Clothes Bazzar Logo
Privacy Policy

Your Privacy is Our Commitment

We believe privacy should be simple, clear, and respected. This policy explains exactly what data we collect, how we use it, and your rights over it.

DPDPA 2023 CompliantIT Act AlignedNo Data SellingPlain Language

Effective Date: 1st January 2026  |  Version 1.0  |  clothesbazzar.in/privacy-policy

What Information We Collect
Contents
ℹ️

Your privacy matters to us. Clothes Bazzar is committed to protecting your personal information and being transparent about what data we collect, how we use it, and your rights over it. This policy is written in plain language so every user, whether buyer or seller, can understand it.

This Privacy Policy ("Policy") explains how Clothes Bazzar ("Company", "we", "us", "our") collects, uses, shares, and protects personal information when you use the Clothes Bazzar platform, including the website (clothesbazzar.in), mobile application, seller panel, and all related services. This Policy applies to all Users: registered Buyers, registered Sellers, and unregistered visitors.

SECTION 01

What Information We Collect

1.1 Information You Provide Directly

Data CategorySpecific Data PointsWho Provides
Identity InformationFull name, date of birth, genderBuyers & Sellers
Contact InformationEmail address, mobile number, WhatsApp numberBuyers & Sellers
Address InformationDelivery address, billing address, pincode, city, stateBuyers (orders)
Business InformationBusiness name, GSTIN, PAN number, registered addressSellers only
Financial InformationBank account number, IFSC code, UPI ID (for payouts)Sellers only
Identity VerificationGovt. photo ID: Aadhaar, PAN, Passport, or Voter IDSellers (KYC)
Product InformationListings, descriptions, images, pricing, inventorySellers only
Payment InformationLast 4 digits of card, UPI ID, payment preferenceBuyers (transactions)
Communication DataSupport tickets, chat messages, dispute recordsAll Users
Account CredentialsUsername, hashed password (never stored in plain text)All registered Users

1.2 Information We Collect Automatically

When you visit or use the Platform, we automatically collect certain technical and behavioral data:

  • Device Information: device type, operating system, browser type and version, screen resolution.
  • Log Data: IP address, access timestamps, pages visited, time spent on each page, referral URL.
  • Location Data: approximate location from IP address; precise GPS location only with your explicit permission.
  • Usage Data: products viewed, searches made, filters applied, items added to cart, purchase history.
  • Session Data: session tokens, login/logout timestamps, authentication status.
  • Crash & Performance Data: error reports, app crash logs, API response times (used to improve the Platform).

1.3 Information from Third Parties

  • Payment Gateways: transaction status, payment method type, partial payment details from partners like Razorpay or PayU.
  • Logistics Partners: delivery status updates, tracking information, delivery confirmation from courier partners.
  • Social Login (if applicable): if you register via Google or Facebook, we receive your name, email, and profile picture.
  • Government Databases: GSTIN verification from the GST Network for Seller KYC.
SECTION 02

How We Collect Your Information

We collect information through the following channels:

  • Registration & Account Creation: when you sign up as a Buyer or Seller on the Platform.
  • Order Placement: when a Buyer places an order, we collect delivery and payment information.
  • Seller Onboarding: when a Seller submits KYC documents, business details, and bank information.
  • Platform Interaction: browsing, searching, clicking, adding to cart, reviewing products.
  • Cookies & Tracking: as detailed in Section 7 of this Policy.
  • Customer Support: when you contact our team via email, chat, or phone.
  • Surveys & Feedback: when you participate in optional surveys or rating requests.
  • Third-Party Integrations: as described in Section 1.3.
SECTION 03

How We Use Your Information

We use your information only for legitimate, specified purposes as described below:

Platform Operations

  • Creating and managing your account.
  • Processing orders, payments, and returns.
  • Facilitating communication between Buyers and Sellers.
  • Providing customer support and resolving disputes.

Seller Management

  • Verifying Seller identity and business credentials (KYC).
  • Calculating and disbursing Seller payouts and commissions.
  • Generating GST-compliant invoices and TCS certificates.
  • Sending settlement statements and financial reports.

Personalization & Discovery

  • Personalizing product recommendations based on browse and purchase history.
  • Showing relevant search results based on location and preferences.
  • Sending personalized promotions and offers (with opt-out available).

Security & Fraud Prevention

  • Detecting, investigating, and preventing fraudulent transactions and return fraud.
  • Verifying user identity during suspicious login attempts.
  • Monitoring for prohibited activities as described in our Terms and Conditions.

