PRIVACY NOTICE / PRIVACY POLICY
Document Version: 1.0Effective Date: 1st Sep 2026Last Updated: 1st Sep 2026Applicable Jurisdiction: IndiaPlatform: Zehbia Website, Web Application, Mobile Application and related services- Home Tailoring Platform
1. INTRODUCTION
Welcome to Zehbia’s Wardrobe - A Tailoring Platform ("Zehbia", "we", "us", "our).
This Privacy Notice explains how Zehbia collects, receives, uses, stores, processes, shares, protects and deletes personal data relating to customers and other individuals who use or interact with our website, mobile application, services, customer portal, home-visit services, tailoring services and related communication channels.
Zehbia is committed to handling personal data responsibly, transparently and securely.
This Privacy Notice is intended to be read together with:
Zehbia Terms & Conditions;
Cancellation & Refund Policy;
Payment Terms;
Offers & Cashback Terms;
Delivery Policy;
Cookie Policy, where applicable; and
Grievance Redressal / Data Rights Procedure.
Where applicable, this Privacy Notice is intended to operate consistently with the Digital Personal Data Protection Act, 2023, and the applicable rules and regulations made thereunder. The DPDP Act establishes the framework for processing digital personal data in India.
2. WHO IS RESPONSIBLE FOR YOUR PERSONAL DATA?
The entity responsible for determining the purpose and means of processing your personal data will be:
Legal Entity Name: KHADIM SOLUTIONSBrand: Zehbia / Zehbia’s Wardrobe - A Tailoring PlatformRegistered Address: 1324 Khadim Villa Mehjoor Nagar Natipora Srinagar Kashmir-JK 190015Email: zehbia@zehbia.comCustomer Support: +91-889-974-9158Grievance Contact: grievance@zehbia.com Data Protection Contact: info@zehbia.com
For purposes of applicable Indian data protection law, the relevant entity may act as the Data Fiduciary for personal data processed through the Zehbia platform.
If Zehbia's business structure changes, this Privacy Notice may be updated to identify the applicable legal entity.
3. WHAT PERSONAL DATA DO WE COLLECT?
We collect only personal data that is reasonably necessary for providing, managing, securing and improving Zehbia's services.
Depending on how you use Zehbia, this may include the following.
3.1 Account and Identification Information
We may collect:
Full name
Mobile number
Email address
Profile photograph, if voluntarily provided
Date of birth or age, where required
Gender or preferred garment category, where voluntarily provided
Login/account identifiers
OTP verification information
Account status
4. CONTACT AND ADDRESS INFORMATION
When you create an address or request a home visit, pickup or delivery, we may collect:
House/flat number
Building name
Street/locality
Area
City
District
State
PIN code
Landmark
Address type, such as Home, Office or Other
Delivery instructions
Contact person/name, where applicable
Alternate contact number, where voluntarily provided
We use this information to facilitate home visits, pickup, delivery and other services requested by you.
5. MEASUREMENT INFORMATION
Zehbia is a tailoring platform and therefore may process garment measurement information.
Depending on the garment, this may include:
Chest
Waist
Hip
Shoulder
Sleeve length
Armhole
Neck
Kurta length
Trouser length
Inseam
Outseam
Thigh
Knee
Cuff
Other garment-specific measurements
Measurement preferences
Fit preferences
Stitching preferences
Alteration instructions
Measurement notes
Measurement history
Measurement version information
Important
Zehbia will not assume that every customer requires the same measurements.
Measurements may be stored according to:
Customer → Garment Type → Measurement Profile → Version → Date
This allows Zehbia to maintain appropriate measurement history while reducing the need to repeatedly collect the same information.
6. PHOTOGRAPHS AND REFERENCE IMAGES
Where the service requires or permits it, customers may voluntarily provide:
Garment reference photographs
Design reference images
Fabric photographs
Stitching/reference photographs
Images relating to an order
Profile photographs
Such images may be processed for purposes such as:
Understanding design requirements;
Communicating tailoring instructions;
Processing an order;
Quality control;
Alterations;
Resolving disputes;
Maintaining order records; and
Providing requested services.
Zehbia will not use customer photographs for public advertising or promotional purposes without an appropriate legal basis and, where required, separate permission/consent.
