Concierge
Your personal dining stylist
This page explains what personal information Anvaya Living collects when you visit our store or place an order, why we collect it, who else sees it, and what you can ask us to do with it. We have written it in plain language and kept it honest about how the store actually works today. If anything here is unclear, please write to us at info@anvayaliving.in and we will explain it.
Anvaya Living is a brand operated by Anvaya Living, with its place of business at A-401, Akshar Alvario, Plot No. 76, Sector 27, Nerul, Navi Mumbai 400706, Maharashtra, India.
For the purposes of Indian data protection law, we are the party responsible for your personal information.
You can reach us by email at info@anvayaliving.in.
This policy covers the Anvaya Living website and the ordering, account and support services we provide through it.
It sits alongside our Terms of Service, Shipping Policy and Returns Policy.
We collect only what we need to run the shop. Here is the complete list.
Account details. If you create an account, we store your email address, your first and last name if you give them, and your password. Your password is stored only as a scrambled value, so nobody at Anvaya Living can read it.
Delivery and billing details. When you check out, we collect the name, company if you enter one, street address, city, state, postal code, country and phone number for delivery and billing.
Order details. We keep a record of what you ordered, the amounts, the date, the delivery method and the status of the order.
Payment references only. If you pay by card, UPI, netbanking or wallet, you enter those details inside Razorpay's own secure payment window. Your card number, UPI PIN, CVV and bank credentials never reach our servers and we never see them. We store only the payment reference numbers Razorpay gives us, which let us confirm the payment and issue a refund if one is due. If you pay cash on delivery, no payment details are collected at all.
Bank details, only to pay you back. A Cash on Delivery order has no card or account for us to refund to, so if such an order has to be refunded we ask you by email for your account name, account number and IFSC code. We use them for that single transfer and delete them once it has gone through. We never ask for them for any other reason, and nobody from Anvaya Living will ever telephone you to ask for them.
Messages you type to the AI Concierge. These leave our site and are described in their own section below.
Product reviews. If you write a review, we store the name you choose to type, your rating, and your title and comments. We do not ask for your email address with a review and we do not offer photo uploads. A review is shown publicly only after a member of our team approves it, and the name you typed is what appears.
Support messages. If you email us, we keep that correspondence so we can help you and refer back to it.
Basic technical information. Our website records ordinary web request information such as the page you viewed, the site or link that referred you, your screen size, your browser language and the network address you connect from. This is described further under analytics and cookies below.
We do not ask for and do not want your date of birth, your government identity numbers, your health information or any other sensitive detail. Please do not send them to us.
We use it for these purposes and no others:
Most of what we do with your information is simply necessary to give you what you asked for. You place an order, so we need your address to deliver it. Under the Digital Personal Data Protection Act 2023 this is processing for a purpose for which you have voluntarily given your information, and it is also necessary to perform our contract with you.
Where consent is the right basis, we ask for it clearly. The tick box at checkout and at account registration is not pre-ticked, and you choose to tick it. We never treat silence or a pre-filled box as agreement.
Some of what we do is required of us by law, such as keeping order and payment records.
We do not use your information for advertising and we do not build a behavioural profile of you.
We share personal information only with the service providers we need to run the shop, and only the minimum each one needs. We do not sell, rent or trade your personal information to anyone, ever.
Razorpay processes online payments. It receives your email address, your name and the phone number on your delivery address so it can prefill and secure the payment, and it collects your payment credentials directly from you.
GoDaddy operates the mailbox and the mail servers that deliver our transactional email. It handles the message we send you, which for an order confirmation includes your email address, your order number, the items and totals and your delivery address.
Cloudflare sits in front of our website to keep it fast and to protect it from attack, so it handles your requests and sees the network address you connect from. Cloudflare Turnstile also runs on our sign-in and account creation forms to check that a real person is filling them in. Turnstile receives a challenge token and your network address. It does not receive your name, email address or password.
OpenCode Zen provides the language model behind the AI Concierge. See the next section.
The delivery company that carries your parcel receives the delivery name, address, phone number and order number so it can deliver to you. Nothing else is shared with it.
Our hosting provider operates the physical server that our website, our database and our backups run on. It provides the machine and the network. It does not use your information for any purpose of its own.
Our analytics tool, described below, receives page and device information but no name, email address or order details.
Everything else stays with us. Your account, addresses, orders, payment references, reviews and support email are held in our own database on our own server. Our product search runs on a search service we host ourselves on the same server, and it indexes our catalogue, not our customers.
We will also disclose information if a court or a lawful authority requires us to, and we will tell you if we are permitted to.
The AI Concierge is a chat assistant that helps you choose pieces and plan a table. We want you to know exactly what happens when you use it.
When you send a message, that message is passed from our server to an external language model provider, OpenCode Zen, so it can compose a reply. What is sent is the recent part of the conversation, meaning the last few messages you and the Concierge have exchanged, together with our instructions to the model and our live product catalogue.
