Legal
Privacy Policy
Last updated: 29 September 2026
This Privacy Policy explains how karto.site ("Karto", "we", "us") collects, uses, shares and protects personal data when you use karto.site, the storefronts we host and our merchant tools (the "Services"). It is written to comply with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and other applicable Indian laws.
1. Who we are
Karto provides software that lets small sellers ("Merchants") run an online storefront and accept payments. We are based in India. You can reach us at support@karto.site.
We act in two roles:
- When you sign up as a Merchant, we are the Data Fiduciary for your account and business data, and decide how and why it is processed.
- When we process the data of your end customers (buyers) on your instructions, we act as a Data Processor and you, the Merchant, are the Data Fiduciary for that data.
2. Personal data we collect
Data you give us as a Merchant:
- Account details: email address, mobile number, and the one-time password (OTP) used to verify it.
- Business profile: store name, legal or business name, product categories, and GSTIN (if you are GST-registered).
- Payment setup: Paytm Merchant ID (MID) and Paytm business VPA, or your manual UPI VPA, and whether you require a payment screenshot.
- Tax rules: HSN codes, price bands and GST rates you configure.
- Domain: the subdomain, purchased domain or brought-your-own domain, and DNS verification details.
- Store content: products, prices, images, variants and stock levels.
Data we process on behalf of Merchants (about their end customers):
- Name, mobile number and delivery address.
- Order details and status (amount, items, payment mode, confirmation and RTO-prevention status).
- Spin-the-wheel leads: mobile number and any coupon awarded.
- Abandoned-cart records used to send recovery reminders.
- A payment screenshot, where the Merchant has enabled that requirement in manual-UPI mode.
Data collected automatically: device and browser information, IP address, pages viewed, and cookies or local storage (see "Cookies").
3. How and why we use personal data
We use personal data to:
- Create and manage your account, and provide customer support.
- Build and operate your storefront and product catalogue.
- Process orders and payments, and generate UPI QR codes or payment links.
- Send transactional messages to customers over WhatsApp, SMS or email - order confirmation, address confirmation and abandoned-cart reminders.
- Prevent return-to-origin (RTO) losses and confirm delivery addresses.
- Run spin-the-wheel lead capture, discounts, combos and festive campaigns.
- Calculate platform fees and bill you, and maintain fee ledgers.
- Provision and verify your domain.
- Keep the Services secure, prevent fraud and abuse, audit actions and comply with legal obligations.
- Maintain a support and backup copy of core records (see "Sharing" and "Retention"), gated by consent.
4. Consent and notice
We collect and use personal data with your consent, unless a lawful ground in the DPDP Act lets us proceed without fresh consent. We give you a clear notice of the data and purpose at the point of collection, and record consent with its purpose, source, timestamp and status in a consent log.
You may withdraw consent at any time by writing to us. Withdrawal does not undo processing already carried out, and may stop us from providing the feature that depended on that consent.
For end-customer data, the Merchant is responsible for giving the customer a notice and obtaining valid consent. We provide the collection mechanisms and act on the Merchant's instructions.
5. When we may process without fresh consent
The DPDP Act allows processing for certain legitimate uses without fresh consent - for example, to perform a contract you are a party to, to comply with a legal obligation or a court order, for medical or safety emergencies, or for specified state functions. Where we rely on these, we limit processing to what is necessary.
7. Where we store data
We currently store and process personal data in India. If this changes, we will transfer data only in accordance with the DPDP Act and any conditions the Government of India prescribes, and we will update this policy.
8. How long we keep data
We keep personal data only as long as needed for the purposes above:
- Account and business data while your account is active, and for a reasonable period afterwards.
- Order, payment and billing records for as long as needed to maintain fee-ledger integrity, resolve disputes, provide support and meet legal, tax and accounting requirements - including after a store stops using the Services.
- Consent records, so we can honour and prove your choices.
- After that, we securely delete or anonymise the data.
Merchants cannot unilaterally delete customer records that we must retain for billing, support and compliance. End customers may request erasure through the process in "Your rights" below.
9. Security
We use reasonable technical and organisational safeguards, including encryption of data in transit and at rest, encryption of payment credentials, access controls and activity logging. No system is completely secure; if you believe your data has been compromised, contact us immediately at support@karto.site.
10. Your rights as a Data Principal
Under the DPDP Act you have the right to:
- Access a summary of the personal data we process about you and how we process it.
- Ask us to correct, complete or update your data.
- Ask us to erase your data, where it is no longer needed for the purpose it was collected for (subject to our legal and billing retention duties).
- Withdraw consent at any time.
- Nominate someone to exercise your rights in the event of your death or incapacity.
- File a grievance with our Grievance Officer.
To exercise any of these rights, write to our Grievance Officer at support@karto.site. We will respond within the time required by law. If you are not satisfied, you may complain to the Data Protection Board of India.
11. End customers: data controlled by Merchants
When you buy from a storefront on Karto, the Merchant is the Data Fiduciary for your data; Karto processes it on the Merchant's behalf. To access, correct or delete your personal data, or to withdraw consent, please contact the store or Merchant first - they can raise the request with us.
We will act on the Merchant's instructions and as required by law. Some records may need to be retained for billing, support and compliance reasons even after an erasure request.
12. Children
The Services are meant for businesses and are not directed at children under 18. We do not knowingly process a child's data without verifiable consent from a parent or lawful guardian. If you believe a child's data has been provided to us, contact us and we will take appropriate action.
14. Third-party links and services
Storefronts and messages may link to third-party sites and apps, such as payment apps. Their privacy practices are governed by their own policies, and we are not responsible for them.
15. Changes to this policy
We may update this policy from time to time. We will post the new version with a revised effective date and, where the law requires it, ask for fresh consent.
16. Grievance Officer and contact
For any questions or requests about this policy, or to exercise your rights, contact our Grievance Officer:
- Name: [To be updated]
- Designation: [To be updated]
- Email: support@karto.site
- Phone: [To be updated]
- Address: [To be updated]