Privacy Policy
Privacy Protocol.
This Privacy Policy establishes the principles, purposes, procedures and controls governing the collection, generation, receipt, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure, transmission, restriction, deletion and other processing of personal data undertaken by Young Bridge through its digital commerce infrastructure and associated customer interfaces.
Scope & Applicability
This Privacy and Data Protection Policy (“Policy”) governs the processing of personal data undertaken by Young Bridge (“Young Bridge”, “we”, “us”, “our” or “Company”) in connection with the operation of its websites, online storefronts, mobile or web interfaces, customer accounts, order-management systems, customer support channels, marketing interfaces, communications infrastructure and other services through which this Policy is made available.
This Policy applies to visitors, customers, account holders, prospective customers, business contacts, wholesale customers, creators, collaborators and other individuals whose personal data is processed in connection with our services.
Where a particular service, campaign, form or transaction provides a separate privacy notice, that notice shall be read together with this Policy and may provide additional processing-specific information.
This Policy is intended to operate with applicable Indian data-protection and information-technology legislation, including the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, and other applicable statutory, regulatory and contractual requirements, to the extent and from the date such provisions apply to the relevant processing activity.
Regulatory Terminology
Unless the context otherwise requires, terminology used in this Policy is intended to correspond with the terminology used in applicable data-protection legislation.
Governance Principles
Young Bridge seeks to apply a structured data-governance approach to personal-data processing. Subject to applicable law and operational requirements, our processing framework is intended to incorporate the following principles:
- Purpose limitation: personal data should be collected and processed for specified and legitimate purposes.
- Data minimisation: data collection should be reasonably proportionate to the purpose for which the information is required.
- Transparency: individuals should receive meaningful information regarding material processing activities.
- Accuracy: reasonable measures should be taken to maintain relevant personal information in an accurate and current state.
- Security: appropriate technical and organisational safeguards should be maintained having regard to the nature and risk of the processing.
- Retention limitation: personal information should not be retained indefinitely where it is no longer reasonably required for a legitimate purpose or legal obligation.
- Accountability: applicable data-processing activities should be capable of being administered, reviewed and appropriately documented.
Sources & Methods of Collection
Personal data may be obtained through direct and indirect collection mechanisms.
Direct Collection
Direct collection occurs when you voluntarily submit information through checkout forms, account registration, contact forms, customer-support communications, warranty requests, return requests, subscription forms, surveys, promotional campaigns or other interfaces.
Automated Collection
Certain technical information may be generated automatically when a user accesses or interacts with our website. Such information may include IP address, device characteristics, browser information, operating-system information, referring URL, timestamps, session identifiers, page interactions, diagnostic information and other technical telemetry.
Third-Party Collection
Certain information may be received from payment processors, logistics providers, fraud-prevention systems, analytics providers, advertising platforms, authentication providers, marketplace platforms or other service providers where such processing is legally permissible and relevant to the provision of our services.
Categories of Personal Data
The following matrix describes representative categories of information that may be processed. The actual information collected depends upon the service, transaction and interaction involved.
| Data Domain | Examples | Processing Context | Potential Recipients |
|---|---|---|---|
| Identity | Name, account identifier, profile information | Account and order administration | Internal systems, service providers |
| Contact | Email, mobile number, delivery address | Communication and fulfilment | Logistics, communication providers |
| Transaction | Order ID, products purchased, transaction status | Commerce operations | Payment and logistics providers |
| Technical | IP address, browser, device and OS data | Security, diagnostics and analytics | Hosting, security and analytics providers |
| Behavioural | Pages viewed, clicks, product interactions | UX, analytics and marketing | Analytics / advertising providers, where deployed |
| Communication | Messages, enquiries, support history | Customer support and dispute management | Customer-support personnel/providers |
Purposes of Processing
Personal data may be processed to perform, administer, secure and improve the services made available through Young Bridge.
- order creation, validation and fulfilment;
- payment authorisation, reconciliation and settlement;
- shipping, logistics and delivery management;
- returns, refunds, exchanges and warranty administration;
- customer authentication and account administration;
- customer-service and grievance management;
- fraud detection and transaction-risk analysis;
- cybersecurity, threat detection and abuse prevention;
- website performance monitoring and technical diagnostics;
- product, service and user-experience optimisation;
- marketing attribution and campaign measurement;
- promotional communications where legally permissible;
- accounting, taxation and business-record maintenance;
- legal claims, dispute resolution and enforcement of contractual rights; and
- compliance with applicable statutory and regulatory requirements.
