Your privacy matters to us. Clothes Bazzar is committed to protecting your personal information and being transparent about what data we collect, how we use it, and your rights over it. This policy is written in plain language so every user, whether buyer or seller, can understand it.
This Privacy Policy ("Policy") explains how Clothes Bazzar ("Company", "we", "us", "our") collects, uses, shares, and protects personal information when you use the Clothes Bazzar platform, including the website (clothesbazzar.in), mobile application, seller panel, and all related services. This Policy applies to all Users: registered Buyers, registered Sellers, and unregistered visitors.
What Information We Collect
1.1 Information You Provide Directly
| Data Category | Specific Data Points | Who Provides |
|---|---|---|
| Identity Information | Full name, date of birth, gender | Buyers & Sellers |
| Contact Information | Email address, mobile number, WhatsApp number | Buyers & Sellers |
| Address Information | Delivery address, billing address, pincode, city, state | Buyers (orders) |
| Business Information | Business name, GSTIN, PAN number, registered address | Sellers only |
| Financial Information | Bank account number, IFSC code, UPI ID (for payouts) | Sellers only |
| Identity Verification | Govt. photo ID: Aadhaar, PAN, Passport, or Voter ID | Sellers (KYC) |
| Product Information | Listings, descriptions, images, pricing, inventory | Sellers only |
| Payment Information | Last 4 digits of card, UPI ID, payment preference | Buyers (transactions) |
| Communication Data | Support tickets, chat messages, dispute records | All Users |
| Account Credentials | Username, hashed password (never stored in plain text) | All registered Users |
1.2 Information We Collect Automatically
When you visit or use the Platform, we automatically collect certain technical and behavioral data:
- Device Information: device type, operating system, browser type and version, screen resolution.
- Log Data: IP address, access timestamps, pages visited, time spent on each page, referral URL.
- Location Data: approximate location from IP address; precise GPS location only with your explicit permission.
- Usage Data: products viewed, searches made, filters applied, items added to cart, purchase history.
- Session Data: session tokens, login/logout timestamps, authentication status.
- Crash & Performance Data: error reports, app crash logs, API response times (used to improve the Platform).
1.3 Information from Third Parties
- Payment Gateways: transaction status, payment method type, partial payment details from partners like Razorpay or PayU.
- Logistics Partners: delivery status updates, tracking information, delivery confirmation from courier partners.
- Social Login (if applicable): if you register via Google or Facebook, we receive your name, email, and profile picture.
- Government Databases: GSTIN verification from the GST Network for Seller KYC.
How We Collect Your Information
We collect information through the following channels:
- Registration & Account Creation: when you sign up as a Buyer or Seller on the Platform.
- Order Placement: when a Buyer places an order, we collect delivery and payment information.
- Seller Onboarding: when a Seller submits KYC documents, business details, and bank information.
- Platform Interaction: browsing, searching, clicking, adding to cart, reviewing products.
- Cookies & Tracking: as detailed in Section 7 of this Policy.
- Customer Support: when you contact our team via email, chat, or phone.
- Surveys & Feedback: when you participate in optional surveys or rating requests.
- Third-Party Integrations: as described in Section 1.3.
How We Use Your Information
We use your information only for legitimate, specified purposes as described below:
Platform Operations
- Creating and managing your account.
- Processing orders, payments, and returns.
- Facilitating communication between Buyers and Sellers.
- Providing customer support and resolving disputes.
Seller Management
- Verifying Seller identity and business credentials (KYC).
- Calculating and disbursing Seller payouts and commissions.
- Generating GST-compliant invoices and TCS certificates.
- Sending settlement statements and financial reports.
Personalization & Discovery
- Personalizing product recommendations based on browse and purchase history.
- Showing relevant search results based on location and preferences.
- Sending personalized promotions and offers (with opt-out available).
Security & Fraud Prevention
- Detecting, investigating, and preventing fraudulent transactions and return fraud.
- Verifying user identity during suspicious login attempts.
- Monitoring for prohibited activities as described in our Terms and Conditions.
Legal & Regulatory Compliance
- Complying with GST laws, TCS obligations, and other applicable Indian regulations.
- Responding to lawful requests from government authorities, courts, or law enforcement.
- Maintaining records as required under the Information Technology Act, 2000.
Platform Improvement
- Analyzing usage patterns to improve features and performance.
- Conducting A/B testing and product research.
- Generating anonymized, aggregated analytics reports (no individual identification).
We do NOT sell your personal data to advertisers or third-party data brokers. We do NOT use your data for profiling or automated decision-making that has significant legal effects on you without human review.
