Accounts
Optional and protected
Browsing remains available without an account. Registration uses WordPress and requires only basic identity and contact details.
Privacy Policy
A plain-language guide to what AANYA receives, why it is used, and the choices available to you.
Accounts
Browsing remains available without an account. Registration uses WordPress and requires only basic identity and contact details.
Contact
Form details are used to review, route and respond to your inquiry.
Retailers
A retailer handles information you provide after leaving AANYA.
AANYA may receive standard technical information sent by your browser, such as requested pages and general device or browser information. If you register, WordPress stores your full name, email address, username and protected password credentials. If you use our Contact form, we receive the information you choose to provide, including your name, email address and inquiry details.
Do not send passwords, payment details, identity documents, medical records, health history, home addresses or other sensitive data.
Account information is used to create, authenticate, secure and recover your account. Signed-in users may view their username and email address, update basic profile details, save account preferences and searches, review recently viewed products, and maintain a private Wishlist of published product IDs. These account records are stored with the WordPress user account and can be changed or cleared from the account area. Wishlists are not public, shared, or used to reserve products, stock, or prices. Email addresses remain read-only in the account area. Password-reset messages are sent only through WordPress mechanisms. We use technical information to operate, secure and improve the website. Contact-form information is used only to understand, route and respond to the inquiry, prevent abuse and meet applicable obligations.
Contact submissions are delivered by email to the AANYA team and do not become public posts. Short-lived, non-readable rate-control identifiers may be used to limit duplicate or abusive submissions.
Some outbound retailer links may be affiliate links. When you follow one, the retailer may receive technical referral information and applies its own privacy policy. The retailer—not AANYA—handles checkout, payment, delivery, returns and information submitted on its service.
Account records are retained while the account remains part of the service and as otherwise reasonably required for security or legal obligations. Inquiry emails are retained only as reasonably needed to address the message, maintain operational records or meet legal requirements. Passwords are handled by WordPress and are not stored separately by AANYA. No internet transmission is completely risk-free, but we use reasonable safeguards and collect only relevant information.
You may ask about access, correction or deletion of personal information connected to an interaction. Use the Contact form and choose “Privacy or data request.” Do not upload identity documents; if verification is legally necessary, a safer method will be explained.
AANYA is not directed to children and does not knowingly seek children’s personal information. Visitors access the site from different locations; any applicable rights depend on the law and context involved.
Signed-in users may download a copy of their account profile, preferences, saved searches, recently viewed products and Wishlist after re-entering their current password. The one-time ZIP is stored outside the public web directory and expires after 15 minutes.
Account deletion requires password re-authentication and an email confirmation link that expires after one hour. Confirmation starts a seven-day grace period during which the request can be cancelled. Final deletion removes the WordPress user and its account preferences, searches, recent products and Wishlist data, invalidates sessions and destroys outstanding privacy tokens and exports. Elevated accounts and accounts with authored platform content are protected from automatic public deletion. Records required for legal or operational purposes may be retained or anonymized. AANYA cannot delete records held by third-party retailers.
AANYA keeps up to 50 successful-login, recognized failed-login, logout, password-change, session-control and account-deletion events for no more than 90 days. Entries use a general device category, browser family and operating-system family. Full IP addresses, precise location, passwords, cookies and session tokens are not stored in this history. Signed-in users can review this information, include it in their data export, sign out other sessions or sign out all sessions. Final account deletion removes the history. Essential password and session-control emails may be sent for account security.
You may upload a JPEG, PNG or WebP avatar for authenticated account presentation. AANYA center-crops and normalizes the image through WordPress and removes unnecessary image metadata. WordPress Media Library files normally have publicly reachable URLs, so do not upload an image you consider private. AANYA does not use Gravatar for account or header avatars and does not create a public profile. Avatar metadata and the processed image are included in an account export. Final deletion removes the AANYA-owned attachment and its generated derivatives when ownership is verified.
AANYA records whether control of an account email has been verified and keeps bounded authentication-method metadata with the WordPress user. Verification links contain a random single-use token, expire after 60 minutes and are stored only as a keyed hash. A request timestamp, cooldown state, email-binding hash and confirmation time may be retained to secure the process. Verification messages are transactional, contain no tracking pixels and do not sign the recipient in.
When Google sign-in is enabled, Google provides a stable account identifier, verified email and minimum name claims for authentication. AANYA stores a keyed protected form of the Google identifier, link status, provider-email snapshot, verification status, and link/last-use times. AANYA never receives the Google password, requests Contacts, Gmail, Drive or unrelated Google API access, or retains long-lived Google access or refresh tokens. Matching email never silently merges accounts. Linking requires proof of both accounts and unlinking requires confirmed password access.
Authentication-method and bounded security-event information is included in account exports without subjects, tokens, codes, state, nonce or credentials. Final deletion removes the Google method and protected index, but does not delete the separate Google account. Google remains an independent third party governed by its own policies.
This policy may be updated when the site or its practices change. Material updates will be reflected on this page. Privacy questions can be submitted through the Contact form.