7. BOOKING INFORMATION
When you book a service, we may collect:
Booking ID
Customer ID
Service type
Pickup/stitching requirement
Preferred date
Preferred time slot
Address
Field Officer assignment
Booking status
Notes/instructions
Pickup status
Visit status
Cancellation information
Rescheduling information
8. ORDER INFORMATION
When you place an order, we may collect and process:
Order ID
Customer ID
Garment type
Quantity
Fabric information
Measurement profile
Stitching specifications
Design preferences
Alteration instructions
Assigned tailor
Warehouse information
Quality-control information
Delivery information
Order status
Order history
Cancellation information
Refund information
Customer communications relating to the order
9. PAYMENT INFORMATION
When you make a payment through Zehbia, we may process:
Payment reference number
Transaction ID
Order ID
Amount
Currency
Payment status
Payment date/time
Payment method
Refund information
Payment gateway response
Invoice information
We do not intend to store complete payment-card credentials such as:
Full card number;
CVV;
Card PIN; or
Internet banking password.
Where payment services are provided by a third-party payment gateway, payment information may be processed directly by that provider in accordance with its own privacy policy and applicable requirements.
Zehbia may retain transaction references necessary for accounting, reconciliation, customer support, fraud prevention, legal compliance and dispute resolution.
10. OTP AND AUTHENTICATION INFORMATION
Zehbia may use mobile OTP authentication.
We may process:
Mobile number;
OTP verification status;
OTP request timestamp;
OTP expiry;
Authentication attempts;
Device/session information;
Security/rate-limiting information.
OTP values should be used only for authentication and should not be retained longer than necessary.
For security purposes, Zehbia may maintain limited authentication logs, such as timestamps, request counts and verification status.
11. DEVICE AND TECHNICAL INFORMATION
When you access Zehbia's website or application, we may automatically collect certain technical information, including:
IP address;
Browser type;
Operating system;
Device type;
Application version;
Session information;
Login timestamps;
Device/security identifiers where technically required;
Error logs;
Crash information;
Approximate network information;
Security and fraud-prevention information.
This information may be used to maintain the security, reliability and performance of the platform.
12. LOCATION INFORMATION
Zehbia may process location-related information where it is necessary for a service you request.
For example, location-related information may be used for:
Home visit scheduling;
Pickup;
Delivery;
Field Officer assignment;
Service availability;
Route/service coordination.
Zehbia will request device-level location permission where such permission is required by the operating system.
Important
Zehbia should not collect continuous background location information unless such functionality is specifically required, clearly disclosed and legally justified.
For normal customer bookings, Zehbia should prefer address information provided directly by the customer rather than continuous GPS tracking.
13. HOW WE USE YOUR PERSONAL DATA
We may process personal data for the following purposes.
13.1 Account Management
To:
Create your account;
Verify your mobile number;
Authenticate you;
Maintain your profile;
Manage login sessions;
Secure your account.
13.2 Providing Tailoring Services
To:
Take and maintain measurements;
Manage measurement profiles;
Process tailoring requests;
Manage fabric pickup;
Assign field officers;
Assign warehouse staff;
Assign tailors;
Perform quality checks;
Manage alterations;
Arrange delivery.
13.3 Booking Management
To:
Create bookings;
Schedule appointments;
Confirm appointments;
Assign personnel;
Reschedule bookings;
Send booking notifications.
13.4 Order Management
To:
Create orders;
Track orders;
Maintain order history;
Process tailoring instructions;
Manage production;
Manage quality control;
Manage delivery;
Resolve order issues.
13.5 Payments
To:
Process payments;
Verify transactions;
Generate invoices;
Process refunds;
Reconcile transactions;
Detect suspicious transactions;
Maintain financial records.
13.6 Customer Support
To:
Respond to queries;
Resolve complaints;
Investigate order issues;
Handle refund requests;
Handle measurement/fitting issues;
Maintain support records.
13.7 Notifications
To send:
OTPs;
Booking confirmations;
Order status updates;
Pickup notifications;
Delivery notifications;
Payment confirmations;
Important service notices;
Account/security alerts.
14. OFFERS, CASHBACK AND MARKETING
Where permitted and appropriately disclosed, Zehbia may use certain personal data to provide:
Offers;
Discounts;
Cashback;
Loyalty benefits;
Promotional communications;
Product/service recommendations.
