Privacy policy
VEDHACART Privacy Policy
Last Updated: December 2025
VEDHACART operates this store and website, including all related information, content, features, tools, products and services (the "Services"). Our Services include:
- Shop β Products delivered UK-wide
VEDHACART is powered by Shopify, which enables us to provide the Services to you. This Privacy Policy describes how we collect, use, and disclose your personal information when you visit, use, or make a purchase or other transaction using the Services or otherwise communicate with us.
Please read this Privacy Policy carefully. By using and accessing any of the Services, you acknowledge that you have read this Privacy Policy and understand the collection, use, and disclosure of your information as described herein.
Personal Information We Collect
When we use the term "personal information," we are referring to information that identifies or can reasonably be linked to you. We may collect the following categories of personal information:
- Contact Details: Name, address, billing address, shipping address, phone number, and email address.
- Financial Information: Credit card, debit card, payment card information, transaction details, and payment confirmation.
- Account Information: Username, password, security questions, preferences and settings.
- Transaction Information: Items you view, add to cart, purchase, return, exchange or cancel, and your order history.
- Communications: Information you include in support tickets, customer service inquiries, and other communications with us.
- Device Information: Information about your device, browser, network connection, IP address, and other unique identifiers.
- Usage Information: How and when you interact with or navigate the Services.
Personal Information Sources
We may collect personal information from the following sources:
- Directly from you: When you create an account, place an order, visit or use the Services, or communicate with us.
- Automatically: Through cookies and similar technologies when you use our Services.
- From service providers: When they collect or process your personal information on our behalf.
- From partners: Or other third parties.
How We Use Your Personal Information
Provide and Improve the Services
To process your payments, fulfil your orders, send order and delivery notifications (via email, SMS, and WhatsApp), process returns and exchanges, create and manage your account, arrange shipping, and create a customised shopping experience.
Marketing and Advertising
To send marketing communications by email, text message or postal mail (with your consent), and to show you relevant advertisements based on your activity.
Security and Fraud Prevention
To authenticate your account, provide a secure payment experience, detect and prevent fraudulent or illegal activity, and secure our Services.
Communicating with You
To provide customer support, respond to your inquiries, and send order updates via SMS, WhatsApp, and email using Twilio.
Legal Reasons
To comply with applicable law, respond to legal process, and enforce our terms and policies.
Legal Basis for Processing (UK GDPR)
We process your personal data based on the following legal grounds:
- Contract: Processing is necessary to fulfil our contract with you, including processing orders, payments, deliveries, and returns.
- Consent: Where you have given consent, such as for marketing communications. You can withdraw consent at any time.
- Legitimate Interest: Processing is necessary for our legitimate business interests, such as improving our services, preventing fraud, and ensuring security, where these interests are not overridden by your rights.
- Legal Obligation: Processing is necessary to comply with legal requirements, such as tax and accounting obligations.
How We Disclose Personal Information
We may disclose your personal information to:
- Shopify: Our e-commerce platform provider.
- Service Providers: Payment processors, analytics providers, cloud storage, fulfilment and shipping partners.
- Communication Providers: Twilio (SMS and WhatsApp notifications).
- Business Partners: For marketing services (with your consent).
- Legal Compliance: When required by law or to protect our rights.
We never sell your personal data to third parties.
Cookies
We use cookies to:
- Keep you logged in
- Remember your preferences and cart items
- Analyse website traffic
- Enable certain features
You can manage cookie preferences in your browser settings.
Your Rights (UK GDPR)
Under UK GDPR and the Data Protection Act 2018, you have the right to:
- Access: Request a copy of your personal data.
- Rectification: Correct inaccurate data.
- Erasure: Request deletion of your data ("right to be forgotten").
- Portability: Receive your data in a portable format.
- Object: Object to processing for marketing purposes.
- Restrict Processing: Ask us to stop or restrict processing.
- Withdraw Consent: Withdraw consent at any time.
To exercise these rights, raise a support ticket at our support page.
Data Retention
We retain your data for:
- Account information: As long as your account is active.
- Order history: 7 years for tax and legal purposes.
- Marketing preferences: Until you unsubscribe.
Data Security
We implement appropriate security measures including:
- SSL encryption on all pages
- Secure payment processing (PCI compliant via Shopify)
- Regular security audits
- Staff training on data protection
Please be aware that no security measures are perfect. We recommend that you do not use unsecure channels to communicate sensitive information to us.
Children's Privacy
Our Services are not directed at children under 16. We do not knowingly collect data from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on you. Any personalisation of your shopping experience (such as product recommendations) is for your convenience only and does not affect your rights or access to our Services.
International Transfers
Your personal information may be transferred, stored and processed outside the UK. If we transfer your personal information out of the UK, we will rely on recognised transfer mechanisms like Standard Contractual Clauses or transfers to countries with adequate protection.
Third Party Websites
The Services may contain links to third-party websites. We are not responsible for the privacy practices of these sites. Please review their privacy policies before providing any information.
Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised policy on this website and update the "Last Updated" date. Significant changes will be notified as required by applicable law.
Complaints
If you have complaints about how we process your personal information, please contact us. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Contact Us
For privacy queries or to exercise your rights:
- Raise a support ticket: our support page
- Website: www.vedhacart.com
- Location: Nottingham, UK
Data Controller: VEDHACART