Privacy policy

Privacy policy

Last updated:

MOST IMPORTANT TERMS AND CONDITIONS


The short version, in plain English. This is a summary written for speed, not a replacement for the real thing. If anything here disagrees with the full Privacy Policy that follows, the full Privacy Policy wins. Each point tells you where to read further.

1. Here Is What We Collect.

Your name or studio name, your email address, links to your website, portfolio, or Instagram, a line about what you do, and whatever you type into the message box. Your browser also announces the usual technical details to us, as it does to every website you visit.

Full detail: Section 4 (Personal Data We Collect).

2. Your Listing Is Public. Genuinely Public.

If we publish your listing, anyone can see it. Search engines will index it and web archives will keep copies. Please submit only what you are happy to have out in the open, and keep anything confidential well away from the message box.

Full detail: Section 6 (Publication of Listings and Introductions).

3. We Pass Your Details on When We Introduce You.

That is rather the point of an introduction. Once your details reach the other side, they handle that information under their own privacy practices, not ours, and we have no control over what they do next.

Full detail: Sections 6 and 9.

4. We Do Not Sell Your Data.

We use Google Analytics 4 and Microsoft Clarity to understand how people use the site. We do not sell your personal data, and we do not hand it to third parties for their own marketing.

Full detail: Section 9 (Disclosure of Data and No Sale of Personal Data).

5. One Cookie Is a Microsoft Advertising Identifier.

Microsoft Clarity sets an identifier called MUID on Microsoft's own domain, and Microsoft may use it for advertising across its network. We neither control it nor use it, but we would rather tell you than let you find out from a cookie scanner. It is set only if you consent, and you can decline it.

Full detail: Sections 9 and 24, and the Cookie Policy.

6. Cookies: We Ask Before We Set Them.

Non-essential cookies load only after you say yes on the consent banner. You can change your mind at any time through the cookie settings on the site, and saying no does not stop you browsing, viewing listings, or making a submission.

Full detail: Section 7 (Cookies) and the Cookie Policy.

7. You Can Ask Us to Correct or Delete Your Data.

Email us and we will act on it. We can remove your listing from our site. We cannot reach into Google's cache or a web archive and delete their copy, because those are not ours to delete.

Full detail: Sections 16, 17, and 39.

8. If Something Goes Wrong, Here Is Where to Complain.

Write to hello@reborngoods.co, or to help@nonzero.space. If we do not put it right, you can approach the Data Protection Board of India, or your local data protection authority if you are in the EEA or the UK.

Full detail: Section 42 (Grievance Redressal and Contact).

Still with us? Good. The full Privacy Policy begins overleaf, and it governs.

Table of Contents

Section

Page

Most Important Terms and Conditions

1

1. Introduction

6

2. Definitions

7

3. Name and Address of the Controller

9

4. Personal Data We Collect

10

5. Purposes and Use of the Data We Collect

11

6. Publication of Listings and Introductions

12

7. Cookies

13

8. Contact Possibility via the Platform

14

9. Disclosure of Data and No Sale of Personal Data

14

10. International Data Transfers and Global Audience

15

11. Restricted Jurisdictions, Sanctions, and Export Control

15

12. Security

16

13. Routine Erasure and Blocking of Personal Data

17

14. Period for Which the Personal Data Will Be Stored

17

15. Children's Privacy

18

16. Rights of the Data Subject

18

17. Your Rights Under India's Digital Personal Data Protection Act

20

18. CCPA Proviso

21

19. Legal Basis for the Processing

23

20. The Legitimate Interests Pursued by the Controller or by a Third Party

24

21. Provision of Personal Data as a Statutory or Contractual Requirement

24

22. Data Protection Provisions About the Application and Use of Google Tag Manager and the Google Site Tag

24

23. Data Protection Provisions About the Application and Use of Google Analytics 4

25

24. Data Protection Provisions About the Application and Use of Microsoft Clarity

26

25. Data Protection Provisions About the Application and Use of Google Search Console

27

26. Data Protection Provisions About the Application and Use of Webflow

28

27. Data Protection Provisions About the Application and Use of Framer

29

28. Data Protection Provisions About the Application and Use of Submittable

29

29. Data Protection Provisions About the Application and Use of Amazon Web Services

30

30. Data Protection Provisions About the Application and Use of Cloudflare

30

31. Data Protection Provisions About the Application and Use of Fastly

31

32. Data Protection Provisions About the Application and Use of DigitalOcean Spaces

31

33. Data Protection Provisions About the Application and Use of Google Fonts, Google Hosted Libraries, and Google Static Content

32

34. Data Protection Provisions About the Application and Use of UNPKG

32

35. Data Protection Provisions About the Application and Use of Google Workspace

33

36. Data Protection Provisions About the Application and Use of WhatsApp

33

37. Data Protection Provisions About Domain, DNS, and Transport Layer Security Services

34

38. Data Protection Provisions About the Application and Use of Google Ads and DoubleClick

35

39. Public Indexing, Crawling, and Archiving

35

40. Data Protection Provisions About Cookie Consent Management

36

41. Personal Data Breach

36

42. Grievance Redressal and Contact

37

43. Changes to This Privacy Policy

37

44. Governing Law and Jurisdiction

38

1. Introduction

Non Zero Design LLP (hereinafter referred to as "Non Zero", "Reborn Goods", "we", "us", "our") operates Reborn Goods and is delighted that you have shown interest in our services and any services which are provided via https://www.reborngoods.co/, together with any software, APIs, mobile website and mobile applications related, linked, or otherwise connected thereto (collectively, the "Platform"). Data protection is a high priority for Non Zero. The use of the Platform is generally possible without any indication of personal data; however, if a data subject wants to use certain services offered via our Platform (such as submitting a brand or builder through our forms), processing of personal data may become necessary. Where the processing of personal data is necessary and there is no statutory basis for such processing, we generally obtain consent from the data subject.

