Effective Date: December 1, 2025
CozyVora (“CozyVora”, “we”, “us”, or “our”) is committed to protecting your privacy and handling your personal information with transparency and care. This Privacy Policy explains how we collect, use, share, store, and protect your information when you visit cozyvora.com (the “Site”), place an order, interact with us, or use any of our services.
By using the Site, you agree to the terms described in this Privacy Policy. If you do not agree, please discontinue use of the Site.
For the purposes of applicable data protection laws (including GDPR), CozyVora is the data controller of your personal information.
1. Information We Collect
We collect information in several ways to operate our business, fulfill orders, improve customer experience, and maintain security.
1.1 Information You Provide
We collect information you provide directly, including:
- Name
- Email address
- Phone number
- Billing and shipping address
- Order details and transaction history
- Payment confirmation details (payment processing is handled by third-party providers; we do not store full card numbers or CVV)
- Messages or attachments sent through email, WhatsApp, Instagram, Facebook, or support channels
- Custom design files (if you submit artwork for printing)
- Responses to forms or surveys
- Account registration information (username, password, preferences)
1.2 Information Collected Automatically
When you interact with our Site, we automatically collect:
- IP address
- Device type, operating system, and browser information
- Pages viewed, time spent on pages, and navigation paths
- Referring website URLs
- Session behavior and interaction patterns
- Geographic location (country/region level, derived from IP address)
1.3 Information from Cookies & Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience on the Site. Cookies are small data files stored on your device that help us provide and improve our services.
Types of Cookies We Use:
(a) Essential Cookies: Required for Site functionality, including shopping cart, checkout, account login, and security features. These cookies are necessary for the Site to operate and cannot be disabled.
(b) Analytics Cookies: Help us understand how visitors use the Site, including pages visited, time spent, and user behavior. These cookies collect data to improve Site performance and user experience.
(c) Advertising & Marketing Cookies: Used to show relevant advertisements on third-party platforms and to measure marketing campaign effectiveness. These cookies may track your activity across websites to personalize advertising.
(d) Preference Cookies: Remember your choices and settings to provide a personalized experience.
Managing Your Cookie Preferences:
You can control cookies through:
- Your browser settings (most browsers allow you to block or delete cookies)
- Our cookie consent banner (you can change your preferences at any time)
- Privacy settings in your browser or operating system
Disabling essential cookies may affect Site functionality, including checkout and account features.
For more information on managing cookies in your browser, visit: https://www.allaboutcookies.org/manage-cookies
1.4 Information From Third-Party Tools
We may receive limited data from:
- WooCommerce (our e-commerce platform, which processes order data, customer accounts, and transaction information on our behalf)
- WordPress (our content management system, which may collect usage data for security and performance purposes)
- Google Analytics (site usage and performance data)
- Google Merchant Center (product listing performance)
- Meta Platforms (Facebook, Instagram) (advertising performance and audience insights)
- Zoho Mail (email communications and support inquiries)
- Wordfence (security monitoring, IP addresses, login attempts)
- Payment gateways (Razorpay, PayPal) (payment processing and fraud prevention)
- Order processing systems in our production and logistics network (essential order details: name, address, phone number, email, product specifications)
WooCommerce and WordPress are self-hosted on our secure servers and do not share your data with external parties except as necessary to process orders and provide services.
Payment information is handled securely by our payment providers. CozyVora does not directly store full credit card numbers, debit card numbers, or CVV codes.
2. How We Use Your Information
2.1 Legal Basis for Processing
We process your personal information based on the following legal grounds:
(a) Contract Performance: To fulfill orders, process payments, provide customer support, and deliver services as part of our Terms of Service.
(b) Legitimate Interests: To improve the Site, prevent fraud, maintain security, conduct business analytics, and optimize user experience.
(c) Consent: For marketing communications, advertising personalization, and non-essential cookies (where required by law). You may withdraw consent at any time.
(d) Legal Obligations: To comply with tax laws, accounting requirements, and legal requests from authorities.