Legal & Regulatory Compliance

  • Complying with GST laws, TCS obligations, and other applicable Indian regulations.
  • Responding to lawful requests from government authorities, courts, or law enforcement.
  • Maintaining records as required under the Information Technology Act, 2000.

Platform Improvement

  • Analyzing usage patterns to improve features and performance.
  • Conducting A/B testing and product research.
  • Generating anonymized, aggregated analytics reports (no individual identification).
📌

We do NOT sell your personal data to advertisers or third-party data brokers. We do NOT use your data for profiling or automated decision-making that has significant legal effects on you without human review.

SECTION 04

Legal Basis for Processing (Indian Law Compliance)

Clothes Bazzar processes your personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDPA) and the IT (SPDI) Rules, 2011. Our legal bases for processing are:

Legal BasisWhen We Rely on This
ConsentWhen you provide voluntary consent (e.g., marketing emails, allowing location access). You may withdraw consent at any time.
Contractual NecessityWhen processing is necessary to perform our contract with you (e.g., processing your order, disbursing seller payments).
Legal ObligationWhen we are legally required to process data (e.g., GST compliance, TCS deduction, court orders).
Legitimate InterestWhen processing serves our legitimate business interests (e.g., fraud prevention, platform security, analytics) without overriding your rights.
Vital InterestsIn exceptional circumstances to protect the life or safety of a person.
SECTION 05

How We Share Your Information

We do not sell, rent, or trade your personal information. We share your data only in the following limited and controlled circumstances:

Sellers (for Buyers)
When you place an Order, your delivery name, address, and phone number are shared with the Seller to enable fulfillment. Your payment details and email are NOT shared with Sellers.
Buyers (for Sellers)
Sellers see order details including product ordered, quantity, and delivery pincode for fulfillment purposes only.
Logistics Partners
Your name, delivery address, and phone number are shared with courier partners to enable delivery and tracking.
Payment Gateways
Your payment information is processed by PCI-DSS certified gateway partners. We do not store full payment card data.
GST Authorities
Transaction data and TCS details are shared with relevant GST authorities as required by Indian law.
Law Enforcement & Courts
We may disclose personal data in response to lawful requests, such as court orders, subpoenas, or regulatory investigations under Indian law.
Fraud Prevention Partners
Anonymized or flagged transaction data may be shared with fraud detection services to protect the Platform.
Business Transfers
In the event of a merger or acquisition, User data may be transferred to the acquiring entity under the same privacy protections.
With Your Consent
We may share your information with third parties where you have given us explicit prior consent.
SECTION 06

Data Retention

We retain your personal data for as long as necessary to fulfill the purposes described in this Policy and comply with legal obligations.

Data TypeRetention PeriodReason
Account InformationAccount duration + 3 years post-closureLegal obligation & dispute resolution
Order & Transaction Records7 years from transaction dateGST & tax compliance
Seller KYC DocumentsRegistration duration + 5 yearsRegulatory compliance
Payment Records7 years from transactionGST / Income Tax Act
Return & Dispute Records5 years from closureLegal evidence preservation
Communication & Support Logs3 years from interactionDispute resolution
Cookie / Tracking DataMaximum 12 monthsAnalytics & personalization
Inactive Account Data2 years after last login, then deleted/anonymizedStorage optimization
SECTION 07

Cookies & Tracking Technologies

The Platform uses cookies and similar tracking technologies to enhance your experience. Here is what we use and why:

Cookie TypePurposeDuration
EssentialRequired for Platform to function, including login sessions, cart management, and security tokens.Session
PerformanceCollect anonymous data on how pages are used, including load time, errors, and click paths.12 months
FunctionalRemember your preferences, such as saved addresses, language, and filter settings.12 months
AnalyticsUsed by Google Analytics to understand user behavior and improve Platform.24 months
MarketingUsed (with consent) to show relevant ads on platforms like Facebook and Google.12 months

You may control cookie preferences through your browser settings or our Cookie Preference Center. Disabling essential cookies may affect Platform functionality. Marketing cookies require your explicit consent and can be withdrawn at any time.

