Privacy Policy

Privacy Policy

This Privacy Policy is an electronic record under the Information Technology Act, 2000, and the rules made thereunder, including amendments relating to electronic documents and records. No physical, electronic, or digital signature is required for this Privacy Policy to be valid.

This is a legally binding agreement between you and Edith Collections ("we," "us," "our"). It takes effect once you accept it — whether by clicking "I Accept," by using our website, or through any other form of acknowledgment — and governs your use of www.edithvibes.com ("the Website").

This document is published in accordance with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, under the Information Technology Act, 2000, which require publication of a privacy policy for the collection, use, storage, and transfer of sensitive personal data.

Please read this Privacy Policy carefully. By using the Website, you confirm that you understand, agree to, and consent to its terms. If you do not agree, please do not use the Website.

By providing your information or using the Website's features, you consent to the collection, storage, processing, and transfer of your Personal and Non-Personal Information as described in this policy. You agree that this handling of your information will not result in loss or wrongful gain to you or any third party.

Information We Collect

To access certain services on our Website, you may be asked to provide information such as: name, email address, gender, age, PIN code, credit or debit card details, and password, along with details such as occupation or interests. This information helps us improve our services and provide a more relevant, user-friendly experience.

What information is required depends on the specific service being used. We may use this information to maintain, protect, and improve our services (including advertising) and to develop new offerings.

Information that is freely available in the public domain, or furnished under the Right to Information Act, 2005 or any other applicable law, is not treated as sensitive personal data.

What Personal Data We Collect, and Why

Comments
When you leave a comment on our site, we collect the information included in the comment form, along with your IP address and browser user agent string, to help detect spam.

An anonymized version of your email address (a "hash") may be shared with the Gravatar service to check whether you use it. You can view Gravatar's privacy policy at automattic.com/privacy. Once your comment is approved, your profile photo becomes publicly visible alongside it.

Media
If you upload images to the Website, please avoid including embedded location data (EXIF GPS). Other visitors can download and extract this data from any images posted on the site.

Cookies
We may use cookies or similar tools to assign visitors a unique, random User ID, helping us understand user interests. Unless you identify yourself (for example, by registering), we have no way of knowing who you are, even with a cookie assigned. Cookies only ever contain information you've directly provided to us, and cannot read data from your device's hard drive. Advertisers may also set their own cookies if you interact with their ads — this is outside our control.

Our servers automatically collect limited connection data, including your IP address, when you visit the Website. This does not identify you personally; it helps us deliver web pages, tailor content to user interests, measure site traffic, and understand our visitors' general geographic locations.

If you leave a comment, you may opt in to saving your name, email, and website in a cookie for convenience on future visits. These cookies last one year.

If you log in to an account on our site, a temporary cookie checks whether your browser accepts cookies (this contains no personal data and is deleted when you close your browser). Login cookies typically last two days, or two weeks if you select "Remember Me." Screen display preference cookies last one year. Logging out removes your login cookies.

If you publish or edit an article, a cookie noting the post ID (no personal data) is saved for one day.

Embedded Content
Pages on our site may include embedded content (videos, images, articles) from other websites. This content behaves as though you visited the source site directly — it may collect data, set cookies, and track your interaction, including recognizing you if you're logged into that external site.

Links to Other Sites
This policy covers our Website only. We are not responsible for the privacy practices of any third-party sites we link to.

Analytics
[Add details here on any analytics tools used, e.g., Google Analytics, and what data they collect.]

Who We Share Your Data With

We do not share your sensitive personal information with third parties without your consent, except in these limited circumstances:

(a) When required by law, a court, or a government authority — for identity verification, prevention or investigation of offences (including cyber incidents), or prosecution — carried out in good faith and only to the extent necessary to comply with applicable law.

(b) With group companies, or their officers and employees, solely to process your information on our behalf. We require these recipients to handle your data in line with our instructions, this Privacy Policy, and appropriate confidentiality and security standards.

How Long We Retain Your Data

Comments and their associated metadata are retained indefinitely, so that follow-up comments from the same user can be recognized and approved automatically rather than held for moderation.

If you register an account with us, we store the personal information in your user profile. You may view, edit, or delete this information at any time, with the exception of your username. Website administrators can also view and edit this data.

Your Data Rights

If you have an account with us or have left comments, you may request an exported file of the personal data we hold about you. You may also request deletion of your personal data by messaging us on WhatsApp at +91 83840 69624, including your registered contact number and email address. We will complete deletion requests within 14 business days, except for data we are legally required to retain for administrative, legal, or security purposes.

Where We Send Your Data

Visitor comments may be reviewed through an automated spam-detection service.

How We Protect Your Data

We take appropriate security measures to prevent unauthorized access, alteration, disclosure, or destruction of your data. This includes regular internal reviews of our data practices, along with encryption and physical security safeguards for the systems where personal data is stored.

All data collected through the Website is stored in a secure, firewall-protected database with restricted, password-protected access. That said, no security system is completely infallible — we cannot guarantee absolute security for data stored with us or transmitted to us over the internet. Please note that anything you post in public discussion areas is visible to anyone with internet access.

As the internet evolves, we may update this Privacy Policy periodically to reflect necessary changes. Any use of information already collected will remain consistent with the policy in effect at the time it was gathered, regardless of later updates.

Grievance Redressal

Any complaints, concerns, or reports of a breach of these terms should be submitted in writing, with an electronic signature, to our designated Grievance Officer at the contact details below.

Edith Collections
Website: www.edithvibes.com
Email: contactus@edithvibes.com
Phone: +91 8796441399


A few things worth flagging before this goes live:

  1. Domain inconsistency — the original references "www.edith.co.in" under the Grievance Officer section, but the policy is written for "www.edithvibes.com." I standardized to edithvibes.com above; let me know if edith.co.in is intentional.
  2. Sensitive categories listed but unused — your original mentioned collecting "sexual orientation," "medical records and history," and "biometric information" in the User Information section, but nothing else in the document explains why or how these would be collected. I dropped these from the rewrite since they weren't referenced anywhere else and seem inconsistent with a fragrance/e-commerce business — but if you do collect this kind of data somewhere (unlikely, but worth confirming), it needs to stay and be explained. If not, removing it is actually safer, since listing sensitive personal data categories you don't actually collect can itself create compliance questions.
  3. Analytics section is empty — the original had a placeholder heading with no content. If you use Google Analytics, Meta Pixel, or similar, that should be named explicitly.
  4. Legal review — this is a binding contract, not marketing copy. I've preserved the legal meaning and improved clarity, but I'd strongly recommend a lawyer sign off before this replaces your live policy, especially given India's DPDP Act (2023) is now layered on top of the older IT Rules this document is based on — a privacy lawyer could confirm whether updates are needed there too.