2.2 Specific Uses
We use your information for legitimate business purposes, including:
- Processing and fulfilling orders
- Verifying payments and preventing fraud
- Providing order updates, tracking information, and delivery notifications
- Delivering customer support and responding to inquiries
- Managing returns, refunds, and warranty claims
- Sending transactional emails and notifications (order confirmations, shipping updates, account alerts)
- Sending marketing messages (only if subscribed or consented)
- Personalizing your shopping experience and product recommendations
- Improving Site performance, functionality, and user experience
- Running analytics to understand customer behavior and preferences
- Conducting advertising and marketing campaigns
- Maintaining security and preventing misuse or abuse of the Site
- Complying with legal obligations and responding to valid legal requests
2.3 Automated Decision-Making
We do not use automated systems to make decisions that significantly affect you without human involvement. Analytics and advertising tools may use algorithms to personalize content and recommendations, but final decisions regarding orders, refunds, returns, and account status are made by CozyVora staff.
3. Marketing Communications
You may receive marketing updates from us through:
- WhatsApp (if you have provided your number and consented)
- Social media messaging (optional, if you initiate contact)
We send marketing communications only if you have subscribed, opted in, or consented.
How to Opt Out:
You may unsubscribe or opt out at any time by:
- Clicking “unsubscribe” in any marketing email
- Replying “STOP” or “UNSUBSCRIBE” to WhatsApp marketing messages
- Contacting support@cozyvora.com with your request
Even if you opt out of marketing, we will still send transactional emails related to your orders, account, and customer support.
3.1 Browser Privacy Signals
Some browsers and privacy tools offer signals such as “Do Not Track” (DNT) or “Global Privacy Control” (GPC) to indicate your privacy preferences.
Where technically feasible and supported by our systems, we aim to respect these signals by disabling non-essential tracking and targeted advertising for the browser and device sending the signal.
Some browser signals may not be fully detected due to technical limitations.
To learn more about these privacy controls:
- Global Privacy Control: https://globalprivacycontrol.org
- Do Not Track: https://allaboutdnt.com
4. How We Share Information
We do not sell your personal data to third parties.
We share information only with trusted service providers and partners who assist in operating our business, and only to the extent necessary to provide services.
4.1 Operational & Processing Partners
Essential order information (name, address, phone, email, product details) may be shared with:
- Our production network (for manufacturing and quality control)
- Our logistics network (for order fulfillment, packaging, and preparation)
- Courier and shipping partners (for delivery and transit tracking)
These partners are contractually obligated to protect your information and use it only for the purposes we specify.
4.2 Payment Processors
To verify and complete payments, we share necessary transaction information with:
- Razorpay (for domestic India payments via UPI, cards, net banking)
- PayPal (for international payments and select domestic transactions)
These payment processors handle your financial information securely and in accordance with their own privacy policies and applicable payment card industry standards.
4.3 Analytics & Platform Integrations
We may share limited browsing and interaction data with:
- Google Analytics (site usage, traffic sources, and behavior analysis)
- Google Merchant Center (product listing performance and visibility in Google Shopping)
- Meta Advertising Tools (Facebook Pixel, Instagram insights) (advertising performance, audience measurement, and campaign optimization)
These services may use your data to show personalized ads across their networks and partner sites.
How to Opt Out of Personalized Advertising:
- Google Ads Settings: https://adssettings.google.com
- Facebook Ad Preferences: https://www.facebook.com/settings?tab=ads
- Network Advertising Initiative Opt-Out: https://optout.networkadvertising.org
- Digital Advertising Alliance Opt-Out: https://www.aboutads.info/choices
You may also use browser extensions like Privacy Badger, uBlock Origin, or built-in browser privacy features to block tracking scripts.
4.4 Security Services
Wordfence and similar security tools may process IP addresses, login attempts, and behavioral data to detect and prevent fraud, malware, spam, and security threats.
