Introduction
At KHAVYN Fashion Private Limited (“KHAVYN”, “we”, “us” or “our”), we are committed to maintaining appropriate security measures for our website and protecting customers while they browse, create accounts, make purchases, communicate with us and use other features available through our website. This Content Security & Permissions Policy explains the security controls used or intended to be used on the KHAVYN website, including Content Security Policy (CSP) and Permissions Policy controls.
1. Content Security Policy
KHAVYN may implement a Content Security Policy (“CSP”) as an additional layer of website security. CSP helps control the sources from which website content and resources may be loaded, including scripts, stylesheets, fonts, images, media, frames and network connections. The purpose of these controls is to reduce security risks such as cross-site scripting (XSS), unauthorized content injection and the execution of unapproved third-party resources. Where technically appropriate, KHAVYN may restrict website resources to KHAVYN-controlled sources and specifically authorized third-party service providers.
2. Authorized Third-Party Services
Certain website functionality may require KHAVYN to permit resources or connections from trusted third-party service providers. These may include, as applicable: • Payment gateways and payment-processing partners; • Shipping and logistics providers; • Analytics and website-performance services; • Advertising and marketing platforms; • Customer-support and communication services; • Email and notification service providers; • Content delivery networks (CDNs); • Review, authentication and fraud-prevention services; and • Other technology providers necessary for operating the KHAVYN website. Access to third-party domains should be limited to services required for legitimate website functionality.
3. Payment Security
KHAVYN may use authorized third-party payment gateways for processing online transactions. Payment-related scripts, frames and network connections should only be permitted from KHAVYN and the payment service providers integrated with the website. Sensitive payment information processed directly by a payment gateway is subject to the security practices, terms and privacy policies of the respective payment service provider. KHAVYN does not intend to grant unrestricted website access to unrelated third-party payment services.
4. Browser Permissions
KHAVYN follows the principle of limiting browser permissions to those reasonably required for website functionality. Unless a feature specifically requires them and the appropriate permission is enabled, the KHAVYN website should not request access to sensitive device capabilities such as: • Camera; • Microphone; • Precise location; • Bluetooth; • USB devices; • Accelerometer; • Gyroscope; or • Magnetometer. Where browser functionality such as payment processing, fullscreen content, autoplay or picture-in-picture is required, permissions may be restricted to KHAVYN or specifically authorized services.
5. Customer Location Information
KHAVYN may request customers to provide delivery-related information, including address, landmark and other location details necessary to process and deliver an order. Such information is different from accessing a customer's device-based precise geolocation. Device geolocation should remain disabled unless KHAVYN introduces a feature that specifically requires it and appropriate consent or permission is obtained.
6. Secure Connections
KHAVYN intends to use HTTPS/SSL encryption to protect communications between customers' browsers and the KHAVYN website. Where technically appropriate, security controls may also be implemented to require secure HTTPS connections and prevent website resources from being loaded through insecure HTTP connections.
7. Framing and Content Protection
KHAVYN may restrict unauthorized websites from embedding or framing KHAVYN webpages. These controls are intended to reduce risks associated with clickjacking and unauthorized presentation or manipulation of KHAVYN website content.
8. Content-Type and Referrer Protection
KHAVYN may implement browser security headers designed to: • Prevent browsers from incorrectly interpreting the content type of website resources; • Limit unnecessary disclosure of referring-page information to external websites; and • Strengthen isolation between KHAVYN and unrelated websites where technically appropriate.
9. Cookies, Analytics and Advertising Technologies
The KHAVYN website may use cookies, analytics tools, advertising technologies and similar technologies for website functionality, performance measurement, customer experience, marketing and other purposes described in KHAVYN's Privacy Policy and Cookie Policy. Content Security Policy settings do not replace customer consent requirements or KHAVYN's obligations under applicable privacy and data-protection requirements.
10. Third-Party Websites and Services
KHAVYN's website may contain links to or integrations with third-party websites and services. Third-party websites operate independently and may maintain their own security, privacy, cookie and permissions practices. KHAVYN does not control the security practices of independent third-party websites after a customer leaves the KHAVYN website. Customers are encouraged to review the applicable policies of such third parties.
11. Security Monitoring and Updates
KHAVYN may periodically review and update its website security configuration to reflect: • Changes to website functionality; • Addition or removal of third-party services; • Changes to payment or logistics integrations; • New browser-security standards; • Identified security risks; and • Applicable legal or regulatory requirements. Security configurations may therefore change without requiring amendments to every provision of this public-facing policy.
12. Responsible Website Use
Users must not attempt to circumvent KHAVYN's website security controls, obtain unauthorized access to systems or customer information, introduce malicious code, interfere with website functionality, or use the website for unlawful purposes. KHAVYN reserves the right to restrict access and take appropriate action where unauthorized or potentially harmful activity is detected.
13. No Guarantee of Absolute Security
KHAVYN takes reasonable measures intended to protect its website and customer information. However, no website, electronic communication, internet transmission or information-security system can be guaranteed to be completely secure. Customers should also take appropriate precautions, including protecting their account credentials and using secure devices and internet connections.
14. Relationship With Other KHAVYN Policies
This policy should be read together with KHAVYN's Privacy Policy, Cookie Policy, Terms & Conditions, Shipping & Delivery Policy, Cancellation Policy, Return & Refund Policy, Exchange Policy, Disclaimer and Grievance Policy. Where personal information is collected or processed, KHAVYN's Privacy Policy and other applicable policies will govern such processing.
15. Changes to This Policy
KHAVYN may modify this Content Security & Permissions Policy from time to time to reflect changes in technology, website functionality, business practices, security requirements or applicable law. The revised policy may be published on the KHAVYN website with an updated “Last Updated” date.
16. Contact
For questions or concerns regarding this policy or the security of the KHAVYN website, customers may contact KHAVYN Fashion Private Limited through the contact information published on www.khavyn.com.
KHAVYN FASHION PRIVATE LIMITED
GSTIN: 27AAMCK8767F1ZW • Registered Office: Samarth Nagar, New Sangavi, Pune – 411027, Maharashtra
For questions regarding this policy, email legal@khavyn.com
