Every purchase helps extend a garment's life. Join the loop.
Privacy Policy

CHIR Privacy Policy

This policy explains what personal data CHIR collects, why we collect it, where it is stored, when it is shared, and how you can request deletion or correction.

We keep the language practical and user-facing so it can be published on the website and referenced in Play Console, OAuth verification, and in-app support flows.

Last updated: June 30, 2026
Support: chirservices@gmail.com
CHIR is a sustainable fashion marketplace for buying, renting, reselling, and donation workflows. These pages are published for the CHIR website and app so users can review legal terms, privacy details, and account deletion guidance before they take action.

1. Who We Are

CHIR is a sustainable fashion marketplace that supports buying, renting, reselling, and clothing donation workflows across the CHIR website and mobile app. This Privacy Policy explains how we handle personal data when you create an account, browse the marketplace, upload content, submit payments, request refunds, or use the admin-reviewed support flows.

We act as the data controller for the information we collect through CHIR and we use service providers such as Firebase, Cloudinary, and Razorpay to operate the service.

2. Information We Collect

We collect only the data needed to run the marketplace and provide account support:

  • Identity and contact data: name, display name, username, email address, mobile number, profile photo, and role.
  • Account and verification data: Google Sign-In details, OTP verification data where implemented, sign-in state, and account status.
  • Profile and address data: gender, bio, address, city, state, and pincode.
  • Marketplace data: listings, descriptions, category, size, brand, condition, availability, images, and seller details.
  • Order and rental data: cart items, shipping address, order IDs, rental dates, delivery status, tracking history, and order or rental history.
  • Donation and return data: donation requests, return requests, pickup details, proof images, and moderation notes.
  • Payment data: payment method, payment status, Razorpay order or payment IDs, manual UPI transaction references, payment notes, proof screenshots, and refund destination details.
  • Account deletion data: deletion requests, request status, and the reason you choose to provide.
  • Technical and device data: session identifiers, browser or app version details, device information, recent search terms, cart and wishlist data, request logs, and diagnostics data if enabled in the Firebase project.

The Android app also uses camera and photo library access when you choose to capture or upload listing, payment, donation, or return images. The browser version uses file pickers and web storage for recent searches, carts, and wishlist persistence.

3. How We Use Information

We use your data to provide the service you asked us to deliver:

  • Authenticate accounts and keep sign-in sessions working.
  • Publish and moderate listings, rentals, donations, and return requests.
  • Process checkout, manual UPI verification, Razorpay payments, COD orders, and rental deposits.
  • Show your dashboard, order history, rental history, wishlist, saved cart, and account details.
  • Review returns, calculate refunds, and send approved refunds to the destination you provide.
  • Prevent abuse, fraud, spam, duplicate requests, and platform misuse.
  • Support customer service, dispute resolution, and compliance with legal, tax, and audit obligations.

4. Storage and Service Providers

CHIR uses the following storage mechanisms:

  • Firebase Authentication for sign-in and identity management.
  • Cloud Firestore for user profiles, products, orders, rentals, donations, return requests, carts, account deletion requests, and admin logs.
  • Firebase Storage and Cloudinary for uploaded images and supporting media.
  • Local browser storage and Android SharedPreferences for session caches, carts, wishlists, recent searches, and pending profile updates.
  • Server-side API routes for payment verification, account sync, donations, return requests, and account deletion handling.

We protect data in transit using HTTPS and service-provider security features. Access to moderation and refund workflows is restricted to authenticated admins.

5. Third-Party Services and Sharing

We do not sell personal data. We only share it when it is necessary to operate CHIR:

  • Firebase / Google services for authentication, storage, database, hosting, and optional analytics.
  • Cloudinary for unsigned image uploads and media hosting.
  • Razorpay for payment processing and payment verification.
  • Authorized CHIR admins who review products, payments, returns, rentals, donations, and deletion requests.
  • Delivery or logistics partners when a shipment, pickup, or return workflow requires them.
  • Legal, regulatory, or law-enforcement authorities when disclosure is required by law.

We share only the minimum information necessary for each purpose and we expect our service providers to protect the information they process.

6. Cookies and Local Storage

The website stores small pieces of information in browser localStorage so carts, wishlists, and recent searches can persist across sessions. The Android app may use SharedPreferences or similar local storage for equivalent session state.

You can clear this local data by signing out, deleting your account, or clearing the browser or app storage on your device.

7. Payments

CHIR supports Razorpay, manual UPI, and cash on delivery where the checkout flow shows those options. If a payment is processed through Razorpay, CHIR does not receive or store your full card details.

We may retain payment references, proof screenshots, and refund destination details so we can verify orders, complete refunds, and resolve disputes.

8. Legal Bases For EEA And UK Users

Where GDPR or similar laws apply, we rely on the following legal bases:

  • Performance of a contract when we process your account, orders, rentals, payments, and support requests.
  • Legitimate interests when we moderate content, prevent fraud, protect the platform, and keep audit records.
  • Consent when we rely on user permissions for certain uploads or optional communication features.
  • Legal obligation when we keep records that tax, accounting, consumer-protection, or anti-fraud rules require.

9. Data Retention

We keep account, order, rental, donation, return, and support records only for as long as reasonably needed to operate the service, protect against fraud, resolve disputes, and meet legal obligations.

If you request deletion, we remove or anonymize the data we can safely remove. Some records may still be kept when retention is required for payment reconciliation, legal compliance, fraud prevention, moderation audits, or dispute handling. Images or documents tied to active or completed transactions may also be retained if they are needed to support those records.

Local browser storage or device caches are cleared when you sign out or complete the account deletion flow.

10. Security Measures

We use technical and organizational controls designed to reduce the risk of unauthorized access:

  • Token-based authentication and server-side verification for protected API routes.
  • Firestore and Storage security rules.
  • Role-based admin access and audit logs for moderation activity.
  • Payment verification using Razorpay signatures and authenticated backend checks.
  • Restricted admin-only data access for moderation and refund workflows.

No online system is perfectly secure, but we work to protect the information you entrust to us.

11. Your Rights

You can ask us to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete profile details.
  • Delete your account and request deletion of associated personal data.
  • Object to or restrict certain processing where applicable.
  • Withdraw consent for optional data uses where that consent applies.
  • Receive a copy of your data where portability rights apply.

To exercise these rights, use the in-app deletion flow or contact us using the details below.

12. Children

CHIR is not intended for children under 18. We do not knowingly collect personal data from children. If you believe a child has shared data with us, contact us and we will review the request promptly.

13. International Transfers

Some service providers may process or store information outside India. When that happens, we rely on the provider's contractual and security commitments to protect the data they process for CHIR.

14. Policy Updates

We may update this policy from time to time. When we do, we will publish the updated version on the website and, where practical, reflect the same version inside the Android app.

15. Contact

If you have privacy questions or want to submit a request, contact us at:

  • Email: chirservices@gmail.com
  • Phone: +91 9708310250
  • Website: https://chir.co.in
Delete AccountData Deletion InstructionsTerms & Conditions

Your Cart 🛍️

🛒

Your cart is empty.
Start shopping consciously!