← Sable Monarch

Policies

Privacy Policy

Effective 01 May 2026

Sable Monarch (“we”, “our”, “us”) takes your privacy seriously. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the rights you have over it under the Digital Personal Data Protection Act, 2023 and other applicable Indian law.

01

Data We Collect

We collect the following categories of personal data:

  • Account data — your name, email address, and phone number when you sign in via login link or create an account.
  • Order data — delivery address, garment selections, sizing, design choices, payment confirmation tokens.
  • Design inputs — text prompts, uploaded reference images, and the AI-generated outputs derived from them.
  • Usage data — IP address, device and browser type, pages visited, and basic interaction analytics, used to operate and improve the Service.
  • Cookies and similar technologies — small identifiers stored in your browser to keep you signed in, remember your cart, and protect against cross-site request forgery.

We do not knowingly collect data from anyone under the age of 18. If you believe we have, please contact us and we will delete it.

02

Why We Use Your Data

  • To create and manage your account.
  • To accept, produce, and deliver your orders and to send transactional confirmations, production updates, and shipping notifications.
  • To process payments and prevent fraud.
  • To run the AI generation pipeline (your prompt is sent to a model provider so that an image can be returned to you).
  • To maintain a personal design history that you can re-use across future orders.
  • To debug and improve the Service, monitor uptime, and protect against abuse.
  • To comply with applicable legal and tax obligations.
03

Lawful Basis

We process personal data on the basis of (a) your consent, given when you submit information to the Service; (b) the necessity to perform our contract with you (your order); and (c) our legitimate interest in operating, securing, and improving the Service. You may withdraw your consent at any time, subject to obligations we are legally required to fulfil (for example, retaining tax records).

04

Who We Share With

We share data with the following categories of processors, each bound by their own privacy commitments:

  • Razorpay — payment processing.
  • fal.ai — AI image generation; receives your prompt and any uploaded reference image for the duration of generation.
  • Cloudinary — image hosting for generated and uploaded designs.
  • Resend — transactional email delivery (order confirmations, login-link sign-in).
  • Neon — managed Postgres database where order and account records are stored.
  • Vercel — application hosting and content delivery.
  • Telegram — used internally to forward production briefs to our manufacturing partner; only the data needed to fulfil the order is sent.
  • Our manufacturing partner — receives your name, delivery address, garment specs, and the design files required to produce your order.

We do not sell your personal data to advertisers.

05

Data Retention

We keep account and order records for as long as your account is active and for a reasonable period thereafter to comply with tax, accounting, and dispute-resolution requirements. Design history is kept until you delete it or close your account. You may request deletion at any time.

06

Your Rights

Under the Digital Personal Data Protection Act, 2023 you have the right to:

  • access a summary of your personal data;
  • request correction or completion of inaccurate data;
  • request erasure of your data, subject to legal retention obligations;
  • withdraw consent for any processing that is consent-based;
  • nominate a person to exercise these rights on your behalf in case of incapacity;
  • file a grievance with our Grievance Officer (see Section 09).

To exercise any of these rights, email info@sablemonarch.com from the address registered with your account. We will respond within thirty (30) days.

07

Security

We use industry-standard safeguards including TLS for data in transit, hashed and tokenised storage of credentials, role-based access controls, rate limiting, and CSRF protection on all state-changing endpoints. No system is perfectly secure; if we become aware of a personal-data breach, we will notify affected users and the Data Protection Board of India as required by law.

08

International Transfers

Some of our processors operate servers outside India. By using the Service you consent to your personal data being transferred to and processed in those jurisdictions, subject to safeguards equivalent to those required under Indian law.

09

Grievance Officer

In accordance with the Information Technology Act, 2000 and the rules thereunder and the Digital Personal Data Protection Act, 2023, the contact details of our Grievance Officer are:

We aim to acknowledge grievances within 48 hours and resolve them within 30 days.

10

Changes to This Policy

We may update this Privacy Policy from time to time. The “Effective” date at the top reflects the latest revision. Material changes will be highlighted on the website or sent to your registered email address.

Sable Monarch · India