This Privacy Policy explains what personal data Vesting (vesting.in, "we") collects, why, how long we keep it, and the rights you have over it. It is written to align with the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, alongside the Information Technology Act, 2000.
The short version: every tool works without an account, we run no advertising or analytics trackers, and we never sell personal data.
1. Data we collect, and why
If you only browse (no account)
- Server and security logs — your IP address, browser user-agent, pages requested and timestamps. Purpose: operating the site, diagnosing errors, and preventing abuse and fraud.
- Essential cookies — a session cookie needed for the site to function (for example, security tokens that protect forms). It contains no tracking identifiers. We set no advertising or analytics cookies.
If you create an account
- Registration data — your name, email address, and password. Passwords are stored only as strong one-way hashes (Argon2id); we cannot read them. Purpose: creating and securing your account and sending essential account email (verification, password reset).
- Optional profile details — phone number and address fields, only if you choose to fill them in. Purpose: completing your profile; they are never required to use the tools.
- Sign-in records — login attempts with IP address and browser user-agent, and a record of administrative actions where applicable. Purpose: account security, rate-limiting brute-force attacks, and fraud prevention.
- "Remember me" cookie — set only if you tick the option at login; it keeps you signed in for up to 30 days and is deleted when you log out.
- Two-factor authentication secret — only if you enable 2FA, to verify your authenticator codes.
What we do not collect
- The numbers you type into calculators are processed in your browser and are not transmitted to or stored on our servers.
- No advertising identifiers, no cross-site tracking, no sale or rental of personal data — to anyone, ever.
2. Third parties
- Email delivery — account emails (verification, password reset) are delivered through Zoho ZeptoMail, a transactional email service, which processes your email address solely to deliver those messages.
- Hosting — the site runs on managed cloud infrastructure; server logs reside there.
- Embedded content — some pages load resources from third parties, which receive your IP address as part of serving them: Google Fonts (typography), Google Maps (branch-location maps on IFSC/SWIFT pages) and jsDelivr (the charting library on calculators). These providers' own privacy policies apply to that processing.
- Rate providers — gold, silver and currency rates are fetched by our servers from data providers; no personal data about you is sent to them.
3. How long we keep data
- Failed sign-in records — deleted after 24 hours (kept only to rate-limit attacks).
- Inactive session records — deleted after 30 days.
- Expired security tokens (verification, reset, remember-me) — purged automatically on expiry.
- Account data — kept while your account exists; deleted on verified erasure requests, except where law requires longer retention.
- Application logs — kept for a limited operational period for security and troubleshooting.
4. How we protect data
- Passwords hashed with Argon2id; two-factor authentication available on every account.
- Encrypted connections (HTTPS with HSTS), a strict Content-Security-Policy, CSRF protection on every form, and rate-limiting on sign-in.
- Administrative actions are recorded in an audit trail.
No system can be guaranteed 100% secure, but security is engineered into the service, not bolted on. In the event of a personal-data breach we will notify affected users and the Data Protection Board of India as required by law.
5. Your rights
Under the DPDP Act you have the right to:
- access a summary of the personal data we hold about you;
- correct or update inaccurate or incomplete data (much of this you can do directly in your profile);
- erase your data by deleting your account;
- withdraw consent at any time, as easily as it was given;
- grievance redressal — have your complaint heard and addressed;
- nominate a person to exercise these rights on your behalf in case of death or incapacity.
To exercise any of these, see the Contact page (subject line "Data Request"). We verify requests against your registered email before acting on them, and respond within the timelines prescribed by law.
6. Children
The Service is intended for users aged 18 and above and is not directed at children. We do not knowingly process children's personal data; if you believe a minor has created an account, contact us and we will remove it.
7. Changes to this policy
If we change what we collect or how we use it, we will update this page and its "Last updated" date. Material changes affecting account holders will be notified by email.
8. Contact & grievances
For any privacy question, data request or grievance, contact us as described on the Contact page.
Last updated: July 2026