FASHION ARC
Privacy Policy
Fashion Arc is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our website (fashionarc.co), mobile app, or any related services (collectively, the “Platform”).
By using the Platform, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use Fashion Arc.
Fashion Arc is committed to protecting your privacy and operates in full compliance with the laws of Bangladesh.
1. Information We Collect
We follow principles of data minimization and purpose limitation, collecting only what's required for these services.
Personal Information
- Name, mobile number, email address, delivery address, and basic payment-related
details (when you create an account or place an order).
- Any additional information you voluntarily provide when contacting support (e.g.,
through messages or chat).
Device & Usage Information
- Device type, operating system, browser type, IP address, and approximate location
(city-level only, never precise GPS).
- Pages visited, products viewed, items added to cart or wishlist, search terms, time
spent on the Platform, and interaction data (clicks, scrolls, preferences such as size filters, language, or brand favorites).
Order & Transaction Information
- Order details, purchased products, selected Brands, delivery status, and payment
method(e.g., via bKash, Upay or Nagad transfers).
Marketing & Communication Information
- Your preferences and explicit consent for receiving promotions, first-order coupons,
product stories, newsletters.
We do not collect sensitive personal data (such as health, biometric, or financial details beyond basic transaction needs) unless strictly necessary and with your explicit consent.
- How We Collect Information
We only collect data through these sources, always in line with data minimization and purpose limitation principles (as required under Bangladesh's Digital Commerce Operational Guidelines 2021 and the Personal Data Protection Ordinance 2025):
- Directly from you: When you register an account, place orders, contact our support team
(via chat, email, or phone), or voluntarily participate in promotions, surveys, or first-order coupon sign-ups. This includes details like your name, delivery address, or preferences you share to personalize your shopping.
- Automatically: Through cookies, pixels, tags, web beacons, and similar tracking
technologies during your visits to the Platform. These help us recognize your device, remember preferences (e.g., size filters or wishlist items), and improve the overall experience. For full details on types and management, refer to the Cookies section below.
- From third parties: Only when necessary for order fulfillment and service delivery, such
as:
- Payment gateways (e.g., bKash, Upay, Nagad) sharing transaction confirmation data.
- Delivery partners providing status updates.
- Collaborating Brands sharing limited fulfillment-related info (e.g., stock availability for your
selected items).
- How We Use Your Information
All data usage follows principles of purpose limitation and data minimization under
Bangladesh's laws, including the Digital Commerce Operational Guidelines 2021
(requiring prior consent, clear explanation of purposes, and transparency on processing) and the Personal Data Protection Ordinance 2025 (PDPO 2025, mandating explicit, informed, specific, and revocable consent for processing, with lawful bases like contract performance or legitimate interests where applicable).
We use your information only to:
- Process and fulfill orders , including coordinating consolidated multi-brand
deliveries so you can buy from multiple brands in one go with lower, shared shipping fees and less hassle.
- Provide customer support and communicate about your orders (e.g.,
confirmations, issues, or queries via chat, email, or phone).
- Personalize your shopping experience to make discovery easier—such as size
recommendations based on past preferences, wishlist saving, saved filters (e.g., brand, category, or style), and tailored product suggestions across collaborating brands.
- Send essential order-related communications , including updates, tracking
information, delivery notifications, and post-purchase follow-ups.
- Offer promotions, first-order coupons, product stories, newsletters, and
marketing communications related to new arrivals, brand collaborations, seasonal
campaigns, or exclusive deals— only with your explicit prior consent (e.g., via
opt-in during registration/checkout or preferences settings).
- Improve the Platform , analyze anonymized or aggregated usage trends (e.g.,
popular categories, search patterns), enhance features, and prevent fraud or abuse to keep shopping safe and reliable for all users and Brands.
- Comply with legal obligations (e.g., tax records, dispute resolution) and protect the
rights, property, and safety of Fashion Arc, our users, collaborating Brands, and the platform ecosystem.
4. Sharing Your Information
All sharing is limited, purpose-specific, and compliant with Bangladesh's laws, including the Digital Commerce Operational Guidelines 2021 (requiring prior consent for personal data collection/processing and transparency on use/storage/sharing) and the Personal Data Protection Ordinance 2025 (PDPO 2025).