The processing of personal data, such as the name, brand or studio name, email address, portfolio or social media links, or the content of a message of a data subject, shall always be in line with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Digital Personal Data Protection Act, 2023 of India read with the Digital Personal Data Protection Rules, 2025 (together, the "DPDP Act"), and in accordance with the country-specific data protection regulations applicable to Non Zero. By means of this Privacy Policy, our enterprise would like to inform the general public of the nature, scope, and purpose of the personal data we collect, use, and process. Furthermore, data subjects are informed, through this Privacy Policy, of the rights to which they are entitled.

As the controller (and, for the purposes of the DPDP Act, the Data Fiduciary), Non Zero has implemented numerous technical and organisational measures to ensure the protection of personal data processed through this Platform. However, Internet-based data transmissions may, in principle, have security gaps, so absolute protection may not be guaranteed. For this reason, every data subject is free to transfer personal data to us via alternative means, for example, by telephone or post.

This Privacy Policy should be read together with our separate Cookie Policy, which describes in detail the cookies and similar technologies used on the Platform, and with our Terms and Conditions, which govern your access to and use of the Platform.

2. Definitions

This Privacy Policy is based on the terms used by the European legislator for the adoption of the General Data Protection Regulation (GDPR). Our Privacy Policy should be legible and understandable for the general public, as well as our customers and business partners. To ensure this, we would like to first explain the terminology used. Where relevant, we have indicated the corresponding term under the DPDP Act. In this Privacy Policy, we use, among other things, the following terms:

  1. Personal data Personal data means any information relating to an identified or identifiable natural person ("data subject", referred to as a "Data Principal" under the DPDP Act). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

  2. Data subject / Data Principal Data subject is any identified or identifiable natural person whose personal data is processed by the controller responsible for the processing. Under the DPDP Act, such a person is referred to as a Data Principal.

  3. Processing Processing is any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

  4. Restriction of processing Restriction of processing is the marking of stored personal data with the aim of limiting their processing in the future.

  5. Profiling Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements.

  6. Pseudonymisation Pseudonymisation is the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

  7. Controller / Data Fiduciary Controller, or controller responsible for the processing, is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Under the DPDP Act, this role corresponds to that of the Data Fiduciary.

  8. Processor / Data Processor Processor is a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller. Under the DPDP Act, this role corresponds to that of the Data Processor.

  9. Recipient Recipient is a natural or legal person, public authority, agency, or another body, to which the personal data are disclosed, whether a third party or not.

  10. Third party Third party is a natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

  11. Consent Consent of the data subject is any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

  12. Consent Manager Consent Manager means, under the DPDP Act, a person registered with the Data Protection Board of India who acts as a single point of contact to enable a Data Principal to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform.

  13. Brand and Builder Brand means a person or entity that uses the Platform to discover or seek an introduction to providers of goods or services. Builder means a person or entity listed or seeking to be listed on the Platform as such a provider. These terms have the meanings given to them in our Terms and Conditions.

3. Name and Address of the Controller

The controller for the purposes of the General Data Protection Regulation (GDPR), other data protection laws applicable in the Member States of the European Union, the California Consumer Privacy Act (CCPA), and the Data Fiduciary for the purposes of the DPDP Act, is:

Non Zero Design LLP

Enam Sambhav, BKC WeWork Enam Sambhav, C-20, G Block Rd, G Block BKC, Bandra Kurla Complex, Bandra East, Mumbai, Maharashtra 400051, India

Email: hello@reborngoods.co or help@nonzero.space

4. Personal Data We Collect

We collect personal data in two ways: data that you provide to us directly, and data that is collected automatically when you access the Platform.

Data you provide to us through the "Submit a Brand" form.

  • Name or brand name

  • Email address

  • Website, portfolio, or Instagram link

  • The content of the message you choose to send us

Data you provide to us through the "Submit a Builder" form.

  • Name or studio name

  • Website or portfolio link

  • A description of what you do

  • Instagram or portfolio link

  • The content of the message you choose to send us

  • Email address, where you provide one or where we require one in order to respond

You should not include any sensitive personal information in the free text message field. All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information. Where you submit information relating to a company, firm, studio, or other entity, you confirm that you are authorised to do so.

Data collected automatically.

When a data subject, or an automated system, calls up the Platform, a series of general data and information is collected and stored in the server log files. This may include the browser type and version, the operating system, the referrer URL, the date and time of access, the Internet protocol (IP) address, and similar technical data, as well as data and information that may be used in the event of attacks on our information technology systems. When using this general data and information, Non Zero does not draw any conclusions about the data subject; rather, this information is processed for the purposes described in the section titled "Purposes and Use of the Data We Collect". The anonymised data of the server log files are stored separately from all personal data provided by a data subject.

In addition, our analytics and session analysis tools collect behavioural data about how the Platform is used, including pages viewed, links clicked, scroll depth, and interaction patterns, as further described in the sections below and in our Cookie Policy.

5. Purposes and Use of the Data We Collect

We use the personal data we collect for the following purposes:

  • To review, assess, and curate submissions received through our forms;

  • To publish a listing or profile on the Platform, where we accept a submission;

  • To respond to enquiries and briefs, and to reach out to you where there is a potential business prospect, collaboration, or introduction;

  • To make introductions between brands and builders, including by sharing your contact details and brief information with the other party;

  • To deliver the content of our Platform correctly and to optimise it;

  • To ensure the long-term viability and security of our information technology systems and website technology;

  • For analytics and statistical purposes, to understand how visitors use the Platform and to improve its usability;

  • To comply with applicable legal obligations; and

  • To provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack.

