Privacy Policy

Last updated: 14 September 2026

LUSTRE CARAT, operated by Madhavi Diam, respects your privacy and is committed to protecting the personal information you share with us. This policy explains what we collect, why we collect it, who we share it with, and how we keep it safe.

It applies to lustrecarat.com and to the LUSTRE CARAT mobile app for Android and iOS. Where something applies to only one of them, we say so.

For the purposes of India's Digital Personal Data Protection Act, 2023, Madhavi Diam is the Data Fiduciary for the personal data described here. Where the EU or UK GDPR applies, we act as the Data Controller.

Information We Collect

Information you give us

  • Contact and identity details: name, email address, mobile number, and shipping and billing addresses, provided at sign-up or checkout.

  • Mobile number for sign-in: in the app, your mobile number is your account. We send a one-time password to it to verify that the number is yours.

  • Order information: the items you buy, the amount paid, and the delivery details for each order.

  • Delivery area: the PIN code used to check whether we deliver to you. You can type it in, or let the app suggest it from your device location if you allow that. The app remembers the last one so you are not asked again. See Permissions below.

  • Photographs you attach: reference images you add to a custom order enquiry, and photographs you add to a product review. Photographs attached to a review are published with that review and can be seen by anyone browsing the product.

  • Anything you write to us: the contents of emails, enquiries and support requests you send.

Information collected automatically

  • Usage and interaction data: the products you view, what you add to your bag, the screens or pages you visit, and the orders you place.

  • Device and technical data: device model, operating system version, app version, language, and general connection information.

  • Identifiers: a customer account identifier, an app-instance identifier used for measurement, a notification token that tells us which device to send your order updates to, and, on Android, the device advertising identifier.

  • Diagnostics: crash reports and performance timings, such as how long a screen or a network request took.

  • Session recordings (app only): see the section on the mobile app below.

  • Cookies (website only): used to remember your region, keep your bag, and improve your browsing experience.

Payment information

Card, UPI and banking details are collected and processed directly by our payment gateway, Razorpay, in their own secure interface. They do not pass through our servers and we never see or store them. We receive only a payment reference, the amount, and whether the payment succeeded.

Where you choose Pay on Delivery, you pay a booking amount online through Razorpay and the balance in cash or UPI to the delivery agent. We do not collect or store any details of that final payment.

The Mobile App

The app uses a small number of third-party tools to keep it working and to understand how it is used. We want to be specific about these rather than describe them in general terms.

  • Firebase Authentication (Google): sends the one-time password that signs you in. Your mobile number is shared with Google for this purpose.

  • Firebase Analytics (Google): records events such as viewing a product, adding to the bag, and placing an order, so we can see which parts of the app are used and where people run into difficulty.

  • Firebase Crashlytics (Google): reports crashes, with the technical detail we need to fix them.

  • Firebase Performance Monitoring (Google): measures app start time and how long requests take.

  • Microsoft Clarity: records app sessions. This is described in full below.

  • Meta (Facebook and Instagram): measures advertising, as described below.

  • Razorpay: processes payments, as described above.

Once you sign in, your customer account identifier is attached to the analytics, crash and session data above. This means that data is linked to your account rather than anonymous. We do it so that we can tell whether a problem affected one person repeatedly or many people once, and so we can help you when you contact us about an order.

Advertising measurement

We advertise the app on Facebook and Instagram. So that we can tell which of those advertisements are worth running, the app tells Meta when it is installed from one, and what you do afterwards: viewing a piece, adding one to your bag, starting checkout, and placing an order, together with the order value. If you are signed in, your customer account identifier is included, and on Android your device advertising identifier is too.

Meta is different from the providers above, and we would rather say so plainly. The others act only on our instructions. Meta also uses this information for its own advertising purposes, including building audiences so that our advertisements can be shown to you and to people who resemble our customers. That is a sharing of your information for advertising rather than a provider processing it for us.

On iPhone and iPad we do not track you across other companies’ apps and websites. The app asks for no tracking permission and reads no advertising identifier there; Apple reports installs to us in aggregate instead. On Android you can reset or delete your advertising ID at any time in Settings, under Privacy, and doing so does not affect the app.

Meta’s use of this data is governed by the Meta Privacy Policy .

Session recordings

We use Microsoft Clarity to record app sessions: the screens you visit, and taps and scrolls within them. We use these recordings to find bugs, to see where people get stuck, and to improve the app.

Fields that carry personal or sensitive information, including your name, contact details, delivery address and the one-time password used to sign in, are masked so that they are not readable in a recording. We do not use recordings to build a profile of you for advertising, and we do not sell them.

Microsoft processes this data on our behalf. Their use of it is governed by the Microsoft Privacy Statement .

Advertising identifier

On Android, the app accesses the device advertising identifier. It is used for the measurement described under Advertising measurement above: attributing an install to the advertisement it came from, and letting Meta build advertising audiences. It is also read by Google's measurement library to count users and gauge how the app performs.

You can reset or delete this identifier at any time in your device settings, under Privacy or Ads. Resetting it does not stop you using the app.

On iPhone and iPad, no advertising identifier is read. The app does not ask for permission to track you across other companies' apps and websites, and does not do so. If that ever changes, we will ask for your permission first and update this policy.

