VastraHQ is operated by VastraHQ Labs Private Limited, a company incorporated under the Companies Act, 2013, with registered office at H.NO. 19 AMALTAS COLON, PHASE -1 KOLAR ROAD, MP Bhoj Open University, Huzur, Bhopal- 462016, Madhya Pradesh, India (CIN: U62099MP2026PTC085704). This Privacy Policy explains what personal data we collect, how we use it, where it goes, how long we keep it, and how you can contact us.
Contact / grievance email: support@vastrahq.com
1. Summary
This summary is for convenience. Sections 2 onwards are the full notice and govern.
- What we collect: your account details, the business profile you enter, the garment photographs you upload, the outputs we generate for you, your purchase records, technical and usage data, an approximate city estimated from your IP address when you sign up, the campaign parameters of any advertising link you arrive through, and, while our advertising measurement is switched on, an advertising click identifier.
- Why: to run the service, generate your images and videos, manage your organisation, credits and support, keep the service safe, measure our advertising, and meet legal obligations.
- Who else sees it: the providers that run VastraHQ for us, named in Section 7; our payment provider; Meta, if you contact us on WhatsApp; and, while our advertising measurement is switched on, Meta again in the limited form described in Section 6.
- Where it goes: the records we hold ourselves, and your files, are stored in India; our sign-in, hosting-edge and payment providers hold some account data outside India. AI processing runs on Google Cloud, and some models — including the one that generates your videos — are served from Google's global endpoints.
- How long: while your account is active. Operational logs, 180 days. Payment records, eight financial years.
- Your choices: ask for access, correction, deletion, or withdrawal of consent by emailing support@vastrahq.com, and complain to the Data Protection Board of India if we do not resolve it.
- What we do not do: we do not sell your personal data, and we do not use your content to train generative AI models (Section 4). We do not send you marketing email. Where your organisation has never made a paid purchase, Section 16 of our Terms of Service lets us show the outputs you generate in our own marketing; Section 3 below explains that and how to opt out.
2. The Data We Collect
We collect:
- Account data: your name, your email address, your phone number where your sign-in provider supplies it, sign-in identifiers, and session information.
- Business profile: the details you enter in the app about your business — business name, contact name, WhatsApp number, Instagram handle, the categories you sell, and any onboarding notes. This belongs to your organisation and is stored by us in our own database. We use the WhatsApp number and Instagram handle to contact you about your account and your support requests.
- Uploaded content: the garment photographs you upload, their original filenames, and their technical properties.
- Attributes derived from your photographs: we analyse each uploaded photograph automatically to derive attributes of the garment — for example its category, fabric, construction, embellishment, and the audience it is intended for — and we store those attributes and use them to route generation.
- Generated content: the AI-generated images, catalogues, videos, captions, and other outputs created for you, together with the choices that produced them, such as theme, poses, and template.
- Usage data: projects created, generations requested, credit usage, feature usage, and app activity.
- Support correspondence: what you send us when you contact us, including by email, by phone, and over WhatsApp. WhatsApp is operated by Meta, so anything you send us there is also processed by Meta under its own terms; if you would rather not use it, email us instead.
- Technical data: device information, browser information, cookies, session data, and request logs. Our hosting and cloud providers generate standard server logs that include IP addresses. Our own application records do not store your IP address or your browser user-agent string, with one exception: when an automated system calls our webhooks often enough to be rate-limited, we log that caller's source IP address.
- Approximate location: the city, region, and country estimated from your IP address when you create an account. The estimate is made by our hosting provider at the network edge, and only the city, region, and country reach us — the IP address itself is not stored in our own records. This is approximate and is not precise or device location; we do not collect GPS or device location data.
- Advertising attribution data: if you reach VastraHQ through a link that carries campaign parameters, we record those parameters (for example which campaign and which city the advertisement was shown in) and store them against your organisation when you save your profile. This happens whether or not the advertising and measurement technologies described in Section 5 are switched on. Where present, we also record an advertising click identifier while advertising measurement is switched on.
- Referring website: if you arrive at VastraHQ by following a link from another website, the website address (domain name only) that the link came from — for example a search engine or a social media site. We store only the site name, never the specific page, search terms, or web address you came from.
- Billing data: your purchase records — the pack purchased, credits, amount, currency, status, and our payment provider's order and payment identifiers. Card and other payment-instrument details are entered on the payment provider's own checkout page and never reach VastraHQ. We do pass your name, email address, and phone number to the payment provider so that it can process the payment and send you its receipt. We do not collect a Goods and Services Tax identification number.
