Vastra Textiles Pvt. Ltd. ("Vastra", "we", "us") operates vastra.co.in and the associated retail and wholesale services. We are the Data Fiduciary for the personal data described below under the Digital Personal Data Protection Act, 2023 (the "DPDP Act"). This policy applies from the date shown above and explains what we collect, why, who we share it with, and the rights you hold over it.
We ask for the minimum we need to sell you cloth, raise a compliant tax invoice and deliver a parcel. We do not sell personal data, and we do not use it to train third-party advertising profiles.
Personal data we collect
- Account details — name, email address, mobile number, password (stored only as an argon2 hash, never in readable form) and your saved preferences.
- Business and KYC details for trade accounts — company name, GSTIN, PAN, business type and the details of the person authorised to transact on the company's behalf.
- Addresses — shipping and billing addresses, including the state, because the place of supply determines whether your invoice carries CGST + SGST or IGST.
- Order and transaction data — carts, quotations, RFQs, orders, invoices, credit notes, returns and the correspondence attached to them.
- Payment data — we receive a payment status, a gateway reference and the last four digits of a card. Full card numbers, UPI PINs and net-banking credentials are captured by the payment gateway and never reach our servers.
- Communications — enquiries, RFQ messages, WhatsApp and email threads with our trade desk, and support tickets.
- Content you publish — product reviews, ratings and photographs you choose to upload.
- Technical data — IP address, device and browser type, pages visited and referring URL, collected through cookies and server logs.
Why we use it
- To create and operate your account, and to authenticate you.
- To process orders, quotations and RFQs, take payment, and arrange delivery.
- To issue GST-compliant tax invoices, credit notes and e-way bills, and to meet our obligations under the CGST Act and the Companies Act, 2013.
- To approve and price trade accounts — verifying GSTIN and PAN, and applying the wholesale tier or company price book you qualify for.
- To provide customer support, handle returns and resolve disputes.
- To detect and prevent fraud, payment abuse and misuse of the platform.
- To send transactional messages you cannot opt out of while you have an active order (order confirmations, dispatch and delivery updates, payment receipts).
- To send marketing — new arrivals, restocks and trade offers — only where you have given consent, which you may withdraw at any time.
Cookies and similar technologies
We use a small number of cookies and equivalent browser storage. Strictly necessary cookies keep you signed in, hold your cart together before you sign in (a guest session identifier) and protect forms against cross-site request forgery; the site cannot function without them. Preference storage remembers choices such as your recently viewed items. Analytics storage, where enabled, tells us which pages are used and where journeys break, in aggregate.
You can clear or block cookies in your browser settings. Blocking strictly necessary cookies will sign you out and empty your cart.
Who we share it with
- Payment gateways (Razorpay and Stripe) — to authorise and settle payments, and to process refunds.
- Logistics and courier partners — the recipient name, address and phone number needed to deliver, and to raise an e-way bill where the consignment value requires one.
- Cloud hosting, object storage and email/SMS providers acting as our processors under contract.
- Professional advisers — auditors, chartered accountants and lawyers, where a specific engagement requires it.
- Government authorities, courts and law-enforcement agencies, where we are legally required to disclose.
- An acquirer, in the event of a merger, restructuring or sale of the business — with notice to you.
Every processor is bound by contract to use your data only for the purpose we specify, to keep it secure, and to return or delete it when the engagement ends.
Transfers outside India
Our primary infrastructure is hosted in India. Some processors — notably payment and email providers — may process data outside India. Where that happens we rely on contractual safeguards and transfer only to countries not restricted by the Central Government under the DPDP Act.
How long we keep it
- Tax invoices, credit notes and the accounting records attached to them — eight financial years, as required by the CGST Act and the Companies Act, 2013. These survive account deletion because retaining them is a statutory obligation, not a choice.
- Account and profile data — for as long as your account is active, and for three years after you close it, to settle disputes and returns.
- RFQs and quotations — 24 months from the date of the last activity on the thread.
- Support correspondence — 24 months from resolution.
- Marketing consent records — until you withdraw consent, plus the period needed to evidence that the withdrawal was honoured.
- Server and security logs — 180 days.
Your rights as a Data Principal
- Access — ask for a summary of the personal data we hold about you and how it has been processed.
- Correction — have inaccurate or incomplete data corrected or completed, directly in your account or by writing to us.
- Erasure — ask us to delete your personal data. We will do so except where retention is required by law (see the statutory records above); the operational copy of your order history is scrubbed of identifying detail.
- Withdraw consent — withdraw any consent you have given, as easily as you gave it. Withdrawal does not affect processing already carried out.
- Nomination — nominate a person to exercise these rights on your behalf in the event of your death or incapacity.
- Grievance redressal — raise a complaint with our Grievance Officer before approaching the Data Protection Board of India.
You can exercise most of these from Account → Profile, or by writing to grievance@vastra.co.in. We may ask you to verify your identity before we act, and we will respond within the timelines set out below.
Children's data
The platform is intended for users aged 18 and over. We do not knowingly collect the personal data of a child without verifiable parental consent, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has given us personal data, write to our Grievance Officer and we will delete it.
How we protect your data
- All traffic to and from the site is encrypted in transit (TLS).
- Passwords are stored as argon2id hashes; nobody at Vastra can read your password.
- Access to customer data inside our systems is role-based and limited to staff who need it for their work, with sessions held on short-lived access tokens.
- Card data is never stored on our servers — payments are tokenised by the gateway.
- Backups are encrypted, and access to production data is logged.
If something goes wrong
In the event of a personal data breach we will notify the Data Protection Board of India and every affected Data Principal in the manner and within the timelines required by the DPDP Act, with a description of what happened, its likely consequences and the steps we are taking.
Grievance Officer
Meera Desai, Grievance Officer Vastra Textiles Pvt. Ltd. 214, Millennium Textile Market, Ring Road, Surat, Gujarat 395002, India Email: grievance@vastra.co.in Phone: +91 261 400 1200
We acknowledge every complaint within 48 hours of receipt and work to resolve it within 30 days, in line with the Consumer Protection (E-Commerce) Rules, 2020. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India.
Changes to this policy
We may update this policy as the business or the law changes. The revision date is shown at the top of this page. Where a change materially affects how we use your personal data, we will tell you by email or an in-app notice before it takes effect.
Questions?
We’re happy to clarify any of our policies.
