#1. Who we are, and who is responsible
VEVARTE ("we", "us", "our") is a furniture and interiors retailer trading from E-100/14, Lower Ground, Main Boulevard, DHA, Lahore, Punjab, Pakistan, and online at vevarte.com. Ahsan Raza Khokhar, Founder & Chief Executive, is accountable for how personal information is handled here, and there is no committee behind that — if something has gone wrong with your data, one named person answers for it.
Where a data-protection law applies to you, we are the controller of the information described below, meaning we decide why and how it is processed. Where we use outside providers — hosting, payments, delivery, email — they act as processors on our written instructions, and are listed in section 6.
Privacy questions, requests and complaints: privacy@vevarte.com. We read that address ourselves. If you would rather write, the postal address above reaches the same desk.
#2. The four rules we hold ourselves to
Policies of this kind are usually written to permit as much as possible. This one is written to describe what we actually do, which is considerably less. Four commitments sit above everything below and constrain it.
- We ask for the minimum. A delivery needs an address and a phone number. It does not need your date of birth, your occupation, or your income bracket, so we do not have a field for any of them.
- We do not sell or rent personal information, to anyone, for any consideration, in any jurisdiction, under any definition of "sell" — including the broad ones in California and Colorado law.
- Non-essential tracking is opt-in. Analytics and advertising cookies stay off until you choose otherwise, everywhere in the world, not only where the law compels it.
- We tell you when something goes wrong. If a breach is likely to affect you, you hear it from us, and you hear it quickly — see section 10.
#3. What we collect
Grouped by how it reaches us, because that is what determines whether you have a choice about it.
| Category | Examples | How it reaches us | Do you have to give it? |
|---|---|---|---|
| Order and delivery data | Name, phone number, delivery address, order contents, delivery notes ("gate is on the side street") | You type it at checkout, or tell it to us in the showroom or on WhatsApp | Yes, to receive goods. There is no way to deliver a wardrobe anonymously |
| Payment metadata | Amount, method, last four digits, authorisation reference, bank transfer sender name | From the payment provider or your bank after a payment | Yes, to complete a purchase |
| Correspondence | Emails, WhatsApp messages, showroom enquiry notes, complaint records, call notes | You contact us | No — but we cannot answer a question you have not asked |
| Reviews and submitted content | Your display name, rating, review text, any photograph you attach | You submit it, knowing it will be public | No. Entirely voluntary |
| Device and usage data | IP address, browser and device type, pages viewed, referring page, approximate city | Automatically, from the request your browser makes | The request itself is unavoidable; storing it for analytics is not, and needs your consent |
| Cookie and local storage data | Consent choice, cart contents, wishlist, recently viewed pieces | Stored in your own browser | Cart and consent are essential; the rest you can clear at any time |
| Marketing preferences | Email or WhatsApp opt-in, the date and source of that opt-in, unsubscribe events | You opt in | No. Opt-in only, always |
| Showroom CCTV | Recorded images inside and at the entrance of the showroom | Automatically, while you are on the premises. Signage is posted at the door | Not while you are in the shop, no |
We also hold information that is not personal at all: aggregate sales figures, stock levels, which categories sell in which month. None of that identifies anyone and this policy does not restrict it.
#4. Why we use it, and on what legal basis
The "legal basis" column matters if the GDPR or UK GDPR applies to you — see the EEA and UK notice. If neither applies, read it as the reason we consider the use fair.
| Purpose | Information used | Legal basis |
|---|---|---|
| Take, confirm and deliver your order; arrange installation | Order and delivery data, payment metadata | Performance of a contract with you |
| Take payment and detect fraudulent orders | Payment metadata, IP address, order history | Contract; legitimate interests in not being defrauded |
| Answer enquiries and handle complaints | Correspondence, order history | Contract, or legitimate interests in running a shop people can talk to |
| Honour the guarantee and process returns | Order data, correspondence, photographs you send of a fault | Contract; compliance with consumer law |
| Keep books, invoices and tax records | Order and payment data, tax identifiers | Legal obligation — the Sale of Goods Act 1930 and Pakistani tax law |
| Understand which pages and pieces people actually look at | Device and usage data, in aggregate | Consent (analytics cookies) |
| Show advertising, including personalised advertising | Device data, cookie identifiers | Consent (advertising cookies). Off entirely until you allow it |
| Send offers, new arrivals and journal posts | Email or phone number, marketing preferences | Consent, withdrawable in one click |
| Publish your review | Display name, rating, review text | Consent, given when you submit it |
| Protect the premises and stock | CCTV footage | Legitimate interests in security of people and goods |
| Defend a legal claim, or bring one | Whatever is relevant to the claim | Legitimate interests; establishment or defence of legal claims |
Where we rely on legitimate interests, we have weighed them against your rights and recorded the reasoning. Ask at privacy@vevarte.com and we will send you the assessment for the purpose you are asking about.
#7. Where your information goes
Two places, and it is worth being exact because most policies are vague here. We are in Pakistan — the showroom, the staff, the delivery crews and anyone reading your order. Our data is in the United States: the Firestore database sits in Google's `nam5` multi-region and the server logic runs in `us-central1` beside it. That location is permanent — a Firestore database cannot be moved after creation — and it is a deliberate, recorded decision rather than an accident.
For visitors protected by the GDPR or UK GDPR: Google LLC self-certifies under the EU-U.S. Data Privacy Framework and its UK Extension, and transfers to Google additionally rely on the European Commission's Standard Contractual Clauses incorporated in Google's Data Processing Terms. Access by us in Pakistan relies on the SCCs where a processor is exporting, and on Article 49(1)(b) — necessity for a contract you asked for — where you have placed an order. Pakistan has no adequacy decision, and we say so plainly rather than leaving it to be discovered.