We share data only in these cases:
- With collaborating Brands (as data processors/sub-processors): Limited order
details—such as the specific product(s) purchased, quantity, size/color preferences, delivery address, and contact info (name/phone)—solely to enable order fulfillment, warehouse pickup, and accurate dispatch. Brands receive only what's essential for processing your multi-brand order and are bound by strict confidentiality and purpose-limited use (no marketing or unrelated sharing allowed without your consent).
- With delivery partners: Name, delivery address, phone number, and basic order details
(e.g., items, tracking ID) to complete secure, consolidated delivery—especially important for multi-brand orders to minimize costs and environmental impact.
- With payment service providers (e.g., bKash, Nagad, Upay): Transaction-specific
information (amount, order ID, payment method confirmation) to securely process payments.
- With service providers (e.g., analytics tools, cloud hosting, IT support, or fraud
detection services): Limited data under strict confidentiality agreements, data processing agreements (as per PDPO 2025 requirements for processors), and only for Platform improvement, security, or operational support. These providers are prohibited from using data for their own purposes.
- When required by law: To comply with valid court orders, government requests, regulatory
obligations (e.g., tax authorities, dispute resolution under Consumer Rights Protection Act 2009), or to protect the rights, safety, and property of Fashion Arc, our users, collaborating Brands, or the public.
Important commitments under PDPO 2025 and Digital Commerce Guidelines:
- We do not sell your personal information to third parties—ever.
- No sharing occurs for unrelated purposes (e.g., marketing by third parties) without your
explicit, informed consent.
- All recipients (Brands, partners, processors) must implement appropriate security
measures, confidentiality, and purpose limitation.
- Cross-border sharing (if any future need arises, e.g., international cloud services) will only
occur with safeguards like adequacy decisions, consent, or contractual protections, and in compliance with PDPO restrictions on confidential/restricted data.
5. Cookies
We use cookies and similar tracking technologies (such as pixels, tags, web beacons, and local storage) to enhance your experience on the Fashion Arc Platform and make shopping more convenient and personalized.
Cookies are small text files placed on your device (computer, phone, or tablet) when you visit our website or use our mobile app. They allow us to recognize your device on return visits, remember your preferences, and improve how the Platform works.
Types of cookies we use:
Essential cookies
These are necessary for the Platform to function properly. They enable core features such as navigating between pages, adding items to your cart, processing secure checkouts, and maintaining your session. These cookies do not require your consent.
Performance and analytics cookies
These help us understand how users interact with the Platform — for example, which pages are visited most often, how long sessions last, and whether errors occur. This information helps us continuously improve the site, app, and overall user experience.
Functionality cookies
These remember choices you make (such as preferred language, size filters, saved items, or wishlist contents) so you do not have to re-enter them each time you visit.
Advertising and marketing cookies
These track your browsing behavior to deliver more relevant product recommendations, promotions, first-order coupons, and brand collaborations. They may also help us and our trusted partners measure the effectiveness of marketing campaigns and seasonal promotions.
We may use both session cookies (which disappear when you close your browser) and persistent cookies (which remain on your device for a set period to recognize you on future visits).
Third-party cookies
Some cookies are placed by our authorized service providers (such as analytics tools, payment gateways, delivery partners, or collaborating Brands). These third parties may use cookies for their own purposes, subject to their own privacy policies.
Your choices and control
You can manage or disable cookies through your browser or device settings at any time.
Most browsers allow you to accept, reject, or delete cookies. Please note that disabling essential cookies may affect how the Platform works — for example, you may not be able to add items to your cart, complete purchases, or benefit from consolidated multi-brand delivery.
By continuing to use the Fashion Arc Platform, you consent to our use of cookies and similar technologies as described in this section. Where required by applicable law, we will seek your explicit consent for non-essential cookies.
For more information about how we collect, use, share, and protect your personal data (including through cookies), please review our separate Privacy Policy [link to be added when available].
6. Data Security
We implement reasonable technical and organizational measures to protect your data from unauthorized access, loss, alteration, disclosure, or misuse. These include:
- Encryption for data in transit (e.g., HTTPS/SSL/TLS protocols across the Platform to
secure communications during browsing, registration, ordering, and payments).
- Access controls (e.g., role-based permissions, multi-factor authentication where applicable
for internal systems, and regular security audits).
- Secure credential handling for account protection: Passwords you provide during
registration or login are stored using industry-standard one-way hashing techniques (with unique salts per user). This means passwords are transformed into irreversible codes—never kept in plain text, and impossible for our staff, developers, or unauthorized parties to view, decrypt, or use to access your account.
- Other safeguards such as firewalls, intrusion detection, regular vulnerability scanning,
secure coding practices, and data minimization to limit what we store.
We also require our collaborating Brands, delivery partners, payment gateways, and service providers to maintain equivalent security standards through contractual obligations (e.g., data processing agreements aligned with PDPO 2025 requirements).
Important notes:
- No method of transmission over the internet or electronic storage is 100% secure. While
we strive for best-in-class protection, we cannot guarantee absolute security against all threats (e.g., sophisticated cyberattacks).
- In the unlikely event of a data breach that may affect your rights or freedoms, we will notify
you and relevant authorities promptly, as required under the Personal Data Protection Ordinance 2025 (PDPO 2025) (effective November 6, 2025, with phased enforcement for certain provisions) and Digital Commerce Operational Guidelines 2021.
7. Your Rights
Under Bangladesh's laws—including the Personal Data Protection Ordinance 2025
(PDPO 2025) (gazetted November 6, 2025, effective immediately for most provisions, with some phased enforcement) and the Digital Commerce Operational Guidelines 2021—you have strong, enforceable rights as a data subject. These rights are non-waivable and help ensure transparency, fairness, and protection of your privacy while we process data only for legitimate purposes like order fulfillment and platform improvement.
You have the right to:
- Access your personal data — Obtain confirmation of whether we process your data,
receive a copy of it in an intelligible format (including details on what is held, purposes, recipients, and retention), and get information on automated processing if applicable (PDPO Sections 10–11, right to access and data portability).
- Rectify, update, or complete your data — Request correction of inaccurate, incomplete,
misleading, or outdated information to ensure accuracy (PDPO Section 12).
- Withdraw consent — At any time, withdraw your previously given consent for processing
(including marketing) without affecting the lawfulness of prior processing. Upon withdrawal, we must stop processing promptly (PDPO Section 13; also aligns with Digital Commerce Guidelines requiring revocable consent).
- Request erasure/deletion — Ask for deletion of your data when it is no longer necessary,
consent is withdrawn, processing is unlawful, or other grounds apply—subject to legal retention obligations (e.g., for tax, accounting, or dispute resolution) (PDPO Section 13 and related provisions).
- Restrict processing — In certain cases (e.g., while verifying accuracy or objecting to
processing), limit how we use your data.
- Object to processing — Oppose processing for direct marketing (including promotions,
first-order coupons, or newsletters) or based on legitimate interests, with us ceasing such activities unless compelling grounds exist.
- Not be subject to solely automated decisions — With significant effects (if we ever use
such), with rights to human intervention, explanation, and challenge.
How to exercise these rights To access, correct, delete, withdraw consent, or make any request:
- Email us at hello@fashionarc.co with your full name, registered mobile number/email, order
details (if relevant), and a clear description of your request.
- We will verify your identity and respond within reasonable timeframes. No fee is charged
unless requests are manifestly unfounded or excessive.
- Data Retention
We retain your personal information only for as long as it is necessary to fulfill the purposes outlined in this Privacy Policy (such as processing orders, providing support, personalizing your experience, or fulfilling marketing consents you have given), or as required by applicable Bangladeshi laws.
Retention periods are determined based on:
Operational needs
- Account and profile data (name, email, phone, preferences, wishlist, saved filters):
Retained while your account is active, plus a reasonable period after closure (usually 6–12 months) to handle any reactivation, support queries, or disputes.
- Order and transaction data: Kept for at least 5–6 years after the order date to comply
with tax, accounting, VAT, and e-commerce record-keeping requirements under Bangladesh's tax laws, Value Added Tax Act, and Digital Commerce Operational Guidelines 2021 (which mandate preserving business-related information for at least 6 years).
