Privacy & Cookie Policy

At Aartdeco, we value the trust you place in us. This Privacy & Cookie Policy explains how we collect, use, store, and protect your personal information when you visit our website, create an account, place an order, or interact with us.

By using www.aartdeco.com, you agree to the practices described in this policy.

Who We Are

Aartdeco is a brand operated by AARTO LLP.

Registered Office

132, Motilal Nehru Road, 3rd Floor, Kolkata, West Bengal – 700029

GSTIN: 19ACMFA7935Q1ZE

Email: aartdeco@aarto.in

Phone: +91 7439805153

Customer Support Hours: Monday – Friday, 10:00 AM – 5:00 PM IST

Information We Collect

When you interact with our website, we may collect the following information.

Information you provide

  • Name
  • Email address
  • Phone number
  • Billing and shipping address
  • Account login details
  • Order history and purchase information
  • Messages or enquiries submitted to us
  • Marketing preferences

Information collected automatically

When you browse our website, we may automatically collect:

  • IP address
  • Device and browser information
  • Pages visited and browsing activity
  • Products viewed or added to cart
  • Referring website information
  • Website performance and usage data

Customer Accounts

Customers may choose to create an account on our website to enjoy a faster checkout experience, access order history, save addresses, and manage preferences.

You are responsible for maintaining the confidentiality of your account credentials and for all activities that occur under your account.

How We Use Your Information

We use your information to:

  • Process and fulfil orders
  • Deliver products and provide shipping updates
  • Create and manage customer accounts
  • Respond to enquiries and customer support requests
  • Process faster returns, refunds, and exchanges
  • Improve overall website performance and customer experience
  • Detect and prevent fraud or misuse
  • Send newsletters, promotions, and marketing communications where you have opted in
  • Comply with legal and regulatory obligations

Payment Information

We currently accept:

  • Debit Cards
  • Credit Cards
  • Net Banking
  • UPI
  • Digital Wallets
  • PayPal
  • Razorpay

All online payments are processed through secure third-party payment providers. Aartdeco does not store your complete card details, banking credentials, or payment passwords on its servers.

Marketing & Communications

With your consent, we may send you updates about:

  • New collections and product launches
  • Promotions and special offers
  • Editorial features and styling inspiration
  • Brand news and announcements

You may unsubscribe from marketing communications at any time by clicking the unsubscribe link in our emails or by contacting us directly.

Cookies & Tracking Technologies

We use cookies and similar technologies to improve your browsing experience and understand how our website is used.

Cookies help us:

  • Keep your shopping cart active
  • Remember your preferences
  • Improve website functionality
  • Analyse website traffic and performance
  • Measure the effectiveness of marketing campaigns

We may use services such as:

  • Shopify Analytics
  • Google Analytics
  • Meta Pixel (Facebook & Instagram)
  • Email marketing platforms
  • Advertising and remarketing tools

Some third-party services may place their own cookies on your device when you interact with our website.

Managing Cookies

You can choose to accept or decline non-essential cookies when visiting our website. You can also manage or remove cookies through your browser settings at any time. Please note that disabling certain cookies may affect website functionality, including shopping cart and account features.

Cookies Set by Our Platform — Shopify

Our website is hosted on Shopify Inc., a third-party e-commerce platform. Shopify automatically sets a range of cookies that are necessary for the platform to function. These are not cookies set directly by Aartdeco but are part of the infrastructure on which our store operates. Below is a comprehensive inventory of the cookies typically set by Shopify, their purpose, and their duration.

Cookie names and durations are accurate at the time of writing but may change as Shopify updates its platform. For the most current list of Shopify cookies, refer to Shopify's own Cookie Policy at shopify.com/legal/cookies.

Each cookie below is listed with its type, followed by its purpose and duration. Third party: No (Shopify) in every case except where stated.

