Legal Document

Privacy Policy

A complete, verified account of every piece of data Vestrostyles collects, why it is collected, how it is protected, and what rights you hold under Indian law.

Version 1.1.0Effective April 11, 2026DPDP Act 2023DPDP Rules 2025IT Amendment Rules 2026
01

Statutory Notice & Accessibility

In accordance with Section 5 of the DPDP Act 2023, this Privacy Policy is provided in English to the Data Principal (you). Vestrostyles is legally committed to providing this document in any of the 22 languages listed in the Eighth Schedule to the Constitution of India upon request.

02

Data Fiduciary Identification

Vestrostyles operates as the Data Fiduciary, determining the purpose and means of processing your personal data.

FieldDetails
Legal Entity NameVestrostyles
Registered OfficeGF-104, East Azad Nagar, East Delhi, New Delhi - 110051
Brand NameVestrostyles
Official Websitewww.vestrostyles.com
Support Emailinfo@vestrostyles.com
Grievance OfficerAnupam Jain, Grievance Redressal Officer
Grievance Emailinfo@vestrostyles.com
03

What Data We Collect — Complete & Verified

We follow the principle of Data Minimisation — collecting only what is strictly necessary. The following is a verified record of every category of personal data our platform processes.

04

How We Collect Data

MethodWhat It Collects
Account Registration FormFull name, email, password
Waitlist Sign-Up FormEmail, phone number
Profile Update FormFull name, avatar (optional)
Checkout Address FormsFull shipping / billing address details
Authorised Payment GatewayPayment method and unique transaction IDs (processed server-side)
Product Reviews FormStar rating, written review text
Middleware & Infrastructure (automatic)IP address (transient), user-agent (transient), session cookies
05

How Your Data Is Used

We use your personal data solely for the following declared purposes:

01Order Processing & Fulfilment
Processing your purchase, coordinating with authorised logistics partners, and sending order confirmation updates.
02Authentication & Account Security
Managing your login session, email verification, and protecting your account through secure cloud infrastructure.
03Customer Communication
Sending transactional emails only (order confirmations, waitlist confirmations). We do not send marketing emails without a separate explicit opt-in.
04Payment Verification & Fraud Prevention
Secure cryptographic verification of every transaction through our payment processing partners before order confirmation.
05Shipping Rate Calculation
Passing your postal code to logistics rate engines to calculate and display dynamic shipping costs at checkout.
06Legal & Tax Compliance
Retaining transaction records as required under the GST Act and Indian accounting regulations.
07Security Monitoring
Logging technical identifiers on access to sensitive routes for intrusion and abuse prevention.
08Platform Improvement
Aggregate, non-identifiable analytics on order patterns. No individual profiling.
07

Data Processors & Third-Party Disclosures

We share your data only with authorised, vetted Data Processors who process data strictly on our behalf:

Service CategoryData SharedPurpose
Payment Processing ServicesContact info and order amountSecure payment processing. We never store raw card numbers.
Cloud Infrastructure ProvidersAll stored personal dataSecure database and authentication infrastructure.
Logistics & Delivery PartnersShipping address and contact infoPhysical delivery of your orders.
Email & Notification ServicesName and email addressSending transactional and waitlist emails.
08

Data Retention Schedule

Data CategoryRetention PeriodJustification
Financial & Legal Records (Orders, Invoices)7 yearsMandatory compliance — GST Act and Income Tax Act
Account Profile & SettingsUntil account deletionProviding platform services and account management
Waitlist & Marketing DataUntil drop concludes or opt-outProduct launch notifications
Security & Audit LogsUp to 1 yearSecurity governance and fraud prevention
09

Security Commitment

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing your personal data.

  • Encryption: We use industry-standard encryption protocols (TLS) for data in transit and at rest.
  • Access Controls: Strict internal access policies ensure that your data is only accessible to authorised personnel on a need-to-know basis.
  • Payment Security: All payments are processed through PCI-DSS compliant partners. We never store raw card or banking credentials.

Breach Response Protocol

In the event of a personal data breach, Vestrostyles will notify the Data Protection Board of India within the statutory period (typically 72 hours of discovery) and will inform affected users as required by law.

10

Your Rights as Data Principal

Under the DPDP Act 2023, you are entitled to:

RightHow to Exercise
Right to AccessEmail info@vestrostyles.com to receive a summary of your data being processed
Right to CorrectionLog in → Account Settings → Edit Profile; or email info@vestrostyles.com
Right to Erasure (Account Deletion)Email info@vestrostyles.com with subject: 'Account Deletion Request'. We erase within 30 days, subject to legal retention requirements.
Right to NominationDesignate someone to exercise your rights in event of death or incapacity. Contact info@vestrostyles.com.
Right to Grievance RedressalIf unresolved within 30 days, escalate to the Data Protection Board of India.
11

Anti-Dark Pattern Commitment

Vestrostyles fully adheres to the CCPA Guidelines for Prevention and Regulation of Dark Patterns 2023:

CommitmentImplementation
No Basket SneakingOnly items you explicitly add are included. We never add products, insurance, or add-ons without your active selection.
No Hidden ChargesShipping cost is calculated and displayed transparently before payment confirmation.
No Forced ContinuityVestrostyles does not offer subscription products at this time.
Transparent PricingThe price displayed on the product page is the price you pay.
Clear ConsentAll consent checkboxes are unchecked by default and require your active selection.
12

Mandatory AI & Synthetic Content Disclosure

In accordance with the IT Amendment Rules 2026:

  • Synthetic Media: If Vestrostyles uses AI-generated imagery for product models, backgrounds, or promotional content, it will be clearly labelled as “Synthetically Generated” or “AI-Generated Image” adjacent to the content.
  • Automated Decisions: We do not use fully automated decision-making processes that significantly affect your legal rights without human oversight.
  • AI in Commerce: Product recommendations (if any) use aggregate, non-personal signals. No individual profiling is used for discriminatory pricing.
13

Cookies & Tracking

CookieTypePurposeDuration
Session CookieStrictly NecessaryKeeps you authenticated across pagesUntil logout / expiry
Auth TokenStrictly NecessarySecure auth token — inaccessible to JavaScriptSession
14

Children's Privacy

Vestrostyles is not directed at individuals under the age of 18 years. We do not knowingly collect personal data from minors. If you believe a child has submitted data to us, contact info@vestrostyles.com immediately for prompt deletion.

15

Changes to This Policy

We may update this Privacy Policy when our data practices change:

  • The “Last Updated” date at the top will be revised
  • A notice will be displayed on the website for 14 days after any material change
  • For significant changes, we will email all registered users

Continued use of our platform after a policy update constitutes acceptance of the revised terms.

16

Contact & Grievance Redressal

FieldDetails
Grievance OfficerAnupam Jain
DesignationGrievance Redressal Officer
Emailinfo@vestrostyles.com
Response TimeWithin 30 days of receipt
Registered AddressGF-104, East Azad Nagar, East Delhi, New Delhi - 110051

v1.1.0 — Vestrostyles Legal Team — April 11, 2026

Codebase-verified