2A. What We Collect, Why, And On What Basis
The same information, mapped. Where we rely on consent you can withdraw it at any time (Section 12); where we rely on a purpose you gave the data for voluntarily, or on a legal obligation, withdrawing consent does not apply but the other rights in Section 12 do.
- Account data — to create and secure your account and sign you in; provided by you voluntarily for that purpose; shared with our sign-in provider; kept while your account is active.
- Business profile — to run your organisation, brief generations, and contact you about your account; provided by you voluntarily for that purpose; not shared outside our own systems; kept while your account is active.
- Uploaded photographs and derived garment attributes — to generate the outputs you ask for; provided by you voluntarily for that purpose; shared with our AI-infrastructure provider; kept while your account is active.
- Generated outputs — to deliver and store your results; the same basis; the same recipients; kept while your account is active.
- Usage and technical data — to operate, secure, debug, and rate-limit the service, and to meet our log-retention obligations; legal obligation and the operation of the service you asked for; kept 180 days.
- Support correspondence — to answer you; provided by you voluntarily for that purpose; processed by the channel operator you chose (email, phone, or WhatsApp); kept while your account is active.
- Approximate location and advertising attribution data — to understand which campaign or city an account came from; the campaign parameters arrive in the link you clicked and the approximate city is derived when you sign up, so we hold them on the basis that you provided them for that purpose; where a jurisdiction requires your consent before we switch on the advertising and measurement technologies in Section 5, we ask for it first and rely on that consent; shared with Meta only as Section 6 describes; kept as Section 9 describes.
- Referring website — to tell advertising traffic apart from search, social, and direct visits; your browser supplies the referring site as a standard part of following a link, and we keep only the domain name; we do not use it to build a profile of your browsing; not shared with anyone; kept as Section 9 describes.
- Billing data — to take payment, issue receipts, handle refunds, and meet tax and accounting obligations; performance of your purchase and legal obligation; shared with our payment provider; kept eight financial years.
3. How We Use Your Data
We use data to:
- provide and operate VastraHQ;
- generate images, catalogues, videos, and other outputs;
- manage accounts, organisations, projects, credits, purchases, and support;
- maintain and improve the reliability, quality, safety, and operation of the service (this does not include training generative AI models on your content — see Section 4);
- measure how well our advertising works — for example, which advertising campaign or city an account signup or purchase came from — and share limited conversion signals with our advertising partner (see Section 6);
- understand which websites people find VastraHQ through, so we can tell advertising traffic apart from search, social, and direct visits. We use only the site name for this, and we do not use it to build a profile of your browsing;
- show generated outputs in VastraHQ's own marketing, demonstrations, case studies, and promotional materials, but only on the terms in Section 16 of our Terms of Service: that licence applies only where your organisation has never completed a paid purchase, it ends for outputs generated after your first paid purchase, and you can opt out at any time by emailing support@vastrahq.com;
- detect abuse, security issues, or policy violations;
- comply with legal obligations.
We use your email address only for messages about your account, your purchases, your generations, and your support requests. We do not use it to send you marketing, and we would ask for your separate consent before doing so.
4. AI Processing Of Your Photographs
To generate outputs, uploaded images and related inputs are processed by reputable third-party cloud AI-infrastructure providers acting on our behalf.
We do not sell your uploaded images.
AI training. We do not use your uploaded content, or the outputs generated from it, to train, fine-tune, or improve any generative AI model — ours or a third party's — and our agreements with our AI-infrastructure providers do not permit them to use your content to train their models. We may use your content to operate, evaluate, and improve the non-generative classification and safety systems that route and screen generations, and to investigate abuse. If we ever want to use your content to train a generative model, we will ask you first and will not do it without your separate, express consent. Section 5 of our Terms of Service says the same thing in the same words.
Generated still images carry an embedded, standard, machine-readable marker identifying them as created by a trained AI model. That marker is ordinary file metadata: it is not visible to a viewer, it is not tamper-proof, and it can be removed by common image tools. Video outputs do not carry the marker today and we are extending the marking to them. Section 7 of our Terms of Service sets out what this does and does not do.
5. Cookies And Similar Technologies
We use:
- Strictly necessary cookies — required for sign-in, sessions, security, and basic service operation. These are always set.
