Legal : Privacy policy

Effective20 September 2026

Privacy Policy

Effective 20 September 2026. This policy explains what we collect, why, who we share it with, how we share it and how we keep it safe. It applies to this website and to every product sold under the 25th Hour name.

1. Who is responsible

25th Hour is a trading name of Vedilink ("we", "us", "our"), operating from India. Vedilink is the data controller, the party that decides how and why your information is handled for everything described here.

2. Information we collect

We collect only what we need to sell, deliver and support our products.

WhatExamplesWhere it comes from
Account informationName, email address, password hash, company nameYou, at sign-up
Order and billing informationOrder ID, product, amount, currency, billing address, tax ID, card brand and last four digits, invoicesYou and Stripe, at checkout
Support correspondenceEmails you send us and our replies, attachments and logs you choose to shareYou
Licence and usage recordsLicence keys issued, activation and download records, product versionGenerated when you use a paid product
Website and technical dataIP address, browser and device type, pages viewed, referring page, timestampsCollected automatically when you visit

We do not collect sensitive personal data such as health, biometric, or government identity information and we ask you not to send it to us. We do not sell personal information to anyone.

3. How we use it

  • To create and run your account and to deliver the products you buy.
  • To take payment, issue invoices and receipts and process refunds.
  • To provide support and answer your questions.
  • To send service messages: receipts, licence keys, renewal notices, security notices and changes to these policies.
  • To keep our products and systems secure and to detect and prevent fraud and abuse.
  • To understand which pages and features are used, so we can improve them.
  • To meet our legal, tax and accounting obligations in India and elsewhere.

We rely on the performance of our contract with you, your consent where we ask for it (for example, marketing email or non-essential cookies), our legitimate interest in running and securing the business and compliance with law. Marketing email, if we ever send it, is opt-in and every message has an unsubscribe link.

4. Payment information

Payments are processed by Stripe, a PCI-DSS Level 1 certified payment provider. Card details are entered directly into Stripe's systems. We never receive or store your full card number, expiry, or CVV. From Stripe we receive the transaction status and limited details, card brand, last four digits, billing country and the amount which we keep as part of our order records for accounting and tax purposes.

5. Cookies and analytics

This website uses strictly necessary cookies to keep you signed in, to remember your session at checkout and for security. These are required for the site to work.

Where we use analytics to count visits and see which pages are read, we configure it to collect aggregate data and to truncate or anonymise IP addresses and we do not use it to build advertising profiles. We do not run third-party advertising or cross-site tracking cookies. You can block or delete cookies in your browser; strictly necessary cookies cannot be turned off without breaking sign-in and checkout.

6. Who we share it with

We share personal information only with the parties below and only for the purpose listed:

PartyPurposeWhat they receive
StripePayment processing, fraud prevention, invoicingName, email, billing address, payment details, amount
Email and support providerSending receipts and service email, handling support ticketsName, email, message contents
Hosting and infrastructure providerRunning the website, accounts and downloadsAccount and technical data stored on our behalf
Analytics providerAggregate website statisticsTruncated IP, page and device data
Accountants, auditors, legal advisersTax filing, statutory accounts, legal adviceOrder and invoice records
Government authorities and courtsWhere disclosure is required by law or valid legal processOnly what is legally required
An acquirerIf the business is sold or reorganised, under confidentiality and with notice to youCustomer and order records

These providers act as our processors under written agreements that require them to use the information only for the purpose we specify, to keep it secure and confidential and to delete or return it when the engagement ends. We do not sell, rent, or trade personal information and we do not share it for third-party marketing.

7. How disclosure happens

Information reaches these parties over encrypted connections (TLS 1.2 or higher) through their APIs when you check out or contact us, or through access-controlled accounts held by named staff. We do not send personal information by unencrypted file transfer and we do not post it to public repositories or endpoints. Disclosures to authorities are made in writing, are logged and are limited to what the request legally requires; where we are permitted to tell you about such a request, we do.

8. International transfers

Some of our providers, including Stripe, operate outside India. Where your information is transferred abroad, we require contractual protections, standard contractual clauses or equivalent safeguards so that it stays protected to the standard described in this policy.

9. How long we keep it

  • Account information: while your account is open, then up to 12 months after closure.
  • Order, invoice and tax records: 8 years, as required by Indian tax and company law.
  • Support correspondence: 3 years from the last message in the thread.
  • Website and analytics logs: up to 14 months, in aggregate form after that.

When a period ends we delete the information or anonymise it so it can no longer identify you.

10. How we protect it

  • All traffic to this site and our services is encrypted in transit with HTTPS/TLS; stored data is encrypted at rest by our hosting provider.
  • Passwords are stored only as salted hashes; we cannot read them.
  • Access is limited to staff who need it for their work, on a least-privilege basis, with multi-factor authentication required on every administrative account.
  • Card data never touches our servers; it is handled entirely by Stripe, which maintains PCI-DSS Level 1 certification.
  • We keep software and dependencies patched, review access periodically and log administrative activity.
  • We maintain reasonable security practices consistent with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant authorities as required by law, describe what happened and tell you what to do about it.

11. Your rights and choices

You can ask us to:

  • give you a copy of the personal information we hold about you;
  • correct information that is wrong or out of date;
  • delete your information, where we are not required to keep it for tax or legal reasons;
  • stop marketing email, at any time;
  • withdraw a consent you previously gave;
  • nominate someone to exercise these rights on your behalf if you are unable to.

Email privacy@vedilink.com from the address on your account. We respond within 30 days and do not charge for reasonable requests. These rights are provided under the Digital Personal Data Protection Act, 2023; if you are in the EEA or UK, the equivalent GDPR rights apply and if you are a California resident, you have the CCPA rights of access, deletion and non-discrimination. We do not sell personal information.

12. Children

Our products are for developers and businesses and are not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, write to us and we will delete it.

13. Data in our SDKs and tools

Our SDKs run inside applications you build. Unless a product's documentation explicitly says otherwise, they do not send end-user data, camera frames, or scene data to us. Where a product includes optional diagnostics or crash reporting, it is off by default, documented in that product's README and you choose whether to enable it. If you use our SDK in your own application, you are responsible for the privacy notice you give your users.

14. Changes to this policy

We update this policy when our practices change. The effective date at the top shows the current version. For material changes we notify account holders by email at least 30 days in advance.

15. Grievance officer and contact

For any question or complaint about privacy, contact our grievance officer, appointed under the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023:

We acknowledge complaints within 48 hours and resolve them within one month. If you are not satisfied with our response, you may complain to the Data Protection Board of India or your local data protection authority.