Trust, Security & Privacy
This page is maintained by the JoyToys team to answer common questions about how we handle your data, payments and account security. It describes our current practices and is not an independent certification.
Account & access
Customer accounts use email/password or Google sign-in. Sessions are managed by our authentication provider and stored only in your browser.
Admin features are gated by server-side role checks — client-side flags alone never grant access.
Payments
Online payments are processed by Razorpay. We never see or store full card numbers, UPI PINs, or net-banking credentials on our servers.
Every payment is verified server-side by validating Razorpay's signed response before an order is marked paid.
Data we collect
To fulfil orders we collect your name, shipping address, phone, email and order history. Guest checkout is supported — an account is not required to place an order.
Order data is stored in our managed backend with row-level access policies so signed-in customers see only their own orders.
Order lookup for guests
Guest customers track orders by entering their order number together with the email or phone used at checkout. The lookup runs server-side and returns masked contact details only — it never exposes another customer's information.
Third parties we use
- Razorpay — payment processing
- Shiprocket — shipping & tracking
- Supabase (Lovable Cloud) — database, auth & storage
We share with each provider only the data needed to deliver your order.
Contact & data requests
To request a copy or deletion of your data, or to report a security concern, email support@joytoys.in. We respond to verified requests within a reasonable timeframe.
See also our Shipping & Returns policy and FAQ.
