance: meeting our obligations under Indian law, including GST record-keeping.

3. Who Processes Your Data

We do not sell your personal data. It is shared only with the following processors, each for the stated purpose:

  • Razorpay Software Private Limited (payments, India) — receives the order amount and, so you do not have to retype them, your name, email address and phone number in the payment window. Governed by Razorpay’s Privacy Policy.
  • Resend (transactional email) — receives your email address and the contents of each email we send you, including your GST invoice PDF, which contains your name, delivery address, phone number and itemised order.
  • Cloudflare (Turnstile bot protection) — receives your IP address each time you sign up, sign in, or submit the wholesale form.
  • Neon (database hosting) — stores the data described in section 1.
  • Vercel (website hosting) — processes every request to this site and retains server logs.
  • Google (optional “Sign in with Google”) — only if you choose to use it. If you have a Google profile picture, your browser loads it from Google’s servers.
  • Microsoft (Clarity analytics) — only if you accept analytics cookies. See section 4.
  • Have I Been Pwned (breached-password check) — receives only the first five characters of a SHA-1 hash of a proposed password. Your password never leaves our servers and cannot be reconstructed from what is sent.
  • Legal obligation: we may disclose data where required by law or a court order.

We do not use Google Analytics, advertising pixels, or any advertising network, and we currently do not share delivery addresses with any courier — shipping is arranged manually.

4. Cookies and Analytics

Essential cookies and storage — always active, because the site cannot function without them:

  • Session cookie (next-auth.session-token) — keeps you signed in. HTTP-only, and expires after 7 days.
  • Security cookies — protect against cross-site request forgery during sign-in.
  • Cart storage — your basket is kept in your browser’s local storage so it survives a page reload.
  • Consent record — remembers the choice you made in our cookie banner.

Analytics — off unless you choose “Accept All”:

With your consent we use Microsoft Clarity, which records how visitors move through the site, including an anonymised replay of your session. Text content is masked before it leaves your browser, and the checkout, account and order pages are excluded entirely, so your name, address, phone number and order details are not captured. If you choose “Essential Only”, or dismiss the banner without choosing, Clarity is never loaded at all.

You can change or withdraw your choice at any time using the Cookie preferences link in the site footer, or by clearing your browser storage for this site. We use no advertising or marketing cookies.

5. Your Rights Under the DPDP Act, 2023

As a Data Principal under Indian law, you have the right to:

  • Access: request a summary of the personal data we hold about you. Email us and we will compile and send it.
  • Correction: update your name, phone and WhatsApp number yourself under Account → Profile, or ask us to correct anything else.
  • Erasure: delete your account from Account → Profile, or by contacting us. Please read section 7, which explains exactly what erasure does and does not remove.
  • Grievance redressal: raise a complaint with our Grievance Officer (section 8).
  • Withdraw consent: withdraw analytics consent at any time via the Cookie preferences link in the footer.

To exercise any of these rights, contact us at support@hillcrestwear.in. We will respond within 30 days.

6. How Long We Keep Your Data

DataRetention
Orders, invoices and order items6 years from the end of the financial year, as required by GST Rule 56
Account and saved addressesUntil you delete your account (see section 7)
Email delivery records24 months
IP addresses from passcode requests30 days
One-time passcodes and password reset tokens7 days after they expire
Unverified sign-ups7 days after they expire
Rate-limiting records1 day
Wholesale enquiries24 months

7. What Account Deletion Does

We want to be precise about this, because deletion cannot be total while Indian tax law requires us to keep sales records. When you delete your account:

  • Removed: your name, profile photo, password, phone number, WhatsApp number and username. Your email address is replaced with an anonymous placeholder. Your saved cart, sign-in links, passcodes and reset tokens are deleted outright.
  • Retained: your past orders and invoices, for the 6-year GST period above. They are unlinked from your identity, but the delivery address on each historic order is preserved, because a tax invoice must remain intact.
  • Retained deliberately: your email address is added to our do-not-contact list, so that deleting your account cannot result in us emailing you again. This is the one piece of identifying data we keep because you asked to be forgotten. You may ask us to remove it as well.

Deletion is immediate and cannot be undone. You will be signed out on your next request.

8. Grievance Officer

In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023:

Name: A Grievance Officer has not yet been appointed. Please direct all privacy queries to the email address below.

Email: support@hillcrestwear.in

Response time: within 30 days of receiving the grievance

9. Data Security

Traffic is encrypted with TLS. Passwords are hashed with bcrypt and checked against known breach corpora. Payment card data never touches our servers — it is handled entirely by Razorpay, which is PCI-DSS compliant. Access to order and account data requires an authenticated session, and every record is scoped to its owner. No system is perfectly secure, and we cannot guarantee absolute security.

10. Children’s Privacy

Our website is not directed at children under 18 and we do not knowingly collect their personal data. If we learn that we have, we will delete it promptly.

11. Changes to This Policy

We may update this policy. Material changes will be posted here with an updated “Last Updated” date.

12. Contact Us

Questions about this policy? Email support@hillcrestwear.in. See also our Terms & Conditions and Return & Refund Policy.