4.5 Legal Requirements & Protection of Rights
We may disclose information if required by law, regulation, legal process, or governmental request, including to:
- Comply with subpoenas, court orders, or valid legal requests
- Enforce our Terms of Service or other policies
- Protect CozyVora’s rights, property, or security
- Protect the rights, safety, or security of our users or the public
- Investigate or prevent fraud, abuse, or illegal activity
4.6 Business Transfers
In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, your personal information may be transferred to the acquiring entity or successor. We will notify you via email or prominent notice on the Site before your information is transferred and becomes subject to a different privacy policy.
5. Your Rights and Choices
Regardless of where you live, we provide the following rights over your personal information. These rights are not absolute and may be subject to certain legal exceptions or limitations.
5.1 Right to Access
You may request a copy of the personal data we hold about you, including information about how we collect, use, and share it.
5.2 Right to Correction
You may request correction of inaccurate, incomplete, or outdated information. You can also update your account information directly through your account settings.
5.3 Right to Deletion
You may request deletion of your personal data, except where retention is required for:
- Legal obligations (tax records, accounting requirements)
- Fraud prevention and security
- Resolving disputes or enforcing agreements
- Completing transactions or providing services you have requested
5.4 Right to Restrict Processing
You may request that we limit the use of your data in certain circumstances, such as while we verify accuracy or assess a legal claim.
5.5 Right to Object to Marketing
You may opt out of marketing communications at any time using the methods described in Section 3.
5.6 Right to Data Portability
You may request an export of your data in a structured, commonly used, machine-readable format (such as CSV or JSON) for transfer to another service.
5.7 California & US State Privacy Rights
If you are a California resident or reside in certain US states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, or Utah), you may have additional rights under the California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), or similar state laws:
(a) Right to Know: Request detailed information about the categories and specific pieces of personal information we have collected about you, including sources, purposes, and third parties with whom we share data.
(b) Right to Delete: Request deletion of your personal information, subject to certain exceptions.
(c) Right to Opt Out of Sale/Sharing: Request that we do not “sell” or “share” your personal information for targeted advertising purposes.
(d) Right to Correct: Request correction of inaccurate personal information.
(e) Right to Limit Use of Sensitive Personal Information: If applicable, request limitations on the use of sensitive personal information.
(f) Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights (such as by denying services, charging different prices, or providing a different level of service).
Note on “Sale” or “Share” of Data:
CozyVora does not sell personal information in the traditional sense (we do not exchange your data for money with data brokers). However, our use of advertising cookies and pixels (such as Google Ads and Meta Pixel) may be considered “sharing” for targeted advertising purposes under certain state privacy laws.
How to Exercise Your Rights:
To opt out of targeted advertising:
- Use the opt-out links provided in Section 4.3
- Adjust your cookie preferences through our cookie consent banner
- Contact us at support@cozyvora.com or business@cozyvora.com
To exercise other rights (access, deletion, correction):
- Email: support@cozyvora.com or business@cozyvora.com
- Include your full name, email address, and order number (if applicable) to help us verify your identity
5.8 European Economic Area (EEA) & United Kingdom Rights
If you reside in the EEA or UK, you have additional rights under the General Data Protection Regulation (GDPR) and UK GDPR:
(a) Right to Object: You may object to processing of your personal information for direct marketing, legitimate interests, or scientific/historical research purposes.
(b) Right to Restrict Processing: You may request restriction of processing in certain situations (such as while we verify data accuracy or assess your objection).
(c) Right to Withdraw Consent: Where we rely on your consent to process personal information, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
(d) Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority if you believe we have violated your privacy rights. For the EEA, you can find a list of data protection authorities here: https://edpb.europa.eu/about-edpb/about-edpb/members
How to Exercise Your Rights:
Contact us at: support@cozyvora.com or business@cozyvora.com
5.9 Verification & Response
We may need to verify your identity before processing your requests, as permitted or required by law. We may request additional information (such as email confirmation, order number, or other identifying details) to ensure we are responding to the correct person.
We will respond to verified requests within the timeframes required by applicable law (typically 30 days, with possible extensions for complex requests).
You may designate an authorized agent to make requests on your behalf. We will require proof that the agent is authorized to act on your behalf before processing such requests.
