Legal

Privacy Policy

Effective date: 25 July 2026

1. Overview

Klaarme ("we", "us", or "our") operates a digital platform for boutique and couture fashion stores, including services for store management, virtual try-on, inventory, staffing, and customer-facing shopping. This Privacy Policy describes how we collect, use, store, and protect personal data when you use our platform, whether as a store owner, staff member, or end customer. We are committed to protecting your privacy in accordance with the Digital Personal Data Protection Act, 2023 (DPDPA), India, and applicable regulations. We also aim to align with international best practices, including the General Data Protection Regulation (GDPR) for users in the European Union. By using Klaarme, you agree to the collection and use of information as described in this policy.

2. Data Controller

"Klaarme" is the trade name of RENU, a sole proprietorship registered in India (GSTIN: 07AGNPR0105J1ZE), and is the data controller for personal data collected on this platform. Contact for privacy inquiries: Email: [email protected] Website: https://klaarme.com Registered Address: New Delhi, India For store owners using Klaarme as their business management tool, you may also act as a data controller for your customers' data processed through our platform. You are responsible for ensuring you have a lawful basis for processing your customers' data.

3. Data We Collect

We collect the following categories of personal data: **Account & Identity** - Mobile phone number (used as primary identifier and for OTP authentication) - Name, email address (optional) - Profile information **Store Owner & Staff Data** - Store name, address, business details - Employee ID, designation, date of joining - Attendance records, check-in/check-out times and location (if geo-fencing enabled) - Salary and payroll information - Documents uploaded by the store owner **Customer Data** - Body measurements and sizing profiles - Order history, garment preferences - Payment information (processed via our third-party payment processor; we do not store full card details) - Try-on session images (uploaded by you or store staff for virtual fitting) - Appointment details **Usage & Technical Data** - Device type, browser type, IP address - Pages visited, features used, session duration - Cookies and similar tracking technologies (see Section 7) **Communications** - WhatsApp and SMS messages sent via the platform (through our third-party messaging providers) - Notification preferences

4. How We Use Your Data

We use your personal data for the following purposes: **Platform Operation** - Creating and managing your account - Processing orders, payments, and invoices - Managing inventory, staff, appointments, and store operations - Sending OTP authentication codes **Customer Experience** - Enabling virtual try-on using AI (garment and fabric visualisation) - Storing measurements for repeat orders - Order tracking and delivery notifications **Communications** - Transactional notifications: order confirmations, payment receipts, appointment reminders - WhatsApp and SMS messages (with your consent) - Marketing campaigns from stores you have engaged with (opt-in only) **Business Operations** - Payroll processing, attendance tracking, and HR management for store employees - Analytics and platform improvement - Legal and compliance obligations **Security & Fraud Prevention** - Detecting and preventing unauthorised access - Maintaining audit logs

6. Data Sharing & Third Parties

We do not sell your personal data. We share data with third parties only as necessary to operate the platform: **Payment Processing** Payments are processed by a PCI-DSS compliant third-party payment processor. Their privacy policy governs data they receive. **Messaging & Notifications** WhatsApp messages are delivered via the WhatsApp Business Platform operated by Meta Platforms, Inc. When we send you a WhatsApp message, your mobile number and message content are processed by Meta in accordance with WhatsApp's Privacy Policy (https://www.whatsapp.com/legal/privacy-policy). SMS messages are delivered via a third-party SMS gateway provider. Both providers act as data processors on our behalf and process only the data necessary to deliver messages. **Cloud Infrastructure** Data is stored on our cloud infrastructure provider, with servers located in India. We choose India-region hosting to keep your data within Indian jurisdiction. **AI Features** Try-on images are processed by a third-party AI service for garment/fabric visualisation. Images are transmitted securely and not retained by the provider beyond processing. Do not upload images containing sensitive or identifying personal information beyond what is necessary for the try-on. **Legal Disclosure** We may disclose data to law enforcement or government authorities if required by law, court order, or to protect rights, safety, or property. **Business Transfers** If Klaarme is acquired, merged, or sells its assets, your personal data may be transferred to the successor entity as part of that transaction. We will notify you if this results in a materially different use of your data. **Subprocessors** We use the following categories of subprocessors. Specific vendors may change; we will update this list as our infrastructure evolves. | Provider | Purpose | |---|---| | Cloud hosting (India-region) | Application hosting, database, file storage | | Payment processor | Payment collection and processing | | Meta Platforms, Inc. (WhatsApp) | WhatsApp message delivery | | SMS gateway provider | SMS message delivery | | Email delivery provider | Transactional and account emails | | AI/ML service provider | Virtual try-on image processing | | CDN provider | Content delivery, DDoS protection | Some subprocessors (e.g. Meta, AI providers) may process data outside India as part of delivering their service, even though our primary infrastructure is hosted in India.