- Advertising and measurement cookies and similar technologies — used to understand which advertisement or campaign brought you to VastraHQ. These operate only while our advertising measurement is switched on. They include a first-party cookie we set ourselves, which records the campaign information from the link you first arrived through and is kept for up to 90 days, and cookies set by Meta's advertising pixel while it is active on our site.
As at the date at the top of this policy, our advertising and measurement technologies are OFF. We update this line in the same change that switches them on or off, so this policy always states which is true.
You can clear or block cookies through your browser settings. Blocking advertising and measurement cookies does not affect your ability to use VastraHQ; blocking strictly necessary cookies will prevent sign-in from working.
Where the law applicable to you requires your consent before non-essential cookies are set, we will not set them without that consent. We will not switch on advertising and measurement technologies for visitors in a jurisdiction that requires prior consent until we have a mechanism in place to obtain it.
6. Sharing And Disclosure
We do not sell your personal data.
We may disclose data only:
- to operate the service through our providers;
- to our advertising partner, in the limited form described below;
- to Meta, where you choose to contact us on WhatsApp, because WhatsApp is operated by Meta;
- by publishing generated outputs in VastraHQ's own marketing, on the terms in Section 3 above and Section 16 of our Terms of Service;
- if required by law, legal process, or government request;
- to protect the rights, safety, or security of VastraHQ, users, or others;
- in connection with a business transfer, merger, acquisition, or restructuring.
Advertising measurement. While our advertising measurement is switched on, we advertise VastraHQ on Meta (Facebook and Instagram) and, to understand which advertisements bring people to VastraHQ, we share limited event information with Meta: that a page or a piece of content was viewed, that an account was created, or that a credit purchase was completed, together with the purchase amount and currency. Where an email address is used for this purpose it is hashed before it leaves our systems. Hashing is a protective measure, not anonymisation — the hash still relates to you, and Meta matches it against its own records; Meta never receives your email address in readable form. We also share a pseudonymous identifier derived from your organisation's internal id.
Because part of that measurement runs as a pixel inside your browser, Meta also receives, for the pages the pixel is active on, the address of the page, your IP address, and your browser user-agent. That is how a browser pixel works and we cannot switch it off selectively; it is also why our internal administration pages are excluded from the pixel entirely. We do not share your uploaded garment photographs, your generated images, your name, or your phone number with Meta. Meta uses this information for advertising measurement under its own privacy policy, and not solely on our behalf, which is why we list it here rather than in Section 7.
7. Service Providers
We share data with the providers that run VastraHQ for us. They act on our behalf and may use your data only to provide their service to us:
- Clerk — authentication, sign-in, and session management.
- Google Cloud Platform — application hosting, database, file storage, logging, and scheduling, in Mumbai, India (asia-south1).
- Google Cloud Vertex AI — the AI models that generate your images and videos and that classify and check your uploads.
- Vercel — web hosting and network edge, which also performs the approximate-location lookup described in Section 2.
- Razorpay — payment processing.
Meta appears in this policy in two other places, and in neither does it act solely on our behalf: it operates WhatsApp, so a support conversation you start there is processed by Meta under its own terms; and, while our advertising measurement is switched on, it is our advertising-measurement partner as described in Section 6.
We keep this list current. When we add or change a provider, we update this section and the date at the top of this policy. Where you are a business customer using VastraHQ to process someone else's personal data, Section 20B of our Terms of Service gives you 14 days' notice in the app before we add a sub-processor.
8. Where Your Data Is Processed
The records we hold in our own systems — your business profile, purchase records, uploaded photographs, generated files, and the account records we keep alongside them — are stored in India (Mumbai, asia-south1).
Your sign-in provider is the system of record for your account identifiers (name, email address, phone number, sign-in identifiers, and session information) and holds a copy of them on its own infrastructure, which may be outside India. Our hosting-edge and payment providers may likewise process limited data outside India.
AI processing is performed by Google Cloud Vertex AI on our behalf. Some of those models are served from Google's global endpoint rather than from a single region, which means processing may occur in any Google region. Video generation runs on that global endpoint. If our primary video model is unavailable, a fallback model runs in the United States.
Indian data-protection law currently permits personal data to be transferred outside India except to a country that the Central Government restricts by notification, and no such country has been notified. If that changes, we will update this section and, where required, obtain your consent.
9. How Long We Keep Data
We keep data for as long as we need it to provide the service, resolve disputes, prevent abuse, and meet legal obligations. In practice:
- Account, organisation, and business-profile records — while your account is active, and afterwards only for as long as the law requires.