Marketing communications may be sent through channels such as:
SMS;
Email;
Push notifications;
WhatsApp or similar communication channels, where applicable.
You may have the ability to opt out of promotional communications.
Service vs Marketing Messages
Even if you opt out of promotional communications, Zehbia may continue sending essential service communications, such as:
OTPs;
Security alerts;
Booking confirmations;
Order updates;
Payment confirmations;
Delivery notifications;
Account-related notices.
15. NOTICE BOARD AND AD CENTRE
Zehbia may operate:
Notice Board;
Ad Centre;
Promotional banners;
Offers;
Campaigns;
Partner promotions.
Some advertisements may be displayed based on general audience categories or service context.
Unless separately disclosed and legally permitted, Zehbia should not provide identifiable customer personal data to advertisers merely for their own independent marketing purposes.
16. LEGAL BASES / PURPOSES FOR PROCESSING
Zehbia may process personal data where permitted under applicable law, including where:
you provide consent for a specified purpose;
processing is necessary to provide a service requested by you;
processing is necessary for a permitted legitimate purpose under applicable law;
processing is required to comply with a legal obligation;
processing is necessary for security, fraud prevention or protection of rights;
processing is necessary to respond to a lawful request or legal process; or
another lawful basis permitted under applicable Indian law applies.
Where consent is relied upon, Zehbia will seek to make the request understandable and appropriately specific.
17. CONSENT
Where Zehbia relies on consent, consent will be obtained through an appropriate mechanism.
For example, the registration process may contain:
☐ I have read and understood the Privacy Notice and agree to the processing of my personal data as described in it.
Where separate consent is required for an optional purpose, Zehbia should use a separate consent mechanism rather than bundling unrelated purposes into a single mandatory acceptance.
Example
Marketing consent should not be disguised as a condition for creating an account where marketing is not necessary for providing the requested service.
18. WITHDRAWAL OF CONSENT
Where processing is based on consent, you may withdraw your consent through the mechanisms made available by Zehbia.
Withdrawal of consent does not affect the lawfulness of processing that occurred before the withdrawal.
Withdrawal may also affect Zehbia's ability to provide certain services where the relevant data is necessary for that service.
For example, if information necessary to complete a requested tailoring service is deleted or its processing is restricted, Zehbia may be unable to complete that service.
19. DATA MINIMISATION
Zehbia follows the principle that personal data should be collected only to the extent reasonably necessary for the relevant purpose.
Accordingly:
Zehbia should not collect unnecessary personal information;
Measurement fields should be garment-specific;
Optional information should be clearly identified;
Location access should not be unnecessarily continuous;
Payment credentials should not be unnecessarily stored;
Personal data should not be retained indefinitely.
20. DATA SHARING
Zehbia may share personal data with selected third parties where necessary for providing services, operating the platform, maintaining security, complying with law or performing other disclosed purposes.
These may include:
20.1 Field Officers
Relevant information may be shared with an assigned Field Officer, such as:
Customer name;
Contact number;
Appointment information;
Service address;
Booking details;
Relevant measurement information;
Pickup/delivery instructions.
Field Officers should only receive information necessary for performing their assigned responsibilities.
21. TAILORS AND PRODUCTION STAFF
Relevant information may be made available to assigned tailoring/production personnel, including:
Order ID;
Garment type;
Measurements;
Stitching instructions;
Fabric/design information;
Alteration requirements;
Relevant reference images.
Personnel should not have unrestricted access to unrelated customer information.
22. WAREHOUSE AND QUALITY-CONTROL STAFF
Where required for operations, relevant order information may be shared with:
Warehouse personnel;
Quality-control personnel;
Dispatch personnel.
Access should be restricted according to operational responsibility.
23. DELIVERY PARTNERS
Where third-party delivery services are used, relevant information may be shared, such as:
Customer name;
Delivery address;
Contact number;
Order/delivery reference;
Delivery instructions.
Only information reasonably necessary for delivery should be shared.
24. SERVICE PROVIDERS
Zehbia may use third-party technology/service providers for:
Cloud hosting;
Database infrastructure;
SMS/OTP;
Email;
Push notifications;
Payment processing;
Analytics;
Error monitoring;
Customer support;
Backup;
Security;
CDN;
Website/application infrastructure.
Such providers should receive only the information reasonably necessary for the services they provide and should be contractually or otherwise appropriately governed where required.