7. Google API Services & Limited Use

Klaarme offers an optional Google Calendar integration that lets store owners connect their Google account to sync customer appointments. **What we access**: With your explicit consent (via Google's OAuth screen), we access your Google Calendar events and your Google account email address. **How we use it**: Calendar events are read to help you avoid double-booking appointments. When you book, reschedule, or cancel an appointment in Klaarme, we create, update, or delete the corresponding event on your connected Google Calendar. Your account email is used only to display which Google account is connected in your settings. **Limited Use Compliance**: Klaarme's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use data obtained through Google Workspace APIs to develop, improve, or train generalised or foundational AI/ML models. Calendar data is used solely to provide the appointment-sync feature described above and is never sold or shared with third parties for advertising. **Revoking access**: You can disconnect Google Calendar at any time from Settings → Integrations, or by revoking Klaarme's access directly at https://myaccount.google.com/permissions. Disconnecting stops all further access; previously created calendar events are not automatically deleted.

8. Cookies & Tracking

We use cookies and similar technologies: **Essential Cookies** - Authentication token (HttpOnly JWT cookie): Required for secure login. Cannot be disabled. **Analytics Cookies** - Usage analytics to understand how users interact with the platform and improve features. You can control non-essential cookies through your browser settings. Disabling analytics cookies does not affect your ability to use the platform.

9. Data Retention

We retain personal data for as long as necessary for the purposes described: - **Account data**: Retained while your account is active, and for 30 days after deletion request (to allow recovery) - **Order and payment records**: 7 years, as required by Indian tax and accounting law (GST compliance) - **Try-on images**: Retained for the duration of the session and associated order; deleted upon account deletion request - **Attendance and payroll records**: As required by Indian labour laws (typically 3–5 years) - **Communication logs**: 90 days for transactional messages; 1 year for audit compliance After retention periods, data is securely deleted or anonymised. **Deletion Process** When you request deletion, your data is marked deleted immediately and removed from active systems. It may persist in encrypted backups for up to 30 days before permanent deletion, after which it cannot be recovered. **Audit Logs** We maintain security and audit logs, including login history, admin actions, and support access to your account, to investigate security incidents and support requests. These logs are retained separately from account data per Section 8's communication log retention period.

10. Your Rights

Under the DPDPA 2023 and applicable law, you have the following rights: - **Right to Access**: Request a copy of personal data we hold about you - **Right to Correction**: Request correction of inaccurate or incomplete data - **Right to Erasure**: Request deletion of your personal data (subject to legal retention requirements) - **Right to Data Portability**: Receive your data in a structured, machine-readable format (CSV, Excel, or JSON, delivered as a downloadable ZIP archive). Export links remain available for 7 days after generation. - **Right to Withdraw Consent**: Withdraw consent for marketing or non-essential data processing at any time - **Right to Grievance Redressal**: Lodge a complaint with us or with the Data Protection Board of India To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. **Store Owners**: You are also responsible for facilitating your customers' data rights for data you process through our platform.

11. Data Security

We implement appropriate technical and organisational measures to protect your personal data: - HTTPS encryption for all data in transit - HttpOnly JWT cookies to prevent XSS-based token theft - Passwords are not stored; authentication uses OTP via verified mobile number - Access controls: role-based permissions restrict data access to authorised personnel - Our payment processor handles payment card data under PCI-DSS compliance - Regular security reviews No method of transmission over the internet is 100% secure. We cannot guarantee absolute security, but we take reasonable precautions.

12. Children's Privacy

Klaarme is not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided personal data to us, contact [email protected] and we will delete it promptly.

13. International Users

Our platform is primarily intended for users in India. Data is stored in India. If you access the platform from outside India, be aware that your data will be transferred to and processed in India, where data protection laws may differ from your jurisdiction. For EU/EEA users: We are working towards full GDPR compliance. Where GDPR applies, we rely on consent and legitimate interests as our legal bases, and we honour all rights under GDPR Articles 15–22.

14. Automated Decisions & Consent Records

**Automated Decisions** Our AI-powered virtual try-on and garment recommendation features generate automated visualisations and suggestions. These are provided for convenience only. No legally or financially significant decision about you is made solely by automated means, and outputs should not be relied upon for medical, body-health, or legal purposes. **Consent Records** We maintain records of consent (including opt-in and opt-out timestamps for marketing communications) to demonstrate compliance with the DPDPA 2023 and TRAI regulations. **Breach Notification** If a personal data breach occurs that is likely to affect you, we will notify affected users and, where required, the Data Protection Board of India, without undue delay, in accordance with applicable law.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of material changes via the platform or by WhatsApp/SMS to your registered number. The updated policy will be effective from the date of publication. Continued use of Klaarme after changes constitutes acceptance of the revised policy.

16. Contact Us

For privacy-related questions, requests, or complaints: Email: [email protected] Website: https://klaarme.com/about Registered Address: New Delhi, India We aim to respond to all privacy inquiries within 30 days.

Also see our Terms of Service.