Consent Management
Where consent is the applicable basis for processing, Young Bridge seeks to provide information sufficient to enable the individual to understand the relevant processing purpose before consent is provided.
Consent mechanisms may be implemented through checkboxes, preference centres, cookie controls, account interfaces, transactional interfaces, communication preferences or other mechanisms appropriate to the relevant processing activity.
Where technically and legally applicable, consent withdrawal mechanisms are intended to be accessible through a process that is reasonably comparable to the process by which consent was provided.
Withdrawal of consent may affect our ability to provide certain optional services or communications. It will not necessarily affect processing that has another lawful basis or that is required for compliance with applicable law.
Orders, Payments & Fulfilment
When an individual places an order, information necessary for transaction execution may pass through multiple processing environments, including the e-commerce platform, payment gateway, banking/payment network, fraud-prevention infrastructure and logistics provider.
The information disclosed to each participant should be limited to information reasonably required to perform its assigned function, subject to the architecture and contractual arrangements applicable to the relevant service.
Data Processors & Vendors
Young Bridge may appoint Data Processors to perform specific processing activities on its behalf. Processor relationships may involve hosting, payment infrastructure, communications, analytics, customer support, security, logistics and other operational services.
Depending on the nature of the engagement, contractual arrangements may address confidentiality, permitted processing purposes, access restrictions, security obligations, incident escalation, data deletion or return, sub-processing and cooperation with legally applicable obligations.
Third-party processors remain responsible for their own processing activities where they independently determine purposes and means outside the instructions or role for which they were engaged.
Disclosure & Permitted Sharing
Personal data may be disclosed where such disclosure is reasonably necessary for the provision of goods or services, fulfilment of contractual obligations, protection of legitimate business interests, prevention of fraud or abuse, resolution of disputes, or compliance with applicable law.
Operational Disclosure
This may include disclosure to payment processors, logistics providers, technology vendors, hosting providers, customer-support providers, security vendors and professional advisers.
Legal Disclosure
Information may be disclosed where required by applicable law, judicial process, lawful governmental direction, regulatory requirement or other legally enforceable request.
Corporate Transactions
Where legally permissible, personal data may form part of information reviewed or transferred in connection with a merger, acquisition, restructuring, financing, asset transfer or similar corporate transaction, subject to applicable confidentiality and data-protection requirements.
Cookies & Tracking Technologies
Young Bridge may use HTTP cookies, first-party identifiers, third-party cookies, pixels, tags, local storage, session identifiers, device identifiers and comparable technologies.
Strictly Necessary Technologies
These technologies may be necessary for authentication, shopping-cart functionality, checkout, security, fraud prevention and other core commerce functionality.
Analytics
Analytics technologies may collect aggregated or pseudonymised information concerning traffic, navigation, interaction patterns, device characteristics and website performance.
Marketing & Attribution
Where deployed, marketing technologies may measure advertising impressions, clicks, conversions and campaign attribution or facilitate interest-based advertising.
Cookie preferences may be controlled through browser settings or available consent-management mechanisms. Restricting essential technologies may impair certain website functions.
Analytics, Personalisation & Profiling
Where enabled, Young Bridge or its service providers may analyse interaction data for purposes including product recommendations, website optimisation, campaign measurement, fraud prevention, customer segmentation or service personalisation.
Such processing may involve statistical analysis, behavioural segmentation, event tracking, attribution modelling or other automated analytical techniques.
Young Bridge does not intend to use automated processing to make legally significant decisions about individuals unless such processing is separately disclosed and legally permitted.
Technical & Organisational Security
Security controls are designed according to the nature, volume, sensitivity and risk profile of the relevant processing activity.
Access to personal data and administrative systems may be restricted according to role, operational necessity, authentication status and authorised privileges.
Administrative and account systems may employ authentication mechanisms designed to reduce unauthorised access.
Where supported by the applicable infrastructure, appropriate cryptographic and secure-transport mechanisms may be used to protect information in transit and, where applicable, at rest.
Relevant systems may maintain technical logs and monitoring information to support security analysis, diagnostics and incident investigation.
Relevant service providers may be subject to contractual, technical or operational security requirements appropriate to the services provided.
Security events may be assessed, contained, investigated, remediated and escalated according to their nature and applicable legal requirements.
Despite reasonable safeguards, no network, information system, electronic transmission or storage environment can be guaranteed to be completely secure. Accordingly, Young Bridge does not represent that information will remain immune from every conceivable security threat.