  • _session_id — Strictly Necessary. Maintains your session state across page requests — keeps you logged in and your cart intact as you navigate. Duration: Session (ends when browser is closed).
  • _shopify_y — Functional / Analytics. Shopify analytics — tracks unique visitors over time and distinguishes new visitors from returning ones. Duration: 1 year.
  • _shopify_s — Functional / Analytics. Shopify analytics — tracks session-level activity and referral data for the current browsing session. Duration: 30 minutes.
  • _shopify_sa_t — Analytics. Shopify analytics — used to track marketing campaign attribution (source of traffic to the store). Duration: 30 minutes.
  • _shopify_sa_p — Analytics. Shopify analytics — tracks the page from which a marketing link was clicked, used for attribution reporting. Duration: 30 minutes.
  • _shopify_fs — Analytics. Shopify analytics — records the first visit of a user to the store, used in conjunction with _shopify_s. Duration: 1 year.
  • _shopify_evids — Strictly Necessary. Used by Shopify to prevent cross-site request forgery (CSRF) attacks during checkout. Duration: Session.
  • _shopify_ga — Analytics. Bridges Shopify's analytics with Google Analytics (where installed), allowing purchase attribution. Duration: Persistent (varies). Third party: No (Shopify / Google).
  • cart — Strictly Necessary. Stores the contents of your shopping cart between pages and across sessions so items are not lost. Duration: 2 weeks.
  • cart_ts — Strictly Necessary. Records the timestamp of the last cart interaction, used for cart expiry logic. Duration: 2 weeks.
  • cart_sig — Strictly Necessary. A security signature for cart integrity verification, preventing unauthorised cart manipulation. Duration: 2 weeks.
  • checkout_token — Strictly Necessary. Stores a token identifying the active checkout session, used to maintain checkout state across page loads. Duration: 1 year.
  • secure_customer_sig — Strictly Necessary. Stores a secure hash to authenticate a logged-in customer's session without exposing credentials. Duration: 20 years.
  • storefront_digest — Strictly Necessary. Used for password-protected storefronts to verify that a visitor has entered the correct store password. Duration: Persistent.
  • _cmp_a — Strictly Necessary. Stores your cookie consent preferences as recorded through the Shopify consent banner. Duration: 1 year.

Cookies Set by Payment Gateways

When you proceed to checkout, our website connects to one or more third-party payment gateways to process your transaction securely. These providers set their own cookies, which are used to facilitate secure payment processing, prevent fraud, and comply with financial regulations. Aartdeco does not control these cookies and does not have access to the data they collect beyond what is necessary to confirm payment.

The specific payment gateways active on your site will be confirmed once your Shopify store's payment settings are finalised. Below is a general description of the types of cookies commonly set by payment processors.

Each cookie below is listed with its type, followed by its purpose and duration. Third party: Yes (Payment Gateway) in every case.

  • [gateway]_session — Strictly Necessary. Maintains your payment session during the checkout process. Ensures your payment details are transmitted securely and the transaction is not interrupted. Duration: Session.
  • [gateway]_fraud — Strictly Necessary. Fraud prevention and risk assessment. Analyses device and session characteristics to detect and prevent fraudulent transactions. Duration: Session – 30 days.
  • [gateway]_pref — Functional. Remembers previously used payment methods to speed up future checkouts (e.g. saved UPI handles or card prefixes). Duration: 30–180 days.
  • [gateway]_csrf — Strictly Necessary. Cross-site request forgery (CSRF) protection token, ensuring payment form submissions originate from a legitimate source. Duration: Session.

Once your payment gateway configuration is finalised (Razorpay, PayU, Stripe, Shopify Payments, or others), this table should be updated with the exact cookie names, durations, and links to each provider's cookie policy. Your web developer or Shopify partner can assist with this audit.

Cookies Set by Instagram and Meta

Our website embeds Instagram content, including product feeds and social posts, to showcase our work and allow visitors to view our social presence without leaving the site. These embeds are served directly by Meta Platforms Inc. (the parent company of Instagram and Facebook). As a result, Meta may set cookies on your device when you visit a page that contains an Instagram embed, regardless of whether you are logged in to Instagram or Facebook.