25. CURRENT / PLANNED ZEHBIA TECHNOLOGY PROVIDERS
The actual provider list must be finalized before production launch.
The implementation may include providers such as:
Important: This table must be updated with the actual providers before publication.
26. DATA PROCESSORS
Where a third party processes personal data on Zehbia's behalf, Zehbia will seek to establish appropriate contractual, technical and organisational safeguards.
Third-party processors should not be permitted to use Zehbia customer data for unrelated purposes unless separately authorised and legally permitted.
27. INTERNATIONAL DATA TRANSFERS
Some technology providers used by Zehbia may process or store information outside India.
Where personal data is transferred outside India, Zehbia will implement such transfer in accordance with applicable Indian law, including any restrictions, requirements or conditions applicable to transfers to jurisdictions outside India.
Zehbia may update this Privacy Notice when material changes occur in its international data-processing arrangements.
28. DATA SECURITY
Zehbia will implement reasonable technical and organisational security measures appropriate to the nature of personal data and the risks associated with its processing.
These measures may include:
Encryption in transit;
Encryption at rest where appropriate;
Secure password/token handling;
JWT and refresh-token controls;
Role-Based Access Control;
Least-privilege access;
Database access controls;
API authentication;
API authorisation;
Rate limiting;
OTP attempt limits;
Session management;
Audit logs;
Security monitoring;
Backups;
Vulnerability management;
Secure software development practices;
Access reviews;
Employee confidentiality obligations.
The final technical controls should be documented internally in Zehbia's security architecture and information-security procedures.
29. ACCESS CONTROL
Zehbia's internal systems should follow the principle of least privilege.
For example:
Customer
→ Own profile→ Own measurements→ Own bookings→ Own orders→ Own payments
Field Officer
→ Assigned bookings/customers only
Tailor
→ Assigned production jobs only
Warehouse
→ Relevant assigned warehouse orders only
Quality Control
→ Relevant QC orders only
Finance
→ Relevant payment/order information
Administrator
→ Access according to assigned administrative permissions.
Access should not automatically mean unrestricted access to all customer data.
30. DATA BREACH AND SECURITY INCIDENTS
If Zehbia becomes aware of a personal data breach, Zehbia will assess and respond to the incident in accordance with applicable law.
Depending on the nature and severity of the incident, Zehbia may:
investigate the incident;
contain the incident;
secure affected systems;
assess affected personal data;
document the incident;
notify relevant authorities where legally required;
notify affected individuals where legally required;
take remedial measures; and
implement measures to prevent recurrence.
The DPDP Rules include specific requirements relating to personal-data breach notifications and security safeguards.
31. DATA RETENTION
Zehbia will not retain personal data indefinitely merely because it has been collected.
Personal data should be retained only for as long as reasonably necessary for:
Providing requested services;
Maintaining order history;
Customer support;
Accounting;
Tax requirements;
Legal claims;
Fraud prevention;
Security;
Compliance with applicable law;
Resolving disputes.
Different categories of information may therefore have different retention periods.
32. PROPOSED RETENTION FRAMEWORK
The following is the recommended starting framework and should be confirmed by Zehbia's legal/accounting team:
Do not publish these periods until the actual business and legal retention schedule has been approved.
33. ACCOUNT DELETION
Customers may request deletion of their Zehbia account through:
In-app account deletion;
Website account deletion;
Customer support;
Other mechanism provided by Zehbia.
Where an account-deletion feature is provided, Zehbia should clearly explain what will happen when the account is deleted.
Certain information may need to be retained where required or permitted by law, including:
Financial records;
Tax records;
Transaction records;
Fraud/security records;
Legal claims;
Regulatory records;
Information required to establish, exercise or defend legal rights.
Where information cannot immediately be deleted because of such requirements, access and further processing should be restricted to the relevant purpose.
34. DELETION OF MEASUREMENT DATA
Because measurements are a core Zehbia service feature, customers may request deletion of measurement profiles where applicable.
If measurement information is deleted:
Future tailoring may require fresh measurements;
Existing orders may still require certain historical information where necessary;
Legally required records may not be immediately deleted.
35. CUSTOMER RIGHTS
Subject to applicable law and any conditions or exceptions provided by law, individuals may have rights relating to their personal data, including rights to:
Obtain information about processing;
Access information;
Request correction;
Request erasure/deletion;
Withdraw consent where consent is the basis;
Obtain information regarding grievance mechanisms;
Nominate another individual to exercise rights in specified circumstances.
