Legal
Privacy Policy
Effective date 24 August 2026 · Last updated 24 August 2026
This page is published in English only. The English text is the authoritative version.
1. Who we are
Vistarah Global Private Limited is the controller for personal data collected through https://www.vistarahglobal.com.
We are an India-based B2B export partnership company. This website is for business information, enquiries and quotations. It does not process online orders or payments.
We have not appointed a named Data Protection Officer, EU representative or UK representative in this policy. Whether an EU or UK representative is legally required for Vistarah's actual targeting and processing is a launch-blocker for owner and qualified-counsel review before production publication.
2. Personal data we collect
Enquiry forms (the Contact form and the Request-a-Quote form) ask for company name, your name, business email and contact number, and may optionally receive product of interest, destination port, volume, required-by date, end use, a free-text message or specification, and one file attachment. The country is derived from the dialling code selected with the contact number, not asked separately.
The site stores a first-party language-preference cookie named vg-locale when a visitor chooses a language, and a first-party consent cookie named vg-consent when a visitor accepts or declines optional cookies.
Enquiry and quote submissions are sent to Zoho CRM for lead and enquiry management. If a submission cannot be recorded in Zoho CRM, the submitted details are emailed to Vistarah's sales inbox instead so the enquiry is not lost. Bot-protection uses Cloudflare Turnstile, which processes a token and limited technical data to tell humans from automated abuse.
Zoho Bookings and the contact-page Google map are click-to-load: each iframe loads only after the visitor asks for it, and Zoho or Google may then receive request data and set third-party cookies.
With the visitor's consent, the site may load Google Tag Manager for configured measurement and advertising tags, including Google Analytics 4, Google Ads conversion tracking, Microsoft Clarity, Bing/UET, LinkedIn Insight, Meta Pixel/CAPI browser events and a Zoho CRM visitor tracking script, as well as Zoho SalesIQ (live chat and visitor context) and Zoho PageSense (on-site analytics, including heatmaps and funnel measurement). These are not loaded before consent is given, and can be declined.
We do not intentionally collect special-category data, children's data, payment-card data or consumer checkout data through this website. Please do not send such data unless Vistarah has specifically requested it for a lawful and documented purpose.
3. Why we use personal data and GDPR/UK GDPR lawful bases
We use enquiry data to respond to a business request, assess feasibility, prepare quotations or specifications, perform counterparty checks where relevant, maintain correspondence records and protect against fraud or unlawful trade activity.
For EU/EEA and UK visitors, enquiry handling normally relies on steps requested before entering a contract and Vistarah's legitimate interests in responding to B2B enquiries, keeping business records and preventing fraud. Legal or regulatory checks may rely on legal obligation where applicable.
The language-preference cookie remembers the visitor's selected locale. Google Tag Manager, its configured measurement or advertising tags, Zoho SalesIQ and Zoho PageSense rely on the visitor's consent, recorded in the vg-consent cookie; they are not loaded before consent and consent can be withdrawn by declining in the cookie banner or clearing the cookie. Non-essential third-party cookies are not loaded before a visitor chooses to load the Zoho scheduler or accepts optional cookies.
We do not use solely automated decision-making or profiling that produces legal or similarly significant effects about individuals through the website.
4. Sharing, processors and international transfers
We may share personal data with website hosting and IT providers, Zoho CRM (lead and enquiry management), Zoho Mail (the fallback route for enquiries that cannot be recorded in the CRM), Cloudflare (bot protection), Zoho Bookings and Google Maps if their click-to-load embeds are opened, Google Tag Manager and configured tag providers such as Google, Microsoft, LinkedIn, Meta and Zoho if optional cookies are accepted, Zoho SalesIQ and Zoho PageSense if optional cookies are accepted, professional advisers, and public authorities where legally required.
For trade enquiries that progress beyond the website, information may also be shared with logistics providers, inspection laboratories, banks, insurers, customs brokers, government agencies or counterparties only as needed for a specific transaction and subject to transaction documents.
