What we collect
Only what an order or a conversation actually needs. There is no advertising profile of you here and we have never bought or sold a customer list.
- Identity and contact. Your name, email address, phone number, and the delivery and billing addresses you enter.
- Order history. The pieces you bought, their prices, the atelier that made them and the dates they moved.
- Measurements. Twelve to sixteen figures for made-to-measure work, plus fitting notes taken by the cutter. Held only for customers who have commissioned something.
- Correspondence. What you write to us and what we write back, including notes from a consultation.
- Technical. IP address, browser, device type, pages visited and referring site — aggregated, and used to keep the site working.
- Saved in your browser. Your bag, wishlist and saved addresses live in this browser’s local storage, not on our servers, until you place an order.
Why we collect it
Each of these has a lawful basis under the Digital Personal Data Protection Act, 2023, and under the GDPR where it applies to you.
- To perform the contract. Taking payment, cutting to your measurements, delivering, altering and repairing.
- Legal obligation. Tax and GST records, and export documentation for international shipments.
- Legitimate interest. Fraud checks, keeping the site standing, and understanding which rooms people actually browse.
- Consent. Marketing email, and nothing else. You give it by subscribing and withdraw it with one click in any message.
Cookies
We set two kinds. Necessary cookies hold your session and your bag; the site does not function without them and they cannot be turned off. Analytics cookies count visits in aggregate and are set only if you accept them — declining changes nothing about what you can see or buy.
We run no advertising cookies, no cross-site trackers and no third-party pixels. Analytics are self-hosted and IP addresses are truncated before they are stored. Your browser’s cookie settings will clear ours along with everyone else’s.
Payment data
We never see your card. Payment is taken by our PCI-DSS Level 1 gateway, which returns a token and the last four digits — that token is all we store, and it cannot be used anywhere but on our own account. UPI, net banking and cash-on-delivery follow the same rule: the money moves through the provider, not through us.
For a bridal commission taken in a boutique, the deposit is charged on a terminal in the room and the receipt is emailed. No card details are written down, photographed or held in a file.
Who else sees it
A short list, and every one of them is contractually bound to use the data only to do the job we hired them for.
- The payment gateway, for the transaction itself.
- Our logistics partners, who receive a name, an address and a phone number so the box arrives.
- The atelier making your piece, which receives your measurements and your first name — never your address or your payment details.
- Our email provider, for order confirmations and, if you asked for it, the newsletter.
- Auditors, tax authorities and law enforcement, where we are legally required to produce records.
Data is stored on servers in India. Where an international delivery requires it, the recipient details travel to the destination country’s customs authority and nowhere else.
How long we keep it
- Order and tax records
- Eight years, which is what Indian tax law requires of us.
- Measurements and fitting notes
- Five years from your last order, because a returning customer should not have to be measured twice.
- Correspondence
- Twenty-four months from the last message in the thread.
- Marketing consent
- Until you withdraw it, then a suppression record so we do not re-add you.
- Analytics
- Fourteen months, aggregated, with no identifier attached to you.
Your rights
You can ask us to show you everything we hold, correct anything wrong, delete what we are not legally required to keep, or send it to you in a portable file. You can object to processing based on legitimate interest, and you can withdraw marketing consent at any time.
We answer within thirty days and there is no charge. We will ask you to confirm who you are first, which is the one hoop we cannot remove. If you are not satisfied, you may complain to the Data Protection Board of India, or to your local supervisory authority if you are in the EU or the UK.
Contact
- Data protection officer
- privacy@houseofvastra.com
- By post
- House of Vastra, 14 Rampart Row, Kala Ghoda, Fort, Mumbai 400001
- By phone
- +91 22 4021 8888, Mon–Sat 10:00–20:00 IST
If this policy changes we will post the new version here with a new date, and email anyone whose data the change materially affects rather than relying on you to notice.