The DPDP Act expressly establishes rights for Data Principals, including access to information, correction/erasure, grievance redressal and nomination, subject to the Act's provisions.
36. CORRECTION OF PERSONAL DATA
If information associated with your Zehbia account is inaccurate, incomplete or outdated, you may request correction through available account-management features or by contacting Zehbia.
For example, you may request correction of:
Name;
Mobile number;
Email;
Address;
Measurement;
Stitching preference;
Other account information.
37. GRIEVANCE REDRESSAL
If you have a privacy or personal-data concern, you may contact:
Grievance Officer / Privacy ContactName: Suhail FarooqDesignation: Manager OperationsEmail: zehbia@zehbia.com Phone: +91-889-974-9158Address: 1324 Khadim Villa Mehjoor Nagar Natipora Srinagar Kashmir JK-190015
Zehbia will establish an appropriate grievance mechanism and process complaints in accordance with applicable law.
38. NOMINATION
Where applicable under the DPDP framework, Zehbia will provide a mechanism through which a Data Principal may nominate another individual to exercise specified rights in the event of death or incapacity, subject to applicable legal requirements.
The exact procedure will be published when the corresponding statutory requirements become applicable to Zehbia.
39. CHILDREN'S PERSONAL DATA
Zehbia's services are intended primarily for individuals capable of independently using the services in accordance with applicable law.
Where Zehbia processes personal data relating to children, Zehbia will implement the safeguards required under applicable law.
Zehbia will not knowingly use children's personal data for:
Behavioural monitoring;
Targeted advertising; or
Other prohibited purposes,
where such processing is prohibited by applicable law.
Where parental/guardian consent or other requirements apply, Zehbia will implement appropriate mechanisms.
40. CUSTOMER-PROVIDED INFORMATION ABOUT OTHER PEOPLE
Customers should not provide Zehbia with another person's personal data unless they have the authority or lawful basis to provide it.
For example, if a customer creates an order for:
A spouse;
Parent;
Child;
Relative;
Employee;
Another customer,
the customer should ensure that they are authorised to provide the information.
41. CUSTOMER CONTENT
Where customers upload:
Images;
Designs;
Reviews;
Feedback;
Instructions;
Other content,
Zehbia may process that content to provide the requested services.
Customers should not upload:
Unnecessary personal information of others;
Government IDs unless specifically requested through an authorised Zehbia process;
Financial credentials;
Passwords;
OTPs;
Sensitive information unrelated to the tailoring service.
42. COOKIES AND SIMILAR TECHNOLOGIES
Zehbia may use cookies and similar technologies to:
Maintain login sessions;
Remember preferences;
Improve website functionality;
Measure performance;
Detect fraud/security issues;
Understand usage patterns;
Provide relevant functionality.
Where required, Zehbia will provide appropriate cookie controls and information.
A separate Cookie Policy may be published where the website uses non-essential cookies or similar technologies.
43. ANALYTICS
Zehbia may use analytics technologies to understand:
Website usage;
Application performance;
Feature usage;
Error rates;
User journeys;
Technical performance.
Analytics should be configured to minimise unnecessary collection of personal data.
Where third-party analytics services are used, their applicable privacy terms should also be reviewed.
44. PERSONALISATION
Zehbia may use information such as:
Garment preferences;
Previous orders;
Measurements;
Service history;
Offers previously used,
to improve the customer's experience.
Personalisation will be subject to applicable legal requirements and the purposes communicated to the customer.
45. AUTOMATED DECISION-MAKING
Zehbia may use automated systems for limited operational purposes such as:
Fraud detection;
Security monitoring;
Appointment allocation;
Notification delivery;
Operational prioritisation.
Zehbia will not use automated processing to make decisions producing legally significant or similarly significant effects on individuals unless such processing is lawful and appropriately disclosed.
46. THIRD-PARTY WEBSITES AND SERVICES
Zehbia may contain links to third-party websites or services.
Examples may include:
Payment gateways;
Social media;
Maps;
Delivery tracking;
Partner websites.
Zehbia is not responsible for the privacy practices of independent third parties.
Customers should review the applicable privacy notices of those services before providing information.
