Draft, for internal review
Privacy Policy
Last updated 16 August 2026
This policy explains how VVC Group ("we", "us", "our") collects, uses, and protects personal data in connection with the gift card program offered through partner institutions and redeemable at Tanishq showrooms operated by VVC Group. It applies to cardholders who check a card's value online or redeem it in-store, and to VVC Group staff who use the redemption system.
What we collect
From cardholders: name, mobile number, and email address, collected either when your partner institution issues your card, or by our staff at the time of redemption if not already on file. We collect this to verify it's really you redeeming the card, to send a one-time verification code, and to keep a record of who a gift was for. We also store the card number and a one-way cryptographic hash of the PIN, never the PIN itself, plus redemption details (outlet, date, staff member, invoice number) once a card is redeemed, and technical data (IP address, browser/device information) when you check a card online.
We do not collect payment card numbers, bank details, government ID numbers, or any health, biometric, or other special-category data through this application. The jewelry purchase itself, including any payment, happens outside this system at the point of sale.
From staff: name, mobile number, login email, and role/outlet assignment, used to operate the redemption system and to verify staff identity during each redemption through a one-time code.
Invoice files: when staff attach a sale invoice to a redemption, that file is stored securely and is not shown to the cardholder or displayed publicly, only the invoice number is, since retail invoices can contain other information beyond what a cardholder needs to see.
How we use your data
- To verify a gift card's authenticity, value, and status when checked online.
- To confirm the identity of the person redeeming a card, through a one-time code.
- To prevent fraud, including monitoring repeated failed PIN or verification attempts.
- To maintain records required for reconciliation with partner institutions.
- To communicate with you about your card when needed.
We do not sell personal data, and we do not use cardholder data for marketing without separate, explicit consent.
Who we share data with
We use a small number of service providers to operate this system, each processing data on our behalf under contract: Supabase (database, authentication, and file storage), Vercel (application hosting), Resend and, where enabled, an SMS provider (delivering one-time verification codes), and Upstash (short-lived verification codes and rate-limiting data, automatically deleted within minutes). We do not share personal data with any other third party except where required by law, or with your partner institution for reconciliation of issued and redeemed cards.
How long we keep data
Cardholder and redemption data is retained for the duration of the applicable campaign plus 7 years thereafter, in line with standard financial record-keeping requirements under Indian tax law. Where a deletion request is honored but the underlying transaction record must be retained for legal or audit purposes, we remove personal identifiers from that record rather than deleting it outright.
Your rights
Under India's Digital Personal Data Protection Act, 2023, you have the right to access, correct, or request erasure of your personal data, and to withdraw consent where processing is based on consent. Submit a request here, or contact us at privacy@vvcgroup.com.
Security
Card PINs are stored as salted, peppered cryptographic hashes and are never displayed again after issuance. Invoice files are stored in access-controlled storage, not publicly accessible. Staff access to full cardholder contact details is limited to what's needed to complete a redemption or provide support.
Children's data
This program is not directed at, and we do not knowingly collect data from, individuals under 18.
Contact us
VVC Group
[Registered office address, to be added before external use]
privacy@vvcgroup.com
Grievance Officer (required under the DPDP Act): [name and contact to be designated before this policy is published externally].