0
Your Cart
0
Your Cart

Privacy & Security Statement

Last updated: 2 September 2026

This page explains, what happens to your information when you use Saṃsāra (the “Site”). If you only read one section, read “Your choices and rights” — it tells you how to see, change, or delete what we hold, and who to contact if something feels wrong.

Who we are

Saṃsāra is operated by [Hemptons Investment Holdings Ltd. (Ireland)] (“we”, “us”, “our”). Saṃsāra is a Hemptons brand. We are the party responsible for deciding how and why your personal information is processed through this Site.

What we collect

We only collect what we need to operate the Site, fulfil orders, and keep matters secure. Depending on how you use the Site, this may include:

  • Contact details you provide us — name, email address, phone number, delivery and billing address.
  • Order details — what you purchased, when, and any communication about that order.
  • Account information e.g. login details and order history.
  • Payment information — handled directly by our payment processor. We do not store your full card details on our own servers (see “How we protect your information”).
  • Technical and usage information — IP address, browser type, device type, pages viewed, and how you navigate the Site, mostly collected automatically through cookies.
  • Anything you send us directly — messages, reviews, or support requests.
  • Product reviews and comments — if you leave one, we collect what you write, plus your IP address and browser information, to help detect spam.

We do not collect information we don’t have a clear use for, and we do not ask for more than a transaction or request reasonably requires.

How we use it

  • To process and deliver your orders, and to contact you about them.
  • To provide customer support and respond to questions.
  • To keep the Site secure and working properly, and to diagnose problems.
  • To improve the Site — understanding, in aggregate, what people use and struggle with.
  • To send you marketing communications, but only if you’ve opted in — see “Marketing communications” below.
  • To meet legal, tax, and accounting obligations.

What we don’t do

  • We do not sell your personal information to third parties.
  • We do not share your information with other businesses for their own marketing purposes.
  • We do not collect more than we need, or repurpose your information for something unrelated to why you gave it to us, without telling you first.
  • We do not keep your payment card details on our own systems.

Cookies and similar technology

Cookies are small files stored in your browser that help the Site reference and helps the site to understand how it is used. We use a few categories:

  • Essential — required for the Site and checkout to work (e.g. keeping items in your cart). If you have an account, a login cookie keeps you signed in for 2 days, or 2 weeks if you select “Remember Me”; a separate cookie remembers your display preferences for a year. A short-lived cookie on our login page simply checks whether your browser accepts cookies at all — it holds no personal data and disappears when you close your browser. None of these can be switched off without breaking core functionality.
  • Comment/review convenience — if you leave a product review or comment and choose to save your name, email, and website for next time, we set a cookie for that. It lasts one year and is entirely optional.
  • Analytics — help us understand traffic and usage patterns, in aggregate. These do not identify you by name.
  • Marketing/advertising — used to show you more relevant ads, only if you’ve allowed this. If we use these, you’ll be asked to consent before they’re set, and you can withdraw that consent at any time.

You can decline, block or delete cookies through your browser settings at any time; doing so may limit some features, particularly checkout.

Who we share information with

We share information only where it’s necessary to operate the site /service / business, and only with parties bound to protect it:

  • Payment processors, to complete your transaction.
  • Delivery and logistics partners, to get your order to you.
  • Service providers who help us operate the Site (e.g. hosting, e-mail, analytics), under contract, and only for the purpose we’ve engaged them for.
  • Law enforcement or regulators, only where we’re legally required to.
  • A buyer, if we ever sell or transfer part of the business — and only under the same protections described here.
  • If you request a password reset, the confirmation email includes your IP address — a standard, platform-level fraud-prevention measure, not something we add ourselves.

If any of these partners are located in a different country to you, we take reasonable steps to make sure your information still gets a comparable level of protection to what’s described in this document.

How long we keep it

We keep personal information only for as long as we need it for the purpose it was collected — to complete an order, respond to a query, or meet a legal obligation (for example, tax and accounting records, which SA law and most other jurisdictions require us to retain for a set number of years – typically 5 years). After that, we delete or anonymise it.

One exception: comments and reviews are kept indefinitely, along with their metadata, so we can recognise you and auto-approve genuine follow-up comments instead of holding everyone in a moderation queue. You can still ask us to delete a specific comment or review at any time.

How we protect your information

Practically, that means:

  • All data sent between your browser and the Site is encrypted in transit (HTTPS/TLS).
  • Payment card data is handled by a PCI DSS-compliant payment processor — it passes through our systems only in encrypted form, if at all, and is never stored by us in plain text.
  • Access to customer data internally is limited to people who need it to do their job.
  • We use standard technical safeguards — firewalls, access controls, and monitoring — appropriate to the sensitivity of the data involved.

No method of transmission or storage is 100% secure, and we can’t guarantee absolute security — but if something goes wrong, here’s our commitment: if we become aware of a breach that puts your information at risk, we will notify affected users and the relevant regulator without undue delay, and tell you what happened and what we’re doing about it.

Your choices and rights

Wherever you’re based, you generally have the right to:

  • Ask what personal information we hold about you, and get a copy of it.
  • Ask us to correct information that’s wrong or out of date.
  • Ask us to delete your information, subject to what we’re legally required to keep (e.g. for tax purposes).
  • Object to, or opt out of, how we use your information — including marketing, at any time.
  • Withdraw consent, where we’re relying on consent, without it affecting anything that happened before you withdrew it.

If you have an account with us, you can see, edit, or delete most of this information yourself at any time from your account dashboard — the one exception is your username, which can’t be changed once set.

To exercise any of these, contact us at hallo@thesamsara.shop. We’ll respond within a reasonable time and, where a specific law gives you a shorter guaranteed deadline or an additional right (for example, a right to complain to a specific regulator), we’ll honour that too.

Marketing communications

We only send marketing e-mails to people who have opted in — either by ticking a box when signing up, or by giving clear permission at checkout. We don’t pre-tick that box for you, and we don’t add you to marketing lists just because you made a purchase.

Every marketing email includes a one-click unsubscribe. You can also unsubscribe any time by e-mailing : hallo@thesamsara.shop. Once you opt out, we stop — we don’t ask again unless you opt back in yourself.

Children

The Site is not directed at children, and we don’t knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact us and we’ll delete it.

Changes to this statement

If we materially change how we handle your information, we’ll update the date at the top of this page and, where the change is significant, make a reasonable effort to let you know directly (e.g. by email or a Site notice) before it takes effect.

Contact us

For anything in this document, or if something about how your data is handled doesn’t sit right with you: hallo@thesamsara.shop.