Free Shipping Above ₹999100% Handmade CrochetCustom Orders Welcome — WhatsApp UsSecure UPI Payments
Free Shipping Above ₹999100% Handmade CrochetCustom Orders Welcome — WhatsApp UsSecure UPI Payments
    Skip to main content
    New Spring Collection is Live · Free Shipping Above ₹999 · Custom Orders Welcome — WhatsApp Us!

    Security Policy

    सुरक्षा नीति

    Last Updated: July 27, 2026

    1. Payment Security

    All payments on kaarihandmade.com are processed through Cashfree Payments, a PCI-DSS Level 1 certified payment gateway. Kaari never stores, processes, or transmits your card numbers, CVV, or UPI PINs on its servers. Payment credentials are entered directly on Cashfree's encrypted payment page and tokenized — we only receive a payment status callback.

    2. Data Encryption

    All data in transit is encrypted via TLS 1.3 with HSTS enabled. Data at rest in our Supabase PostgreSQL database is encrypted with AES-256. Authentication tokens (JWT) are signed and have a limited lifetime. Sensitive credentials (Cashfree keys, Supabase service-role key) are stored as environment secrets and never committed to source control.

    3. Authentication & Access Control

    User accounts use Supabase Auth with email/password or Google OAuth. Passwords are hashed with bcrypt — we cannot see your plaintext password. Admin access to the dashboard is restricted by role-based access control (RBAC) and requires an authenticated session with admin privileges. Row-Level Security (RLS) policies ensure users can only access their own order data.

    4. Rate Limiting & Abuse Prevention

    All public API endpoints enforce rate limiting (e.g., 10 order creations per minute per IP, 3 contact submissions per hour). Abusive patterns are blocked at the edge function layer. Idempotency keys prevent duplicate orders from network retries or double-clicks.

    5. Content Security Policy (CSP)

    Our Content Security Policy restricts which domains can serve scripts, styles, images, and API calls. Inline scripts are disallowed except for Next.js hydration. External connections are limited to our CDN (Cloudinary), payment gateway (Cashfree), and map service (Nominatim).

    6. Data Retention

    Personal data is retained only as long as necessary for the purpose it was collected. Order data is retained for 7 years for tax/audit compliance (GST). Contact messages are retained for 1 year. Unverified guest data is purged after 30 days. See our Privacy Policy for the full retention schedule.

    7. Vulnerability Disclosure

    If you discover a security vulnerability, please report it to security@kaarihandmade.com with a detailed description. We acknowledge receipt within 48 hours and aim to provide a fix or mitigation within 30 days. Please do not publicly disclose the vulnerability until we have had a chance to address it.

    8. DPDP Act 2023 Compliance

    We comply with the Digital Personal Data Protection Act, 2023. You have the right to access, correct, erase, or nominate a representative for your personal data. To exercise these rights, visit your Account page and submit a data principal request, or contact our Data Protection Officer at dpo@kaarihandmade.com. We respond to all requests within 30 days as required by §12 of the Act.

    9. Incident Response

    In the event of a personal data breach, we will notify affected users and the Data Protection Board of India within 72 hours of becoming aware of the breach, as required by §8(6) of the DPDP Act. Our incident response plan includes containment, assessment, notification, and post-incident review.