1. Introduction
This Privacy Policy explains how we collect, use, store, share, and protect personal data in the course of providing our quick-commerce fashion services — including product discovery, Try & Buy doorstep trials, delivery, payments, and customer support. We are committed to processing personal data lawfully, fairly, and securely in accordance with the DPDP Act, 2023.
By engaging with our services or interacting with our application, you acknowledge that you have read and understood this Privacy Policy.
2. Definitions
- Data Principal: The individual to whom personal data relates.
- Data Fiduciary: The entity that determines the purpose and means of processing personal data.
- Data Processor: Any entity that processes personal data on behalf of a Data Fiduciary.
- Personal Data: Any data about an individual who is identifiable by or in relation to such data.
Depending on the engagement, we may act as a Data Fiduciary (e.g., for our employees and application users) or a Data Processor (e.g., when processing partner-provided data during application usage).
3. Categories of Personal Data We Collect
We may collect the following types of personal data:
3.1 From Customers
- Names, email addresses, phone number
- Delivery address and order details
- User access logs, system identifiers (if applicable)
3.2 From Website Visitors
- Contact form details
- IP address, browser metadata, cookies
3.3 From Job Applicants
- Resumes, qualifications, employment history
- Contact details
We do not intentionally collect sensitive personal data unless required for a specific engagement and explicitly authorized.
4. Purpose of Processing
We use personal data only for lawful, specific, and limited purposes connected to our fashion quick-commerce and related services. These purposes include:
- Delivering the best and immense free styling.
- Fulfilling orders, doorstep trials, deliveries, returns, and payments.
- Improving our services, website functionality, and user experience.
- Managing client relationships and communication.
- Providing recommendations and remediation guidance.
- Ensuring security of our systems and infrastructure.
- Recruitment and HR operations.
- Maintaining legal, regulatory, and contractual compliance.
- Collecting customer feedback.
We do not use personal data for purposes unrelated to the original intent unless required by law or with explicit consent.
5. Legal Basis for Processing
We process personal data based on:
- Consent — when individuals voluntarily provide personal data for a specific purpose (e.g., website forms, marketing communication)
- Contractual necessity (e.g., giving hassle-free service to customers)
- Legal obligations (e.g., regulatory reporting)
- Legitimate interests (e.g., improving service quality, security monitoring)
Where consent is required, it is free, specific, informed, and unambiguous.
6. Data Sharing & Disclosure
We may share personal data with:
- Authorized internal teams involved in service delivery
- Third-party service providers (e.g., delivery partners, payment gateways)
- Regulatory authorities, when legally required
- Partners, strictly as per contractual obligation
We do not sell or trade personal data.
Cross-border transfers are performed only under permitted conditions and with adequate safeguards.
7. Data Retention
Personal data is retained only for as long as necessary to fulfil the purpose of processing, comply with legal requirements, or meet contractual obligations. After the retention period, data is securely deleted.
8. Security Safeguards
We implement reasonable technical and organizational measures, including:
- Access control and least-privilege principle
- Multi-factor authentication
9. Rights of Data Principals
Data Principals have the right to:
- Request access to your personal data
- Request correction or updating of inaccurate data
- Request erasure of personal data
- Withdraw consent at any time
- Nominate another individual to exercise your rights
Requests will be processed within a reasonable timeframe as mandated by the DPDP Act.
10. Personal Data Breach Notification
In the event of a personal data breach, we will notify:
- The Data Protection Board of India, and
- Affected Data Principals
as required under the DPDP Act and applicable rules. Breach notification is a core fiduciary obligation.
11. Grievance Redressal
For any concerns or complaints regarding your personal data, you may contact our Grievance Officer:
Name: Shikhar Chhibber
Email: support@ootfit.com
12. Children's Data
We do not knowingly collect personal data of children (below 18 years) unless explicitly required for a specific engagement and permitted by law.
13. Updates to This Policy
We may update this Privacy Policy periodically to reflect legal, technical, or operational changes. The latest version will always be available on our website.
14. Location Information
Our app may request access to your device's location to provide location-based features and improve your experience. Location data is only collected with your permission and is used solely for the purposes described within the app.
You can enable or disable location access at any time through your device's settings. If you choose not to grant location permission, some features of the app may not function as intended.
We do not sell your location data. Any location information collected is handled securely and is only shared with trusted service providers when necessary to deliver the app's functionality or comply with legal obligations.