Permissions

The app asks for a small number of device permissions. Each one is optional, is used only for the purpose described here, and can be changed at any time in your device settings.

  • Location, while you are using the app: used to suggest your delivery PIN code so that you do not have to type it. We ask the first time you open the app, and again if you tap to use your current location. When you allow it, we read an approximate position once, turn it into a PIN code on your device, and keep only that PIN code. We never read your location in the background, and we do not store or share the position itself. You can type a PIN code instead, and declining changes nothing else about the app.

  • Camera: used only when you choose to take a photograph to attach to a custom order enquiry or to a product review.

  • Photos: used only when you choose to attach a photograph you already have. You pick the photographs yourself and we receive only those; the app cannot see the rest of your library.

  • Notifications: used to send you order and delivery updates, and offers where you have asked for them. You can turn them off at any time.

The app does not request access to your microphone, contacts, calendar, health data or files.

How We Use Your Information

  • To create and manage your account, and to sign you in.

  • To process, fulfil and deliver your orders.

  • To send you order confirmations, delivery updates and receipts.

  • To handle returns, refunds and support requests.

  • To check whether we can deliver to your PIN code.

  • To understand how the site and app are used, and to fix problems and improve them.

  • To detect and prevent fraud, and to keep our systems and your account secure.

  • To send marketing messages, only where you have asked to receive them.

  • To meet our legal, tax and accounting obligations.

We do not use automated decision-making that produces legal or similarly significant effects on you.

Our Legal Basis

Where the DPDP Act applies, we process your data on the basis of the consent you give when you create an account and place an order, and for the legitimate uses that Act permits, such as fulfilling an order you have asked for and meeting a legal obligation.

Where the GDPR applies, our bases are: performance of a contract, for orders and account management; legitimate interests, for security, fraud prevention, and improving our service; consent, for marketing and for non-essential cookies; and legal obligation, for tax and accounting records.

Sharing Your Information

We do not sell your personal information, and we do not share it with data brokers. We share it only as set out here:

  • Payment gateway: Razorpay, to take payment.

  • Courier and logistics partners: your name, address and mobile number, so that your order can be delivered and so the delivery agent can reach you.

  • Technology providers: Google (Firebase) and Microsoft (Clarity), as described above, who process data on our instructions.

  • Meta, for advertising: the measurement described above. Unlike the providers in this list, Meta also uses that information for its own advertising purposes, so this is a sharing of your information for advertising rather than processing on our instructions.

  • Professional advisers and authorities: where we are required to disclose information by law, or to establish or defend a legal claim.

  • A successor business: if our business is sold or reorganised, under the same protections as this policy.

Where Your Data Is Held

Our systems are operated from India. Some of the service providers above process data on servers outside India, including in the United States and the European Union. Where data is transferred abroad, we rely on the contractual protections those providers offer, including the European Commission's Standard Contractual Clauses where applicable.

How Long We Keep It

  • Account details: for as long as your account is open, and deleted when you ask us to close it.

  • Order and invoice records: 8 years from the end of the financial year in which the order was placed, as required by the Companies Act, 2013 and the Central Goods and Services Tax Act, 2017. We cannot delete these on request.

  • Analytics and crash data: retained by our providers on rolling periods, typically no more than 14 months.

  • Session recordings: typically 30 days.

  • Support correspondence: up to 3 years, so we can deal with any follow-up.

Data Security

All data sent between your device and our servers is encrypted in transit using HTTPS. Access to customer data is limited to the people who need it to do their job. We do not store card or banking details at all. No system can be guaranteed completely secure, but we take these measures seriously, and if a breach affects your personal data we will notify you and the Data Protection Board of India as the law requires.

Age Requirement

Buying from us means entering into a purchase contract, which under the Indian Contract Act, 1872 requires you to be 18 or over. Accounts and orders are therefore for adults, and we do not knowingly collect personal information from anyone under 18.

Nothing we sell or publish is unsuitable for a younger audience, and we are glad to be browsed by anyone. The requirement is about who can hold an account and place an order, not about who may look.

If you believe someone under 18 has created an account or given us their personal information, contact us and we will delete it.

Your Rights

You may ask us to:

  • Access the personal data we hold about you, and receive a copy of it.

  • Correct anything that is inaccurate or incomplete.

  • Delete your account and the data held against it. See Delete Your Account for how to do this and what we are legally required to keep.

  • Withdraw consent at any time, including for marketing messages. Withdrawing consent does not affect processing already carried out.

  • Nominate another person to exercise these rights on your behalf if you die or become incapacitated, as the DPDP Act allows.

  • Object to or restrict processing, and to receive your data in a portable form, where the GDPR applies.

To exercise any of these, email contact@lustrecarat.com from the address registered on your account. We respond within 7 working days, and in any case within the period the law requires. There is no charge.

Cookies

The website uses cookies to remember your region, keep your bag, and improve your browsing experience. You can disable cookies in your browser settings, though some features may then not work properly. The app does not use cookies; the equivalent information is stored on your device and cleared when you uninstall it.

Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with a revised "last updated" date. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect.

LustreCarat App
LustreCarat Mobile

For a better experience, download our app

Smoother browsing • Real-time order tracking

Get it on Google PlayDownload on the App Store