47. BUSINESS TRANSFERS
If Zehbia undergoes:
Merger;
Acquisition;
Restructuring;
Sale of assets;
Business transfer;
personal data may be transferred as part of the transaction, subject to applicable law and appropriate safeguards.
Customers will be informed where legally required.
48. GOVERNMENT AND LEGAL DISCLOSURES
Zehbia may disclose personal data where reasonably necessary to:
Comply with applicable law;
Respond to lawful government requests;
Comply with court orders;
Protect customers;
Prevent fraud;
Investigate security incidents;
Protect Zehbia's legal rights;
Establish, exercise or defend legal claims.
Zehbia will seek to limit such disclosure to what is reasonably necessary or legally required.
49. DATA ACCURACY
Customers are responsible for ensuring that information provided to Zehbia is accurate and updated.
This is particularly important for:
Measurements;
Address;
Contact number;
Delivery details;
Stitching instructions.
Incorrect information may result in:
Incorrect fitting;
Failed delivery;
Delayed service;
Additional alteration requirements.
50. MEASUREMENT ACCURACY DISCLAIMER
Tailoring measurements can change due to:
Body posture;
Measurement technique;
Garment style;
Fabric characteristics;
Fit preference;
Measurement conditions.
Zehbia will take reasonable operational measures to maintain measurement records but cannot guarantee that a stored measurement will remain accurate indefinitely.
Customers may request a fresh measurement where appropriate.
51. SECURITY OF CUSTOMER ACCOUNT
Customers are responsible for maintaining reasonable security over:
Their mobile device;
SIM/mobile number;
Email account;
Authentication sessions;
Account access.
Customers should never share:
OTPs;
Passwords;
Authentication codes;
Recovery information.
Zehbia staff should not request a customer's OTP for ordinary customer-support purposes.
52. FRAUD AND SECURITY MONITORING
Zehbia may process technical and account information to detect:
Fake accounts;
Repeated OTP abuse;
Payment fraud;
Account takeover;
Automated attacks;
Suspicious transactions;
Abuse of offers/cashback;
Platform attacks.
This may include maintaining security logs and blocking suspicious activity.
53. MARKETING PREFERENCES
Customers may manage promotional communication preferences through available:
Account settings;
Unsubscribe mechanisms;
Notification settings;
Customer support.
Where legally required, marketing communications will provide an appropriate opt-out mechanism.
54. PRIVACY OF EMPLOYEES AND OPERATIONAL USERS
Zehbia may also process personal data relating to:
Field Officers;
Tailors;
Warehouse staff;
Quality-control personnel;
Delivery personnel;
Administrators;
Other authorised users.
Such processing may be governed by separate internal employee/worker privacy notices and policies.
55. INTERNAL ACCESS TO CUSTOMER DATA
Zehbia personnel may access customer data only where reasonably required for their job responsibilities.
Examples:
Customer Support: customer/account/order information required to resolve an issue.
Field Officer: assigned booking and relevant customer information.
Tailor: assigned order, measurements and stitching instructions.
Warehouse: relevant order and production information.
Finance: payment and transaction information.
Administrator: information necessary for authorised administrative functions.
All privileged access should be logged where appropriate.
56. AUDIT LOGS
Zehbia may maintain audit records concerning activities such as:
Login;
Logout;
Account changes;
Measurement changes;
Order changes;
Payment changes;
Administrative actions;
Permission changes;
Data-access events;
Security events.
Audit records may be retained for security, accountability, fraud prevention and legal purposes.
57. PRIVACY BY DESIGN
Zehbia intends to incorporate privacy and security considerations into the design and development of its platform.
This includes:
Data minimisation;
Role-based access;
Purpose-based processing;
Secure authentication;
Secure APIs;
Access logging;
Controlled data sharing;
Retention controls;
Account deletion;
User rights mechanisms.
58. DATA PROTECTION IMPACT ASSESSMENT
Where required by applicable law or where Zehbia determines that processing presents significant privacy risks, Zehbia may conduct appropriate privacy/security assessments, including a Data Protection Impact Assessment or equivalent internal assessment.
59. SIGNIFICANT DATA FIDUCIARY
If Zehbia is notified or otherwise becomes subject to obligations applicable to a Significant Data Fiduciary, Zehbia will implement the additional requirements applicable to it.