Legal Basis for Processing (Indian Law Compliance)
Clothes Bazzar processes your personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDPA) and the IT (SPDI) Rules, 2011. Our legal bases for processing are:
| Legal Basis | When We Rely on This |
|---|---|
| Consent | When you provide voluntary consent (e.g., marketing emails, allowing location access). You may withdraw consent at any time. |
| Contractual Necessity | When processing is necessary to perform our contract with you (e.g., processing your order, disbursing seller payments). |
| Legal Obligation | When we are legally required to process data (e.g., GST compliance, TCS deduction, court orders). |
| Legitimate Interest | When processing serves our legitimate business interests (e.g., fraud prevention, platform security, analytics) without overriding your rights. |
| Vital Interests | In exceptional circumstances to protect the life or safety of a person. |
How We Share Your Information
We do not sell, rent, or trade your personal information. We share your data only in the following limited and controlled circumstances:
Data Retention
We retain your personal data for as long as necessary to fulfill the purposes described in this Policy and comply with legal obligations.
| Data Type | Retention Period | Reason |
|---|---|---|
| Account Information | Account duration + 3 years post-closure | Legal obligation & dispute resolution |
| Order & Transaction Records | 7 years from transaction date | GST & tax compliance |
| Seller KYC Documents | Registration duration + 5 years | Regulatory compliance |
| Payment Records | 7 years from transaction | GST / Income Tax Act |
| Return & Dispute Records | 5 years from closure | Legal evidence preservation |
| Communication & Support Logs | 3 years from interaction | Dispute resolution |
| Cookie / Tracking Data | Maximum 12 months | Analytics & personalization |
| Inactive Account Data | 2 years after last login, then deleted/anonymized | Storage optimization |
Cookies & Tracking Technologies
The Platform uses cookies and similar tracking technologies to enhance your experience. Here is what we use and why:
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential | Required for Platform to function, including login sessions, cart management, and security tokens. | Session |
| Performance | Collect anonymous data on how pages are used, including load time, errors, and click paths. | 12 months |
| Functional | Remember your preferences, such as saved addresses, language, and filter settings. | 12 months |
| Analytics | Used by Google Analytics to understand user behavior and improve Platform. | 24 months |
| Marketing | Used (with consent) to show relevant ads on platforms like Facebook and Google. | 12 months |
You may control cookie preferences through your browser settings or our Cookie Preference Center. Disabling essential cookies may affect Platform functionality. Marketing cookies require your explicit consent and can be withdrawn at any time.
Data Security
We implement comprehensive technical and organizational measures to protect your personal data from unauthorized access, loss, theft, alteration, or disclosure:
- SSL/TLS Encryption: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher.
- Data Encryption at Rest: Sensitive data (including seller KYC documents and financial information) is encrypted using AES-256.
- Access Controls: User data is accessible only to authorized personnel on a strict need-to-know basis with role-based access controls.
- Password Security: Passwords are never stored in plain text. We use industry-standard one-way hashing (bcrypt) for all password storage.
- Payment Security: We do not store full payment card numbers. All payment processing is handled by PCI-DSS Level 1 certified gateways.
- Regular Security Audits: Our Platform undergoes periodic security assessments and penetration testing by independent professionals.
- Two-Factor Authentication (2FA): Available and recommended for all accounts; mandatory for Sellers.
- Incident Response Plan: In the event of a breach affecting your data, we will notify you within 72 hours as required by applicable law.
No method of data transmission over the internet is 100% secure. While we implement best-in-class security measures, we cannot guarantee absolute security. You are also responsible for maintaining the confidentiality of your account credentials.
Your Rights as a Data Subject
Under the Digital Personal Data Protection Act, 2023 (DPDPA) and other applicable Indian data protection laws, you have the following rights:
To exercise any of these rights, submit a written request to privacy@clothesbazzar.in with the subject line "Data Rights Request - [Your Registered Email]". We will respond within 30 days after verifying your identity.
Children's Privacy
The Platform is not directed at individuals under 18 years of age. We do not knowingly collect personal information from children below the age of 18. If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us immediately at privacy@clothesbazzar.in. We will take prompt action to delete such information from our records.
Third-Party Links & Services
The Platform may contain links to third-party websites, applications, or services, such as social media platforms, payment gateways, logistics tracking pages, or partner service providers. These third-party services have their own independent privacy policies. We have no responsibility or liability for their practices. We encourage you to review the privacy policy of any third-party service before sharing your personal information with them.
Cross-Border Data Transfers
Clothes Bazzar is an India-focused platform. Your personal data is primarily stored and processed on servers located within India. In cases where data is processed by third-party service providers located outside India (e.g., cloud service providers, analytics platforms), we ensure appropriate safeguards are in place, including data processing agreements and compliance with applicable Indian data protection laws.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices or legal obligations. When we make significant changes, we will notify you via registered email and/or a prominent notice on the Platform at least 15 days before the changes take effect. The "Effective Date" at the top of this Policy always reflects the most recent revision. Your continued use of the Platform after the effective date constitutes acceptance of the updated Policy.
Grievance Officer & Contact Information
In accordance with the Information Technology Act, 2000, the IT Rules, 2021, and the DPDPA, 2023, we have designated a Grievance Officer for data protection matters:
If you are not satisfied with our response to your privacy concern, you may approach the Data Protection Board of India (once constituted under the DPDPA, 2023) or any other competent authority as provided under applicable Indian law.
By using Clothes Bazzar, you acknowledge that you have read and understood this Privacy Policy.
© 2026 Clothes Bazzar. All rights reserved. | Last Updated: January 1, 2026 | Version 1.0