Privacy Policy

Young Bridge / Data Protection
Legal Document / 01

Privacy Protocol.

This Privacy Policy establishes the principles, purposes, procedures and controls governing the collection, generation, receipt, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure, transmission, restriction, deletion and other processing of personal data undertaken by Young Bridge through its digital commerce infrastructure and associated customer interfaces.

Document Privacy Policy
Version 7.9.1
Effective Date 27 JULY 2026
Jurisdiction India
Classification Public
01 / Applicability

Scope & Applicability

This Privacy and Data Protection Policy (“Policy”) governs the processing of personal data undertaken by Young Bridge (“Young Bridge”, “we”, “us”, “our” or “Company”) in connection with the operation of its websites, online storefronts, mobile or web interfaces, customer accounts, order-management systems, customer support channels, marketing interfaces, communications infrastructure and other services through which this Policy is made available.

This Policy applies to visitors, customers, account holders, prospective customers, business contacts, wholesale customers, creators, collaborators and other individuals whose personal data is processed in connection with our services.

Where a particular service, campaign, form or transaction provides a separate privacy notice, that notice shall be read together with this Policy and may provide additional processing-specific information.

02 / Definitions

Regulatory Terminology

Unless the context otherwise requires, terminology used in this Policy is intended to correspond with the terminology used in applicable data-protection legislation.

Personal Data
Any data about an individual who is identifiable by or in relation to such data, to the extent covered by the applicable legal framework.
Processing
Any operation or set of operations performed on personal data, whether or not by automated means, including collection, storage, retrieval, use, disclosure, transmission, restriction, deletion or destruction.
Data Principal
The individual to whom the personal data relates, where such terminology applies under Indian law.
Data Fiduciary
The person or entity which, alone or jointly with another person, determines the purpose and means of processing personal data.
Data Processor
A person or entity which processes personal data on behalf of a Data Fiduciary.
Consent
A legally relevant, informed and purpose-linked indication of an individual's agreement to processing where consent constitutes the applicable basis for processing.
Personal Data Breach
A compromise of security safeguards resulting in accidental or unauthorised processing, disclosure, acquisition, sharing, use, alteration, destruction or loss of personal data, to the extent defined by applicable law.
03 / Data Governance

Governance Principles

Young Bridge seeks to apply a structured data-governance approach to personal-data processing. Subject to applicable law and operational requirements, our processing framework is intended to incorporate the following principles:

  • Purpose limitation: personal data should be collected and processed for specified and legitimate purposes.
  • Data minimisation: data collection should be reasonably proportionate to the purpose for which the information is required.
  • Transparency: individuals should receive meaningful information regarding material processing activities.
  • Accuracy: reasonable measures should be taken to maintain relevant personal information in an accurate and current state.
  • Security: appropriate technical and organisational safeguards should be maintained having regard to the nature and risk of the processing.
  • Retention limitation: personal information should not be retained indefinitely where it is no longer reasonably required for a legitimate purpose or legal obligation.
  • Accountability: applicable data-processing activities should be capable of being administered, reviewed and appropriately documented.
04 / Collection

Sources & Methods of Collection

Personal data may be obtained through direct and indirect collection mechanisms.

Direct Collection

Direct collection occurs when you voluntarily submit information through checkout forms, account registration, contact forms, customer-support communications, warranty requests, return requests, subscription forms, surveys, promotional campaigns or other interfaces.

Automated Collection

Certain technical information may be generated automatically when a user accesses or interacts with our website. Such information may include IP address, device characteristics, browser information, operating-system information, referring URL, timestamps, session identifiers, page interactions, diagnostic information and other technical telemetry.

Third-Party Collection

Certain information may be received from payment processors, logistics providers, fraud-prevention systems, analytics providers, advertising platforms, authentication providers, marketplace platforms or other service providers where such processing is legally permissible and relevant to the provision of our services.

05 / Data Inventory

Categories of Personal Data

The following matrix describes representative categories of information that may be processed. The actual information collected depends upon the service, transaction and interaction involved.

Data Domain Examples Processing Context Potential Recipients
Identity Name, account identifier, profile information Account and order administration Internal systems, service providers
Contact Email, mobile number, delivery address Communication and fulfilment Logistics, communication providers
Transaction Order ID, products purchased, transaction status Commerce operations Payment and logistics providers
Technical IP address, browser, device and OS data Security, diagnostics and analytics Hosting, security and analytics providers
Behavioural Pages viewed, clicks, product interactions UX, analytics and marketing Analytics / advertising providers, where deployed
Communication Messages, enquiries, support history Customer support and dispute management Customer-support personnel/providers
06 / Processing

Purposes of Processing

Personal data may be processed to perform, administer, secure and improve the services made available through Young Bridge.

