Legal
Privacy Policy
Last updated: July 2, 2026
Qureshi Jewelers ("we," "us," or "our") operates qureshijewelers.com (the "Site"). This Privacy Policy explains what personal information we collect, how we use it, with whom we share it, and the choices you have. By using the Site, you agree to the practices described here.
Section 1
Information We Collect
Information You Give Us Directly
- Name, email address, shipping and billing address, and phone number when you create an account or place an order
- Password (stored as a hashed value — never in plain text) when you register with email and password
- Communications you send us (support emails, contact-form submissions)
- Email address when you subscribe to our newsletter
Information We Collect Automatically
- Log data: IP address, browser type, operating system, referring URL, pages viewed, and time spent on pages
- Device identifiers and cookie data (see Section 6)
- Session and interaction data via Google Analytics (IP anonymization is enabled)
Information From Third-Party Sign-In (Google OAuth)
If you choose to sign in with Google, we receive only your name, email address, and profile picture from Google. We do not receive your Google password, phone number, contacts, or any other Google account data.
Payment Information
We never see or store your card number, CVV, or full payment account details. All payment data is entered directly into a Stripe-hosted secure iframe (Stripe PaymentElement) and transmitted directly to Stripe's servers. Stripe is PCI DSS Level 1 certified and our integration qualifies as PCI SAQ A (the lowest risk tier). We store only the Stripe Customer ID that Stripe assigns to you, not your payment credentials. PayPal transactions are similarly processed entirely within PayPal's environment.
Section 2
How We Use Your Information
- To process, fulfill, and ship your orders
- To send order confirmations, shipping notifications, tracking updates, and receipts
- To provide customer support and respond to your inquiries
- To send cart-recovery emails for orders you began but did not complete (cart data is retained temporarily for this purpose)
- To send promotional emails and marketing communications — only if you have opted in
- To improve and personalize our website, product offerings, and user experience
- To detect and prevent fraud, abuse, and unauthorized access
- To comply with legal obligations
Section 3
Sharing of Information
We do not sell, rent, or trade your personal information to any third party. We share data only in the following limited circumstances:
- Stripe — processes all credit/debit card payments. Stripe receives your payment details directly; we receive only a Stripe Customer ID. Stripe's privacy policy is available at stripe.com/privacy.
- PayPal — processes PayPal payments. PayPal handles all associated financial data independently of our systems.
- Supabase / Amazon Web Services (AWS) — our database and authentication infrastructure. Your account data (name, email, shipping addresses, order history, wishlist) is stored in a Supabase database hosted on AWS. Row-Level Security (RLS) is enforced so that each user can only access their own records.
- Shipping carriers (e.g., USPS, UPS, FedEx) — receive your name and delivery address solely to fulfill your shipment.
- Google Analytics — receives anonymized browsing data (pages viewed, session duration, referral source). IP anonymization is enabled. Google Analytics does not receive your name, email, or order details.
- Meta (Facebook) Pixel — receives purchase event data (order value, currency) for ad attribution purposes only. It does not receive your name, email address, or other personal contact information.
- TikTok Pixel — same as Meta Pixel: order value and currency only, for ad attribution. No personal contact information is transmitted.
- Legal disclosure — we may disclose your information if required by law, court order, or government authority, or to protect the rights, property, or safety of Qureshi Jewelers, our customers, or others.
Section 4
Database & Security
We store the following personal data in our Supabase database (hosted on AWS):
- Name and email address
- Shipping addresses
- Order history (items purchased, amounts, dates)
- Wishlist items
- Abandoned cart data (retained temporarily for cart recovery emails, then purged)
- Stripe Customer ID (a reference token — not payment credentials)
We implement Row-Level Security (RLS) on all user tables so that each authenticated user can only read and write their own records. Our server-side administrative operations use a Supabase service-role key that is never exposed to browsers or included in client-side code.
Authentication sessions use short-lived JWT tokens. Refresh tokens are stored in your browser's localStorage and are used only to obtain new access tokens — they are never transmitted to third parties.
Section 5
Cookies & Tracking Technologies
We use cookies and similar tracking technologies for the following purposes:
- Session management — to keep you logged in across pages
- Analytics — Google Analytics collects anonymized usage data to help us improve the Site
- Ad attribution — Meta Pixel and TikTok Pixel use cookies to attribute purchases to ad campaigns
You can instruct your browser to refuse all cookies or alert you when cookies are sent. Note that some features of the Site may not function properly if cookies are disabled. We do not engage in cross-site behavioral tracking beyond the ad-attribution pixels described above.
Section 6
Data Retention
We retain your personal information for as long as your account is active or as needed to provide services to you. Specific retention periods:
- Account information: retained until you request deletion
- Order records: retained for a minimum of 7 years for tax and legal compliance
- Abandoned cart data: purged automatically after 30 days if no purchase is completed
- Analytics data: retained per Google Analytics' default retention settings (26 months)
- Marketing opt-in records: retained until you unsubscribe or request deletion
Section 7
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access — request a copy of the personal data we hold about you
- Correction — request that inaccurate data be corrected
- Deletion — request that we delete your personal information, subject to legal retention requirements
- Opt-out of marketing — unsubscribe from marketing emails at any time using the link in any email or by contacting us
- Data portability — request your data in a structured, commonly used format
To exercise any of these rights, email us at support@qureshijewelers.com. We will respond within 30 days. We may need to verify your identity before processing certain requests.
Section 8
Children's Privacy
Our Site is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If we learn that we have inadvertently collected such information, we will delete it promptly.
Section 9
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Material changes will be communicated by email to registered users. Continued use of the Site after any update constitutes your acceptance of the revised policy.
Section 10
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
