Privacy Policy
Last updated: June 2025
This Privacy Policy describes how CoreKit ("we", "us", or "our") collects, uses, stores, and protects your personal data when you visit or make a purchase from our website. This policy is compliant with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India.
1. Data We Collect
When you use our platform, we may collect the following categories of personal data:
- Identity data: Full name, date of birth, gender
- Contact data: Email address, phone number, delivery address
- Transaction data: Order history, payment method details (card last four digits, UPI ID), invoice records
- Usage data: Pages visited, products viewed, search queries, time spent on site
- Device data: IP address, browser type, operating system, device identifiers
- Communication data: Emails, chat messages, and support tickets you send us
2. Purpose of Processing
We process your personal data for the following purposes:
- To create and manage your account
- To process and fulfil your orders, including payment and delivery
- To send order confirmations, shipping updates, and invoices
- To provide customer support and resolve disputes
- To personalise your shopping experience and show relevant product recommendations
- To comply with legal obligations under Indian law (GST, consumer protection, etc.)
- To detect and prevent fraud, abuse, and security incidents
- To send marketing communications (only where you have provided consent; you may withdraw consent at any time)
3. Legal Basis for Processing
Under the DPDP Act 2023, we process your data on the following bases:
- Consent: For marketing emails, SMS, and personalised recommendations. You may withdraw consent at any time by updating your account preferences or emailing us.
- Contract: To perform the contract of sale when you place an order.
- Legal obligation: To comply with GST, customs, FEMA, and other applicable Indian legislation.
- Legitimate interests: To prevent fraud, improve our services, and maintain platform security.
4. Data Sharing
We do not sell your personal data. We may share it with trusted third parties only as necessary:
- Payment processors: Razorpay, UPI networks — to process payments securely
- Logistics partners: Shiprocket, Delhivery, Blue Dart — to deliver your orders
- Cloud infrastructure: AWS / Google Cloud — for hosting and data storage within India or in compliant regions
- Marketing tools: Only where you have opted in to communications
- Government / law enforcement: When required by law, court order, or regulatory authority
5. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. Transaction records are retained for a minimum of 7 years in accordance with Indian accounting and tax laws. You may request deletion of your account and associated data at any time, subject to legal retention obligations.
6. Your Rights Under DPDP Act 2023
As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the following rights:
- Right to access: Request a summary of the personal data we hold about you and the purposes for which it is processed.
- Right to correction: Request correction of inaccurate or incomplete personal data.
- Right to erasure: Request deletion of your personal data, subject to legal retention requirements.
- Right to grievance redressal: Lodge a complaint with our Grievance Officer (see the Grievance page) and, if unsatisfied, with the Data Protection Board of India.
- Right to withdraw consent: Withdraw previously given consent at any time; withdrawal does not affect processing already carried out.
- Right to nominate: Nominate another individual to exercise your rights in the event of your death or incapacity.
To exercise any of these rights, email us at privacy@store.com. We will respond within 30 days.
7. Cookies
We use cookies and similar tracking technologies to enhance your browsing experience, analyse site traffic, and personalise content. You can control cookie preferences through your browser settings. Disabling cookies may affect certain features of the website.
8. Security
We implement industry-standard security measures including TLS encryption in transit, AES-256 encryption at rest, role-based access controls, and regular security audits to protect your personal data against unauthorised access, disclosure, alteration, or destruction.
9. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email or a prominent notice on the website at least 15 days before they take effect. Continued use of the platform after such notice constitutes acceptance of the updated policy.
10. Contact Us
For privacy-related queries or to exercise your DPDP rights, contact our Data Protection Officer at privacy@store.com. For unresolved complaints, you may approach our Grievance Officer (see the Grievance page) or the Data Protection Board of India.