Retention & Deletion
Personal data shall be retained only for so long as reasonably necessary to fulfil the purpose for which it was collected, perform contractual obligations, maintain transaction records, resolve disputes, prevent fraud, establish or defend legal claims, or comply with applicable statutory and regulatory obligations.
Retention Determinants
- nature and sensitivity of the information;
- purpose for which the information was collected;
- ongoing customer or contractual relationship;
- statutory, tax and accounting record requirements;
- applicable limitation periods;
- fraud-prevention and security requirements; and
- pending or reasonably anticipated disputes or legal claims.
At the end of the applicable retention period, information may be securely deleted, anonymised, aggregated or otherwise rendered unavailable for ordinary operational use, subject to technical backups and legally permissible retention.
Data Principal Rights
Subject to applicable law, an individual may exercise rights relating to personal data processed by Young Bridge. The availability, scope and procedural requirements of individual rights depend upon the applicable statutory framework and the relevant processing activity.
Request information regarding applicable processing activities and personal data, subject to statutory limitations and verification requirements.
Request correction or updating of inaccurate or incomplete personal information.
Request deletion of personal data where the applicable legal framework permits such deletion.
Withdraw consent where consent constitutes the applicable legal basis for the relevant processing activity.
Raise a grievance concerning processing, privacy, security or exercise of applicable rights.
Where applicable, exercise nomination-related rights recognised by the governing legal framework.
Requests may be submitted through the designated privacy or grievance channel identified in this Policy. We may implement reasonable identity-verification measures before disclosing, correcting or deleting personal data in order to prevent unauthorised requests.
Children's Personal Data
Young Bridge does not intentionally design its general commerce services to solicit personal data from children in circumstances prohibited by applicable law.
Where a transaction or service involves products intended for children, the fact that a product is intended for children does not by itself mean that Young Bridge is intentionally collecting personal data directly from a child.
Where applicable law imposes heightened requirements concerning children's personal data, including consent, monitoring, profiling or targeted advertising restrictions, the relevant statutory requirements shall apply.
Cross-Border Data Processing
Young Bridge may utilise cloud infrastructure, software services, payment systems, analytics platforms, security services or other technology providers whose infrastructure may be located outside India.
Consequently, personal data may be accessed, transmitted, stored or otherwise processed across jurisdictions where permitted by applicable law.
Cross-border processing arrangements may be subject to contractual safeguards, security controls, access restrictions and other measures appropriate to the relevant processing activity.
Applicable restrictions concerning transfer of personal data to jurisdictions notified or otherwise regulated under Indian law shall be observed to the extent applicable to Young Bridge and the relevant processing activity.
Personal Data Breach Management
Young Bridge maintains an incident-response approach intended to identify, assess, contain, investigate, remediate and document material security incidents affecting personal data.
Incident Lifecycle
- detection or identification of a suspected security event;
- preliminary classification and risk assessment;
- containment and access restriction;
- investigation and determination of affected systems or data;
- remediation and security hardening;
- preservation of relevant technical or forensic information;
- notification or reporting where required by applicable law; and
- post-incident review and corrective action.
Where notification is legally required, Young Bridge will follow the applicable statutory notification framework and prescribed timelines.
Privacy Grievance Mechanism
Individuals may raise privacy-related complaints concerning the collection, use, disclosure, security or retention of their personal data through the designated grievance channel.
A grievance should, where reasonably possible, include sufficient information to identify the relevant transaction, account, communication or processing activity and should avoid unnecessarily including sensitive information in the initial communication.
Young Bridge may request additional information reasonably necessary to authenticate the requester, investigate the matter and determine an appropriate response.
Policy Amendments
Young Bridge may periodically revise this Policy to reflect changes in its processing activities, technology architecture, business operations, contractual relationships, applicable legislation, regulatory guidance or security practices.
Material changes may be reflected through an updated effective date, revised version number or additional notice where required by applicable law.
The latest published version of this Policy constitutes the version applicable to processing undertaken after its effective date, subject to any specific transitional provisions or notices required by law.
Last Updated: [DATE]
Version: 1.0
Policy Owner: [LEGAL ENTITY / PRIVACY FUNCTION]
Classification: Public
Questions About Your Data?
If you require clarification concerning the information contained in this Policy, wish to exercise an applicable privacy right, withdraw consent where applicable, or submit a privacy grievance, please contact Young Bridge using the designated contact information above.
This Policy should be read together with the Young Bridge Terms & Conditions, Cookie Policy, Shipping & Delivery Policy, Return & Refund Policy, Cancellation Policy and other applicable policies governing your use of our services.