Legal

Privacy Policy.

Last updated: June 2026.

1. Who we are

The Sovia ("we", "us", "our") is a private fashion service founded by Pallavi Patodi and operated under [LEGAL ENTITY TO BE INSERTED], based in Mumbai, India. This privacy policy explains how we collect, use, and protect your information when you visit thesovia.in or communicate with us via WhatsApp, email, or in person.

2. What we collect

When you contact us, we collect:

  • Your name (if shared)
  • Your WhatsApp number
  • Your mobile number (if shared)
  • Pinterest board URLs you send us
  • Instagram handle (if shared)
  • Inspiration images, photos, sketches, or screenshots you upload
  • Free-text notes about your occasion, preferences, or style
  • Your delivery address (when you place an order)
  • Payment details (handled through secure third-party processors — we never store full card numbers)

We do not collect: tracking cookies for advertising, social media surveillance pixels, or any data you have not explicitly shared with us.

3. How we use it

Strictly to:

  • Respond to your inquiries and curate pieces for you
  • Process orders, payments, and deliveries
  • Send order updates over WhatsApp or email
  • Improve our service based on your feedback

We do not sell, rent, or share your data with third parties for marketing.

4. Who has access

Only Pallavi and a small team of authorized staff at The Sovia. Karigars, partner ateliers, and shipping providers receive only the minimum information needed (e.g. measurements, delivery address).

5. Analytics

We use Microsoft Clarity to understand how visitors use our website. Clarity collects anonymized session data (clicks, scrolls, page views) — no personal information. You can opt out at clarity.microsoft.com/opt-out.

6. Your rights

Under the Indian Digital Personal Data Protection Act, 2023 and similar laws abroad, you have the right to:

  • Access the personal data we hold about you
  • Correct or update it
  • Request its deletion
  • Withdraw consent at any time

To exercise any of these, write to privacy@thesovia.in.

7. Data retention

We retain conversation and order history for as long as you remain an active client, plus seven years thereafter for tax and audit purposes. After that, data is permanently deleted unless you ask us to delete it sooner.

8. Security

We use industry-standard encryption for data in transit and at rest. Payment processing happens through PCI-compliant providers (Razorpay, Stripe). We never store full payment card numbers on our servers.

9. Grievance officer

In accordance with the DPDP Act, our designated Grievance Officer is:

[NAME TO BE INSERTED]

Email: grievance@thesovia.in

Response time: within 30 days

10. Changes

We will post any updates to this policy on this page with a revised date. Material changes will be communicated via WhatsApp or email to active clients.