We may contact you by email, and, where you have provided a number and consented to being contacted in that way, by messaging services such as WhatsApp, in connection with your submission, your listing, or an introduction. You may ask us to stop contacting you at any time by writing to hello@reborngoods.co. Any promotional or commercial communications sent by telephone call or short message service will be sent only in accordance with applicable law, including the Telecom Commercial Communications Customer Preference Regulations, 2018.

We do not use the personal data you provide through our forms for automated decision-making that produces legal or similarly significant effects concerning you. Decisions on curation, listing, vetting, and introductions are made by our team as an exercise of editorial judgement.

6. Publication of Listings and Introductions

Reborn Goods is a public discovery platform. Where we accept a submission, some or all of the information you provide, including your name or studio name, a description of what you do, and links to your website, portfolio, or social media profiles, will be published on the Platform and will be visible to the public, to search engines, and to third-party crawlers and archiving services. You should submit only information that you are content to have published.

Where an introduction is made, we will share the relevant contact details and brief information with the other party for that purpose. Once an introduction has been made, the recipient becomes an independent controller in respect of the information shared with them, and their use of that information is governed by their own privacy practices and not by this Privacy Policy. We are not responsible for the manner in which any brand or builder handles information shared with them through an introduction.

You may ask us to remove or amend your listing at any time by writing to hello@reborngoods.co. We will use reasonable efforts to effect removal within a reasonable period. Please note that removal from the Platform does not, and cannot, remove copies that may persist in search engine caches and indexes, in third-party archives such as web crawling and archiving services, or in the records of any person to whom an introduction was made. It also does not affect information you have shared directly with any other user.

7. Cookies

The Platform of Reborn Goods uses cookies and similar technologies. Cookies are text files that are stored on a computer system via an Internet browser. Many cookies contain a so-called cookie ID, which is a unique identifier of the cookie. Through the use of cookies, we can provide the users of this Platform with more user-friendly services that would not be possible without the cookie setting, and can optimise the information and offers on the Platform with the user in mind.

The data subject may, at any time, prevent the setting of cookies through our Platform by means of a corresponding setting of the Internet browser used, and may thus permanently deny the setting of cookies. Furthermore, cookies that have already been set may be deleted at any time via an Internet browser or other software programs. If the data subject deactivates the setting of cookies in the Internet browser used, not all functions of our Platform may be entirely usable. On first access to the Platform, you are also presented with a cookie consent banner that allows you to accept or decline non-essential cookies and to manage your preferences, and you may revisit those preferences at any time through the cookie settings control on the Platform.

A detailed description of the specific cookies used on the Platform, including their name, provider, purpose, and duration, is set out in our separate Cookie Policy, which forms part of and should be read together with this Privacy Policy.

8. Contact Possibility via the Platform

The Platform of Reborn Goods contains information that enables quick electronic contact with our enterprise, as well as direct communication with us, which also includes a general email address. If a data subject contacts the controller by email or via a form, the personal data transmitted by the data subject are automatically stored. Such personal data, transmitted on a voluntary basis by a data subject to the controller, are stored for the purpose of processing the submission or enquiry or contacting the data subject. Submissions made through the forms on the Platform are routed to and received at hello@reborngoods.co.

9. Disclosure of Data and No Sale of Personal Data

We do not sell your personal data. We use analytics and performance tools, namely Google Analytics 4 and Microsoft Clarity, for our own understanding of how the Platform is used, and not for onward sale or disclosure to unrelated third parties.

Certain third-party tools used on the Platform set identifiers on their own domains that those providers may also use for their own analytics or advertising purposes on their own networks, independently of us. Where such identifiers are set, they are set only after you have given consent through our cookie consent banner, and you may withdraw that consent at any time through your cookie preferences. Those identifiers, and the categories to which they belong, are set out in our Cookie Policy.

We disclose personal data in the following circumstances: to the other party to an introduction, as described above; to the service providers and processors described in the sections below, who process personal data on our behalf and under our instructions in order to operate, host, secure, and analyse the Platform; where required to do so by law, regulation, or a lawful request from a competent authority; and where necessary to protect our rights, property, or safety, or that of our users or the public.

10. International Data Transfers and Global Audience

Non Zero Design LLP is a limited liability partnership incorporated in India, with its registered office in Mumbai, Maharashtra. The Platform is, however, accessible to, and may be used by, visitors located anywhere in the world. If you access the Platform from outside India, please be aware that your information may be transferred to, stored in, and processed in India, as well as in other countries where our service providers operate, including the United States and the European Economic Area.

These countries may have data protection laws that are different from, and in some cases less protective than, the laws of your country of residence. Where we transfer personal data internationally, we take steps to ensure that appropriate safeguards are in place in accordance with applicable law, and that the recipients are bound to protect the personal data to a standard consistent with this Privacy Policy. By using the Platform or submitting personal data to us, you acknowledge and, where required by law, consent to such transfer, storage, and processing.

Nothing in this Privacy Policy shall be read as targeting, or as an offer of goods or services to, individuals in any jurisdiction where doing so would be unlawful for Non Zero.

11. Restricted Jurisdictions, Sanctions, and Export Control

The Platform is not directed to, and is not intended for use by, any person located in, ordinarily resident in, or organised under the laws of any country or territory that is subject to comprehensive economic sanctions or embargoes, including but not limited to the Democratic People's Republic of Korea (North Korea), Iran, Syria, Cuba, and the Crimea, Donetsk, and Luhansk regions. The Platform is likewise not available to any person who is designated on any applicable restricted-party or sanctions list, including the lists maintained by the Government of India, the United Nations Security Council, the European Union, and the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC).

By accessing or using the Platform, you represent and warrant that you are not located in any such country or territory, and that you are not a person with whom dealings are prohibited under applicable sanctions or export control laws. We reserve the right to restrict or deny access to the Platform, and to decline to process any submission or enquiry, where we believe that doing so is necessary to comply with such laws.

