Legal
Privacy Policy
Last Updated: May 20, 2026
1. Introduction
At Thiyas Collections, we value the trust you place in us and are committed to safeguarding your personal data. This Privacy Policy explains how we collect, use, disclose, and protect your information in accordance with the European Union General Data Protection Regulation (GDPR) when you visit our website, submit requests, or interact with our brand.
By accessing our website, you consent to the processing of your data as described in this policy. If you have any questions or concerns regarding your privacy, please reach out to us at info@thiyascollections.com.
2. Information We Collect
We collect information to deliver a beautiful, premium browsing experience and to respond to your specific requests. The data we collect includes:
- Enquiry Form Data: When you contact us regarding a bespoke piece or accessory, we collect your name, email address, phone number (optional), subject, and message content.
- Usage & Device Information: We automatically record technical metrics from your visit, such as IP addresses, browser types, device operating systems, screen resolutions, and general referral links.
- Cookies and Trackers: We utilize subtle cookie technologies to optimize our site navigation, maintain dark-mode selections, and track interactions.
3. How We Use Your Data
We process your personal information strictly for legitimate business and legal purposes, specifically:
- To address your product inquiries, support requests, and customize brand consultations.
- To measure and improve our site functionality, responsive designs, and core performance (Web Vitals).
- To comply with EU corporate regulations, tax audits, and legal requirements.
- To prevent fraudulent behaviors, maintain database security, and protect our systems.
4. Data Shared with Third Parties
We do not sell, rent, or trade your personal data with third-party marketers. To operate our premium showcase, we securely transmit and store data with vetted technical infrastructure providers:
- Supabase: For cloud hosting, transactional logs, and secure database storage of contact forms.
- Resend: For formatting and distributing instant notification emails to the brand administrators when a message is received.
- Google Analytics: To monitor overall site traffic and anonymized user behavior trends, allowing us to optimize marketing performance.
- TikTok Shop / Checkout Providers: When you complete checkout redirects, transactional buyer data is gathered and processed directly by the designated checkout partner.
5. GDPR Compliance & Your Rights
As a European-based luxury brand, we fully support your data privacy rights. Under the General Data Protection Regulation (GDPR), you possess the following rights regarding your personal information:
- Right of Access: You can request a copy of the personal data we store about you.
- Right to Rectification: You can request corrections to incomplete or inaccurate data.
- Right to Erasure ("Right to be Forgotten"): You can request that we delete your stored personal information.
- Right to Restriction: You can request that we limit how we process your information.
- Right to Data Portability: You can request a structured file containing your data.
- Right to Object: You can object to our handling of your data for specific business tasks.
To exercise any of these rights, please email us directly. We will address your request within 30 days.
6. Data Security & Retention
We implement industry-standard encryption protocols (SSL/HTTPS) to secure all information transmitted to and from our website. Our database servers are housed in secure, enterprise-grade cloud centers.
We retain your contact inquiries and database records only for as long as necessary to fulfill the requested services, complete brand audits, or comply with statutory retention timelines. Once it is no longer required, we safely delete or permanently anonymize your records.
7. Contact Information
If you have any questions, feedback, or data erasure requests concerning this Privacy Policy, please contact our designated Data Protection Coordinator at: