Back to Protocol Hub
THE BRANDATTIRE
· DATA SECURITY

Privacy Policy & Data Protection

Effective: September 2026 · DPDPA 2023 (India), GDPR (EU), CCPA/CPRA (California) Compliance

Zero Payment Data Retention & Merchant of Record Isolation

TheBrandAttire never stores, logs, or directly handles raw credit card numbers, CVVs, or UPI banking credentials on local servers. All transactional authorizations and escrow settlements are executed through certified PCI-DSS Level 1 Merchant of Record (MoR) infrastructure, including Dodo Payments Inc. (supporting global credit cards and Indian UPI/RuPay) and Stripe Inc.

1. Information We Collect

We collect the absolute minimum personal and institutional data required to conduct walking billboard micro-auctions and garment fulfillment:

  • For Sponsoring Brands & Bidders: Corporate entity name, verified company domain, lead representative full name, contact email address, SMS telephone for critical outbid alerts, brand destination URL, and vector logo artwork (SVG/PNG).
  • For Keynote Creators & Attendees: Full name, public social media profile handle (X/Twitter, LinkedIn, GitHub), verified conference itinerary/stage confirmation, garment silhouette and sizing specifications, and bank/UPI payout disbursement addresses.
  • Technical Telemetry: IP address, device viewport geometry (to render optimal attire canvas aspect ratios), and transaction session tokens. We do not use third-party cross-site advertising trackers.

2. Specific Purposes of Processing

In compliance with applicable data protection legislation, your data is processed strictly for the following enumerated legitimate purposes:

  • Vector Asset Delivery & Self-Execution: Supplying verified vector decal artwork (.SVG, .AI, or high-res .PNG) directly to winning sponsors and creators for self-printing and direct application onto personal attire.
  • Escrow Settlement & MoR Invoicing: Authorizing hold amounts, generating itemized tax receipts, issuing instant outbid refunds via Dodo Payments, and remitting net creator earnings.

3. Digital Personal Data Protection Act (DPDPA 2023 — India)

For users, brands, and creators operating in or transacting from India (including UPI and RuPay payments):

  • Data Fiduciary Commitment: TheBrandAttire acts as a responsible Data Fiduciary. Processing of personal data is limited to lawful purposes with transparent notice and verifiable consent.
  • Right to Grievance Redressal: Indian Data Principals have a statutory right to resolve data grievances by writing to our designated Grievance Officer at [email protected]. Matters will be resolved within 30 days.
  • Right to Nominate & Withdraw Consent: You have the right to nominate an individual to act on your behalf in the event of incapacity, or withdraw previously granted marketing consent at any time.
  • Cross-Border Transfers: Cross-border data flows are conducted in strict conformity with rules notified by the Central Government of India.

4. Ironclad Guarantee: Zero Sale of Data

TheBrandAttire has NEVER sold, rented, or commercialized user, brand, or creator personal data to third-party advertisers, data brokers, or marketing consortiums, and will NEVER do so.

Brand contact information displayed on the verified public directory is limited to designated institutional sponsorship leads voluntarily provided for partnership inquiries.

5. GDPR & CCPA/CPRA Statutory Rights

Depending on your jurisdiction, you have the right to access your stored data dossier, request rectification of inaccurate records, receive data in a portable JSON format, or exercise the right to be forgotten (permanent erasure) by contacting [email protected].