  • order creation, validation and fulfilment;
  • payment authorisation, reconciliation and settlement;
  • shipping, logistics and delivery management;
  • returns, refunds, exchanges and warranty administration;
  • customer authentication and account administration;
  • customer-service and grievance management;
  • fraud detection and transaction-risk analysis;
  • cybersecurity, threat detection and abuse prevention;
  • website performance monitoring and technical diagnostics;
  • product, service and user-experience optimisation;
  • marketing attribution and campaign measurement;
  • promotional communications where legally permissible;
  • accounting, taxation and business-record maintenance;
  • legal claims, dispute resolution and enforcement of contractual rights; and
  • compliance with applicable statutory and regulatory requirements.
07 / Consent

Consent Management

Where consent is the applicable basis for processing, Young Bridge seeks to provide information sufficient to enable the individual to understand the relevant processing purpose before consent is provided.

Consent mechanisms may be implemented through checkboxes, preference centres, cookie controls, account interfaces, transactional interfaces, communication preferences or other mechanisms appropriate to the relevant processing activity.

Where technically and legally applicable, consent withdrawal mechanisms are intended to be accessible through a process that is reasonably comparable to the process by which consent was provided.

Withdrawal of consent may affect our ability to provide certain optional services or communications. It will not necessarily affect processing that has another lawful basis or that is required for compliance with applicable law.

08 / Commerce

Orders, Payments & Fulfilment

When an individual places an order, information necessary for transaction execution may pass through multiple processing environments, including the e-commerce platform, payment gateway, banking/payment network, fraud-prevention infrastructure and logistics provider.

01
Customer
02
Commerce
03
Payment
04
Fulfilment
05
Delivery

The information disclosed to each participant should be limited to information reasonably required to perform its assigned function, subject to the architecture and contractual arrangements applicable to the relevant service.

09 / Processors

Data Processors & Vendors

Young Bridge may appoint Data Processors to perform specific processing activities on its behalf. Processor relationships may involve hosting, payment infrastructure, communications, analytics, customer support, security, logistics and other operational services.

Depending on the nature of the engagement, contractual arrangements may address confidentiality, permitted processing purposes, access restrictions, security obligations, incident escalation, data deletion or return, sub-processing and cooperation with legally applicable obligations.

Third-party processors remain responsible for their own processing activities where they independently determine purposes and means outside the instructions or role for which they were engaged.

10 / Disclosure

Disclosure & Permitted Sharing

Personal data may be disclosed where such disclosure is reasonably necessary for the provision of goods or services, fulfilment of contractual obligations, protection of legitimate business interests, prevention of fraud or abuse, resolution of disputes, or compliance with applicable law.

Operational Disclosure

This may include disclosure to payment processors, logistics providers, technology vendors, hosting providers, customer-support providers, security vendors and professional advisers.

Legal Disclosure

Information may be disclosed where required by applicable law, judicial process, lawful governmental direction, regulatory requirement or other legally enforceable request.

Corporate Transactions

Where legally permissible, personal data may form part of information reviewed or transferred in connection with a merger, acquisition, restructuring, financing, asset transfer or similar corporate transaction, subject to applicable confidentiality and data-protection requirements.

11 / Cookies

Cookies & Tracking Technologies

Young Bridge may use HTTP cookies, first-party identifiers, third-party cookies, pixels, tags, local storage, session identifiers, device identifiers and comparable technologies.

Strictly Necessary Technologies

These technologies may be necessary for authentication, shopping-cart functionality, checkout, security, fraud prevention and other core commerce functionality.

Analytics

Analytics technologies may collect aggregated or pseudonymised information concerning traffic, navigation, interaction patterns, device characteristics and website performance.

Marketing & Attribution

Where deployed, marketing technologies may measure advertising impressions, clicks, conversions and campaign attribution or facilitate interest-based advertising.

Cookie preferences may be controlled through browser settings or available consent-management mechanisms. Restricting essential technologies may impair certain website functions.

12 / Profiling

Analytics, Personalisation & Profiling

Where enabled, Young Bridge or its service providers may analyse interaction data for purposes including product recommendations, website optimisation, campaign measurement, fraud prevention, customer segmentation or service personalisation.

Such processing may involve statistical analysis, behavioural segmentation, event tracking, attribution modelling or other automated analytical techniques.

Young Bridge does not intend to use automated processing to make legally significant decisions about individuals unless such processing is separately disclosed and legally permitted.

13 / Security

Technical & Organisational Security

Security controls are designed according to the nature, volume, sensitivity and risk profile of the relevant processing activity.

01
Access Control

Access to personal data and administrative systems may be restricted according to role, operational necessity, authentication status and authorised privileges.

02
Authentication

Administrative and account systems may employ authentication mechanisms designed to reduce unauthorised access.

03
Encryption & Secure Transport

Where supported by the applicable infrastructure, appropriate cryptographic and secure-transport mechanisms may be used to protect information in transit and, where applicable, at rest.

04
Logging & Monitoring

Relevant systems may maintain technical logs and monitoring information to support security analysis, diagnostics and incident investigation.

05
Vendor Security

Relevant service providers may be subject to contractual, technical or operational security requirements appropriate to the services provided.

06
Incident Management

Security events may be assessed, contained, investigated, remediated and escalated according to their nature and applicable legal requirements.

