Privacy Policy

Last updated: January 1, 2025

Your privacy matters to us. We collect only what we need to process your orders and improve your experience. We never sell your personal data to third parties. This policy explains exactly what we collect and why.

1. Information We Collect

Account Information

When you create an account: name, email address, phone number, and password (stored as a secure hash — we never store plain-text passwords).

Order Information

Delivery addresses, order history, payment method type (card/UPI/COD — not card numbers), and transaction IDs for order fulfilment and customer support.

Guest Checkout

If you order without an account: name, email, phone, and delivery address for order fulfilment and shipping updates. This data is retained for 12 months.

Device & Usage Data

IP address, browser type, pages visited, and time spent on pages — collected via server logs and cookies for analytics and fraud prevention.

Communications

If you contact us via email or WhatsApp, we retain those communications to resolve your query and improve our service.

2. How We Use Your Information

Order Processing

To process, confirm, and deliver your orders, and to send order confirmation and shipping updates.

Account Management

To authenticate you, save your addresses and preferences, and show your order history.

Customer Support

To respond to your queries and resolve disputes or return requests.

Marketing

To send promotional emails and offers — only if you have opted in. You can unsubscribe at any time.

Fraud Prevention

To detect and prevent fraudulent orders, payment fraud, and abuse of our returns policy.

Legal Compliance

To comply with Indian tax laws (GST), consumer protection laws, and court orders when required.

3. How We Share Your Information

Courier Partners

Your name, phone number, and delivery address are shared with our courier partners (Delhivery, BlueDart, Speed Post) solely for delivery purposes.

Payment Processors

Payment details are handled by Razorpay under their own privacy policy. We receive only a transaction ID and status.

SMS & Email Providers

Your email and phone may be shared with transactional communication providers (MSG91, SendGrid) for order notifications.

Legal Requirements

We may disclose your information if required by law, court order, or to protect VilposBags's rights.

We Never Sell Data

We do not sell, rent, or trade your personal information to any third party for their marketing purposes.

4. Data Retention

Account Data

Retained for as long as your account is active plus 3 years after deletion, for legal and tax purposes.

Order Data

Order history and transaction records retained for 7 years as required by Indian GST law.

Guest Data

Guest checkout data retained for 12 months then automatically deleted.

Marketing Preferences

Marketing opt-in/out status retained indefinitely so we respect your preferences.

5. Your Rights

Access

You can view all personal data we hold about you by logging into your account or emailing privacy@vilposbags.com.

Correction

You can update your name, email, phone, and address directly in your account settings.

Deletion

You can request deletion of your account and personal data. Note: order records required for tax purposes (7 years) cannot be deleted.

Portability

You can request an export of your personal data in CSV format.

Opt-out of Marketing

Use the unsubscribe link in any marketing email, or email privacy@vilposbags.com. Transactional emails (order confirmations, shipping updates) cannot be opted out of.

6. Cookies

Essential Cookies

Required for authentication (login sessions) and cart functionality. Cannot be disabled.

Analytics Cookies

We use privacy-friendly analytics (no third-party tracking pixels) to understand how users navigate our site.

Preference Cookies

Remember your language and display preferences.

No Ad Tracking

We do not use Facebook Pixel, Google Ads remarketing, or any cross-site tracking technologies.

7. Security

Encryption

All data is transmitted over HTTPS (TLS 1.3). Passwords are hashed using bcrypt. We do not store payment card details.

Access Controls

Personal data is accessible only to authorised VilposBags employees on a need-to-know basis.

Breach Notification

In the unlikely event of a data breach affecting your personal information, we will notify you within 72 hours via email.

8. Children's Privacy

Age Restriction

Our services are not directed at individuals under 18 years of age. We do not knowingly collect personal information from minors. If you believe a minor has provided us data, please contact us immediately.

9. Changes to This Policy

Notification of Changes

We will notify you of material changes to this policy via email (if you have an account) and by posting a notice on our website. The "Last Updated" date at the top reflects the most recent revision.

10. Contact Our Privacy Team

Data Protection Officer

For privacy-related queries, data access requests, or complaints: Email: privacy@vilposbags.com Post: Privacy Officer, VilposBags (AgriFresh Pvt. Ltd.), 123 Farm Road, Salt Lake, Kolkata 700091 We aim to respond to all privacy requests within 30 days.

Questions about your privacy?