Skip to content
Free shipping on prepaid orders above Rs. 499 Dermatologically tested · Made in India Use code VORLISE10 for 10% off your first order

Privacy Policy

Last updated: This Privacy Policy explains how Vorlise processes personal data when you browse the website, create an account, place an order, join a mailing list, contact customer care, submit a review or otherwise interact with the store. It is written for customers in India and should be read with the Terms & Conditions and other Help policies.

1. Who is responsible for your data

Vorlise is the customer-facing brand. The legal entity responsible for a particular sale is identified on the invoice or order record. In this policy, “Vorlise”, “we”, “us” and “our” refer to that store operator. For privacy questions, correction requests, consent withdrawal or grievances, contact vorlisecare@gmail.com. Please identify the account, order or communication concerned without sending passwords, one-time passwords, card PINs, CVVs or more identity information than reasonably necessary. We may verify a requester before acting so that another person cannot obtain or alter your data.

2. Data you provide directly

Depending on how you use the store, you may provide your name, email address, mobile number, billing address, delivery address, pin code, account password, order instructions, product selections, coupon information, customer-care messages, review content and return or refund details. If a cash-on-delivery refund requires bank or UPI information, we request only the details reasonably needed to make that payment through an appropriate channel. Do not include health records, government identifiers or sensitive financial credentials in an ordinary support email unless we specifically explain why they are legally and operationally necessary.

3. Data created during transactions

When you shop, our systems create order numbers, cart records, timestamps, item and quantity details, prices, discounts, tax information, payment status, fulfilment status, courier tracking, delivery events, cancellation records, return decisions and support history. We may receive a payment reference, masked payment instrument information, payment method and success or failure status from the gateway. The gateway, bank or payment provider processes full payment credentials under its own security and legal obligations; Vorlise does not need your card PIN, CVV or one-time password to process an order or refund.

4. Data collected from devices and website use

The website and its service providers may process IP address, browser type, device type, operating system, language, approximate region, referral page, pages viewed, buttons used, session identifiers, cookie choices, cart activity, error logs and security events. This information helps deliver pages, keep the cart functioning, remember preferences, measure performance, prevent abuse and diagnose faults. We do not claim that every technical identifier directly names you, but identifiers can become personal data when linked with an account, order or other information. Browser controls can limit cookies, although necessary cart, login or checkout features may then stop working correctly.

5. Why we process personal data

We process data to provide requested goods and services; confirm and fulfil orders; authenticate accounts; take and reconcile payment; calculate tax and discounts; dispatch parcels; send delivery updates; handle cancellations, returns and refunds; answer questions; maintain security; prevent fraud and coupon abuse; keep financial and compliance records; improve website reliability; understand store performance; and establish or defend legal claims. We use contact details for marketing only when there is an appropriate permission or other lawful basis and provide a practical opt-out. We do not collect data merely because it might be useful someday.

6. Consent and customer choices

Where processing depends on consent, the request should explain the relevant purpose in clear language. You may refuse optional marketing without losing the ability to place an ordinary order. You may withdraw consent through an unsubscribe control or by contacting us, with a process reasonably comparable to giving it. Withdrawal does not make earlier lawful processing invalid and does not always require deletion of records that must be retained for an existing order, accounting, security, a legal obligation or a dispute. Product reviews and promotional image permissions can be withdrawn prospectively where applicable, subject to copies already lawfully published or retained.

7. Cookies and similar technologies

Necessary cookies support login, security, cart contents, checkout steps, currency or interface preferences. Analytics technologies can help us understand aggregated visits, page performance and navigation so we can improve the store. Advertising technologies, if enabled, may measure campaigns or support relevant promotion. The exact tools can change as providers and business needs change. Where required, we present a consent choice before using non-essential technologies. You can also clear or block cookies in the browser. Doing so may sign you out, empty a remembered cart, reset choices or prevent checkout from operating normally.

8. Payment, delivery and service providers

We share limited data with providers that perform a genuine store function. A payment provider receives transaction and authentication information. A courier or logistics aggregator receives the recipient name, phone number, delivery address, parcel details and order reference needed to deliver and manage exceptions. Hosting, email, customer-support, security, analytics, accounting and technical providers may process relevant data on our instructions or under their own legal responsibilities. We expect providers to protect data and use it for defined purposes. We do not sell a customer list in exchange for money or disclose data to unrelated parties merely for their independent convenience.

9. Legal disclosure and business changes

We may disclose information when reasonably necessary to comply with law, tax or accounting duties, a valid government or court request, consumer proceedings, fraud investigation, cybersecurity response, product recall, protection of rights or enforcement of a contract. We assess requests and seek to disclose only what is relevant. If the business is reorganised, financed, merged or transferred, customer and order records may be reviewed or transferred as part of that transaction subject to confidentiality, lawful purpose and continued protection. A business change does not permit the new operator to ignore applicable privacy obligations.