The Platform and its underlying technology may be subject to export control and economic sanctions laws, including those of India, the European Union, and the United States. You agree that you will not use, export, re-export, or transfer, directly or indirectly, any part of the Platform or any related technical data in violation of such laws. This clause applies in addition to, and does not limit, any other provision of this Privacy Policy.

12. Security

This Platform ensures that data is encrypted when in transit. Encryption methods such as SSL/TLS are utilised to protect data when it is transmitted to and from this Platform over a secure communications channel, and the Platform is served over HTTPS. The relevant certificates are provisioned through our hosting, domain, and certificate authority service providers. This process involves converting information or data into a code in order to prevent unauthorised access.

We do not collect payments or process any payment card information through the Platform. No payment instrument details are requested, collected, or stored by us in connection with the Platform. We do not receive, hold, or handle any funds passing between a brand and a builder. Should we introduce paid services through the Platform in the future, we will implement appropriate payment security measures and will update this Privacy Policy accordingly before any such processing begins.

Whilst we do everything within our power to ensure that personal data is protected at all times, we cannot guarantee the absolute security and integrity of information that has been transmitted to our Platform, as no method of transmission over the Internet is completely secure. Information published as part of a listing is, by design, publicly accessible and is not confidential.

13. Routine Erasure and Blocking of Personal Data

The controller shall process and store the personal data of the data subject only for the period necessary to achieve the purpose of storage, or as far as this is granted by the applicable legislator in laws or regulations to which the controller is subject.

If the storage purpose is no longer applicable, or if a storage period prescribed by a competent legislator expires, the personal data are routinely blocked or erased in accordance with legal requirements.

14. Period for Which the Personal Data Will Be Stored

The criteria used to determine the period of storage of personal data is the respective statutory retention period. After expiration of that period, the corresponding data is routinely deleted, as long as it is no longer necessary for the fulfilment of, or the initiation of, a contract, or for the purpose of responding to and following up on your submission.

Where you have made a submission that we do not accept, or that does not result in a listing or an ongoing relationship, we retain the associated personal data only for as long as reasonably necessary to deal with the submission and any related follow-up, after which it is deleted or anonymised. Where a listing is published, we retain the associated personal data for so long as the listing remains published, and for a reasonable period thereafter for archival and record-keeping purposes. Where an introduction has been made, we retain a record of that introduction for so long as is necessary for the establishment, exercise, or defence of legal claims.

Where you withdraw your consent, or where the purpose for which your personal data was collected is no longer being served by its retention, we will erase that personal data, and cause our Data Processors to erase it, unless retention is necessary for compliance with any law for the time being in force.

15. Children's Privacy

The Platform is intended for use by businesses and by adults acting in a professional or commercial capacity, and is not directed at children. We do not knowingly collect personal data from children. Under the DPDP Act, the processing of the personal data of a child (a person below the age of eighteen years) requires the verifiable consent of a parent or lawful guardian, and we do not knowingly undertake such processing.

We do not undertake tracking or behavioural monitoring of children, and we do not direct advertising at children. If you are a parent or guardian and believe that a child has provided us with personal data without appropriate consent, please contact us at hello@reborngoods.co, and we will take reasonable steps to delete such information.

16. Rights of the Data Subject

Subject to applicable law, each data subject has the following rights. If you wish to exercise any of these rights, you may contact us at any time at hello@reborngoods.co or help@nonzero.space.

  1. Right of confirmation. You have the right to obtain from the controller confirmation as to whether or not personal data concerning you are being processed.

  2. Right of access. You have the right to obtain from the controller free information about your personal data stored at any time, and a copy of this information, together with the details prescribed by applicable law, such as the purposes of the processing, the categories of personal data concerned, and the recipients or categories of recipients to whom the personal data have been or will be disclosed.

  3. Right to rectification. You have the right to obtain from the controller, without undue delay, the rectification of inaccurate personal data concerning you, and, taking into account the purposes of the processing, the right to have incomplete personal data completed.

  4. Right to erasure (right to be forgotten). You have the right to obtain from the controller the erasure of personal data concerning you without undue delay where one of the grounds prescribed by applicable law applies, and where the processing is not necessary, for example, where the personal data is no longer necessary in relation to the purposes for which it was collected, where you withdraw consent and there is no other legal ground for the processing, or where the personal data has been unlawfully processed.

  5. Right of restriction of processing. You have the right to obtain from the controller restriction of processing where the accuracy of the personal data is contested, where the processing is unlawful and you oppose erasure, where the controller no longer needs the data but you require it for the establishment, exercise, or defence of legal claims, or where you have objected to processing pending verification.

  6. Right to data portability. You have the right to receive the personal data concerning you, which you have provided to the controller, in a structured, commonly used, and machine-readable format, and the right to transmit that data to another controller without hindrance, where the processing is based on consent or on a contract and is carried out by automated means, and where technically feasible.

  7. Right to object. You have the right to object, on grounds relating to your particular situation, at any time, to the processing of personal data concerning you which is based on the legitimate interests of the controller. You also have the right to object at any time to the processing of your personal data for direct marketing purposes, following which we will no longer process your personal data for such purposes.

  8. Rights in relation to automated decision-making and profiling. You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, except in the circumstances permitted by applicable law and subject to suitable safeguards.

  9. Right to withdraw consent. Where the processing of your personal data is based on consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

17. Your Rights Under India's Digital Personal Data Protection Act

If you are a Data Principal whose personal data is processed by Non Zero as a Data Fiduciary, you have the following rights under the DPDP Act, in addition to any rights set out elsewhere in this Privacy Policy:

  • Right to access information. The right to obtain a summary of the personal data being processed and the processing activities undertaken, and the identities of any other Data Fiduciaries and Data Processors with whom the personal data has been shared.

