Atelier

✦ Privacy policy · In force from 8 September 2026

Your shop’s recordsbelong to your shop.

What we hold, where it sits, who else touches it, and how to take it away.

1. Who is responsible

Atelier is provided by Anjali Design Studio, GF-1, Ground Floor, Phoenix Lifestyle, New Fatehpura, Girwa, Udaipur, Rajasthan 313001, India. That is the business responsible for the information described below, and the one to write to about any of it.

2. Two different kinds of information

It helps to separate them, because our role is different for each.

  • Your account information · the shop’s name, the owner’s name, email address and phone number, staff names and logins, and the record of your subscription. We decide what is needed here, so we are responsible for it.
  • Your shop’s business records · your stock, prices, photographs, sales, purchases, ledgers, and the details of your own customers and karigars. You decide what goes in and why. We only hold and process it on your instructions, as your service provider. If one of your customers asks about their details, the answer comes from you, and we will help you give it.

3. What we collect

Given by you

  • Shop name and address, owner’s name, email address, telephone number.
  • Staff names and usernames, and what each is permitted to do.
  • Everything you enter as business records, including photographs of pieces, and any personal details of your own customers you choose to record — typically name, telephone number, and where you record them, address and PAN.

When you try Atelier

  • If you start a trial from this website we keep your name, shop name, email address and telephone number as a lead record, so we can call you about the trial. If you sign in with Google, Google tells us the name and email address on your Google account, and nothing else.
  • The trial form is protected against automated sign-ups by Cloudflare Turnstile, which looks at your browser and your connection to decide whether you are a person. Clause 6 says what it keeps.

Created by using the app

  • An audit log of significant actions — who logged in, who recorded or changed a sale, who approved a deletion. It exists so an owner can see what happened in the shop, it cannot be edited by staff, and we do not use it for anything else.
  • A count of which screens get opened, and how often. It records the name of a screen, a number, and whether the person was an owner or a member of staff — and deliberately records no name and no login, so it can tell us that a feature goes unused but can never tell us, or you, what any one person did. It holds no customer, no piece and no amount. It is kept with your own records, in your own shop’s database.
  • A fault report, when the app breaks on your device. It is sent to us so we can find and fix the fault, and it contains the technical description of what went wrong, the version of the app you were running, the name of the screen you were on, your shop’s account name, and whether you are an owner or a member of staff. It carries no name and no login. The technical description is written by the app itself, but because a fault can occur while the app is handling one of your records, we remove anything shaped like an email address or a telephone number from it before it reaches us. Nothing is sent when the app is working normally.
  • A written description of each stock photograph, produced by the AI service in clause 5 so that Photo Lookup can find a piece from a new photograph. It describes the jewellery — type, metal, stones, shape — and nothing else, and is stored with your own records.
  • When you paste a product link into Reference Quote, our server fetches that page on your behalf, because a browser cannot. The page is kept in a cache for up to a day so the same link does not have to be fetched twice, and your connection’s address is counted for one hour so that nobody can use the fetcher to hammer another website. We do not keep a record of which shop pasted which link.
  • Basic technical information any web service receives, such as the request your browser makes and its approximate origin, used to keep the service running and secure.

Payments

  • Whether your subscription is paid, until when, and the reference numbers of the mandate and its charges.
  • We never see or store your card number, expiry date or CVV. Those go directly to our payment processor and never reach us.

4. Why we hold it

  • To provide Atelier to you — the core reason for almost everything above.
  • To take payment and keep the required financial records.
  • To support you when you contact us, which sometimes means looking at your account to understand a problem you have described.
  • To find and fix faults, from the fault reports described above.
  • To keep the service secure, and to investigate misuse.
  • To find out which parts of Atelier are worth improving, and which are not used at all — from the screen counts above, and from nothing else.
  • To comply with Indian law where it requires us to keep or produce records.

We do not use your data to train anything, and we do not use it to build products for anyone else.

5. Where it is stored, and who else handles it

Atelier is built on services provided by others. These are all of them, what each does, and where it holds data.

  • Google (Firebase) · the database holding your business records, and the login system. Your data is stored in Google’s asia-southeast1 region (Singapore).
  • Cloudinary · stores the photographs of your pieces and any documents you upload, such as a scanned certificate. A photograph is stored at a long, unguessable web address that is not listed anywhere, but it is not behind a login: anyone who has the exact address can open it. That is what lets a quote card or a catalogue you send show the piece to your customer. Do not photograph anything you would not want a customer to see.
  • Cloudflare · serves the app and this website to your browser, receives the fault reports described in clause 3, runs the spam check on the trial form, fetches the product pages you paste into Reference Quote, and holds our nightly backups of the database. A copy of every shop’s records is taken each night; daily copies are kept for 30 days and a monthly copy for a year.
  • Brevo · delivers the email we send you, such as a password reset or a verification, and the fault alerts we send ourselves.
  • Cashfree Payments · takes the subscription payment and holds the card or bank mandate. An Indian payment processor, regulated in India.
  • Shopify · only if you connect your own Shopify store. The credentials you enter are stored in your shop’s own record, readable by the owner login alone, and our server uses them to tell Shopify when a piece has sold. Our server keeps no lasting key to your store and writes nothing about it anywhere.