- Delivery and fulfillment records: Retained for the duration needed to resolve any delivery
issues, returns, refunds, or disputes (typically 12–24 months after order completion).
- Marketing and communication consent records: Kept until you withdraw consent or for
a short period after withdrawal to document compliance.
Legal and regulatory obligations
- We retain certain data longer when required by law, such as for tax audits, financial
reporting, fraud prevention, or resolving legal claims/disputes under the Consumer Rights Protection Act 2009, ICT Act 2006, or Personal Data Protection Ordinance 2025 (PDPO 2025).
- In cases of suspected fraud, abuse, or legal proceedings, relevant data may be retained
until the matter is resolved.
- Under PDPO 2025, personal data must not be retained longer than necessary for the
original purpose, with records of processing activities preserved for at least 5 years.
Security and platform integrity
- Anonymized or aggregated usage data (e.g., trends in popular categories, search patterns)
may be retained indefinitely for analytics and Platform improvement, as it no longer identifies you personally.
What happens when data is no longer needed?
Once the retention period ends, we securely delete, destroy, or irreversibly anonymize your personal information so it can no longer be linked to you. If deletion is not immediately possible due to backups or technical reasons, we isolate and protect the data from further processing until it can be securely removed.
- Children’s Privacy
The Platform is not directed to or intended for use by children under 18 without parental or guardian supervision. Under the Personal Data Protection Ordinance 2025 (PDPO
- , the Ordinance provides strong protections for children (defined in some provisions as
under 8 or minors unable to give informed consent), requiring parental or guardian consent for processing personal data of minors, prohibiting profiling, behavioral tracking, targeted advertising, or automated decisions aimed at children, and restricting data collection where consent cannot be meaningfully obtained.
We do not knowingly collect or process personal information from children under 18 in a way that bypasses parental involvement. Key points:
- Account creation, orders, payments, and any personal data submission (name,
phone, address, preferences) should be handled by adults (18+) or under direct parental/guardian observation and approval.
- For children's products: Parents/guardians are responsible for any data shared when
purchasing kids' items (e.g., delivery address for a child's dress).
- We do not engage in targeted advertising, profiling, or behavioral tracking directed at
minors.
- If we become aware that personal information has been collected from a child under
18 without proper parental consent (e.g., through account registration or order details), we will promptly delete that information and may suspend related access.
Parents or guardians who believe their child has provided us with personal information without supervision should contact us immediately at hello@fashionarc.co. Provide details (e.g., child's name, approximate age, related order/account info), and we will verify and delete the data without delay.
- Changes to This Privacy Policy
We may update or modify this Privacy Policy from time to time to reflect changes in our practices, new legal requirements, or improvements to the Platform.
If we make material changes (changes that significantly affect your privacy rights or how we handle your personal information—such as new ways we collect, use, share, or retain data, or major updates to your rights under PDPO 2025), we will provide reasonable advance notice before the changes take effect. This notice will be given through:
- A prominent announcement on the Platform (e.g., a banner, pop-up notification, or
dedicated section on the website/app).
- Email sent to the address associated with your account (if you have registered one).
- Push notification in the Fashion Arc mobile app (if you have it installed).
Non-material changes: (e.g., minor clarifications, typographical fixes, or updates that do not substantially impact your privacy) will be posted on the Platform and become effective immediately upon publication.
Your continued use of Fashion Arc—whether browsing, creating an account, placing orders, or maintaining an active session—after the effective date of any updated Privacy Policy constitutes your full acceptance of the changes.
11. Contact Us
If you have any questions, concerns, or feedback regarding these privacy policy, the Fashion Arc Platform, your account, orders, or any other matter, please feel free to contact us using the following channels:
Email: hello@fashionarc.co Phone / WhatsApp: 01736988266 Facebook Page: www.facebook.com/fashionarc.co Instagram: www.instagram.com/fashionarc.co Threads: www.threads.com/fashionarc.co Tiktok: www.tiktok.com/@fashionarc.co Website: www.fashionarc.co We aim to respond to all inquiries as promptly as possible, typically within 1–2 working days during business hours.
Last updated: [Insert Date – e.g. February 2026]