Privacy Policy

Your information, handled with care.

A plain-language guide to what AANYA receives, why it is used, and the choices available to you.

Accounts

Optional and protected

Browsing remains available without an account. Registration uses WordPress and requires only basic identity and contact details.

Contact

Purpose-limited

Form details are used to review, route and respond to your inquiry.

Retailers

Separate services

A retailer handles information you provide after leaving AANYA.

Information we receive

AANYA may receive standard technical information sent by your browser, such as requested pages and general device or browser information. If you register, WordPress stores your full name, email address, username and protected password credentials. If you use our Contact form, we receive the information you choose to provide, including your name, email address and inquiry details.

Please do not submit sensitive information.

Do not send passwords, payment details, identity documents, medical records, health history, home addresses or other sensitive data.

How information is used

Account information is used to create, authenticate, secure and recover your account. Signed-in users may view their username and email address, update basic profile details, save account preferences and searches, review recently viewed products, and maintain a private Wishlist of published product IDs. These account records are stored with the WordPress user account and can be changed or cleared from the account area. Wishlists are not public, shared, or used to reserve products, stock, or prices. Email addresses remain read-only in the account area. Password-reset messages are sent only through WordPress mechanisms. We use technical information to operate, secure and improve the website. Contact-form information is used only to understand, route and respond to the inquiry, prevent abuse and meet applicable obligations.

Contact submissions are delivered by email to the AANYA team and do not become public posts. Short-lived, non-readable rate-control identifiers may be used to limit duplicate or abusive submissions.

Cookies, sessions, search and analytics

WordPress uses authentication and session cookies when you sign in, and essential site features may use cookies or browser storage where needed to operate. Search terms and aggregated page usage may be used to understand how the site performs. AANYA does not use contact-form details as public content.

Affiliate links and third-party retailers

Some outbound retailer links may be affiliate links. When you follow one, the retailer may receive technical referral information and applies its own privacy policy. The retailer—not AANYA—handles checkout, payment, delivery, returns and information submitted on its service.

Retention and security

Account records are retained while the account remains part of the service and as otherwise reasonably required for security or legal obligations. Inquiry emails are retained only as reasonably needed to address the message, maintain operational records or meet legal requirements. Passwords are handled by WordPress and are not stored separately by AANYA. No internet transmission is completely risk-free, but we use reasonable safeguards and collect only relevant information.

Your choices and requests

You may ask about access, correction or deletion of personal information connected to an interaction. Use the Contact form and choose “Privacy or data request.” Do not upload identity documents; if verification is legally necessary, a safer method will be explained.

Children and international visitors

AANYA is not directed to children and does not knowingly seek children’s personal information. Visitors access the site from different locations; any applicable rights depend on the law and context involved.

Account export and deletion

Signed-in users may download a copy of their account profile, preferences, saved searches, recently viewed products and Wishlist after re-entering their current password. The one-time ZIP is stored outside the public web directory and expires after 15 minutes.

Account deletion requires password re-authentication and an email confirmation link that expires after one hour. Confirmation starts a seven-day grace period during which the request can be cancelled. Final deletion removes the WordPress user and its account preferences, searches, recent products and Wishlist data, invalidates sessions and destroys outstanding privacy tokens and exports. Elevated accounts and accounts with authored platform content are protected from automatic public deletion. Records required for legal or operational purposes may be retained or anonymized. AANYA cannot delete records held by third-party retailers.

Login and account security history

AANYA keeps up to 50 successful-login, recognized failed-login, logout, password-change, session-control and account-deletion events for no more than 90 days. Entries use a general device category, browser family and operating-system family. Full IP addresses, precise location, passwords, cookies and session tokens are not stored in this history. Signed-in users can review this information, include it in their data export, sign out other sessions or sign out all sessions. Final account deletion removes the history. Essential password and session-control emails may be sent for account security.

Account avatar media

You may upload a JPEG, PNG or WebP avatar for authenticated account presentation. AANYA center-crops and normalizes the image through WordPress and removes unnecessary image metadata. WordPress Media Library files normally have publicly reachable URLs, so do not upload an image you consider private. AANYA does not use Gravatar for account or header avatars and does not create a public profile. Avatar metadata and the processed image are included in an account export. Final deletion removes the AANYA-owned attachment and its generated derivatives when ownership is verified.

Email verification and authentication methods

AANYA records whether control of an account email has been verified and keeps bounded authentication-method metadata with the WordPress user. Verification links contain a random single-use token, expire after 60 minutes and are stored only as a keyed hash. A request timestamp, cooldown state, email-binding hash and confirmation time may be retained to secure the process. Verification messages are transactional, contain no tracking pixels and do not sign the recipient in.

When Google sign-in is enabled, Google provides a stable account identifier, verified email and minimum name claims for authentication. AANYA stores a keyed protected form of the Google identifier, link status, provider-email snapshot, verification status, and link/last-use times. AANYA never receives the Google password, requests Contacts, Gmail, Drive or unrelated Google API access, or retains long-lived Google access or refresh tokens. Matching email never silently merges accounts. Linking requires proof of both accounts and unlinking requires confirmed password access.

Authentication-method and bounded security-event information is included in account exports without subjects, tokens, codes, state, nonce or credentials. Final deletion removes the Google method and protected index, but does not delete the separate Google account. Google remains an independent third party governed by its own policies.

Policy updates

This policy may be updated when the site or its practices change. Material updates will be reflected on this page. Privacy questions can be submitted through the Contact form.