What we know about you

Privacy Policy

We ask for very little, and we would rather tell you exactly what that is than write around it. This is what Solise Paris collects, why we hold it, who else touches it, and what you can make us do with it.

In effect from 21 August 2026

01

Who holds your data

Solise Designs Private Limited, of 14 Blue Hills, NDA Pashan Road, Bavdhan, Pune 411021, Maharashtra, India, trading as Solise Paris, decides why and how your personal data is processed. Under the Digital Personal Data Protection Act, 2023 that makes us the data fiduciary and you the data principal. This policy covers our website, our concierge and assistant, and the Orbit membership.

It sits alongside our Terms & Conditions and our Policies. Where those describe personal data, this policy is the fuller account.

02

What we collect

What you give us

To take an order and get it to you: your name, phone number, email address, delivery address, city, state and pin code. To hold a membership: the same, plus the account you sign in with. If you write to us, or talk to the concierge, whatever you choose to put in that message.

If you leave a review, your rating, your words, and the name on your account, which is published with it.

What we create about you

Your order history and its contents, the totals and discounts applied, delivery status, your customer number, membership code and tier, referral credits earned and spent, and who introduced whom where a referral code was used.

What we collect automatically

Our analytics are first-party and cookieless. We record page views, product clicks, items added to the bag, and how long a page was visible, against a random per-tab identifier that is created when you arrive and destroyed when the tab closes. It is not tied to your name, your account or your device, and cannot be used to recognise you on a later visit.

With those events we store the page path without its query string, and the host a visitor arrived from, never the full referring URL. Where you arrive from a campaign link, the campaign tags travel with the visit.

Our servers see your IP address on every request, as every web server does. We use it only to rate-limit abuse, held in memory for the length of the window and never written to our database or joined to your account.

We do not collect financial account numbers, card numbers, CVVs or one-time passwords. We never ask for them, and you should never send them to us. We do not knowingly collect anything about your health, beliefs, caste, or any other sensitive category, and we ask you not to volunteer it.

03

Why we hold it, and on what basis

The Act lets us process personal data for the certain purpose you gave it for, and where a law requires it. Purpose by purpose, that is:

Taking your order
Confirming it, arranging payment, shipping it, and telling you where it is. Given for that purpose when you check out.
Supporting you after it
Returns, exchanges, refunds, repairs, replating and any complaint. The same purpose, continued.
Running the Orbit
Assigning your customer number and tier, applying member pricing, issuing and redeeming referral credits. Given when you take up the membership your first order carries.
Legal obligations
GST invoicing and tax records, and anything we must produce to a lawful authority. Required of us, whatever either of us would prefer.
Keeping the site standing
Rate-limiting, fraud and abuse prevention, and security. Necessary to provide the service you asked for.
Understanding the site
Anonymous, aggregate analytics, so we can see which pieces are looked at and which pages fail. No individual is identified in it.
Marketing
Only where you have said yes to it, separately. See clause 05.

We do not sell your personal data, we do not rent it, and we do not profile you for advertising.

05

WhatsApp, email and marketing

Choosing to check out through WhatsApp is your consent for us to message you about that order: confirmation, payment, dispatch, delivery, and support afterwards. That is service communication, and it comes with the purchase. The same goes for the emails an order generates.

Marketing is separate, and opt-in. We will not send you launches, offers or Orbit news on WhatsApp or by email unless you have said yes to that specifically. Reply STOP in the thread, use the unsubscribe link in any marketing email, or write to us, and it stops, while the messages your open orders need continue.

WhatsApp is operated by Meta under its own terms and privacy policy. What you send us there passes through its systems as well as ours, and we cannot change that. If you would rather not use it, order or write to us by email or telephone instead, and we will serve you exactly the same.

06

Claire, our assistant

Claire answers questions about our pieces on the site. What you type to her, her reply, the page you were on and the piece you were looking at are stored against the same throwaway per-tab identifier the analytics use, so that a question we answered badly can be found and put right, and so a message that needs a person can be picked up by one.

Your message is sent to Anthropic, whose model generates the reply. We reach it through Anthropic’s commercial API under a business account, whose terms do not permit what you send to be used to train the model. Where you are signed in, your Orbit tier is attached to the conversation so that Claire quotes you the right price, but your name, contact details and address are not.

She is a shop assistant, not a confidante. Please do not type anything into her that you would not put in an email to a shop, and never card details, passwords or one-time codes.

07

Cookies and what sits in your browser

We use no advertising cookies, no third-party trackers, and no cross-site pixels, so there is no consent banner to dismiss. What we do use is:

Sign-in cookies
Set when you sign in, so that the site knows the session is yours. Strictly necessary. Clearing them signs you out.
Per-tab session id
A random string in your browser’s sessionStorage, used to count a visit and to keep a conversation with Claire together. Gone when the tab closes.
Your bag
The pieces you have added are kept in your own browser’s storage so they survive a refresh. They stay on your device until you clear them or check out.

You can clear all of it in your browser at any time. The site keeps working; you will simply be signed out and your bag will be empty.