6. Data Retention
We retain information for as long as necessary to:
- Fulfill orders and provide services
- Maintain accurate business and financial records
- Resolve disputes and enforce agreements
- Comply with legal, tax, and accounting obligations
- Prevent fraud and maintain security
Specific Retention Periods:
- Order and transaction records: Up to 7 years (as required by Indian tax and accounting laws)
- Marketing data: Until you unsubscribe or request deletion
- Account information: Until you request account closure or deletion
- Security logs: Typically 90 days to 1 year (for fraud prevention and security analysis)
If you request account deletion, we will delete or anonymize your personal information within 30 days, except where retention is legally required or necessary to resolve disputes.
7. Data Security
We implement administrative, technical, and physical measures to safeguard your information and protect it from unauthorized access, loss, misuse, alteration, or destruction.
Security Measures Include:
- SSL/TLS encryption for data transmitted between your browser and our Site
- Secure hosting via Hostinger with firewalls and intrusion detection
- Wordfence firewall and malware protection to prevent attacks and unauthorized access
- Encrypted email channels via Zoho Mail for sensitive communications
- Access controls limiting internal access to personal data on a need-to-know basis
- Regular security monitoring and updates to address vulnerabilities
- Secure payment processing through PCI DSS-compliant payment gateways (Razorpay, PayPal)
7.1 Data Breach Notification
In the event of a data breach that affects your personal information, we will:
(a) Notify affected users without undue delay, as required by applicable law
(b) Provide information about the nature of the breach, affected data, and steps being taken to address it
(c) Offer guidance on protective measures you can take (such as password changes or fraud monitoring)
(d) Notify relevant regulatory authorities where legally required
We continuously monitor our systems and work to prevent unauthorized access, but no method of transmission or storage is 100% secure. While we strive to protect your data to the highest reasonable standards, we cannot guarantee absolute security.
8. International Users & Data Transfers
CozyVora operates primarily from India. If you access the Site from outside India, your information may be processed in India or other regions where our service providers operate.
For European Economic Area (EEA), United Kingdom, or Swiss users:
We ensure adequate protection for international data transfers through:
(a) European Commission Standard Contractual Clauses (SCCs)
(b) Adequacy decisions by the European Commission (where applicable)
(c) Service provider agreements that include data protection commitments and safeguards
(d) We transfer data only where necessary to provide our services.
By using the Site and providing your information, you acknowledge and consent to the transfer of your information to India and other jurisdictions as necessary to provide our services.
9. Children’s Privacy
We do not knowingly collect personal data from children under 13 years of age. The Site is not intended for children, and we do not direct our services to children.
If you are between 13 and 18 years of age, you may use the Site only with the involvement, supervision, and consent of a parent or legal guardian who agrees to be bound by our Terms of Service and this Privacy Policy.
If you are a parent or guardian and believe we have collected information from a child under 13 without consent, contact us immediately at support@cozyvora.com and we will delete it promptly.
10. Third-Party Links
The Site may contain links to external websites or services operated by third parties (such as social media platforms, payment providers, or partner sites).
We are not responsible for the privacy practices, content, or security of third-party sites. We encourage you to review the privacy policies of any third-party sites you visit.
Our inclusion of such links does not imply endorsement of the linked sites or their operators, except as disclosed on the Site.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs.
When we make material changes, we will:
- Update the “Effective Date” at the top of this page
- Post the revised Privacy Policy on the Site
- Provide notice as required by applicable law (such as via email or a prominent banner on the Site)
Your continued use of the Site after the effective date of changes indicates your acceptance of the updated Privacy Policy. We encourage you to review this page periodically to stay informed about how we protect your information.
12. Contact Information
For privacy questions, data requests, concerns, or to exercise your rights, contact:
Email: support@cozyvora.com
Business & Compliance: business@cozyvora.com
WhatsApp: +91-93095-23458
For the purposes of applicable data protection laws (including GDPR), CozyVora is the data controller of your personal information.
We aim to respond to general inquiries within 24 hours and to formal data rights requests within 30 days (as required by law).
(Operational note: This policy is aligned with our current processing, production, and logistics systems and may evolve as our infrastructure grows.)