This may include enhanced governance, assessments, audits and other measures prescribed by applicable law.
60. CHANGES TO THIS PRIVACY NOTICE
Zehbia may update this Privacy Notice from time to time.
Changes may be made because of:
New services;
New technology;
Changes to processing;
New service providers;
Legal/regulatory changes;
Security requirements;
Business changes.
The updated version will include a revised "Last Updated" date.
Where a change materially affects how personal data is processed, Zehbia will provide appropriate notice or obtain consent where legally required.
61. VERSION HISTORY
62. CONTACT US
For privacy-related questions, requests or complaints:
Zehbia Privacy Contact
Legal Entity: KHADIM SOLUTIONSBrand: Zehbia’s Wardrobe - A Tailoring PlatformAddress: 1324 Khadim Villa Mehjoor Nagar Natipora Srinagar Kashmir JK-190015Email: zehbia@zehbia.com Grievance Email: grievance@zehbia.com Customer Support: +91-889-974-9158Website: www.zehbia.com | www.zehbia.in
63. DATA RIGHTS REQUEST PROCEDURE
A customer may submit a privacy request through the mechanism provided by Zehbia.
The request may include:
Full name;
Registered mobile number/email;
Nature of request;
Relevant account/order reference, where applicable;
Supporting information reasonably required to verify the requester.
Zehbia may perform reasonable verification before acting on a request in order to protect the customer's account and personal data from unauthorised requests.
64. REQUEST TYPES
Available request categories may include:
A. Access / Information Request
Request information regarding processing of your personal data.
B. Correction Request
Request correction of inaccurate or incomplete personal data.
C. Erasure Request
Request deletion of personal data where applicable.
D. Consent Withdrawal
Withdraw consent where processing is based on consent.
E. Grievance
Raise a complaint regarding processing or privacy.
F. Nomination
Exercise nomination rights where applicable under law.
65. IDENTITY VERIFICATION
Zehbia may need to verify the identity of a person making a data request.
Verification may include:
OTP verification;
Registered email verification;
Account authentication;
Other reasonable verification mechanisms.
Zehbia should not request unnecessary identity documents merely to process an ordinary privacy request.
66. WHEN ZEHBIA MAY RETAIN INFORMATION
Even following an account deletion request, Zehbia may retain certain information where necessary for:
Compliance with law;
Tax/accounting requirements;
Fraud prevention;
Cybersecurity;
Dispute resolution;
Legal claims;
Regulatory requirements;
Establishing, exercising or defending legal rights.
Retained information should not be used for unrelated purposes merely because it remains in a backup or archive.
67. BACKUPS
Deleted information may remain temporarily within secure backups where immediate deletion from backup systems is technically impractical.
Zehbia should ensure that such information:
Is protected;
Is not restored except where necessary;
Is not used for ordinary business processing;
Is deleted or overwritten according to the applicable backup lifecycle.
68. EMPLOYEE CONFIDENTIALITY
Employees, contractors and authorised service personnel who have access to customer data should be subject to appropriate confidentiality obligations.
Access should be revoked when personnel:
Leave Zehbia;
Change roles;
No longer require access.
69. NO SALE OF CUSTOMER PERSONAL DATA
Zehbia does not intend to sell customer personal data as a commercial product.
Zehbia will not disclose customer personal data to third parties for independent commercial purposes except where:
The customer has been appropriately informed and the processing is lawful;
The disclosure is necessary for a requested service;
It is required or permitted by law; or
Another lawful basis applies.
70. PRIVACY POLICY DOES NOT OVERRIDE LAW
Nothing in this Privacy Notice is intended to:
Restrict any mandatory legal requirement;
Exclude any statutory right;
Limit consumer protection rights;
Prevent lawful government action;
Remove rights that cannot legally be waived.
If any provision conflicts with applicable mandatory law, the applicable law will prevail to the extent of the conflict.
71. GOVERNING LAW
This Privacy Notice shall be governed by the laws applicable in India.
Any disputes concerning privacy or personal-data processing shall be handled through the applicable grievance and legal mechanisms available under Indian law.
Nothing in this clause is intended to exclude statutory rights or remedies available to an individual.
72. IMPORTANT PRIVACY COMMITMENT
Zehbia's privacy approach can be summarised as:
Collect what we need.Explain why we need it.Use it for the stated purpose.Give access only to those who need it.Protect it appropriately.Retain it only as long as justified.Delete it when no longer required, subject to law.
