Vasana Vendor Privacy Policy
Last updated: June 2026
This policy explains how Vasana Retail Private Limited collects, uses, stores, shares, and protects your data when you use the Vasana Vendor Portal and sell on the Vasana marketplace. It also explains your obligations when you receive customer data through the platform.
This policy is part of the Vasana Agreement Suite. It should be read alongside the Vendor Terms & Conditions, which govern your commercial relationship with Vasana.
By accepting this policy, you confirm that you have read and understood how your data and your customers' data is handled on the Vasana platform.
Who We Are
Vasana Retail Private Limited is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act). This means we determine why and how personal data is processed on the Vasana platform.
Registered office: 54/55, Surya Apartments, Fraser Road, Maurya Lok Complex, Jamal Road, Patna – 800 001, Bihar, India.
Contact for data protection matters: info@vasanaindia.com
Key Terms Used in This Policy
Personal data means any data about you or any individual who can be identified by or in relation to that data. This includes your name, email, phone number, and business contact details of identifiable individuals within your organisation.
Business data means data related to your business entity that is not personal data — such as your GSTIN, company registration number, product catalogue information, and aggregate sales figures.
Customer data means personal data of consumers who purchase your products through the Vasana platform. This includes their name, delivery address, phone number, and order details.
Processing means any operation performed on data — collecting, storing, using, sharing, correcting, or deleting it.
Data Fiduciary means the entity that determines the purpose and means of processing personal data. Vasana is the Data Fiduciary.
Data Processor means the entity that processes personal data on behalf of and on the instructions of the Data Fiduciary. For customer order data, you are the Data Processor.
What Data We Collect From You
When you register on the Vasana Vendor Portal and operate as a brand partner, we collect the following categories of data:
Registration and identity data: Legal entity name, entity type, registered address, authorised signatory name and designation, email address, phone number, PAN, GSTIN, bank account details (for settlement), and any other information submitted during the registration process.
Onboarding and verification data: Responses to the Evidence-Gate sustainability questionnaire, self-declarations, uploaded certifications and licences (including BIS, CDSCO, FSSAI, GOTS, FairTrade, and similar), product-specific compliance documents, and manufacturing or sourcing details provided during the onboarding process.
Product and catalogue data: Product descriptions, specifications, images, pricing, inventory levels, SKU information, and category classifications submitted through the Vendor Portal.
Operational data: Order acceptance and rejection records, dispatch confirmations, return and exchange processing records, complaint responses, packaging compliance records, and all transactional activity on the Vendor Portal.
Financial data: Commission calculations, settlement statements, penalty records, payment reconciliation data, invoice records, and tax-related information.
Communication data: Messages, notifications, and correspondence exchanged between you and Vasana through the Vendor Portal, email, or any other agreed communication channel.
Technical data: IP address, device information, browser type, login timestamps, and activity logs generated when you access the Vendor Portal. This data is collected automatically for security and platform integrity.
Why We Collect and Use Your Data
We process your data for the following purposes. Each purpose has a legal basis under the DPDP Act 2023.
To perform our agreement with you: Processing your registration, verifying your identity and business credentials, assigning your sustainability tier, calculating commission and processing settlements, managing orders and returns, and communicating with you about your account. Legal basis: necessary for performance of the agreement you have accepted.
To operate the marketplace: Displaying your products to consumers, processing customer orders, facilitating logistics and delivery, managing customer complaints and returns, and maintaining the integrity of the platform. Legal basis: necessary for performance of the agreement and legitimate business operations.
To verify your sustainability claims: Evaluating your Evidence-Gate questionnaire responses, validating uploaded certifications, conducting periodic audits of your compliance with the onboarding declarations, and assigning or adjusting your tier. Legal basis: necessary for performance of the agreement — your tier assignment depends on this processing.
To comply with legal obligations: Maintaining records required by the Income Tax Act, GST law, Companies Act, Consumer Protection Act 2019, E-Commerce Rules 2020, Legal Metrology Act 2009, BIS Act 2016, and other applicable Indian laws. Legal basis: legal obligation.
To protect the platform and its users:Detecting fraud, preventing misuse of the Vendor Portal, investigating complaints, enforcing the Vendor Terms & Conditions, and maintaining the security of the platform. Legal basis: legitimate interest in platform security and integrity.
To improve our services: Analysing aggregate operational data (not individual personal data) to improve platform features, onboarding processes, and the overall vendor experience. Legal basis: legitimate interest, using anonymised and aggregated data.
To communicate with you: Sending you transactional notifications (order alerts, settlement statements, policy updates), operational guidance, and platform announcements. Legal basis: necessary for performance of the agreement.
We do not use your personal data for any purpose other than those described above. We do not sell your personal data to any third party.
YOUR ROLE AS DATA PROCESSOR — PLEASE READ CAREFULLY
When a customer places an order for your product, Vasana shares limited customer data with you to fulfil that order. This data typically includes the customer's name, delivery address, and phone number.