  • Right to correction and erasure. The right to correction, completion, updating, and erasure of your personal data.

  • Right of grievance redressal. The right to have readily available means of grievance redressal in respect of any act or omission regarding the performance of our obligations.

  • Right to nominate. The right to nominate another individual to exercise your rights in the event of your death or incapacity.

  • Right to withdraw consent. Where processing is based on your consent, the right to withdraw that consent as easily as it was given.

You may exercise these rights, or lodge a grievance, by contacting us at hello@reborngoods.co. If your grievance is not resolved to your satisfaction, you may have the right to lodge a complaint with the Data Protection Board of India in accordance with the DPDP Act. Please note that certain provisions of the DPDP Act and the DPDP Rules, 2025 are being brought into force in a phased manner, and we will continue to align our practices with those provisions as they take effect.

18. CCPA Proviso

The California Code of Regulations defines a "resident" as: (1) every individual who is in the State of California for other than a temporary or transitory purpose; and (2) every individual who is domiciled in the State of California who is outside the State of California for a temporary or transitory purpose. All other individuals are defined as "non-residents". If this definition of "resident" applies to you, certain rights and obligations apply regarding your personal information.

Your California Privacy Rights.

If you are a California resident, you have the following rights specifically under the California Consumer Privacy Act:

Right to Know. You have the right to know and see what data we have collected about you over the past 12 months, including: (1) the categories of personal information we have collected about you; (2) the categories of sources from which the personal information is collected; (3) the business or commercial purpose for collecting your personal information; (4) the categories of third parties with whom we have shared your personal information; and (5) the specific pieces of personal information we have collected about you.

Right to Delete. You have the right to request that we delete the personal information we have collected from you, and direct our service providers to do the same, subject to certain exceptions permitted by law.

Right to Opt Out. To the extent that any use of third-party identifiers on the Platform constitutes a "sale" or "sharing" of personal information for cross-context behavioural advertising under applicable California law, you have the right to opt out. You may exercise this right by declining or withdrawing consent to non-essential cookies through our cookie consent banner or cookie settings control, or by writing to us at hello@reborngoods.co.

Right to Non-Discrimination. You have the right not to receive discriminatory treatment for exercising any of your CCPA rights.

Our Platform is configured to recognise opt-out preference signals transmitted by your browser, including the Global Privacy Control signal, where the applicable framework requires us to do so. Where such a signal is received, we will treat it as a request to opt out of the sale or sharing of personal information for the browser and device from which it is sent.

California Civil Code Section 1798.83, also known as the "Shine The Light" law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes, and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. As stated elsewhere in this Privacy Policy, we do not disclose your personal information to third parties for their own direct marketing purposes.

To exercise your rights under the California Consumer Privacy Act, please contact us by sending an email to hello@reborngoods.co. Please provide your full name and email address so that we may respond to your request as quickly as possible. You may be required to verify your identity before we fulfil your request. You can also designate an authorised agent to make a request on your behalf, in which case you must provide us with written authorisation for the agent to act on your behalf, and you will still need to verify your identity directly with us.

19. Legal Basis for the Processing

Article 6(1)(a) GDPR serves as the legal basis for processing operations for which we obtain consent for a specific processing purpose, including the publication of a listing and the setting of non-essential cookies. Where the processing of personal data is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract, such as when responding to submissions or briefs concerning our services, the processing is based on Article 6(1)(b) GDPR. Where we are subject to a legal obligation by which processing of personal data is required, such as for the fulfilment of tax or regulatory obligations, the processing is based on Article 6(1)(c) GDPR. In rare cases, the processing of personal data may be necessary to protect the vital interests of the data subject or of another natural person, in which case the processing is based on Article 6(1)(d) GDPR. Finally, processing operations may be based on Article 6(1)(f) GDPR where the processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. Where the DPDP Act applies, we process personal data on the basis of your consent or for such legitimate uses as are permitted under that Act.

20. The Legitimate Interests Pursued by the Controller or by a Third Party

Where the processing of personal data is based on Article 6(1)(f) GDPR, our legitimate interest is to curate and operate a discovery platform, to contact you, to respond to your submissions and briefs, to make and follow up on introductions, to pursue potential business prospects, to operate and secure the Platform, and to understand and improve how the Platform is used.

21. Provision of Personal Data as a Statutory or Contractual Requirement

We clarify that the provision of personal data may be partly required by law (for example, tax regulations) or may result from contractual provisions (for example, information about a contractual partner). Sometimes it may be necessary, in order to conclude a contract, that a data subject provides us with personal data which must subsequently be processed by us. The non-provision of the personal data may have the consequence that the submission cannot be dealt with, that a listing cannot be published, that an introduction cannot be made, or that a contract with the data subject cannot be concluded. Before personal data is provided by the data subject, the data subject may contact us, and we will clarify whether the provision of the personal data is required by law or contract, or is necessary for the conclusion of a contract, whether there is an obligation to provide the personal data, and the consequences of non-provision.

22. Data Protection Provisions About the Application and Use of Google Tag Manager and the Google Site Tag

On this Platform, the controller has integrated Google Tag Manager, together with the associated Google site tag (gtag.js). Google Tag Manager is a tag management solution operated by Google that allows website operators to manage and deploy measurement tags and code snippets (such as those used by analytics tools) through a single interface, without editing the website code directly. Google Tag Manager itself is a cookie-less domain that facilitates the loading of other tags, which may in turn collect data.

Google Tag Manager triggers other tags that may themselves collect data. Google Tag Manager does not access this data. If a deactivation or an objection has been made at the level of the individual tags (for example, the analytics tags described below), it will be respected. Where a tag sets non-essential cookies or similar identifiers, it is loaded only after you have given your consent through our cookie consent banner. The operator of the service within the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. For further information regarding Google's data processing practices, please refer to Google's Privacy Policy at https://policies.google.com/privacy.