SECTION 08

Data Security

We implement comprehensive technical and organizational measures to protect your personal data from unauthorized access, loss, theft, alteration, or disclosure:

  • SSL/TLS Encryption: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher.
  • Data Encryption at Rest: Sensitive data (including seller KYC documents and financial information) is encrypted using AES-256.
  • Access Controls: User data is accessible only to authorized personnel on a strict need-to-know basis with role-based access controls.
  • Password Security: Passwords are never stored in plain text. We use industry-standard one-way hashing (bcrypt) for all password storage.
  • Payment Security: We do not store full payment card numbers. All payment processing is handled by PCI-DSS Level 1 certified gateways.
  • Regular Security Audits: Our Platform undergoes periodic security assessments and penetration testing by independent professionals.
  • Two-Factor Authentication (2FA): Available and recommended for all accounts; mandatory for Sellers.
  • Incident Response Plan: In the event of a breach affecting your data, we will notify you within 72 hours as required by applicable law.
⚠️

No method of data transmission over the internet is 100% secure. While we implement best-in-class security measures, we cannot guarantee absolute security. You are also responsible for maintaining the confidentiality of your account credentials.

SECTION 09

Your Rights as a Data Subject

Under the Digital Personal Data Protection Act, 2023 (DPDPA) and other applicable Indian data protection laws, you have the following rights:

Right to Access
You have the right to request a copy of the personal data we hold about you. We will provide this within 30 days of a verified request.
Right to Correction
You may request correction of any inaccurate or outdated personal information. You can update most information directly from your account settings.
Right to Erasure
You may request deletion of your personal data where it is no longer necessary, subject to legal retention obligations (e.g., GST records must be retained for 7 years).
Right to Withdraw Consent
Where processing is based on consent (e.g., marketing emails), you may withdraw at any time without affecting the lawfulness of prior processing.
Right to Data Portability
You may request your personal data in a machine-readable format to transfer to another service, where technically feasible.
Right to Object
You may object to processing for direct marketing purposes. We will cease such processing immediately upon receipt of your objection.
Right to Grievance Redressal
You have the right to raise a grievance about our data processing practices with our Grievance Officer (see Section 14).
Right to Nominate
As per DPDPA 2023, you may nominate an individual to exercise your data rights on your behalf in the event of your death or incapacity.

To exercise any of these rights, submit a written request to privacy@clothesbazzar.in with the subject line "Data Rights Request - [Your Registered Email]". We will respond within 30 days after verifying your identity.

SECTION 10

Children's Privacy

The Platform is not directed at individuals under 18 years of age. We do not knowingly collect personal information from children below the age of 18. If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us immediately at privacy@clothesbazzar.in. We will take prompt action to delete such information from our records.

SECTION 11

Third-Party Links & Services

The Platform may contain links to third-party websites, applications, or services, such as social media platforms, payment gateways, logistics tracking pages, or partner service providers. These third-party services have their own independent privacy policies. We have no responsibility or liability for their practices. We encourage you to review the privacy policy of any third-party service before sharing your personal information with them.

SECTION 12

Cross-Border Data Transfers

Clothes Bazzar is an India-focused platform. Your personal data is primarily stored and processed on servers located within India. In cases where data is processed by third-party service providers located outside India (e.g., cloud service providers, analytics platforms), we ensure appropriate safeguards are in place, including data processing agreements and compliance with applicable Indian data protection laws.

SECTION 13

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices or legal obligations. When we make significant changes, we will notify you via registered email and/or a prominent notice on the Platform at least 15 days before the changes take effect. The "Effective Date" at the top of this Policy always reflects the most recent revision. Your continued use of the Platform after the effective date constitutes acceptance of the updated Policy.

SECTION 14

Grievance Officer & Contact Information

In accordance with the Information Technology Act, 2000, the IT Rules, 2021, and the DPDPA, 2023, we have designated a Grievance Officer for data protection matters:

Role
Grievance Officer / Data Protection Contact
Platform
Clothes Bazzar
Privacy Email
privacy@clothesbazzar.in
Grievance Email
grievance@clothesbazzar.in
Address
Clothes Bazzar, Surat, Gujarat, India
Response Time
Acknowledgement within 48 hours. Resolution within 30 days.
Working Hours
Monday to Saturday, 10:00 AM - 6:00 PM IST
📮

If you are not satisfied with our response to your privacy concern, you may approach the Data Protection Board of India (once constituted under the DPDPA, 2023) or any other competent authority as provided under applicable Indian law.

By using Clothes Bazzar, you acknowledge that you have read and understood this Privacy Policy.

© 2026 Clothes Bazzar. All rights reserved.  |  Last Updated: January 1, 2026  |  Version 1.0