10. Retention and deletion

We keep information only for as long as reasonably needed for the purpose described or a valid legal requirement. Order, invoice, tax, payment and refund records can require longer retention than an abandoned cart or an optional marketing preference. Security logs may be kept long enough to detect patterns and investigate incidents. Support messages may be linked to an order so we can understand prior decisions. When data is no longer needed, we delete, anonymise or securely isolate it according to practical system capabilities. Backup copies may remain for a limited cycle and are not normally used for active marketing or routine customer decisions.

11. Security practices

We use reasonable administrative, technical and organisational measures appropriate to the nature of the store and data. Measures may include restricted administrative access, strong authentication, software updates, encrypted connections, payment-provider tokenisation, backups, logging, malware protection and provider review. No website, email account, courier database or internet transmission can be guaranteed completely secure. You also play a role: use a unique password, protect your device, sign out on shared computers and ignore anyone asking for a PIN, CVV or one-time password. Tell us promptly if you suspect account misuse or a fraudulent message using our name.

12. Data incidents

If we become aware of a personal-data breach, we investigate, contain it where possible, preserve relevant evidence and assess the likely impact. We notify authorities and affected people when required by applicable law and provide information that can reasonably help reduce harm. Not every service outage or unsuccessful login attempt is a reportable breach, but each credible event is evaluated. Customers should act quickly on a genuine warning, such as resetting a password or monitoring an account, while remaining alert to phishing messages that imitate a breach notice. We will not ask for payment credentials to “secure” an account.

13. Your privacy rights

Subject to applicable law and verification, you may request information about personal data being processed, correction of inaccurate data, completion or updating of records, erasure when data is no longer required, withdrawal of consent, access to available grievance handling and nomination or another right provided by law. Some requests cannot be completed exactly as asked when retention is necessary for an order, invoice, legal obligation, fraud prevention, security or a live claim. We will explain a refusal or limitation where required. Requests should identify the relevant account or order and the specific outcome sought so that we can respond efficiently.

14. Marketing communication

Marketing may include product launches, education, restock alerts, offers or abandoned-cart reminders where permitted. Transactional messages about account security, payment, dispatch, delivery, returns or a customer-care request are not the same as optional promotion. Use the unsubscribe link where available or email us to stop marketing. It can take a short operational period to apply a preference across scheduled systems, and you may still receive a message already queued. Opting out of marketing does not remove order records or prevent necessary service communication. We do not require marketing consent as a condition for an ordinary purchase.

15. Reviews, photographs and public content

A review, question, social-media tag or image submitted for publication may become visible to other people. Do not include an address, phone number, order invoice, medical document or another person’s personal data in public content. We may moderate a submission to remove sensitive details, abuse, spam or irrelevant material while preserving the substance of a genuine review. If you ask us to remove content, we consider the request and applicable rights, although search engines, screenshots or third-party shares can remain outside our direct control. Private support messages are not published as reviews without an appropriate basis or permission.

16. Children and family purchases

The store is intended for adults able to place a lawful order. We do not knowingly invite children to create accounts or provide personal data independently. A parent or guardian should place an order for a minor and supervise product use according to the label and professional advice. If you believe a child has provided personal data without proper authorisation, contact us with enough information to locate the record. We will review and take appropriate action. Do not send a child’s identity document unless we specifically explain a lawful need and a safer verification method.

17. Cross-border processing

Some technology or communication providers may operate infrastructure or support teams outside your state or outside India. Where personal data is processed across borders, we use providers and arrangements intended to maintain appropriate protection and comply with restrictions applicable at the time. Location can change as cloud networks route traffic or providers update infrastructure. Cross-border processing does not change the purpose limitation described here. If a law prohibits transfer to a particular country or requires an additional safeguard, we will take reasonable steps to comply or use an alternative provider.

18. Complaints and contact

Send privacy questions or grievances to vorlisecare@gmail.com. State that the request concerns privacy, identify the relevant account or order, describe the issue and specify the remedy sought. We may ask for proportionate verification. We aim to acknowledge a grievance promptly and respond after investigating relevant systems and providers. If you remain dissatisfied, request escalation and use any complaint mechanism available under applicable data-protection or consumer law. Exercising a privacy right in good faith will not affect the quality or price of an ordinary order, although deletion can limit account features that depend on the deleted data.

19. Policy updates

We may update this policy when the law, website, provider list, product operations or data practices change. Material changes are presented through an appropriate website, account or email notice when required. The date at the top helps identify the current version. A new policy does not retroactively make an unlawful use lawful. Continue to review privacy choices and contact us if a change is unclear. The policy should be interpreted in a customer-protective manner consistent with applicable data-protection and consumer requirements.

Compliance notice: This policy is intended to reflect principles found in India’s Digital Personal Data Protection framework, including clear notice, specified purpose, appropriate consent, security safeguards, correction, erasure and grievance handling. Actual compliance also depends on the store’s configured plugins, hosting, analytics, payment, courier and marketing providers. The store operator should periodically review those systems with a qualified privacy professional.