23. Data Protection Provisions About the Application and Use of Google Analytics 4

On this Platform, the controller has integrated the component Google Analytics 4 (GA4). Google Analytics is a web analytics service, that is, the collection, gathering, and analysis of data about the behaviour of visitors to websites. A web analysis service collects, among other things, data about the website from which a person has come (the so-called referrer), which sub-pages were visited, and how often and for what duration a sub-page was viewed. Web analytics are mainly used for the optimisation of a website and to carry out a cost-benefit analysis of the Platform. In Google Analytics 4, IP addresses are used only transiently and are not logged or stored by Google in a manner that identifies the individual; IP data is anonymised at collection.

The operator of the Google Analytics component within the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The purpose of the Google Analytics component is the analysis of the traffic on our Platform. Google uses the collected data and information to evaluate the use of our Platform, to compile online reports showing the activities on our Platform, and to provide other related services to us. Google Analytics places a cookie on the information technology system of the data subject. With the setting of the cookie, Google is enabled to analyse the use of our Platform. Personal data, such as the access time, the location from which the access was made, and the frequency of visits, may be transmitted to Google, and some of this data may be transferred to and stored by Google on servers located in the United States of America.

We use Google Analytics 4 for our own internal analysis of how the Platform is used. We do not use it to serve advertising. The cookies set by Google Analytics on this Platform, and their durations, are listed in our Cookie Policy.

The data subject may prevent the setting of cookies through our Platform at any time by means of a corresponding adjustment of the web browser used, and may object to the collection and use of data generated by Google Analytics by downloading and installing the browser add-on available at https://tools.google.com/dlpage/gaoptout. Further information and the applicable data protection provisions of Google may be retrieved at https://policies.google.com/privacy and https://marketingplatform.google.com/about/analytics/terms/us/.

24. Data Protection Provisions About the Application and Use of Microsoft Clarity

On this Platform, the controller has integrated Microsoft Clarity ("Clarity"). Clarity is a service provided by Microsoft that enables website owners to gain detailed insights into user behaviour through tools such as heat maps, session recordings, and aggregated performance metrics. Clarity captures interaction data, including mouse movements, clicks, scroll patterns, and page engagement, to help us analyse visitor behaviour and optimise our website's usability.

Clarity's tracking code, which is embedded on our Platform, operates via first-party and third-party cookies that facilitate session continuity and enable the aggregation of usage statistics. Data gathered by Clarity is transmitted to and processed by Microsoft Ireland Operations Ltd. and stored on Microsoft's Azure platform. Any deactivation measures or user consent preferences implemented on our website, such as cookie opt-in or opt-out settings, are respected by Clarity, and Clarity is loaded only after you have given your consent through our cookie consent banner.

You should be aware that certain identifiers set in connection with Clarity, in particular the MUID identifier described in our Cookie Policy, are set on Microsoft domains and may be used by Microsoft across its own network, including for advertising and analytics purposes, independently of us and in accordance with Microsoft's own privacy practices. We do not receive, control, or use that identifier for advertising purposes.

For further details regarding the data processing practices, security measures, and your rights in relation to Clarity, please refer to Microsoft's Privacy Statement at https://privacy.microsoft.com/en-us/privacystatement and the Clarity privacy information available at https://clarity.microsoft.com/privacy.

25. Data Protection Provisions About the Application and Use of Google Search Console

The controller has integrated Google Search Console ("GSC"). GSC is a free service provided by Google that enables website owners to monitor, maintain, and troubleshoot their site's presence in Google Search results. GSC delivers aggregated performance metrics, such as search impressions, click data, average ranking positions, indexing status, and crawl error reports, that assist us in evaluating and enhancing our website's visibility and content strategy. GSC collects data directly from Google's search index without deploying additional tracking technologies (such as cookies) on our website; as a result, no personal data of our visitors is processed by us via GSC.

For further details regarding the privacy practices applicable to GSC, please consult Google's Privacy Policy at https://policies.google.com/privacy.

26. Data Protection Provisions About the Application and Use of Webflow

The Platform is built and hosted in part using Webflow, a website design, content management, and hosting platform operated by Webflow, Inc. Webflow provides infrastructure that enables us to design, publish, host, and serve the Platform, and it processes the data necessary to deliver the website to your browser, including technical connection data such as your IP address and standard server log information. Where a form is submitted on the Platform, Webflow may process the form data in order to transmit it to us; such submissions are routed to our email address at hello@reborngoods.co.

Webflow acts as our processor in respect of the hosting and form functionality of the Platform. Webflow's infrastructure is served through content delivery and hosting providers, and data may be processed on servers located in the United States. For further information regarding Webflow's data processing practices and security measures, please refer to Webflow's Privacy Policy at https://webflow.com/legal/privacy.

27. Data Protection Provisions About the Application and Use of Framer

Certain pages or components of the Platform are designed, published, or served using Framer, a website design, content management, and hosting service operated by Framer B.V. Framer processes the data necessary to deliver those pages or components to your browser, including technical connection data such as your IP address and standard server log information, and may process form data in order to transmit it to us.

Framer acts as our processor in respect of these services, and data may be processed on servers located outside India, including in the European Economic Area and the United States. For further information regarding Framer's data processing practices and security measures, please refer to Framer's Privacy Policy at https://www.framer.com/legal/privacy-statement/.

28. Data Protection Provisions About the Application and Use of Submittable

The Platform makes use of Submittable, a submission management service operated by Submittable Holdings, Inc., in connection with the receipt, organisation, and review of submissions made through our forms. Where you make a submission that is processed through Submittable, the information you provide, including your name or studio name, email address, links, and message content, is transmitted to and stored within Submittable on our behalf so that we can receive, review, and respond to it.

