Effective Date: April 1, 2026  |  Last Updated: April 27, 2026  |  Version: 2.0

Our Privacy Commitment

At ANNA KEY ("we," "us," or "our"), we are deeply committed to protecting the privacy and personal information of every patron who visits our website www.annakey.shop, places an order, or interacts with our brand in any capacity. This Privacy Policy explains in detail how we collect, use, store, share, and protect your personal data when you access our website, purchase our handcrafted luxury keychains, or engage with our services. By using our website or making a purchase, you consent to the practices described in this policy.

ANNA KEY is a registered business operating from Vagdevi Vilas School, 77/2 Vagdevi School Drive Way, Bengaluru, Bangalore East, Karnataka, 560037, India, under the proprietorship of M. ANNA Sehetty. We are committed to complying with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and all applicable Indian data protection regulations.

1. Information We Collect

We collect various types of information to provide you with the best possible luxury experience. The information we collect falls into the following categories:

1.1 Personal Identification Data

  • Full name, title, and salutation as provided during account registration or checkout
  • Email address for order confirmations, shipping updates, and communication
  • Phone number (mobile and/or landline) for delivery coordination and order verification
  • Residential or office address including city, state, PIN code for shipping and billing purposes

1.2 Transaction & Payment Data

  • Order history, including product details, quantities, order values, and dates of purchase
  • Payment method used (UPI, credit/debit card, net banking, wallet) — we do not store full card numbers or CVV codes
  • Transaction reference numbers and payment confirmation details
  • Billing address if different from shipping address
  • GST number if provided for business purchases

1.3 Bespoke & Personalization Data

  • Custom engraving text, initials, or messages provided for personalized orders
  • Design preferences, material choices, and finish selections for bespoke commissions
  • Corporate branding specifications for bulk or B2B orders
  • Gift messages and recipient details for gift orders

1.4 Technical & Device Data

  • IP address, browser type and version, operating system, and device type
  • Pages visited, time spent on each page, click patterns, and navigation paths
  • Referring website URL and search terms used to find our website
  • Cookie identifiers and session data (see our Cookie Policy for details)

1.5 Communication Data

  • Emails, messages, and correspondence sent to our support or concierge team
  • Feedback, reviews, and testimonials submitted on our website
  • Preferences for receiving marketing communications and newsletters

2. How We Use Your Information

We use the information we collect for the following specific purposes:

Purpose Data Used Legal Basis
Processing and fulfilling your orders Identity, Transaction, Bespoke Data Contractual necessity
Shipping and delivery coordination Identity, Address, Phone Contractual necessity
Payment processing and fraud prevention Transaction, Technical Data Contractual & Legal obligation
Customer support and query resolution Identity, Communication Data Legitimate interest
Sending order updates and shipping notifications Identity, Email, Phone Contractual necessity
Marketing communications (Signature Club) Email, Preferences Consent (opt-in only)
Website improvement and analytics Technical, Device Data Legitimate interest
Legal compliance and dispute resolution All relevant data Legal obligation

3. Data Storage & Retention

Your personal data is stored on secure servers located in India. We retain your information only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Specifically:

  • Order and transaction data: Retained for a minimum of 8 years to comply with Indian tax and accounting regulations under the Income Tax Act and GST Act.
  • Account data: Retained for as long as your account remains active. If you request account deletion, we will erase your data within 30 days, except where retention is required by law.
  • Marketing preferences: Retained until you withdraw your consent by unsubscribing.
  • Technical data (cookies, logs): Retained for a maximum of 12 months, after which it is automatically purged.
  • Communication records: Retained for 3 years from the date of last interaction for quality assurance and dispute resolution.

4. Data Security Measures

We have implemented comprehensive security measures to protect your personal data from unauthorized access, alteration, disclosure, or destruction. These measures include:

  • SSL/TLS Encryption: All data transmitted between your browser and our servers is encrypted using industry-standard 256-bit SSL/TLS encryption.
  • Secure Payment Gateway: All payment transactions are processed through PCI-DSS compliant payment gateways. We never store your full card details on our servers.
  • Access Controls: Access to personal data is restricted to authorized personnel only, on a strict need-to-know basis. All staff with data access undergo background verification.
  • Regular Security Audits: We conduct periodic security assessments and vulnerability testing to identify and address potential risks.
  • Data Backup: Regular encrypted backups are maintained to prevent data loss, stored in geographically separate secure locations within India.
  • Incident Response: We maintain a documented incident response plan. In the event of a data breach, affected users will be notified within 72 hours as required by applicable regulations.