73. CUSTOMER-FACING SHORT PRIVACY NOTICE
For the registration screen, I recommend not displaying the entire Privacy Policy.
Instead, use a short notice such as:
Your Privacy Matters
Zehbia collects and uses your personal information, such as your name, mobile number, address, measurements, booking, order and payment-related information, to provide and manage our tailoring services.
We may share relevant information with authorised personnel and service providers where necessary to complete your requested services.
For more information about how we collect, use, protect, retain and delete your personal data, please read our Privacy Notice.
[Read Privacy Notice]
Then:
☐ I have read and understood the Privacy Notice.
For optional marketing:
☐ I would like to receive offers, discounts, cashback and promotional communications from Zehbia.
The second checkbox should be separate from acceptance of the Privacy Notice.
74. RECOMMENDED APP REGISTRATION SCREEN
For the Zehbia application, I recommend this structure:
Create Your Zehbia Account
Mobile Number
[ +91 _____________ ]
[ Send OTP ]
By continuing, you acknowledge that you have read
and understood the Zehbia Privacy Notice and agree
to the Terms & Conditions.
[ Privacy Notice ] [ Terms & Conditions ]
☐ Send me offers, discounts and cashback updates.
[ Continue ]
This is substantially better than:
"I agree to Terms, Privacy Policy, Marketing, Offers and everything else."
because Zehbia should keep service acceptance and optional marketing logically separate.
75. RECOMMENDED DATA ARCHITECTURE FOR ZEHBIA
This Privacy Policy should also influence the actual database design.
For example:
Customer
│
├── Profile
│
├── Addresses
│
├── Measurement Profiles
│ ├── Garment Type
│ ├── Version
│ ├── Measurements
│ └── Preferences
│
├── Bookings
│
├── Orders
│ ├── Tailor
│ ├── Warehouse
│ ├── QC
│ └── Delivery
│
├── Payments
│
├── Notifications
│
├── Offers / Cashback
│
└── Privacy / Consent Records
For the Privacy/Consent Records, I strongly recommend maintaining fields such as:
ConsentRecord
-------------------------
id
customerId
purpose
consentStatus
consentVersion
privacyNoticeVersion
timestamp
source
withdrawnAt
This will give Zehbia a much better audit trail than simply storing:
marketingConsent = true
76. RECOMMENDED PRIVACY MODULE IN ADMIN
The Zehbia Admin Panel should eventually contain:
Privacy & Compliance
Privacy requests
Access requests
Correction requests
Deletion requests
Consent records
Consent withdrawal
Marketing preferences
Data export requests
Grievances
Data breach incidents
Audit logs
Retention configuration
Processor/vendor register
Privacy policy versions
This should be part of the platform architecture rather than something added after launch.
77. IMPORTANT IMPLEMENTATION REQUIREMENTS BEFORE LAUNCH
The Privacy Policy alone is not sufficient for DPDP compliance.
Before Zehbia goes live, the development team should implement at minimum:
Authentication
OTP expiry
OTP attempt limits
OTP resend cooldown
Rate limiting
Secure refresh-token handling
Session revocation
Authorisation
RBAC
Permission-based access
Resource-level access
Customer can access only their own records
Field Officer can access only assigned records
Tailor can access only assigned jobs
Database
Encryption where appropriate
Restricted DB access
No plaintext passwords
No unnecessary OTP storage
Audit fields
Soft-delete/retention strategy where appropriate
API
Authentication middleware
Authorisation guards
Input validation
Rate limiting
Secure headers
Logging
Error handling without exposing personal data
Privacy
Account deletion
Data correction
Consent management
Marketing opt-out
Privacy-request workflow
Data retention rules
Privacy policy versioning
Operations
Employee confidentiality
Access reviews
Staff offboarding
Incident response
Vendor/processor management
Backup policy
78. REGULATORY BASIS
This document has been drafted with reference to the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, as officially published by the Government of India/MeitY. The notified Rules contain a phased commencement framework, so Zehbia should implement the policy and technical controls in a manner that is ready for the applicable provisions as they become operative.
MeitY's own explanatory material states that the Rules provide the implementation framework for the DPDP Act and emphasise clear, simple communication and contextual explanations.