The practical consequence, stated rather than buried: your order data is stored on US infrastructure and is reachable by us from Pakistan. If that is not acceptable to you, buy in the showroom and pay in cash — we will take the order on paper and it will never enter the system. That option is genuinely available and we will not make it awkward.
#8. How long we keep it
Nothing is kept "indefinitely". Each category has a period, and it runs from the last activity on the record unless stated otherwise.
| Record | Kept for | Why that long |
|---|---|---|
| Order, invoice and delivery records | 7 years | Tax and accounting law, and the outer limit for a contract claim |
| Payment metadata | 6 years | Reconciliation, chargebacks and audit |
| Guarantee records | The guarantee period plus 1 year | So a claim in the last month of cover can still be evidenced |
| Support and WhatsApp correspondence | 24 months | Context for a repeat enquiry, then it stops being useful |
| Complaint files | 7 years | Limitation periods, and so a pattern is visible if one exists |
| Marketing list entries | 36 months of no engagement, then deleted | A list nobody opens is a liability, not an asset |
| Analytics data | 14 months | Google Analytics retention, set to the shortest useful setting |
| Consent records | 12 months after the choice or its withdrawal | To prove what you were asked and what you answered |
| Server and security logs | 90 days | Abuse investigation and debugging |
| Showroom CCTV | 30 days, then overwritten | Long enough to investigate an incident, short enough not to be an archive |
| Published reviews | Until you ask us to remove yours | They are your words and you can withdraw them |
When a period expires the record is deleted or irreversibly anonymised. Anonymised figures — how many dining tables sold in June — survive, because they are no longer about anyone.
#9. Your rights, and how to use them
We extend the following to everyone who asks, wherever you live. We are not going to check whether your country has passed a statute before treating you decently.
- Access
- A copy of the personal information we hold about you, in a readable format.
- Correction
- Fix anything wrong. Usually done the same day.
- Deletion
- Erase it, except where tax or accounting law requires us to keep an invoice — in which case we say exactly what we kept and why.
- Portability
- Your data as machine-readable JSON or CSV, to take elsewhere.
- Objection
- Tell us to stop a processing based on legitimate interests. For direct marketing this is absolute and immediate.
- Restriction
- Freeze processing while a dispute about accuracy or lawfulness is resolved.
- Withdraw consent
- For anything based on consent — cookies, marketing, a published review. Withdrawal is as easy as giving it and does not affect what was lawful beforehand.
- Human review
- We make no automated decisions with legal or similarly significant effects. If that ever changes you will be told, and a person will review any such decision on request.
- Email privacy@vevarte.com saying what you want. Plain language is fine — "send me everything you have" is a valid request and we will treat it as one.
- We acknowledge it and, if we genuinely cannot tell who you are from the request, ask for one proof point — usually the order number and the phone number on it. We will not demand a copy of your passport to release an address you already gave us.
- We respond within 21 days. If a request is unusually complex we may extend, up to 30 days in total, and we will tell you why before the first period expires.
- There is no charge. If a request were truly repetitive or excessive we could charge a reasonable fee or decline, and we would explain which and why — but we have never done so.
Unhappy with the outcome? Section 11 sets out where to escalate. Escalating never requires our permission and never affects how we treat you.
#10. How we protect it, and what happens if that fails
- Every connection to this site is encrypted in transit (TLS), and data is encrypted at rest by Google Cloud.
- Access to customer records is restricted by role and enforced in the database itself, not by hiding menu items — a member of staff without the role is refused by Firestore, not merely shown a smaller screen.
- Card details are handled entirely by the payment provider. They never reach our servers or our staff, so they cannot leak from us.
- Secrets and credentials are held server-side and are never present in anything your browser downloads.
- Staff accounts are individual, never shared, and actions on money, stock and permissions are written to an audit log.
No system is perfectly secure and anyone who tells you otherwise is selling something. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours of becoming aware, and tell affected people directly and without undue delay — describing what happened, what was exposed, and what we are doing about it.
Found a vulnerability? Please report it — see the Security & Vulnerability Disclosure Policy. Good-faith research is welcome and we will not pursue you for it.
#11. Complaints and supervisory authorities
Come to us first at privacy@vevarte.com — most privacy complaints turn out to be a misunderstanding that takes ten minutes to clear up. You are never obliged to, and you do not lose any right by trying.
- Pakistan — the draft Personal Data Protection Bill is not yet enacted, so there is no data-protection regulator here yet. Complaints about unlawful access to a computer system fall under the Prevention of Electronic Crimes Act 2016 and go to the National Cyber Crime Investigation Agency. Consumer complaints go to the District Consumer Court, Lahore.
- EEA — the data protection authority in the country where you live, work, or where the problem happened. A directory is published by the European Data Protection Board.
- United Kingdom — the Information Commissioner's Office, at ico.org.uk.
- United States — your state Attorney General; California residents may also contact the California Privacy Protection Agency.
#12. Children
This is a furniture shop. It is not directed at children, holds nothing that would interest one, and we do not knowingly collect information from anyone under 13 — or under 16 where the GDPR sets that as the age of consent for online services.
Purchases require legal capacity to contract, which in Pakistan means 18 or over.
If you believe a child has given us personal information, write to privacy@vevarte.com and we will delete it — no verification hoops, no argument about whether we were obliged to.
#13. Changes to this policy
When we change this policy the version and date at the top change with it. Substantive changes — a new category of data, a new recipient, a new purpose — are announced by a notice on the site for thirty days, and by email to anyone on our list.
A change is never applied retroactively to information already collected under an earlier version in a way that would surprise you. Where consent was the basis, a materially new purpose means asking again rather than assuming the old answer covers it.