5. Third-Party Data Sharing

We do not sell, rent, or trade your personal information to any third party for marketing or commercial purposes. We share your data only with the following categories of trusted partners, strictly on a need-to-know basis:

  • Payment Processors: Razorpay, PhonePe, and other PCI-DSS compliant gateways for secure transaction processing.
  • Logistics Partners: Premium courier services (Delhivery, Blue Dart, DTDC) for order shipping and delivery tracking.
  • Analytics Providers: Google Analytics for anonymized website usage analysis to improve your browsing experience.
  • Communication Tools: Email service providers for sending order confirmations, shipping updates, and marketing newsletters (only with your consent).
  • Legal & Regulatory Bodies: Government authorities or law enforcement agencies when required by law, court order, or legal process.

All third-party partners are contractually bound to maintain the confidentiality and security of your data and are prohibited from using it for any purpose other than the specific service they provide to ANNA KEY.

6. Cookies & Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience. Cookies are small text files stored on your device that help us recognize you, remember your preferences, and analyze website traffic. We use the following types of cookies:

  • Essential Cookies: Required for the website to function properly, including cart functionality, secure checkout, and session management. These cannot be disabled.
  • Analytical Cookies: Help us understand how visitors interact with our website by collecting anonymized usage data (pages visited, time spent, bounce rate).
  • Functional Cookies: Remember your preferences such as language, currency, and recently viewed products to provide a personalized experience.
  • Marketing Cookies: Used to deliver relevant advertisements and measure the effectiveness of our marketing campaigns. These are only activated with your explicit consent.

You can manage your cookie preferences through your browser settings at any time. Please note that disabling essential cookies may affect the functionality of our website.

7. Your Rights

As a patron of ANNA KEY, you have the following rights regarding your personal data under applicable Indian law:

  • Right to Access: You may request a copy of the personal data we hold about you at any time.
  • Right to Correction: You may request correction of any inaccurate or incomplete personal data.
  • Right to Deletion: You may request deletion of your personal data, subject to our legal retention obligations.
  • Right to Withdraw Consent: Where processing is based on your consent (e.g., marketing emails), you may withdraw that consent at any time by clicking the "Unsubscribe" link in any email or contacting us directly.
  • Right to Data Portability: You may request your personal data in a structured, commonly used, machine-readable format.
  • Right to Object: You may object to the processing of your personal data for direct marketing purposes.
  • Right to Lodge a Complaint: If you believe your data privacy rights have been violated, you have the right to lodge a complaint with the appropriate regulatory authority in India.

To exercise any of these rights, please contact our Privacy Officer at bookkey@annakey.shop. We will respond to your request within 30 days.

8. Children's Privacy

Our website and services are not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child under 18 has provided us with personal data without parental consent, we will take immediate steps to delete such information from our servers. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at bookkey@annakey.shop.

9. International Data Transfers

ANNA KEY primarily operates within India, and your personal data is stored and processed on servers located in India. In the event that your data needs to be transferred to a third-party service provider located outside India (for example, an international payment gateway or analytics service), we will ensure that adequate safeguards are in place to protect your data in compliance with applicable Indian data protection laws.

10. Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our practices, legal requirements, or business operations. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify you via email or a prominent notice on our website. We encourage you to review this policy periodically to stay informed about how we protect your data.

11. Grievance Officer

In accordance with the Information Technology Act, 2000 and the rules made thereunder, the name and contact details of the Grievance Officer are provided below:

Name: M. ANNA Sehetty (Grievance Officer)

Email: bookkey@annakey.shop

Phone: +91 9934999349

Address: Vagdevi Vilas School, 77/2 Vagdevi School Drive Way, Bengaluru, Bangalore East, Karnataka, 560037, India

Response Time: All grievances will be acknowledged within 48 hours and resolved within 30 days of receipt.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please do not hesitate to reach out to us:

📧

Email: bookkey@annakey.shop

📱

Phone: +91 9934999349

📍

Address: Vagdevi Vilas School, 77/2 Vagdevi School Drive Way, Bengaluru, Bangalore East, Karnataka, 560037, India

This Privacy Policy was last reviewed and updated on April 27, 2026. By continuing to use our website, you acknowledge and agree to the terms outlined in this policy.