Payment is cash on delivery; no card number is requested.
Accounts and orders
Your information, for your account and delivery.
This notice explains the data used by the ARELVA website and app to create an account, secure a session, record a cash-on-delivery order and arrange delivery.
Applicable revision: arelva-commerce-privacy-2026-08-23-v1Verification codes and reset links are time-limited.
The receipt keeps the final total and address used at confirmation.
Who handles the data?
The legal seller named in the sales terms handles data needed to fulfil orders. Inovexia operates the ARELVA technical platform on its behalf.
INOVEXIA — ARELVA
Data handled
Account and security
- Email address, verification state and a password retained only as a hash.
- Optional profile, language preference, devices and session expiry dates.
- Saved addresses, recipient and phone when you choose to keep them in the account.
- Saved products as stable identifiers only; the account selection retains no stale title, price or media snapshot.
Cart, order and delivery
- Cart id, products, quantities, server prices and price revision; the secret cart token remains in an HttpOnly cookie.
- Name, verified email, phone, address, notes, accepted terms and notice, reference, items, amounts and order states.
- Locality, parcel profile, final delivery rate, carrier, tracking, hand-off and delivery. Weight/class comes from the server catalogue, not the browser.
Email and technical operation
- Verification codes, reset links and transactional confirmations placed in an encrypted queue.
- Delivery status and bounded bounce/suppression events needed to avoid resending to a failing address; email is delivered by Postmark through the operator’s local relay.
- Request metadata strictly needed for security, abuse prevention and service diagnosis.
The browser keeps a non-secret cart id and selection identifiers. Checkout does not place order contact details in localStorage or sessionStorage. Sessions use secure, HttpOnly, SameSite cookies.
Why the data is used
- Create, verify and secure the account; provide password resets and session controls.
- Preserve and claim the cart after sign-in, and calculate server-owned product and delivery prices.
- Form and fulfil the sales contract, produce a receipt, hand the order to Amana Express or ARELVA-arranged delivery, and handle tracking, cancellation, returns and support.
- Prevent duplicates, fraud and abuse, and protect service integrity and availability.
The terms and privacy checkboxes record the acknowledgements required to order. They are not marketing consent. Marketing requires a separate choice; the current checkout offers no marketing choice.
Recipients
Access is limited to authorized account/order staff, the hosting/database services needed to run the platform, Postmark for transactional messages, and Amana Express or ARELVA-arranged delivery for the data required to deliver. No payment provider receives card data because checkout does not collect it.
Protection measures
- Hashed passwords and revocable, time-limited sessions.
- Each order’s contact and address encrypted using authenticated AES-256-GCM before storage; the email queue uses a separate encryption key.
- Addresses you choose to save are protected by authentication and access controls; they are not described as application-level encrypted.
- Browser-origin checks, size and rate limits, secure production cookies, and private non-cacheable responses.
Retention by purpose
- Verification code: 10 minutes; reset link: 30 minutes; customer session: up to 7 days unless closed earlier.
- Active server cart: 30 days; the local id is removed when the order is created or the cart is deleted.
- Profile and addresses: until you remove them or delete the account.
- Saved products: until you remove them from the selection or delete the account; only stable identifiers are retained.
- Orders, receipts, pricing records, COD status, shipment and returns: for applicable legal, accounting, tax and legal-claims periods. If the account is deleted, records that must be kept are detached from it.
- Email queue: sent messages are deleted after 30 days and terminal failures after 90 days. Non-blocking bounce observations are deleted after 90 days. A non-reversible HMAC fingerprint of an address reported inactive remains only as long as needed to prevent further sends, until reactivation or operator resolution.
Your choices and rights
In the account you can correct your profile, manage addresses and sessions, view receipts or request account deletion. You may also request access, correction, restriction or deletion where applicable. Legal duties may require some order information to be retained. Never send bank details.