For this customer data, Vasana is the Data Fiduciary and you are the Data Processor under the DPDP Act 2023. This means:
You must process customer data only for order fulfilment. You may use customer names, addresses, and phone numbers solely to prepare and dispatch the ordered product, and to respond to customer complaints routed through Vasana. You must not use this data for any other purpose.
You must not contact customers directly for marketing, promotions, feedback requests, or any communication not authorised by Vasana. All customer communication is routed through the Vasana platform.
You must not share, sell, or transfer customer data to any third party. This includes your own marketing partners, analytics providers, affiliated entities, or any other person or organisation. The only exception is sharing with your logistics or fulfilment partners strictly as necessary to deliver the ordered product — and only the minimum data required for delivery.
You must keep customer data secure. You must implement reasonable security measures to protect customer data from unauthorised access, disclosure, alteration, or destruction. This includes access controls within your organisation — only personnel who need the data for order fulfilment should have access to it.
You must delete customer data when it is no longer needed for order fulfilment. Once an order is delivered, the return window has closed, and any associated complaints are resolved, you must delete or anonymise the customer's personal data unless you are required to retain it for a specific legal obligation (such as tax or accounting records under the Income Tax Act — see Data Retention below).
You must notify Vasana of any data breach within 24 hours. If you become aware of any unauthorised access to, disclosure of, or loss of customer data in your possession, you must notify Vasana at info@vasanaindia.com within 24 hours of becoming aware of the breach. Your notification must include what data was affected, how many customers may be impacted, what happened, and what steps you have taken to contain the breach.
Failure to comply with these Data Processor obligations constitutes a material breach of your agreement with Vasana.
Who We Share Your Data With
Vasana shares your data only when necessary and only with the following categories of recipients:
Consumers on the platform: Your brand name, product listings, pricing, sustainability tier, and any public-facing content you provide are displayed to consumers on the Vasana marketplace. Your personal contact details are never shared with consumers.
Logistics partners:Your business address (for pickup) and order-related information are shared with Vasana's logistics partners to facilitate product collection and delivery.
Payment processors and banks:Your bank account details and settlement information are shared with Vasana's payment processing partners to facilitate commission deductions and settlement payments.
Legal and regulatory authorities: We may disclose your data to government authorities, courts, or regulators when required by law, legal process, or government request. We will notify you of such disclosure unless we are legally prohibited from doing so.
Professional advisors: We may share your data with our legal, accounting, and auditing advisors, under confidentiality obligations, for the purpose of obtaining professional advice.
Service providers: We use third-party service providers for hosting, cloud storage, communication, and analytics. These providers process your data on our behalf and under our instructions. They are bound by contractual obligations to protect your data and use it only for the services they provide to us.
We do not share your personal data with other brands on the platform. We do not share your business performance data, sales data, or operational metrics with any third party other than as described above.
Vasana Spotlight Analytics
Vasana may offer an analytics service called Vasana Spotlight to brands on the platform. Spotlight provides aggregated, anonymised consumer analytics — category-level trends, engagement patterns, and broad demographic insights.
Spotlight data is not personal data. The anonymisation process is designed to be irreversible. No individual consumer can be identified from Spotlight data. A minimum cohort threshold is enforced — if a data segment contains fewer than the required number of consumers, it is suppressed entirely.
Spotlight is a separate, optional service. Accepting this Privacy Policy does not enrol you in Spotlight. If you choose to purchase Spotlight, a separate Spotlight Data Use Agreement will govern how you may and may not use the analytics data. That agreement includes prohibitions on re-identification of any individual and on downstream sharing of Spotlight data with third parties.
This Privacy Policy does not govern Spotlight. Spotlight terms are standalone and will be presented at the point of purchase.
Data Security
We implement appropriate technical and organisational measures to protect your data, including:
Access controls: Role-based access within Vasana — only authorised personnel access your data, and only for purposes described in this policy.
Encryption: Data is encrypted in transit (TLS/SSL) and at rest. Bank account details and other sensitive financial data receive additional encryption.
Audit trails: Access to your data is logged. The Vendor Portal generates tamper-evident logs of all agreement acceptance events, including OTP authentication records, timestamps, and document version hashes.
Secure infrastructure: The Vasana platform is hosted on infrastructure that meets industry-standard security certifications. We conduct periodic security assessments and vulnerability testing.
Incident response: We maintain a documented data breach response procedure. If a breach occurs that affects your personal data, we will notify you without undue delay and take immediate steps to contain and remediate the breach.
No system is completely secure. While we take reasonable precautions, we cannot guarantee absolute security of your data. You are responsible for maintaining the confidentiality of your Vendor Portal login credentials.