Aartdeco does not control, access, or process the data collected by Meta through these cookies. The following are the primary Meta / Instagram cookies that may be set through embedded content.

Each cookie below is listed with its type, followed by its purpose, duration, and the third party that sets it.

  • _fb — Targeting / Marketing. Facebook pixel cookie. Tracks visits to pages with Meta pixel or social plugin. Used for ad targeting, conversion measurement, and building Custom Audiences on Meta platforms. Duration: 3 months. Third party: Yes (Meta).
  • datr — Strictly Necessary (Meta). Security cookie used by Meta to identify browsers and prevent CSRF attacks on Facebook accounts. Set on all pages with Facebook / Instagram embeds. Duration: 2 years. Third party: Yes (Meta).
  • sb — Functional (Meta). Stores browser details for account security and login suggestions. Used by Meta to remember your browser even when logged out. Duration: 2 years. Third party: Yes (Meta).
  • wd — Functional (Meta). Stores browser window dimensions. Used by Meta to render Facebook and Instagram content at the correct size. Duration: 1 week. Third party: Yes (Meta).
  • fr — Targeting / Marketing. Primary advertising cookie used by Meta. Tracks browsing behaviour across websites that use Meta services to deliver targeted ads. Duration: 3 months. Third party: Yes (Meta).
  • ig_did — Strictly Necessary (Meta). Device identification cookie used by Instagram for security and fraud prevention. Duration: 10 years. Third party: Yes (Meta / Instagram).
  • ig_nrcb — Functional (Meta). Records whether a user has dismissed Instagram's cookie banner, to avoid showing it repeatedly. Duration: 1 year. Third party: Yes (Meta / Instagram).
  • csrftoken — Strictly Necessary (Meta). Cross-site request forgery protection token used by Instagram on authenticated actions. Duration: 1 year. Third party: Yes (Meta / Instagram).
  • rur — Strictly Necessary (Meta). Routes Instagram API requests to the correct server. Used for load balancing and infrastructure routing. Duration: Session. Third party: Yes (Meta / Instagram).

For full details on how Meta uses these cookies, please review Meta's Cookie Policy at https://www.facebook.com/policies/cookies/ and Instagram's Privacy Policy at https://help.instagram.com/519522125107875.

Sharing Your Information

We strictly do not sell or rent your personal information.

We may share your information with trusted third parties only when necessary, including:

  • Shopify (our e-commerce platform)
  • Payment service providers
  • Logistics and shipping partners
  • Marketing and analytics service providers
  • Professional advisors and regulatory authorities where required by law

These providers are only permitted to use information for the services they perform on our behalf.

International Shipping & Data Transfers

We offer shipping across India and international shipping for qualifying orders. Additional shipping charges may apply for international deliveries.

As part of operating an international e-commerce website, some information may be processed or stored outside India through our technology and service providers. We take reasonable steps to ensure your information remains protected.

Data Security

We implement appropriate technical and organisational safeguards to protect your information from unauthorised access, misuse, disclosure, or loss.

While we strive to use commercially acceptable means to protect your information, no method of transmission over the internet can be guaranteed to be completely secure.

Your Rights

Depending on applicable laws, you may have the right to:

  • Access your personal information
  • Correct inaccurate information
  • Request deletion of your data
  • Withdraw consent for marketing communications
  • Manage cookie preferences
  • Raise concerns regarding how your information is processed

To exercise any of these rights, please contact us at aartdeco@aarto.in.

Third-Party Links

Our website may contain links to third-party websites, payment gateways, and social media platforms. We are not responsible for the privacy practices of these external websites and encourage you to review their policies separately.

Changes to This Policy

We may update this Privacy & Cookie Policy from time to time to reflect changes in our services, legal requirements, or business practices. Any updates will be published on this page with a revised "Last Updated" date.