08

Who else sees it

Only those who help us deliver what you asked for, each of them a processor acting on our instructions and permitted to use your data for nothing else:

Couriers
Your name, delivery address, pin code and phone number, so a parcel can reach you and you can be called about it.
Payment providers
What is needed to take the payment. Card and bank credentials go to them, not through us.
Supabase
Our database and sign-in provider, which stores the account, order and membership records described above, on servers in Singapore.
Google
Only if you choose to sign in with Google, which tells us your name and email address for that purpose.
Meta (WhatsApp)
The concierge channel, where you use it. See clause 05.
Anthropic
The model behind Claire. See clause 06.
Vercel
Our hosting provider, which serves the site from its global network and runs the server code that handles your requests.

Beyond that, we disclose personal data only where the law compels us, to a lawful authority acting within its powers, or to establish or defend a legal claim. If our business is ever sold or merged, your data may pass to the buyer under this same policy, and we will tell you before it does.

09

Processing outside India

Some of the providers above operate outside India, so your data is processed outside India. We would rather tell you exactly where than leave you to wonder:

Your account and orders
Held at rest in our Supabase database in Singapore. That is where your name, contact details, address, order history and membership record live.
The site itself
Served by Vercel from its global network, so the request that draws a page may be handled at whichever location is nearest you.
Assistant messages
Sent to Anthropic in the United States to generate a reply, and stored back in Singapore with the rest.

The Act permits transfer to any country the Central Government has not restricted. None of the above is restricted as at the date of this policy, and we will stop or move any transfer that later becomes so.

Wherever it is processed, our obligations to you under this policy and under the Act travel with it. A processor abroad holds your data on our instructions and for our purposes only.

10

How long we keep it

We keep personal data only as long as the purpose it was given for lasts, and as long as the law obliges us to keep the records that contain it. In practice:

Orders and invoices
Kept for the period tax and company law require, currently eight years from the end of the financial year. We cannot erase these on request.
Account and membership
Kept while your membership stands. Your customer number and tier are the membership, so keeping them is the point of it.
Referral credits
Kept while they can still be earned, matured or spent, and then with the order record that used them.
Assistant conversations
Kept while they are useful for improving answers and resolving what was escalated, then deleted.
Analytics events
Anonymous from the moment they are written, and never linked back to a person.

When you close your account or leave the Orbit, we erase what we are not required to keep, and keep the rest only for that requirement.

11

Your rights

Under the Act you may ask us to:

  • Tell you what we hold, what we have done with it, and who we have shared it with
  • Correct, complete or update it, where it is wrong or out of date
  • Erase it, where we no longer need it and no law makes us keep it
  • Withdraw a consent you have given
  • Nominate someone to exercise these rights for you if you die or cannot act
  • Complain, and have that complaint answered

Write to legal@soliseparis.com from the address on your account, or ask the concierge. We do not charge for any of this, and we answer within 30 days. If a request would let one person reach another’s data, we will verify who you are before we act.

Through a consent manager

The Act lets you give, manage, review and withdraw consent through a Consent Manager registered with the Data Protection Board, rather than dealing with each company separately.

We accept and act on requests routed through a registered consent manager on your behalf, on the same terms and in the same 30 days as a request made to us directly. We will verify that the manager is registered and that it genuinely acts for you, and we will not treat a request as any less valid for having come that way.

The Act also asks something of you: give us information that is true, do not impersonate anyone else, and do not file a false or frivolous complaint.

If you are not satisfied with how we have handled a request, take it to our grievance officer under clause 15. If you are still not satisfied, you may complain to the Data Protection Board of India.

12

Children

Our site and our shop are for adults. We do not knowingly collect the personal data of anyone under 18, and we do not track children or direct advertising at them.

Where a person under 18 is to be given a piece, the order belongs to the parent or guardian placing it, whose data we hold rather than the child’s. If you believe a child has given us data, write to us and we will delete it.

13

Security, and if something goes wrong

We keep what we hold behind reasonable safeguards: access to the database is limited to our servers and to the people who need it, records are protected by row-level rules so one customer’s account cannot read another’s, sign-in is delegated to an established provider, and the site is served over an encrypted connection.

No system is perfect, and we will not pretend otherwise. If a breach affects your personal data, we will tell you and the Data Protection Board, as the Act requires, and we hold ourselves to a clock rather than to a vague promise of promptness:

You
Told without undue delay once we know a breach has affected your data, in plain words: what happened, what data was involved, what it may mean for you, what we are doing, and what you can do.
The Board
Intimated without delay on becoming aware, and given the fuller account within 72 hours, or such longer period as the Board allows on request.

We will tell you even where the breach turns out to be contained, and we will not wait for certainty about the cause before telling you it happened.

Please help us: keep your email account secure, do not forward your sign-in link, and tell us at once if you think your account has been used by someone else.

14

Changes to this policy

We will update this policy when what we do changes. The date at the head of the page shows when it last did. Where a change is material, we will tell you before it takes effect, and where it needs your consent, we will ask for it rather than assume it.

15

Contact and grievances

For anything about your data, or anything else, reach us on any of the below. We reply to every enquiry within 48 hours.

Postal
Solise Designs Private Limited, 14 Blue Hills, NDA Pashan Road, Bavdhan, Pune 411021, Maharashtra, India

Grievance officer

The officer named below answers data complaints as well as consumer ones, and is your point of escalation before the Data Protection Board.

Name
Neeraj Varma
Designation
Grievance Officer
Acknowledgement
Within 48 hours of receipt, with a ticket number.
Resolution
Within 30 days of receipt.

The agreement this policy sits inside is our Terms & Conditions. Shipping, returns and company details are in our Policies.