Effective date: 15 October 2025 — Last modified: .
Vaastu Vedak ("we", "us", "our") respects your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your choices. It applies to vaastuvedak.in and related services (the "Site" or "Services").
1. Introduction
This Privacy Policy explains how we collect and process personal data when you use the Site, create an account, book a consultation, sign in with a third party, communicate with consultants, or otherwise interact with Vaastu Vedak. By using the Site you consent to the collection and use of information as described here.
2. What we collect
We collect information that helps us deliver and improve Services. Types of data we collect include:
Account & identity data
Full name, email address, profile picture (e.g., from Google sign-in), and basic public profile information.
Authentication tokens and provider IDs when you sign in via Google or other identity providers.
Contact & booking data
Phone number, address (line1/line2/city/state/country), booking preferences, service selections, and booking history.
Booking metadata: dates, consultant id, service type, status, and internal notes necessary to schedule and fulfil the service.
Payment & billing data
When payments are taken we collect billing details required to process the transaction. We do not store full card numbers on our servers — payment provider tokens and references may be stored. For card processing, we rely on PCI-compliant third-party providers (see Third-party services).
Usage & device data
IP address, browser and device characteristics, operating system, pages visited, referrer, timestamps, and performance metrics (logs & analytics).
Communications
Messages, chat transcripts (WhatsApp integration), emails, and support requests to the extent necessary for service and troubleshooting.
Derived & aggregated data
We may aggregate and anonymize data for analytics and product improvement; aggregated data is not personal data.
3. How we use your data
We use personal data for the following purposes:
Service delivery: to create accounts, process bookings, manage schedules, communicate with you about bookings, and coordinate consultant visits.
Payments: to bill and collect payments, handle refunds, and prevent fraud.
Authentication: to sign you in (Google tokens, session cookies) and secure your session.
Support: to respond to customer service requests and troubleshoot issues.
Improvements & analytics: to analyze usage patterns, measure and improve Site performance, and develop new features.
Marketing: to send product updates, promotions, offers and service reminders where you have consented or where permitted by law; you can opt out at any time.
Legal & safety: to comply with legal obligations, enforce our Terms, prevent abuse, and protect rights and property.
4. Legal bases (where applicable)
If you are in a jurisdiction that requires us to state lawful bases for processing (e.g., GDPR), our legal bases include:
Contract: processing necessary to perform the contract (bookings, payments, consultations).
Consent: where you have explicitly consented (marketing emails, cookies beyond strictly necessary).
Legitimate interests: to operate, secure, and improve our Service (analytics, fraud prevention), balanced against your rights.
Legal obligation: to comply with applicable law (tax, regulatory requests).
5. When we share data
We never sell your personal information. We share data only as described below or with your explicit consent:
Consultants: when you book a service we share the necessary contact, address and booking details with the assigned consultant so they can provide the service.
Service providers: payment processors, hosting providers, analytics vendors, email/communication services, and other vendors who perform services on our behalf.
Legal & safety: when required by law, in response to lawful requests (court orders, subpoenas), or to protect rights, property or safety.
Business transfers: in the event of a merger, acquisition or sale of assets personal data may be transferred as part of the transaction (with notice where required).
6. Third-party services we use
We integrate with and use third-party services; examples include but are not limited to:
Type
Examples
Why
Identity
Google Sign-In
Authentication and user profile data.
Payments
Stripe / Razorpay (example)
Collect and process payments securely.
Messaging
WhatsApp (wa.me links), Email providers
Booking confirmations and customer communication.
Analytics
Google Analytics, server logs
Product improvement and diagnostics.
Hosting & DB
Web host, cloud provider
Store site data and backups.
Each third party has its own privacy practices — please check their privacy policies. We only share the data necessary for the third party to provide the service.
7. Cookies & tracking
We use cookies and similar technologies to operate the Site and provide a good user experience. Categories:
Essential/Strictly necessary: session cookies, authentication and security — required for the Site to function.
Functional: preferences and UI settings.
Analytics: usage and performance tracking to improve our Service.
Marketing: for personalized communications and advertising (where consented).
You can manage cookie settings in your browser. Disabling cookies may affect Site functionality. For analytics opt-out, please use your browser controls or the provider-specific opt-out mechanisms.
8. Security
We use reasonable administrative, technical and organisational measures to protect data (HTTPS/TLS, access controls, parameterized DB queries, backups). However, no method of transmission or storage is 100% secure — absolute security cannot be guaranteed.
9. Data retention
We retain your personal data only as long as necessary for the purposes described, subject to legal and business retention needs.
Account & profile data: retained while account exists and for a reasonable period after (e.g., 2 years) unless you request deletion.
Bookings & billing records: retained for accounting and legal obligations (commonly 6–7 years depending on local tax law).
Logs & analytics: retained in aggregated / anonymised form; raw logs may be kept for a shorter operational window (30–90 days) unless needed for troubleshooting or legal reasons.
10. Your rights
Depending on your jurisdiction, you may have rights regarding your personal data, such as:
Access: request a copy of the personal data we hold about you.
Correction: ask us to correct inaccurate or incomplete data.
Deletion: request deletion of your personal data (subject to legal retention obligations and exceptions).
Portability: request your data in a structured, commonly used format.
Restriction/Objection: ask us to restrict or object to certain processing (e.g., marketing).
To exercise rights, contact us at the address below. We will respond in accordance with applicable law. We may require verification of identity before fulfilling requests.
11. Children
Our Services are not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child under 18 has provided us with personal data, contact us and we will take steps to delete such data where required by law.
12. International transfers
We operate in India and use service providers worldwide. Your data may be transferred to, stored in, and processed in countries outside your country of residence (including India and other jurisdictions). We take reasonable steps to ensure appropriate safeguards are in place (contracts, standard contractual clauses, or other mechanisms) where required.
13. Data breach
If we identify a personal data breach that is likely to result in a high risk to your rights, we will notify affected users and relevant authorities in accordance with applicable law and take reasonable steps to mitigate the risk.
14. Changes to this policy
We may update this Privacy Policy. When we make material changes we will post a prominent notice on the Site and update the "Last modified" date above. Continued use of the Site after such changes constitutes acceptance of the updated policy.
15. Contact & Data Protection Officer
If you have questions about this Privacy Policy or wish to exercise your rights, contact: