Privacy & data

Privacy Policy

What personal information this site and this showroom collect, why we collect it, who else sees it, how long we keep it, and what you can make us do about it.

Version
1.0
Effective
Last updated
Governing law
Pakistan

Applies to vevarte.com, our WhatsApp and social channels, and the showroom at E-100/14, Lower Ground, Main Boulevard, DHA, Lahore.

In plain English

  • You can browse and read everything here without telling us who you are.
  • We ask for a name, phone number and address only when you place an order — because furniture has to arrive somewhere.
  • We never sell personal information. We have never done it and the business model does not need it.
  • Non-essential cookies — analytics and advertising — are off until you turn them on. Rejecting them costs you nothing on this site.
  • Ask us to show you, correct or delete your data and we answer within 21 days.
  • Payment card details never touch our servers. Our own staff cannot see them either.

A summary, and a reading aid only. The numbered sections below are the operative terms, and where the two differ the sections are what apply.

#1. Who we are, and who is responsible

VEVARTE ("we", "us", "our") is a furniture and interiors retailer trading from E-100/14, Lower Ground, Main Boulevard, DHA, Lahore, Punjab, Pakistan, and online at vevarte.com. Ahsan Raza Khokhar, Founder & Chief Executive, is accountable for how personal information is handled here, and there is no committee behind that — if something has gone wrong with your data, one named person answers for it.

Where a data-protection law applies to you, we are the controller of the information described below, meaning we decide why and how it is processed. Where we use outside providers — hosting, payments, delivery, email — they act as processors on our written instructions, and are listed in section 6.

Privacy questions, requests and complaints: privacy@vevarte.com. We read that address ourselves. If you would rather write, the postal address above reaches the same desk.

#2. The four rules we hold ourselves to

Policies of this kind are usually written to permit as much as possible. This one is written to describe what we actually do, which is considerably less. Four commitments sit above everything below and constrain it.

  • We ask for the minimum. A delivery needs an address and a phone number. It does not need your date of birth, your occupation, or your income bracket, so we do not have a field for any of them.
  • We do not sell or rent personal information, to anyone, for any consideration, in any jurisdiction, under any definition of "sell" — including the broad ones in California and Colorado law.
  • Non-essential tracking is opt-in. Analytics and advertising cookies stay off until you choose otherwise, everywhere in the world, not only where the law compels it.
  • We tell you when something goes wrong. If a breach is likely to affect you, you hear it from us, and you hear it quickly — see section 10.

#3. What we collect

Grouped by how it reaches us, because that is what determines whether you have a choice about it.

Categories of personal information
CategoryExamplesHow it reaches usDo you have to give it?
Order and delivery dataName, phone number, delivery address, order contents, delivery notes ("gate is on the side street")You type it at checkout, or tell it to us in the showroom or on WhatsAppYes, to receive goods. There is no way to deliver a wardrobe anonymously
Payment metadataAmount, method, last four digits, authorisation reference, bank transfer sender nameFrom the payment provider or your bank after a paymentYes, to complete a purchase
CorrespondenceEmails, WhatsApp messages, showroom enquiry notes, complaint records, call notesYou contact usNo — but we cannot answer a question you have not asked
Reviews and submitted contentYour display name, rating, review text, any photograph you attachYou submit it, knowing it will be publicNo. Entirely voluntary
Device and usage dataIP address, browser and device type, pages viewed, referring page, approximate cityAutomatically, from the request your browser makesThe request itself is unavoidable; storing it for analytics is not, and needs your consent
Cookie and local storage dataConsent choice, cart contents, wishlist, recently viewed piecesStored in your own browserCart and consent are essential; the rest you can clear at any time
Marketing preferencesEmail or WhatsApp opt-in, the date and source of that opt-in, unsubscribe eventsYou opt inNo. Opt-in only, always
Showroom CCTVRecorded images inside and at the entrance of the showroomAutomatically, while you are on the premises. Signage is posted at the doorNot while you are in the shop, no

We also hold information that is not personal at all: aggregate sales figures, stock levels, which categories sell in which month. None of that identifies anyone and this policy does not restrict it.

#4. Why we use it, and on what legal basis

The "legal basis" column matters if the GDPR or UK GDPR applies to you — see the EEA and UK notice. If neither applies, read it as the reason we consider the use fair.

PurposeInformation usedLegal basis
Take, confirm and deliver your order; arrange installationOrder and delivery data, payment metadataPerformance of a contract with you
Take payment and detect fraudulent ordersPayment metadata, IP address, order historyContract; legitimate interests in not being defrauded
Answer enquiries and handle complaintsCorrespondence, order historyContract, or legitimate interests in running a shop people can talk to
Honour the guarantee and process returnsOrder data, correspondence, photographs you send of a faultContract; compliance with consumer law
Keep books, invoices and tax recordsOrder and payment data, tax identifiersLegal obligation — the Sale of Goods Act 1930 and Pakistani tax law
Understand which pages and pieces people actually look atDevice and usage data, in aggregateConsent (analytics cookies)
Show advertising, including personalised advertisingDevice data, cookie identifiersConsent (advertising cookies). Off entirely until you allow it
Send offers, new arrivals and journal postsEmail or phone number, marketing preferencesConsent, withdrawable in one click
Publish your reviewDisplay name, rating, review textConsent, given when you submit it
Protect the premises and stockCCTV footageLegitimate interests in security of people and goods
Defend a legal claim, or bring oneWhatever is relevant to the claimLegitimate interests; establishment or defence of legal claims

Where we rely on legitimate interests, we have weighed them against your rights and recorded the reasoning. Ask at privacy@vevarte.com and we will send you the assessment for the purpose you are asking about.

#5. Cookies, analytics and advertising

This is summarised here and set out in full — including a table of every cookie by name — in the Cookie Policy.

Three categories exist on this site. Strictly necessary cookies remember your cart, your consent choice and keep checkout secure; they cannot be switched off, and no law requires consent for them. Analytics tells us which pages are read and which pieces are looked at. Advertising allows advertising partners to select and measure ads, and to personalise them.

Analytics and advertising are denied by default, before you interact with the banner at all. We implement this through Google Consent Mode, which means the relevant tags are constrained rather than merely unloaded, and it applies to every visitor regardless of country.

You can change your mind whenever you like: the Manage cookies link in the footer of every page reopens the panel, and clearing your browser storage resets us to asking. Your choice is remembered for 12 months.

If and when advertising runs here, third parties — including Google — will set their own cookies and use device identifiers under their own privacy policies, and the Advertising & Sponsorship Disclosure names them and explains the opt-outs that work network-wide.

#6. Who else sees your information

We share the minimum necessary, with the parties below, and with nobody else. This list is exhaustive as at the date above.

RecipientWhat they receiveWhyWhere they process it
Google Cloud / Firebase (Google LLC)Everything stored by the site — orders, correspondence, filesHosting, database and file storageUnited States (Firestore nam5 multi-region; server logic in us-central1)
Google Analytics (Google LLC)Device and usage data, only with your consentTraffic measurementRegional; IP truncated
Google AdSense (Google LLC)Device and cookie data, only with your consent, only if advertising is activeAd selection, delivery and measurementGlobal
Payment providers and banksAmount, reference, and whatever your card scheme requiresTaking paymentPakistan, and the card scheme’s own network
Delivery crews and couriers (TCS, Leopards, M&P)Name, address, phone number, parcel descriptionGetting the goods to youPakistan
Workshops and makers, for commissionsFirst name and the specification. Never your address or phone numberMaking the piecePakistan
Meta Platforms (WhatsApp, Facebook, Instagram)The messages you choose to send us there, and your profile as that platform exposes itBecause you contacted us on their serviceGlobal
Accountant, auditor and legal advisersRecords relevant to their engagementStatutory accounts, tax filing, advicePakistan
Government, tax authority, police or a courtOnly what a valid, lawful demand actually requiresLegal obligationPakistan

If the business is ever sold or merged, records may transfer with it, and you will be told before that happens — not afterwards. A buyer inherits this policy and cannot broaden it retroactively without asking you again.

#7. Where your information goes

Two places, and it is worth being exact because most policies are vague here. We are in Pakistan — the showroom, the staff, the delivery crews and anyone reading your order. Our data is in the United States: the Firestore database sits in Google's `nam5` multi-region and the server logic runs in `us-central1` beside it. That location is permanent — a Firestore database cannot be moved after creation — and it is a deliberate, recorded decision rather than an accident.

For visitors protected by the GDPR or UK GDPR: Google LLC self-certifies under the EU-U.S. Data Privacy Framework and its UK Extension, and transfers to Google additionally rely on the European Commission's Standard Contractual Clauses incorporated in Google's Data Processing Terms. Access by us in Pakistan relies on the SCCs where a processor is exporting, and on Article 49(1)(b) — necessity for a contract you asked for — where you have placed an order. Pakistan has no adequacy decision, and we say so plainly rather than leaving it to be discovered.

The practical consequence, stated rather than buried: your order data is stored on US infrastructure and is reachable by us from Pakistan. If that is not acceptable to you, buy in the showroom and pay in cash — we will take the order on paper and it will never enter the system. That option is genuinely available and we will not make it awkward.

#8. How long we keep it

Nothing is kept "indefinitely". Each category has a period, and it runs from the last activity on the record unless stated otherwise.

RecordKept forWhy that long
Order, invoice and delivery records7 yearsTax and accounting law, and the outer limit for a contract claim
Payment metadata6 yearsReconciliation, chargebacks and audit
Guarantee recordsThe guarantee period plus 1 yearSo a claim in the last month of cover can still be evidenced
Support and WhatsApp correspondence24 monthsContext for a repeat enquiry, then it stops being useful
Complaint files7 yearsLimitation periods, and so a pattern is visible if one exists
Marketing list entries36 months of no engagement, then deletedA list nobody opens is a liability, not an asset
Analytics data14 monthsGoogle Analytics retention, set to the shortest useful setting
Consent records12 months after the choice or its withdrawalTo prove what you were asked and what you answered
Server and security logs90 daysAbuse investigation and debugging
Showroom CCTV30 days, then overwrittenLong enough to investigate an incident, short enough not to be an archive
Published reviewsUntil you ask us to remove yoursThey are your words and you can withdraw them

When a period expires the record is deleted or irreversibly anonymised. Anonymised figures — how many dining tables sold in June — survive, because they are no longer about anyone.