Submittable acts as our processor in respect of this service and processes the data in accordance with its data processing terms. Data may be processed on servers located in the United States. For further information regarding Submittable's data processing practices, please refer to Submittable's Privacy Policy at https://www.submittable.com/privacy/.

29. Data Protection Provisions About the Application and Use of Amazon Web Services

The Platform makes use of Amazon Web Services (AWS), including Amazon Elastic Compute Cloud (EC2), Amazon CloudFront (a content delivery network), AWS Global Accelerator, and AWS Lambda (a serverless compute service), provided by Amazon Web Services, Inc. and its affiliates. These services host and execute components of the Platform, cache and deliver content from servers located close to the visitor in order to reduce latency and improve performance, route traffic across the AWS global network, and execute back-end functions that support the operation of the Platform.

In providing these services, AWS processes technical connection data, including your IP address and standard request and log data, which is necessary to route and deliver content and to operate the relevant functions. Some of this processing may take place on servers located in the United States. AWS acts as our processor in respect of these services. For further information regarding AWS's data processing practices and security measures, please refer to the AWS Privacy Notice at https://aws.amazon.com/privacy/.

30. Data Protection Provisions About the Application and Use of Cloudflare

The controller uses Cloudflare, a content delivery network and security service operated by Cloudflare, Inc. Cloudflare sits between your browser and our hosting infrastructure in order to accelerate the delivery of content, to balance load, and to protect the Platform against malicious traffic, such as denial-of-service attacks. For these purposes, Cloudflare processes technical connection data, including your IP address, the pages requested, and information about your browser and device, and it may set technical cookies that are strictly necessary to identify trusted web traffic and to secure the Platform.

Cloudflare acts as our processor in respect of these services and processes data through its globally distributed network. For further information regarding Cloudflare's data processing practices, please refer to Cloudflare's Privacy Policy at https://www.cloudflare.com/privacypolicy/.

31. Data Protection Provisions About the Application and Use of Fastly

The Platform is delivered in part through Fastly, an edge cloud, load balancing, and content delivery network operated by Fastly, Inc., which is used by our hosting provider to serve and load-balance content efficiently. Fastly caches content at edge locations and routes requests to the appropriate server in order to improve the speed, reliability, and availability of the Platform. For these purposes, Fastly processes technical connection data, including your IP address and standard request and log information, which is necessary to deliver the requested content to your browser.

Fastly acts as a processor in respect of the delivery of the Platform. For further information regarding Fastly's data processing practices, please refer to Fastly's Privacy Policy at https://www.fastly.com/privacy/.

32. Data Protection Provisions About the Application and Use of DigitalOcean Spaces

The Platform stores and serves certain static assets, such as images and media files, using DigitalOcean Spaces, an object storage and content delivery service operated by DigitalOcean, LLC. When such an asset is loaded, your browser connects to the DigitalOcean network, and in doing so DigitalOcean processes technical connection data, including your IP address and standard request and log information, which is necessary to deliver the requested asset to your browser.

DigitalOcean acts as our processor in respect of this service, and data may be processed on servers located outside India, including in the United States. For further information regarding DigitalOcean's data processing practices, please refer to DigitalOcean's Privacy Policy at https://www.digitalocean.com/legal/privacy-policy.

33. Data Protection Provisions About the Application and Use of Google Fonts, Google Hosted Libraries, and Google Static Content

On this Platform, the controller uses Google Fonts (including the Google Font API and the Google-hosted web font loader), Google Hosted Libraries and the AJAX Libraries API, and Google's static content network (gstatic.com), in order to display fonts and to load common front-end assets and JavaScript libraries in a uniform manner. These services are provided by Google. When a page of our Platform is loaded, your browser may retrieve the relevant fonts, libraries, or assets from Google's servers in order to display the content correctly. For this technical purpose, your browser must connect to Google's servers, and in doing so, Google may become aware of your IP address and the fact that our Platform has been accessed through your device.

The use of these services is in the interest of a consistent and appealing presentation of our Platform, and constitutes a legitimate interest within the meaning of Article 6(1)(f) GDPR. The operator of these services within the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Further information can be found at https://developers.google.com/fonts/faq and in Google's Privacy Policy at https://policies.google.com/privacy.

34. Data Protection Provisions About the Application and Use of UNPKG

The Platform loads certain JavaScript libraries, modules, and related resources from UNPKG, a free, open-source content delivery network for packages published to the npm registry. When a page of our Platform is loaded, your browser may retrieve these resources directly from the UNPKG network in order to display and operate the content correctly. For this technical purpose, your browser must establish a connection to the UNPKG servers, and in doing so, the operator of the network may become aware of your IP address and the fact that our Platform has been accessed through your device.

The use of UNPKG is in the interest of the reliable and efficient delivery of our Platform and constitutes a legitimate interest within the meaning of Article 6(1)(f) GDPR. UNPKG is operated as a community service and is served through third-party infrastructure providers; we do not control, and are not responsible for, the independent data processing practices of those providers.

35. Data Protection Provisions About the Application and Use of Google Workspace

The controller uses Google Workspace (Google Apps for Business) as its email hosting and business productivity service, with email authentication mechanisms. When you contact us by email, or when a submission made through a form on the Platform is delivered to our inbox, the content of your communication and the associated personal data (such as your name, email address, links, and message content) are processed and stored within Google Workspace on our behalf, so that we can receive, review, and respond to your communication.

Google acts as our processor in respect of this service and processes the data in accordance with its data processing terms. The operator within the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Further information is available in Google's Privacy Policy at https://policies.google.com/privacy.