14 / Retention

Retention & Deletion

Personal data shall be retained only for so long as reasonably necessary to fulfil the purpose for which it was collected, perform contractual obligations, maintain transaction records, resolve disputes, prevent fraud, establish or defend legal claims, or comply with applicable statutory and regulatory obligations.

Retention Determinants

  • nature and sensitivity of the information;
  • purpose for which the information was collected;
  • ongoing customer or contractual relationship;
  • statutory, tax and accounting record requirements;
  • applicable limitation periods;
  • fraud-prevention and security requirements; and
  • pending or reasonably anticipated disputes or legal claims.

At the end of the applicable retention period, information may be securely deleted, anonymised, aggregated or otherwise rendered unavailable for ordinary operational use, subject to technical backups and legally permissible retention.

15 / Rights

Data Principal Rights

Subject to applicable law, an individual may exercise rights relating to personal data processed by Young Bridge. The availability, scope and procedural requirements of individual rights depend upon the applicable statutory framework and the relevant processing activity.

01
Access / Information

Request information regarding applicable processing activities and personal data, subject to statutory limitations and verification requirements.

02
Correction

Request correction or updating of inaccurate or incomplete personal information.

03
Erasure

Request deletion of personal data where the applicable legal framework permits such deletion.

04
Consent Withdrawal

Withdraw consent where consent constitutes the applicable legal basis for the relevant processing activity.

05
Grievance Redressal

Raise a grievance concerning processing, privacy, security or exercise of applicable rights.

06
Nomination

Where applicable, exercise nomination-related rights recognised by the governing legal framework.

Requests may be submitted through the designated privacy or grievance channel identified in this Policy. We may implement reasonable identity-verification measures before disclosing, correcting or deleting personal data in order to prevent unauthorised requests.

16 / Children

Children's Personal Data

Young Bridge does not intentionally design its general commerce services to solicit personal data from children in circumstances prohibited by applicable law.

Where a transaction or service involves products intended for children, the fact that a product is intended for children does not by itself mean that Young Bridge is intentionally collecting personal data directly from a child.

Where applicable law imposes heightened requirements concerning children's personal data, including consent, monitoring, profiling or targeted advertising restrictions, the relevant statutory requirements shall apply.

17 / International Processing

Cross-Border Data Processing

Young Bridge may utilise cloud infrastructure, software services, payment systems, analytics platforms, security services or other technology providers whose infrastructure may be located outside India.

Consequently, personal data may be accessed, transmitted, stored or otherwise processed across jurisdictions where permitted by applicable law.

Cross-border processing arrangements may be subject to contractual safeguards, security controls, access restrictions and other measures appropriate to the relevant processing activity.

Applicable restrictions concerning transfer of personal data to jurisdictions notified or otherwise regulated under Indian law shall be observed to the extent applicable to Young Bridge and the relevant processing activity.

18 / Incident Response

Personal Data Breach Management

Young Bridge maintains an incident-response approach intended to identify, assess, contain, investigate, remediate and document material security incidents affecting personal data.

Incident Lifecycle

  1. detection or identification of a suspected security event;
  2. preliminary classification and risk assessment;
  3. containment and access restriction;
  4. investigation and determination of affected systems or data;
  5. remediation and security hardening;
  6. preservation of relevant technical or forensic information;
  7. notification or reporting where required by applicable law; and
  8. post-incident review and corrective action.

Where notification is legally required, Young Bridge will follow the applicable statutory notification framework and prescribed timelines.

19 / Grievance

Privacy Grievance Mechanism

Individuals may raise privacy-related complaints concerning the collection, use, disclosure, security or retention of their personal data through the designated grievance channel.

A grievance should, where reasonably possible, include sufficient information to identify the relevant transaction, account, communication or processing activity and should avoid unnecessarily including sensitive information in the initial communication.

Young Bridge may request additional information reasonably necessary to authenticate the requester, investigate the matter and determine an appropriate response.

Privacy & Grievance Desk
Legal Entity
[LEGAL ENTITY NAME]
Privacy Contact
[PRIVACY EMAIL]
Grievance Officer
[NAME / DESIGNATION]
Grievance Email
[GRIEVANCE EMAIL]
Telephone
[CUSTOMER CARE NUMBER]
Address
[REGISTERED / BUSINESS ADDRESS]
20 / Amendments

Policy Amendments

Young Bridge may periodically revise this Policy to reflect changes in its processing activities, technology architecture, business operations, contractual relationships, applicable legislation, regulatory guidance or security practices.

Material changes may be reflected through an updated effective date, revised version number or additional notice where required by applicable law.

The latest published version of this Policy constitutes the version applicable to processing undertaken after its effective date, subject to any specific transitional provisions or notices required by law.

Final / Legal Notice

Questions About Your Data?

If you require clarification concerning the information contained in this Policy, wish to exercise an applicable privacy right, withdraw consent where applicable, or submit a privacy grievance, please contact Young Bridge using the designated contact information above.

This Policy should be read together with the Young Bridge Terms & Conditions, Cookie Policy, Shipping & Delivery Policy, Return & Refund Policy, Cancellation Policy and other applicable policies governing your use of our services.