- Uploaded photographs and generated outputs — while your account is active. They have no automatic expiry; we delete them when you ask us to (see Section 10).
- Operational and request logs — a rolling 180 days, retained within India, as the CERT-In Directions of 28 April 2022 require of system logs.
- The approximate city, region, and country described in Section 2, and the advertising campaign parameters described there — stored on your organisation's profile and retained while your account is active. They are deleted with your account under Section 10, and they are not held only as a 30-day log line.
- Database backups — we keep recent automated snapshots of our database with a point-in-time recovery window. Data you have asked us to delete may persist in those backups until they are overwritten.
- Payment and transaction records — retained for eight financial years, as section 128(5) of the Companies Act, 2013 requires for books of account, and for as long as our payment provider's merchant terms require if that is longer, even after your account is closed. We use them only for legal, tax, accounting, and dispute-resolution purposes.
- Aggregated activity counts held against your organisation's internal identifier, used for operational reporting and containing no content and no contact details — retained for 24 months, after which they are deleted or aggregated further so that they no longer relate to your organisation.
10. Deletion Of Your Data
You can ask us to delete your account or your data by emailing support@vastrahq.com.
We do not currently offer a self-service delete button, and deletion is carried out by our team. We acknowledge a deletion request within 24 hours and aim to complete it within 30 days; if a particular case needs longer, we will tell you why, and we tell you when it is done. On completion we delete your uploaded photographs, your generated outputs, and your account, organisation, and business-profile records.
When an account ends — whether you close it or we terminate it — we keep your uploaded content and generated outputs available for you to retrieve for 30 days before deleting them, unless you ask us to delete them immediately or the law requires us to remove them sooner.
Two things are not deleted, and we would rather say so than surprise you: the payment and transaction records described in Section 9, which the law and our payment provider's terms require us to keep, and data sitting in routine backups, which is overwritten on the cycle described in Section 9.
Archiving a garment in the app removes it from your projects list but does not delete it from our systems. Tell us if you want it deleted.
11. The Law This Policy Is Written To
India's data-protection regime is in transition. The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 have been made, but their substantive obligations — notice, consent, data-principal rights, breach reporting, and cross-border transfer — commence on 13 May 2027. Until then, the rules in force are the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the CERT-In Directions of 28 April 2022 issued under section 70B(6) of that Act.
This policy is written to meet the rules that apply today, and we already apply the standards set by the Digital Personal Data Protection Act and Rules — including the rights in Section 12, the response times in Section 17, and the breach commitment in Section 16 — ahead of their commencement. We will revise this policy as the remaining provisions commence.
12. Your Rights
You may exercise any of the following rights by emailing support@vastrahq.com. We may need to verify your identity first, and we will respond within the times published in Section 17.
- Access — ask what personal data of yours we hold, how we process it, and who we have shared it with.
- Correction and completion — ask us to correct data that is inaccurate or misleading, complete data that is incomplete, and update data that is out of date.
- Erasure — ask us to delete your personal data, on the terms in Section 10.
- Withdrawal of consent — withdraw consent you have given, at any time. Withdrawing consent may limit or end our ability to provide the service.
- Nomination — nominate another individual to exercise your rights on your behalf if you die or become unable to exercise them yourself. To nominate someone, email support@vastrahq.com with their name and contact details, and we will confirm the nomination to you. If your nominee later needs to act, we will ask them for proof of identity and of the event that triggers the nomination before we act on their request.
- Grievance redressal — complain to our Grievance Officer about how we have handled your data or your request (Section 17).
If you are not satisfied with how we handle your request or your complaint, you may complain to the Data Protection Board of India.
13. Our Internal Access To Your Content
Authorised VastraHQ personnel can view your uploaded photographs, your generated outputs, and your account and organisation records through an internal console, in order to operate, support, debug, and secure the service.
Access to that console is limited to a named internal allow-list. Your contact details — email address, phone number, WhatsApp number, Instagram handle, and contact name — are masked by default in it. Revealing any one of them is a separate action that writes an audit record before the value is shown, and it does not proceed if that record cannot be written. Every view and every action taken in the console is logged, and the log records who looked at which field, never the value itself. The console offers no export or bulk download of your content, and it provides no way to edit the content itself.
The console does let an operator act on your account: archive a garment, re-run a generation for you (which can charge your organisation's credits), reconcile a stuck generation, adjust your credit balance, and change your organisation's limits. Each of those actions is audited.