What is not sent is just as important. Your name, your email address, your account, your orders, your cookies and your network address are not sent. Your browser never talks to the provider directly.
Anvaya Living does not save your Concierge conversation. We write no record of it to our database and we do not log what you typed. The provider handles what it receives under its own terms.
Please treat the Concierge as a public conversation and do not type anything into it that you would not want to leave our site. If you would rather not use it, simply do not open it. Nothing in the shop requires it.
We use a small number of cookies, and all of them exist to make the shop work. We set no advertising cookies, no retargeting cookies and no cross-site tracking cookies of any kind.
Cookies your browser cannot read, set by our server and used only by it:
Cookies that only remember a preference:
A cookie that groups your own visit together:
A random identifier for your current visit, so we can see a whole journey through the shop as one visit rather than as unconnected page views. It tells us that someone looked at three products and then stopped at the delivery step; it does not tell us who. It lasts only as long as your browsing session and is discarded when you close your browser. If you place an order, we delete it from that order straight away, so it is never attached to your name or address. It is set by us, read only by us, and never shared.
Your browser also holds a short-lived note of your most recent order so the confirmation page loads quickly. It is cleared when you close the tab.
Because none of these cookies track you across other websites, we do not show you a cookie consent banner. You can delete cookies at any time in your browser settings, though signing in and checking out will not work without the ones listed above.
We measure how the shop is used with Umami, an analytics tool that does not use cookies and does not identify individual visitors. It records the page viewed, the referring link, screen size and language, and it derives an approximate country from your network address rather than storing that address as an identifier.
It runs on a server at analytics.orbitqube.com, operated on our behalf by OrbitQube, our technology partner. The data is not shared with any advertising network.
We also record a few first-party commerce events on our own server, such as an item being added to or removed from a cart and a checkout being started. These records contain product and order reference numbers, and the visit identifier described above so that one visit reads as one journey. They carry no name, no email address and no network address, they never leave our server, and the visit identifier is removed as soon as an order is placed. We also record the reason a checkout could not be completed, for example that we do not yet deliver to a postcode, so we can fix what is getting in your way.
We do not run Google Analytics, Google Tag Manager, a Facebook pixel or any comparable third-party tracker, and we have no newsletter or marketing list. The only email we send you is about an order you placed or a message you sent us.
Your information is stored in our database on a server located in India. It is backed up daily to the same server, and the backups are kept for a limited rolling period and can only be read by our administrators. We do not currently hold a copy of customer data anywhere else. If that changes, we will update this policy before it does.
How long we keep things:
If you ask us to delete your information we will do so, except for the order records the law requires us to retain.
The whole site is served over an encrypted connection. Passwords are stored only in hashed form. Session cookies cannot be read by scripts in your browser. Our database is not reachable from the public internet. Administrative access to the shop is limited to a small number of named accounts. Sensitive values such as passwords, tokens and card fields are stripped from our system logs before they are written.
No system is perfectly secure, and we will not pretend otherwise. If a breach ever affects your personal information, we will tell you what happened, what it means for you and what we are doing about it, and we will notify the authorities where the law requires it.
You can ask us to:
To use any of these rights, email info@anvayaliving.in from the address on your account and tell us what you would like. We may ask a question to confirm it is really you. We will respond within 30 days, and usually much sooner. We do not charge for this.
There is no self-service delete button in your account at present, so please write to us and a person will handle it.
Our products are for adults and our store is not directed at children. We do not knowingly collect personal information from anyone under the age of 18. If you believe a child has given us their information, write to info@anvayaliving.in and we will delete it.
Once the relevant provisions of the Digital Personal Data Protection Act 2023 come into force, verifiable parental consent will be required before a child's data is processed, and we will comply with that requirement.
We want to be straight with you about the state of Indian data protection law.
The Digital Personal Data Protection Act 2023 and its Rules of 2025 have been notified, but they take effect in stages. The substantive duties, covering notice and consent, security safeguards, breach reporting, children's data and your rights as a data principal, apply from a date in 2027 set by those Rules. We have written this policy to meet those requirements now rather than waiting.
Until then, the operative rules are Section 43A of the Information Technology Act 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011, and this policy is published in compliance with them.
We also follow the Consumer Protection (E-Commerce) Rules 2020, which require us to publish our identity, our contact details and a grievance mechanism.
Once the Data Protection Board of India is operating and the relevant provisions are in force, you will be able to complain to it if you are unhappy with how we have handled your information. We would rather you told us first, so we can put it right.
If we change how we handle your information, we will update this page and change the date at the bottom. If a change is significant, for example a new service provider receiving your data, we will say so plainly on this page and, where the law requires it, tell you directly.
In line with the Consumer Protection (E-Commerce) Rules 2020 and the Information Technology Rules 2011, we have appointed a Grievance Officer.
We acknowledge every complaint within 48 hours of receiving it and resolve it within 30 days. We give you a reference number in our reply so you can follow it up.
For anything to do with your personal information, your account or this policy:
Last updated: 10 August 2026