VandoStore logo
MarketplaceAboutPricingVision
Sign In

Policies

Data Policy

This operational companion to our Privacy Policy explains data categories, purposes, retention, service providers, security, and the role of automation in the marketplace. It describes our current approach and will evolve as legal requirements and the product change.

Last updated July 12, 2026Purpose limitationRetention by designSecurity & uptime transparency

On this page

Who does what with dataHow we group dataWhy each category existsRetention scheduleSharing and subprocessorsSecurity and availabilityAutomation, ranking, and moderationControls and how to make a request

Related

Privacy PolicyTerms of ServiceCookie PolicySystem status

Purpose limitation

Retention by design

Security & uptime transparency

01

Who does what with data

Clear roles prevent blurry responsibility. Here is how we define ours.

VandoStore decides the purposes and means of personal-data processing needed to run the marketplace. Under India's DPDP framework this role is generally called a data fiduciary; other applicable laws may use different terms.

Processors (sometimes called subprocessors) are vendors who handle data only to provide a service for us — hosting, payments, email, monitoring, identity, and similar. They should not use your data for their own unrelated products.

Other users are independent when they message you or complete a private sale. Once you share something in a chat, they become responsible for how they treat that information offline.

02

How we group data

Thinking in categories helps us apply the right protection and retention to each type of information.

We avoid collecting sensitive data unless it is necessary for verification, fraud prevention, or a legal requirement. When we do collect higher-risk data, access is tighter.

  • Identity & profile: name, contact details, profile media, city, verification status.
  • Marketplace records: listings, photos, prices, listing credits, offers, messages, reports, and moderation notes.
  • Financial metadata: listing-credit payments, invoices, and payment-provider references (not full card PANs).
  • Technical & security: device signals, IPs, session diagnostics, rate-limit and abuse signals.
  • Support records: tickets and emails you send us, including attachments.

03

Why each category exists

Purpose limitation is a core GDPR and DPDP idea: collect for a reason, use for that reason.

If a new purpose does not fit the original one and is not legally required, we either avoid it or ask you first.

  • Service delivery: sign-in, listings, credits, offers, chat, and profile tools.
  • Trust & safety: verification, spam/fraud detection, content moderation, dispute support.
  • Reliability & product quality: performance metrics, crash diagnosis, feature usage trends.
  • Compliance: tax/accounting retention, responding to lawful requests, enforcing Terms.

04

Retention schedule

We prefer short, purpose-tied retention over keeping everything forever "just in case."

When a retention period ends, we delete or irreversibly de-identify the data, unless a specific legal hold applies.

  • Profile & account: lifetime of the account + a limited post-closure buffer for recovery and fraud checks.
  • Listings & messaging: retained while useful for your history and safety investigations; reduced after inactivity or closure.
  • Verification artefacts: kept only as long as needed for the verification decision and anti-abuse needs.
  • Billing & invoices: retained for statutory financial periods (often multi-year).
  • Security logs: typically weeks to months, longer only when investigating an incident.
  • Marketing preferences: until you opt out or your account is deleted.

05

Sharing and subprocessors

We share the minimum needed for each job, under contractual and technical controls.

Before a vendor gets production access to personal data, we expect basic diligence: security posture, purpose limits, and an agreement that matches the sensitivity of the data.

  • Cloud hosting & storage for application and media files.
  • Authentication providers for secure sign-in.
  • Payment processors for listing-credit purchases.
  • Email and messaging infrastructure for transactional notices.
  • Monitoring/analytics tools for reliability (minimised where possible).
  • Authorities only when lawfully required or to prevent serious harm.
We do not sell personal data. If you need a current overview of major processor categories for a formal request, email data@vandostore.com.

06

Security and availability

ISO 27001-style thinking means confidentiality, integrity, and availability — not only "encryption" as a slogan.

Confidentiality: access limited to people and systems that need it; credentials and secrets handled carefully.

Integrity: changes to critical data and configuration should be intentional, reviewable, and recoverable.

Availability: we monitor whether core services respond. You can always see a live summary on our Status page and in the site footer.

  • Encryption in transit for normal web traffic.
  • Role-based access for internal tools.
  • Health checks for application and database connectivity.
  • Incident response habits: detect, contain, communicate when required, learn.
  • Vendor review for processors that handle personal data.

07

Automation, ranking, and moderation

We use software to keep the marketplace usable — ranking, spam filters, risk signals — with human judgment for high-impact calls.

Automated systems may flag unusual activity, low-quality listings, or likely spam. Those signals can affect queues, visibility, or temporary limits.

When an automated signal could seriously affect your ability to use the platform (for example, a hard suspension), we aim to involve human review where practical, and you can contact support to appeal.

We do not use your private messages to train public AI models for unrelated products. AI features inside VandoStore (such as listing assistance) are used to help you complete tasks on the platform under our safety rules.

08

Controls and how to make a request

Self-serve where we can; a human inbox where we must.

In your account you can usually update profile fields, manage communications, and close or stop using the service.

For access, correction, portability, deletion beyond self-serve tools, or questions about retention and processors, contact us. We will verify the request, complete it within applicable legal timelines, and explain if something cannot be fully deleted because of a legal hold.

  • Privacy channel: privacy@vandostore.com
  • Data governance: data@vandostore.com
  • General support: support@vandostore.com
  • Live platform health: /status

Need assistance?

Data handling questions

Need detail on retention, processors, exports, or how a specific feature uses data? Write to our data governance inbox.

Email data@vandostore.comRead Privacy Policy
VandoStore logo

India's marketplace for buying and selling pre-loved goods — local, verified, and a bit more careful.

support@vandostore.com
Coming soon on
Download on the App StoreGet it on Google Play

Explore

MarketplacePopular categoriesTop citiesLatest dealsTrust and safetySafety policy

Company

AboutContactStatusPricingGet verified

Categories

MobilesElectronicsLaptopsFashionHome decor

Legal

PrivacyTermsData policySafety policyCookiesBilling
VisaMastercardUPIRuPayNetBanking
Checking…

© 2026 VandoStore. All rights reserved.

Privacy·Terms·Cookies·Data