Separately from the console, a narrow set of engineering staff can reach our production systems directly — for incident response, migrations, and operational maintenance. That access is necessary to run the service, it is limited to people who need it, and it is not written to the console's audit log. We would rather tell you that than claim an audit trail covers everything.
14. Security
We use reasonable technical and organizational safeguards to protect data. However, no online service is completely secure.
The measures we can describe specifically are:
- Data is encrypted in transit, and our database and file storage use our cloud provider's encryption at rest.
- Your files are never publicly readable. They are served only through short-lived signed links.
- Application routes require an authenticated session, apart from a small explicit list of public pages that our build checks.
- Data is scoped to your organisation, and a request for another organisation's data is refused.
- We re-encode every photograph you upload for use in the service, and the re-encoded copies carry no camera or location metadata (EXIF and GPS).
- We apply rate limits on uploads, generations, purchases, and automated callbacks.
- We keep database backups with point-in-time recovery, as described in Section 9.
- Our systems synchronise their clocks to the Network Time Protocol servers of the National Informatics Centre and the National Physical Laboratory, as the CERT-In Directions of 28 April 2022 require.
We maintain a documented information-security policy and programme covering managerial, technical, operational, and physical controls commensurate with the information we hold, as contemplated by rule 8 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. We do not currently hold a third-party information-security certification, and we do not claim one.
15. Children
VastraHQ is not intended for users under 18, and we do not knowingly collect data from children. Our Terms of Service also prohibit uploading a photograph depicting a person under 18, require children's and babywear garments to be photographed unworn, and record that VastraHQ does not generate depictions of people under 18.
If you believe a child's personal data has reached us, write to support@vastrahq.com and we will delete it.
16. Data Breach
If a personal-data breach occurs, we will notify every affected user without undue delay.
We report reportable cyber incidents to the Indian Computer Emergency Response Team (CERT-In) within six hours of noticing them or being notified of them, as the CERT-In Directions of 28 April 2022 require.
We also already apply the standard set by the Digital Personal Data Protection Rules ahead of their commencement: intimation to affected users and initial particulars to the Data Protection Board of India without delay, and detailed particulars to the Board within 72 hours.
Where you are a business customer and a breach affects personal data you are responsible for, Section 20B of our Terms of Service sets out what we tell you and when.
17. Grievance Officer And Response Times
Grievance Officer: Dimple Lulla, Director, VastraHQ Labs Private Limited — grievance@vastrahq.com, +91 86020 53889.
We publish the following commitments, and we apply whichever is shorter, these or the period the law allows:
- Acknowledgement of any request or complaint — within 24 hours.
- Resolution of complaints about content, takedowns, or misuse of the service — within 15 days.
- Resolution of privacy requests (access, correction, erasure, withdrawal of consent, nomination) and of billing complaints — within 30 days.
- Removal of material reported by an individual, or by someone acting for them, as exposing a private area, showing them in nudity or a sexual act, or depicting them by impersonation including in a morphed image — within 24 hours of the complaint, with no court order required.
- Removal of material covered by a valid court or government order — within 36 hours of our receiving the order.
18. Data Protection Officer
VastraHQ has not been designated a Significant Data Fiduciary under the Digital Personal Data Protection Act, 2023, and is not required to appoint a Data Protection Officer. The Grievance Officer named in Section 17 is your point of contact for all data-protection matters.
19. Changes To This Policy
We may update this Privacy Policy from time to time. The latest version always shows its updated date at the top. Where a change materially affects how we use your personal data, we will tell you in the app and, where we hold a working email address for you, by email, before it takes effect. That is the same notice channel Sections 9 and 25 of our Terms of Service use, so the two documents cannot give you notice on different terms.
Previous versions of this policy are archived and available on request from support@vastrahq.com.
20. Contact / Grievance
For privacy questions, deletion requests, or complaints, contact:
Grievance Officer: Dimple Lulla, Director, VastraHQ Labs Private Limited — grievance@vastrahq.com, +91 86020 53889.
VastraHQ is operated from Bhopal, Madhya Pradesh, India. VastraHQ Labs Private Limited's registered office is at H.NO. 19 AMALTAS COLON, PHASE -1 KOLAR ROAD, MP Bhoj Open University, Huzur, Bhopal- 462016, Madhya Pradesh, India (CIN: U62099MP2026PTC085704).