Personal data may be processed in India and in other countries where our service providers operate. Where EU/EEA or UK transfer rules apply, Vistarah should use an appropriate transfer mechanism, such as adequacy regulations, standard contractual clauses, the UK IDTA or UK addendum, as applicable to the provider and data flow.
Zoho's own privacy and data-processing materials should be reviewed and the correct Zoho region, data-processing addendum and sub-processor terms confirmed before CRM or Bookings is used for production personal data.
5. Retention, security and breach handling
We retain website enquiry, quotation and scheduling data according to the purpose, transaction status, legal-record needs, dispute risk and any applicable tax, company, trade or regulatory requirement. Specific operational retention periods must be approved before production CRM launch.
When personal data is no longer required, we will delete, anonymise or archive it according to an approved retention process, unless retention is required for a legal claim, investigation, audit or mandatory record.
We use reasonable technical and organisational safeguards, including access controls, limited internal access, secure service-provider configuration and incident review. No website or email system can be guaranteed completely secure.
If a personal-data breach occurs, Vistarah will assess the facts and notify regulators and affected individuals where required by applicable law.
6. Your rights and complaint routes
Depending on your location and the law that applies, you may request access, correction, completion, updating, deletion, restriction, objection, portability, withdrawal of consent, grievance handling or review of certain decisions.
For India, the Digital Personal Data Protection Act, 2023 and notified rules support notice, consent or permitted lawful processing, data-principal rights and grievance redressal as applicable. Vistarah's privacy and grievance contact is contact@vistarahglobal.com unless a separate statutory appointment is approved.
For the EU/EEA, the GDPR may apply where Vistarah's processing falls within its territorial scope. You may also complain to your local supervisory authority. GDPR Articles 13 and 14 transparency information is provided through this Privacy Policy.
For the United Kingdom, the UK GDPR, Data Protection Act 2018 and the Data (Use and Access) Act 2025 amendments may apply where territorial scope is met. You may complain to Vistarah first and may also contact the Information Commissioner's Office.
For the United States, we do not sell personal information. Optional advertising or retargeting tags are loaded only after consent where configured, and comprehensive state privacy rights are handled where the relevant law applies to Vistarah after threshold and territorial analysis.
For Canada, PIPEDA or substantially similar provincial laws may apply to personal information handled in commercial activity. You may contact Vistarah and may complain to the Office of the Privacy Commissioner of Canada where applicable.
For the UAE, federal UAE privacy law may apply where its territorial scope is met. DIFC and ADGM regimes are separate and are not claimed to apply unless a specific transaction or establishment triggers them.
For Australia, the Privacy Act 1988 and Australian Privacy Principles may apply if Vistarah is covered by the Act, including turnover or other statutory triggers. We do not assume coverage until the business facts are confirmed, but we will handle privacy requests fairly where feasible.
7. Cookies, third-party links and changes
Our separate Cookie Policy explains the vg-locale and vg-consent cookies, the consent banner that gates Google Tag Manager, configured tags, Zoho SalesIQ and Zoho PageSense, and click-to-load Zoho Bookings behavior.
The website may link to third-party sites, certificate issuers, social media and Google Maps, and shows a static Google map image on the contact page. Their privacy practices are not controlled by Vistarah.
We may update this Privacy Policy when website behavior, law, service providers or business processes change. Material changes will be handled as required by law.
Contact
Vistarah Global Private Limited, CIN U82990HR2025PTC139181, IEC/PAN AALCV6631L, GSTIN 06AALCV6631L1ZU. Registered office: 2132/26, Pech Paras Ram, Old Anaj Mandi, Rohtak, Haryana 124001, India. Corporate office: B-7, 7th Floor, Worxspace Coworking, Welldone Tech Park, Sector 48, Gurugram, Haryana 122018, India.
Privacy, grievance and general legal contact: contact@vistarahglobal.com | +91 9810286336.