Data Retention
We retain your data only as long as necessary for the purposes described in this policy, or as required by law. The following retention periods apply:
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Active account data | Duration of agreement + 30 days after termination | Contractual — final settlements and outstanding matters |
| Financial and tax records | 8 years from end of relevant financial year | Income Tax Act, 1961; GST law |
| Agreement acceptance records (OTP logs, document hashes, consent records) | 8 years from date of acceptance | IT Act 2000, S.3A — legal proof of agreement |
| Onboarding and verification data | Duration of agreement + 3 years after termination | Audit, dispute resolution, regulatory compliance |
| Operational and transactional data | 8 years from date of transaction | Consistent with financial record-keeping |
| Communication records | 3 years from date of communication (longer if related to a dispute) | Business records; dispute resolution |
| Technical and security logs | 1 year from date of generation (longer if related to a security investigation) | Platform security |
When retention periods expire, we delete or irreversibly anonymise the data. Anonymised data (from which you cannot be identified) may be retained indefinitely for analytical and business improvement purposes.
Your Rights Under the DPDP Act 2023
As a data principal whose personal data is processed by Vasana, you have the following rights:
Right to information (Section 11): You can request a summary of your personal data that Vasana processes, the purposes of processing, and the categories of third parties with whom your data has been shared. Submit your request to info@vasanaindia.com. We will respond within 30 days.
Right to correction and erasure (Section 12): You can request correction of any inaccurate or incomplete personal data, and deletion of personal data that is no longer necessary for the purpose for which it was collected. Note that we cannot delete data that we are legally required to retain (such as financial records for 8 years). To request correction or deletion, contact info@vasanaindia.com with the specific data you want corrected or deleted.
Right to grievance redressal (Section 13):If you are dissatisfied with how we handle your data or respond to your rights requests, you may file a grievance with our Grievance Officer (see below). If you are not satisfied with the Grievance Officer's response, you may file a complaint with the Data Protection Board of India.
Right to nominate (Section 14): You may nominate another person to exercise your data rights on your behalf in the event of your death or incapacity. To register a nomination, contact info@vasanaindia.com.
Right to withdraw consent:Where processing is based on your consent, you may withdraw consent at any time by contacting info@vasanaindia.com. Withdrawal of consent applies prospectively — it does not affect the lawfulness of processing carried out before the withdrawal. Note that withdrawal of consent for processing that is necessary to perform the agreement may result in Vasana's inability to continue providing services to you under the Vendor Terms & Conditions.
We will never deny you services or penalise you for exercising your data rights, except where the data processing is necessary to perform our agreement with you and withdrawal would make performance impossible.
DATA BREACH NOTIFICATION — PLEASE READ CAREFULLY
If Vasana experiences a data breach affecting your personal data, we will:
- Notify you without undue delay, with a description of the breach, the data affected, and the steps we are taking to contain it.
- Notify the Data Protection Board of India within 72 hours of becoming aware of the breach, as required by the DPDP Rules 2025.
If you experience a data breach affecting customer data in your possession, you must:
- Notify Vasana at info@vasanaindia.com within 24 hours of becoming aware of the breach.
- Provide details of what data was affected, how many customers may be impacted, what happened, and what remediation steps you have taken.
- Cooperate fully with Vasana's breach response, including providing information required for Vasana to notify the Data Protection Board and affected consumers.
Failure to report a breach within 24 hours is a material breach of this policy and of the Vendor Terms & Conditions.
Cross-Border Data Transfers
Vasana stores and processes your data in India. We do not transfer your personal data outside India except where necessary for specific services (such as cloud hosting infrastructure) and only to countries or territories permitted under the DPDP Act 2023 and any notifications issued by the Central Government.
Where a cross-border transfer is necessary, we ensure that appropriate safeguards are in place, including contractual obligations on the recipient to protect your data to a standard equivalent to the DPDP Act.
If Vasana expands to international markets in the future, this section will be updated to reflect the specific jurisdictions and applicable transfer mechanisms before any cross-border data sharing begins.
Changes to This Policy
We may update this policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations.
For material changes — changes that affect the categories of data we collect, the purposes for which we process it, or the third parties with whom we share it — we will notify you via the Vendor Portal and your registered email at least 30 days before the changes take effect. You will be asked to review and re-accept the updated policy through the Vendor Portal before the changes apply to you. If you do not accept the updated policy, you may terminate your agreement with Vasana.
For non-material changes— minor corrections, formatting updates, or clarifications that do not change the substance of the policy — we will update the policy on the portal and update the "Last updated" date. No re-acceptance is required.
The current version of this policy is always available at portal.vasanaindia.com/legal/privacy-policy.
Grievance Officer
If you have any questions, concerns, or complaints about this policy or about how your data is handled, contact our Grievance Officer:
Name: Aayush Raj
Designation: Grievance Officer, Vasana Retail Private Limited
Email: info@vasanaindia.com
Phone: +91 82920 80657
Response timeline:
- Your grievance will be acknowledged within 48 hours of receipt.
- We aim to resolve your grievance within 90 days.
If you are not satisfied with the resolution, you may file a complaint with the Data Protection Board of India.
Contact Us
For all data protection enquiries, rights requests, and breach reports:
Email: info@vasanaindia.com
Phone: +91 82920 80657
For breach reports, use the subject line: URGENT — Data Breach Report
Vasana Retail Private Limited
54/55, Surya Apartments, Fraser Road
Maurya Lok Complex, Jamal Road
Patna – 800 001, Bihar, India