Last updated: 26 Jul 2026
Rupashree Jewellers RB ("we") operates the Jonaki online store at jonaki.online. This policy is our notice under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act 2000 and its Reasonable Security Practices Rules 2011, and the Consumer Protection (E-Commerce) Rules 2020. Last updated: 23 June 2026.
We process your data on two legal grounds:
We share data only with these named processors, for these specific purposes, all under written contracts:
We never sell your personal data to advertisers, data brokers, or any third party.
You have the right to:
To exercise any right, email care@jonaki.online. We acknowledge within 48 hours and resolve within 30 days.
We retain order data for as long as the law requires (typically 8 years under the GST and Income Tax Acts for financial records, 3 years under the Consumer Protection Act for complaint records). After the retention period, we delete or anonymise the data. You can request earlier deletion of any non-financial data by writing to the Grievance Officer.
We follow Rule 8 of the IT (SPDI) Rules 2011 — reasonable security practices including TLS 1.2+ in transit, bcrypt hashing for passwords, signed Razorpay payment verification, principle of least privilege for staff access, and CSP / X-Frame-Options on every page. No system is 100% secure, but we treat protection seriously.
We use cookies for essential functionality (session, cart, CSRF), analytics (GA4, Clarity) and advertising (Meta Pixel, Google Ads). You can control non-essential cookies via your browser settings — most browsers let you block or delete cookies on a per-site basis. The cookies we set do not include card or password data. Disabling essential cookies will break login and checkout.
Jonaki is intended for adults (18+). We do not knowingly collect personal data from anyone under 18. We do not track minors behaviourally and do not target advertising at children. If you believe a child has submitted data to us, email care@jonaki.online and we will erase it within 7 days.
Some processors (Google, Meta, Microsoft Clarity) operate from servers outside India, principally in the United States or European Union. We rely on the Government of India's notified country list under DPDP s.16; if you are in a restricted jurisdiction we will limit the transfer accordingly. Your personal data shared with these processors is either hashed (Meta), anonymised (GA4 IP anonymisation), or session-only (Clarity).
If a breach affects your data, we tell the Data Protection Board of India and we tell you directly, within the timeline DPDP s.8(6) requires. You'll get a plain-English note covering what happened, what data was involved, what we're doing about it, and what you can do to protect yourself.
As required by the DPDP Act s.10 and the Consumer Protection (E-Commerce) Rules 2020 r.5(5), we have designated a Grievance Officer responsible for addressing your queries and complaints. You can reach them at:
We may update this policy from time to time. The "last updated" date reflects the latest version. When anything material changes, we email customers on our marketing list and run a banner on the site for 30 days.
Questions? Email care@jonaki.online or WhatsApp +91 98308 82821.