Bangalore Stores respects your privacy. This page explains what information we collect and how we use it.
What we collect
- Account details: your name and mobile number when you create an account. Sign-in uses a one-time code sent to your mobile number β we do not ask you to create or store a password.
- Order details: the items you buy and the delivery address you give at checkout.
- Store credit records: if a return is approved, we keep a record of the credit issued to you and where it was spent, so your balance is always accountable.
- Cart data: stored in your own browser so your cart is there when you come back.
- Security logs: we briefly record technical details such as IP addresses for sign-in attempts and orders, only to protect accounts against break-in attempts and abuse.
Cookies
We use only essential cookies β one that keeps you signed in and one that remembers your cart. There are no advertising, analytics, or tracking cookies on this site, and we never follow you around the web.
How we use it
- To process and deliver your orders and keep you updated on their status.
- To contact you on WhatsApp or phone about your order.
- We do not sell your information, and we share it only with the partners needed to run the store, listed below.
Partners we share data with
- Cashfree Payments (RBI-regulated): handles online payments (UPI, cards, netbanking, wallets). Your card or UPI details never touch our servers.
- Courier partners (e.g. Delhivery, India Post): receive your name, phone number, and delivery address to deliver your parcel.
- 2Factor.in: delivers the one-time sign-in code to your phone by SMS. They receive only your mobile number and the code.
- Google reCAPTCHA: protects our sign-in form from bots. When you sign in, Google receives standard device information under its own privacy policy.
- Email delivery: order paperwork and staff sign-in codes are sent through a transactional email service; customers do not receive marketing email.
Security & retention
Your data is stored securely, customer sign-in uses one-time codes rather than passwords, and all traffic to this site uses HTTPS.
- Customer accounts have no password at all, so there is none to leak or reuse.
- Staff accounts (used only by us to run the shop) do have a password. It is stored as a salted scrypt hash, never in readable form, and staff sign-in also requires a second factor.
How long we keep things:
- Sign-in codes expire 10 minutes after they are sent and are single-use.
- Abuse-protection records (the counters that stop someone guessing codes repeatedly) are keyed to a phone number or IP address, last only as long as their block window β minutes, up to an hour β and are cleared as soon as you sign in successfully.
- Order records are kept for as long as Indian accounting and tax law requires us to keep them.
- Saved addresses stay until you ask us to remove them (see below); we keep at most eight per customer.
Your choices
To see, correct, or delete your account information, contact us via the Contact page and we'll take care of it.