Some of your data is therefore stored outside India, principally in Singapore. We chose that region because it is the nearest one with the response times the app needs. If you would rather your data did not leave India, tell us before you sign up so you can make an informed decision.

The AI features, and what leaves your device

Several optional features — reading a packing list, a vendor invoice or a diamond certificate from a photograph, pricing a piece from a link or a screenshot, writing a description of a piece, and finding a piece by photographing it — use Google’s Gemini service. The photograph or page text is sent from your browser directly to Google; it does not pass through our servers and we never see it. These features run on an AI account key that we hold for your store, so you have nothing to set up, and we can see how that the key is in use, but never what was sent. What Google does with what it receives is governed by Google’s terms and privacy policy, not ours. Photo Lookup also stores a written description of each of your stock photographs, as clause 3 says. Using these features is your choice; the app works without them.

6. Cookies, counting, and what is kept on your device

Atelier sets no advertising or tracking cookies, on the website or in the app.

Counting readers of this website. These pages use Cloudflare Web Analytics, which reports how many times each page was read and which website a reader arrived from. It sets no cookie, stores nothing on your device, does not identify you, and cannot follow you to any other website. We see totals for a page, never a person. We use it to learn which of these pages are worth writing.

The spam check on the trial form. The form uses Cloudflare Turnstile to tell a person from a script. It may store a short-lived token in your browser for that one purpose and looks at your connection to decide; it is not used for advertising and does not follow you elsewhere.

Signing in with Google. If you choose the Google button, Google sets its own cookies on Google’s domain as part of signing you in. That is between you and Google; we receive only your name and email address.

Counting screens in the app. Separately from the above, the app keeps a tally of which of its screens are opened, described in clause 3. That tally stays inside your own shop’s records, is not sent to any other company, and names nobody.

The app stores a small amount of information in your browser so it can work: your login session so you are not signed out constantly, and a few display preferences. It is on your device, not ours, and clearing your browser data removes it.

This website loads its typefaces from Google Fonts. That means your browser makes a request to Google in order to fetch them.

7. Who we share it with

We do not sell your data, and we do not share it with other shops.

It reaches only:

  • the service providers listed in section 5, each doing the job described there;
  • professional advisers such as our accountant, where necessary;
  • a public authority, where the law requires it of us.

Our own staff can reach your account only to support you or to fix a fault, and are bound to keep what they see confidential.

8. How long we keep it

  • While you are a customer · for as long as your account is open.
  • After you cancel or stop paying · your data stays in place for twelve months so you can still log in and download it. Nothing is deleted as a punishment for not paying. After twelve months we may delete it, and we will email the address on the account 30 days before we do.
  • A trial you did not continue · may be deleted after the trial ends. The lead record behind it is kept until you ask us to remove it, or until we have had no contact with you for a year.
  • When you ask us to delete it · we delete it within 30 days, except anything we must keep for tax or legal reasons, which is kept only for as long as required.
  • Backups · a deleted record can remain in the nightly backups described in clause 5 for up to a year, and is then gone. Backups are not opened except to restore a shop, and a restore is only ever of that shop’s own data.
  • Records of payments are kept for the period Indian financial law requires.

9. Your rights

These are your rights under India’s Digital Personal Data Protection Act, 2023, and under this policy. None of them costs anything.

  • Get a copy. You can export everything yourself from inside the app, at any time, including after cancelling. Ask us and we will do it for you.
  • Correct it. Almost everything is editable in the app; write to us for anything that is not.
  • Delete it. Write to customer care and we will delete your account and its data within 30 days, and confirm when it is done. This cannot be undone, so we will ask you to confirm and offer you an export first.
  • Withdraw consent. Where we rely on your consent — the trial lead record, for instance — you may withdraw it, and we stop.
  • Complain. Write to the address in clause 13, which is our grievance contact. A person will look at it and reply within seven working days. If you are still not satisfied you may raise it with the Data Protection Board of India.

If a request concerns your own customer’s details rather than yours, we act on your instruction as the shop. If one of your customers writes to us directly, we will tell you and help you answer them.

10. Security

Truthfully, and without overstating it:

  • All traffic is encrypted in transit (HTTPS).
  • Access is controlled at the database itself, not only in the app, so one shop cannot read another shop’s records.
  • Staff logins are separate from the owner’s, with their own permissions, and staff cannot delete sales, customers or karigar records.
  • Shops that need it can switch on an additional lock that encrypts sensitive cash records with a key only the owner holds. If that key is lost, we cannot recover those records · that is the point of it, and we say so plainly before it is turned on.

No system is perfect. If there is ever a breach affecting your data, we will tell you what happened, what was affected and what we are doing, without waiting to be asked.

11. Children

Atelier is a business tool and is not intended for anyone under 18. We do not knowingly collect information from children.

12. Changes to this policy

If we change this policy in a way that materially affects you, we will tell you by email before it takes effect. The date at the top of this page is the date the current version took effect.

13. Contact

For anything in this policy, including an export, a deletion request or a complaint. This is also the grievance contact the Digital Personal Data Protection Act asks us to name:

hello.atelierapp@gmail.com
+91 89492 67197
Registered details — contact page