#9. Your rights, and how to use them

We extend the following to everyone who asks, wherever you live. We are not going to check whether your country has passed a statute before treating you decently.

Access
A copy of the personal information we hold about you, in a readable format.
Correction
Fix anything wrong. Usually done the same day.
Deletion
Erase it, except where tax or accounting law requires us to keep an invoice — in which case we say exactly what we kept and why.
Portability
Your data as machine-readable JSON or CSV, to take elsewhere.
Objection
Tell us to stop a processing based on legitimate interests. For direct marketing this is absolute and immediate.
Restriction
Freeze processing while a dispute about accuracy or lawfulness is resolved.
Withdraw consent
For anything based on consent — cookies, marketing, a published review. Withdrawal is as easy as giving it and does not affect what was lawful beforehand.
Human review
We make no automated decisions with legal or similarly significant effects. If that ever changes you will be told, and a person will review any such decision on request.
  1. Email privacy@vevarte.com saying what you want. Plain language is fine — "send me everything you have" is a valid request and we will treat it as one.
  2. We acknowledge it and, if we genuinely cannot tell who you are from the request, ask for one proof point — usually the order number and the phone number on it. We will not demand a copy of your passport to release an address you already gave us.
  3. We respond within 21 days. If a request is unusually complex we may extend, up to 30 days in total, and we will tell you why before the first period expires.
  4. There is no charge. If a request were truly repetitive or excessive we could charge a reasonable fee or decline, and we would explain which and why — but we have never done so.

Unhappy with the outcome? Section 11 sets out where to escalate. Escalating never requires our permission and never affects how we treat you.

#10. How we protect it, and what happens if that fails

  • Every connection to this site is encrypted in transit (TLS), and data is encrypted at rest by Google Cloud.
  • Access to customer records is restricted by role and enforced in the database itself, not by hiding menu items — a member of staff without the role is refused by Firestore, not merely shown a smaller screen.
  • Card details are handled entirely by the payment provider. They never reach our servers or our staff, so they cannot leak from us.
  • Secrets and credentials are held server-side and are never present in anything your browser downloads.
  • Staff accounts are individual, never shared, and actions on money, stock and permissions are written to an audit log.

No system is perfectly secure and anyone who tells you otherwise is selling something. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours of becoming aware, and tell affected people directly and without undue delay — describing what happened, what was exposed, and what we are doing about it.

Found a vulnerability? Please report it — see the Security & Vulnerability Disclosure Policy. Good-faith research is welcome and we will not pursue you for it.

#11. Complaints and supervisory authorities

Come to us first at privacy@vevarte.com — most privacy complaints turn out to be a misunderstanding that takes ten minutes to clear up. You are never obliged to, and you do not lose any right by trying.

  • Pakistan — the draft Personal Data Protection Bill is not yet enacted, so there is no data-protection regulator here yet. Complaints about unlawful access to a computer system fall under the Prevention of Electronic Crimes Act 2016 and go to the National Cyber Crime Investigation Agency. Consumer complaints go to the District Consumer Court, Lahore.
  • EEA — the data protection authority in the country where you live, work, or where the problem happened. A directory is published by the European Data Protection Board.
  • United Kingdom — the Information Commissioner's Office, at ico.org.uk.
  • United States — your state Attorney General; California residents may also contact the California Privacy Protection Agency.

#12. Children

This is a furniture shop. It is not directed at children, holds nothing that would interest one, and we do not knowingly collect information from anyone under 13 — or under 16 where the GDPR sets that as the age of consent for online services.

Purchases require legal capacity to contract, which in Pakistan means 18 or over.

If you believe a child has given us personal information, write to privacy@vevarte.com and we will delete it — no verification hoops, no argument about whether we were obliged to.

#13. Changes to this policy

When we change this policy the version and date at the top change with it. Substantive changes — a new category of data, a new recipient, a new purpose — are announced by a notice on the site for thirty days, and by email to anyone on our list.

A change is never applied retroactively to information already collected under an earlier version in a way that would surprise you. Where consent was the basis, a materially new purpose means asking again rather than assuming the old answer covers it.

Questions about this document

A person reads every one of these addresses. If you are not sure which to use, any of them reaches us.

General and orders
sales@vevarte.com
Privacy and data requests
privacy@vevarte.com
Legal and copyright
legal@vevarte.com
Complaints
complaints@vevarte.com
Telephone
+92 300 7512464
Postal and showroom
E-100/14, Lower Ground, Main Boulevard, DHA, Lahore, Pakistan