36. Data Protection Provisions About the Application and Use of WhatsApp

We may use WhatsApp, a messaging service operated by WhatsApp Ireland Limited and its affiliates within the Meta group, to communicate with brands and builders in connection with submissions, listings, and introductions, where you have provided a number for that purpose or where you contact us through that channel.

Where you communicate with us through WhatsApp, the operator of that service processes your number, your profile information, and metadata relating to the communication in accordance with its own privacy practices, over which we have no control. The content of messages exchanged through WhatsApp is subject to that service's own encryption and retention arrangements. If you would prefer not to be contacted through WhatsApp, please tell us and we will use email instead. Further information is available in the WhatsApp Privacy Policy at https://www.whatsapp.com/legal/privacy-policy.

37. Data Protection Provisions About Domain, DNS, and Transport Layer Security Services

The controller uses GoDaddy, operated by GoDaddy Operating Company, LLC and its affiliates, in connection with the registration and administration of the domain through which the Platform is served and in connection with domain name system resolution, and uses certificates issued by Let's Encrypt, a certificate authority operated by the Internet Security Research Group, in order to secure connections to the Platform over HTTPS.

In providing these services, these providers may process technical connection and registration data. Certificate issuance involves the publication of the domain name in public certificate transparency logs; it does not involve the processing of visitor personal data by us. For further information, please refer to GoDaddy's Privacy Notice at https://www.godaddy.com/legal/agreements/privacy-policy and to the Internet Security Research Group Privacy Policy at https://www.abetterinternet.org/privacy-policy/.

38. Data Protection Provisions About the Application and Use of Google Ads and DoubleClick

The Platform may include components associated with Google's advertising and measurement services, including DoubleClick (now part of Google Marketing Platform). These components are not active at the date of this Privacy Policy, and we do not currently use them to serve or measure advertising.

Where these components are used in the future, they will use cookies and similar identifiers to help measure the performance of, and interaction with, online content, and, where applicable, to support advertising. Such cookies may allow Google to recognise your browser across websites. Non-essential cookies will be set only after you have given your consent through our cookie consent banner, you may withdraw that consent at any time through your cookie preferences, and we will update this Privacy Policy and our Cookie Policy before any such processing begins.

For information about how Google uses data from sites that use its services, and about your choices, including the ability to opt out of personalised advertising, please see https://policies.google.com/technologies/partner-sites and Google's advertising settings at https://adssettings.google.com.

39. Public Indexing, Crawling, and Archiving

The Platform is a public website. Its pages, including published listings, may be accessed, indexed, cached, and archived by search engines and by third-party web crawlers and archiving services, including Common Crawl, which maintains a publicly available archive of web pages. These operators act independently of us and on their own initiative; they are not our processors, and we do not instruct them, control what they collect, or determine how long they retain it.

We use standard technical signals, such as the robots exclusion protocol and meta robots directives, to indicate our indexing preferences, but these are advisory and are not enforceable against every crawler. Removal of a listing from the Platform does not remove copies that may persist in third-party caches, indexes, or archives, and any request for removal of such copies must be made to the operator concerned. This is a further reason to submit for publication only information you are content to have made public.

40. Data Protection Provisions About Cookie Consent Management

The Platform uses a cookie consent management tool in order to obtain, record, and manage your consent to the use of non-essential cookies and similar technologies, and to enable you to review and change your preferences at any time through the cookie settings control made available on the Platform. In order to function, the consent tool stores information about the choices you make (for example, whether you have accepted or declined particular categories of cookies) so that your preferences can be respected on subsequent visits. This processing is necessary to comply with our legal obligations relating to consent and to give effect to your choices.

The Platform also supports the transmission of opt-out preference signals through the United States privacy user signal mechanism, including the Global Privacy Control signal, and will give effect to such a signal where the applicable framework requires. Details of the specific cookies set by the consent management tool, together with all other cookies used on the Platform, are set out in our separate Cookie Policy.

41. Personal Data Breach

We maintain reasonable security safeguards designed to prevent a personal data breach. In the event of a personal data breach affecting your personal data, we will intimate the affected Data Principals and the Data Protection Board of India in the manner and within the timelines prescribed under the DPDP Act and the DPDP Rules, 2025, and will notify any other competent supervisory authority where required by applicable law, including Article 33 and Article 34 GDPR.

Any such intimation will describe, so far as is known to us, the nature and extent of the breach, its likely consequences, the measures we have taken or propose to take to mitigate risk, and the contact details of a person able to answer queries on our behalf.

42. Grievance Redressal and Contact

If you have any questions, concerns, or complaints regarding this Privacy Policy or the manner in which we process your personal data, or if you wish to exercise any of your rights, you may contact us at:

Non Zero Design LLP

Email (privacy and data protection queries): hello@reborngoods.co or help@nonzero.space

We will endeavour to respond to your request within a reasonable time and in accordance with applicable law. If you are located in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local data protection supervisory authority. If the DPDP Act applies to you and your grievance is not satisfactorily resolved, you may approach the Data Protection Board of India.

43. Changes to This Privacy Policy

We may update this Privacy Policy from time to time in order to reflect changes to our practices, the services and service providers we use, or applicable law. When we make changes, we will revise the "Last Updated" date at the top of this Privacy Policy, and, where the changes are significant, we may provide additional notice. We encourage you to review this Privacy Policy periodically to stay informed about how we process personal data.

44. Governing Law and Jurisdiction

This Privacy Policy and any matter relating to the processing of personal data by Non Zero shall be governed by the laws of India. Subject to any mandatory rights that you may have under the data protection laws of your country of residence, and subject to the dispute resolution provisions of our Terms and Conditions, the courts at New Delhi, India, shall have jurisdiction over any dispute arising out of or in connection with this Privacy Policy. Nothing in this clause limits any right you may have to bring a complaint before a competent data protection supervisory authority.