Skip to main content

Privacy Policy

Last Updated: August 2026

At Kinasih Spices & Herbs, we value your trust and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, purchase our premium spices and herbs, or interact with our services.


1. Who We Are (Data Controller)

The data controller responsible for your personal data is:

Kinasih Spices & Herbs [registered legal entity name]

[Registered address, city, postal code, country]

Privacy enquiries: privacy@kinasih.com

Before publishing: replace the placeholders above with the registered legal entity name, registered address, and company number. GDPR Art. 13(1)(a) requires the controller’s identity and contact details to be stated; a trading name alone is not sufficient.


2. Information We Collect

We collect information that you provide directly to us, as well as automatically collected technical metadata, to ensure a secure and smooth shopping experience:

  • Personal Identity Data: Your first name, last name, and contact details.
  • Contact Information: Email address and phone number (required for shipping notifications and courier coordination).
  • Shipping Address: Street address, apartment/suite details, city, state/province, postal code, and country.
  • Technical Metadata: IP address, device type, operating system, and request signatures. This is used by our security controls (including Upstash rate-limiters) to prevent automated checkout abuse, brute forcing, and payment fraud.
  • Session Data: Authenticated account details processed via Auth.js.

Note on Payment Details: We do not store or process your credit card number, bank credentials, or PayPal account logins on our servers. All payments are securely processed and captured through PayPal Business API.


3. Legal Basis and How We Use Your Data

Under global data protection standards (such as GDPR and CCPA), we process your data based on contract necessity, legal obligations, and our legitimate business interests:

  • Performance of a Contract: To process, validate, and fulfill your orders; and to calculate applicable voucher discounts.
  • Courier Coordination: To pass your contact phone number and address to shipping carriers so they can successfully coordinate physical delivery.
  • Fraud Prevention & Rate Limiting (legitimate interests, Art. 6(1)(f)): To safeguard our stock against concurrency race conditions and prevent payment card probing using sliding-window rate limiters.
  • Customer Support (contract / legitimate interests): To respond to your requests, questions, or tracking enquiries.
  • Legal Obligation (Art. 6(1)(c)): To retain order and tax records for the statutory period.
  • Newsletter (consent, Art. 6(1)(a)): Only if you tick the box and then confirm via the link we email you. You can withdraw at any time.
  • Birthday voucher (consent, Art. 6(1)(a)): If — and only if — you choose to add your date of birth to your profile. It is optional and you can delete it at any time.
  • Security logging (legitimate interests): We record administrative actions and sign-in attempts so we can investigate misuse and meet our breach-notification duties.

4. Data Sharing & Third-Party Processors

We do not sell, rent, or trade your personal data. We only share essential information with trusted service providers to run our store:

  • PayPal: Processes your payment details and returns transaction authorization signatures.
  • Postal & Courier Partners: Receives your name, phone number, and physical shipping address to execute parcel delivery.
  • Upstash Redis: Stores IP addresses transiently to operate sliding-window rate limits.
  • Neon PostgreSQL: Hosts our database — order histories, accounts, reviews and voucher assignments.
  • Vercel: Hosts and serves the website. All requests, including their IP addresses, transit Vercel’s infrastructure.
  • Vercel Blob: Stores images you upload with a product review.
  • Resend: Delivers transactional email, and therefore receives your name, email address and order details.
  • Google: Provides Sign-in with Google. If you use it, Google receives authentication requests and supplies us your name, email address and profile picture.
  • Sentry: Receives server error diagnostics if enabled. Configured to exclude request bodies, headers and cookies.

5. International Data Transfers

All of the providers listed above are established in the United States, so your personal data is transferred outside the European Economic Area. These transfers rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the European Commission’s Standard Contractual Clauses, together with a transfer risk assessment. You may request a copy of the safeguards applied by contacting us at the address in section 1.


6. Data Retention

We keep personal data only for as long as it is needed, and enforce these periods automatically with a scheduled deletion job rather than relying on manual clean-up:

  • Orders: the financial record is kept for 7 years to satisfy tax and accounting law. After that, the name, email address and shipping address attached to it are erased and only the anonymous transaction record remains.
  • Account data: kept until you delete your account, which you can do yourself at any time.
  • Notifications: 90 days.
  • Expired login sessions: removed once expired.
  • Unconfirmed newsletter sign-ups: 30 days, then deleted.
  • Newsletter subscription: until you unsubscribe.
  • Security and administrative logs: 2 years.
  • Rate-limiting records: minutes — these expire automatically.

7. Your Privacy Rights

Two of these you can exercise yourself, immediately, from your account settings — no request or waiting period:

  • Access & Portability (Art. 15, 20): “Download my data” gives you everything we hold about you as a machine-readable JSON file.
  • Erasure (Art. 17): “Delete Account” removes your account, reviews, uploaded images, wishlist, vouchers, notifications and newsletter subscription. Past orders are kept for the statutory period described above, but are stripped of your name, email and address and unlinked from you.

You also have the right to:

  • Rectification (Art. 16): correct inaccurate details — your name and date of birth are editable in your profile.
  • Restrict or object (Art. 18, 21): object to processing based on our legitimate interests.
  • Withdraw consent (Art. 7(3)): unsubscribe from the newsletter at any time using the link in any email. Withdrawal does not affect processing carried out before it.
  • No discrimination: we will never deny service or change prices because you exercised these rights.

For anything not self-service, contact privacy@kinasih.com. We respond within one month, as required by Art. 12(3).

Right to complain (Art. 13(2)(d)): if you believe we have mishandled your data you may lodge a complaint with your local supervisory authority. In the EU, that is the data protection authority of the country where you live or work. You do not need to contact us first.


8. Cookies & Local Storage

We use only what the site needs to function. There are no advertising, profiling or analytics trackers, and nothing is shared with ad networks.

  • Session cookie (strictly necessary) — keeps you signed in. Set only when you log in, HttpOnly, and cleared when you sign out.
  • Cart (strictly necessary) — your basket is held in your browser’s local storage, not sent to us until you check out.
  • Cookie notice acknowledgement — a single local-storage flag so we don’t show the notice repeatedly.

9. Children

This store is not directed at children. You must be at least 16 years old to create an account, and we do not knowingly collect data from anyone younger. We ask for a date of birth solely so we can send a birthday voucher; it is optional, and you can remove it at any time from your profile. If you believe a child has given us personal data, contact us and we will delete it.


10. Security Controls

We utilize modern industry-standard security protocols to protect your data. All communication is encrypted via 256-bit Secure Socket Layer (SSL/TLS). Our checkout pipeline implements strict input validation, webhook authentication verification, and multi-layered database transactions to prevent unauthorized access.