Privacy & Cookie Policy
Your trust is central to everything we do. We protect your personal information with modern security protocols and will never sell or misuse your private data.
Zero Stored Cards
Payment details are processed directly via PCI-DSS certified PayHere. Card credentials never touch or reside on our servers.
No Data Selling
Your email, phone, and delivery addresses are used exclusively for fulfilling your orders and communication you request.
Google OAuth Safety
Google Sign-In uses standard OAuth 2.0 tokenization. We only receive your verified email and name to create your account.
When you browse our storefront, register an account, or complete a purchase, we collect necessary contact and delivery details such as your name, email address, telephone number, billing address, and recipient delivery address.
2. Secure Payment Processing:
We do not store your credit or debit card numbers on our servers. All online card transactions are processed directly through PayHere, a Central Bank of Sri Lanka-authorized and PCI-DSS Level 1 certified payment processor.
3. Google Sign-In & Authentication:
If you choose to log in using Google OAuth 2.0, we only access your basic verified profile information (name, email address, profile avatar) to streamline your account creation and sign-in experience.
4. Cookies & Browser Storage:
We use strictly necessary session cookies to maintain your shopping bag, preserve your wishlist items, and remember your login session across page visits.
5. Your Data Rights:
Under Sri Lanka's Personal Data Protection Act No. 9 of 2022 and international data protection standards, you have the right to inspect, update, or request the complete deletion of your customer account and stored personal details at any time by contacting hello@sribatik.lk.
Exercise Your Privacy Rights
You may request a copy of your personal data or ask for permanent account deletion at any time by emailing our Data Protection Officer at hello@sribatik.lk.