Legal

Privacy Policy

Last updated: 29 September 2026

This Privacy Policy explains how karto.site ("Karto", "we", "us") collects, uses, shares and protects personal data when you use karto.site, the storefronts we host and our merchant tools (the "Services"). It is written to comply with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and other applicable Indian laws.

1. Who we are

Karto provides software that lets small sellers ("Merchants") run an online storefront and accept payments. We are based in India. You can reach us at support@karto.site.

We act in two roles:

  • When you sign up as a Merchant, we are the Data Fiduciary for your account and business data, and decide how and why it is processed.
  • When we process the data of your end customers (buyers) on your instructions, we act as a Data Processor and you, the Merchant, are the Data Fiduciary for that data.

2. Personal data we collect

Data you give us as a Merchant:

  • Account details: email address, mobile number, and the one-time password (OTP) used to verify it.
  • Business profile: store name, legal or business name, product categories, and GSTIN (if you are GST-registered).
  • Payment setup: Paytm Merchant ID (MID) and Paytm business VPA, or your manual UPI VPA, and whether you require a payment screenshot.
  • Tax rules: HSN codes, price bands and GST rates you configure.
  • Domain: the subdomain, purchased domain or brought-your-own domain, and DNS verification details.
  • Store content: products, prices, images, variants and stock levels.

Data we process on behalf of Merchants (about their end customers):

  • Name, mobile number and delivery address.
  • Order details and status (amount, items, payment mode, confirmation and RTO-prevention status).
  • Spin-the-wheel leads: mobile number and any coupon awarded.
  • Abandoned-cart records used to send recovery reminders.
  • A payment screenshot, where the Merchant has enabled that requirement in manual-UPI mode.

Data collected automatically: device and browser information, IP address, pages viewed, and cookies or local storage (see "Cookies").

3. How and why we use personal data

We use personal data to:

  • Create and manage your account, and provide customer support.
  • Build and operate your storefront and product catalogue.
  • Process orders and payments, and generate UPI QR codes or payment links.
  • Send transactional messages to customers over WhatsApp, SMS or email - order confirmation, address confirmation and abandoned-cart reminders.
  • Prevent return-to-origin (RTO) losses and confirm delivery addresses.
  • Run spin-the-wheel lead capture, discounts, combos and festive campaigns.
  • Calculate platform fees and bill you, and maintain fee ledgers.
  • Provision and verify your domain.
  • Keep the Services secure, prevent fraud and abuse, audit actions and comply with legal obligations.
  • Maintain a support and backup copy of core records (see "Sharing" and "Retention"), gated by consent.

6. Sharing and disclosure

We share personal data only as needed, and with parties bound by confidentiality and data-protection obligations. We do not sell personal data.

Recipients may include:

  • Payment providers, including the third-party Paytm dynamic-QR and payment-verification service used to generate and verify payments.
  • Messaging providers used to send WhatsApp, SMS or email notifications.
  • Domain registrars and the domain-purchase service used for domain options.
  • Hosting and infrastructure providers, including our server and managed database providers.
  • Our support and backup systems, hosted with our infrastructure provider.
  • Professional advisers, auditors and insurers.
  • Courts, regulators and law-enforcement authorities, where the law requires it.

7. Where we store data

We currently store and process personal data in India. If this changes, we will transfer data only in accordance with the DPDP Act and any conditions the Government of India prescribes, and we will update this policy.

8. How long we keep data

We keep personal data only as long as needed for the purposes above:

  • Account and business data while your account is active, and for a reasonable period afterwards.
  • Order, payment and billing records for as long as needed to maintain fee-ledger integrity, resolve disputes, provide support and meet legal, tax and accounting requirements - including after a store stops using the Services.
  • Consent records, so we can honour and prove your choices.
  • After that, we securely delete or anonymise the data.

Merchants cannot unilaterally delete customer records that we must retain for billing, support and compliance. End customers may request erasure through the process in "Your rights" below.

9. Security

We use reasonable technical and organisational safeguards, including encryption of data in transit and at rest, encryption of payment credentials, access controls and activity logging. No system is completely secure; if you believe your data has been compromised, contact us immediately at support@karto.site.

10. Your rights as a Data Principal

Under the DPDP Act you have the right to:

  • Access a summary of the personal data we process about you and how we process it.
  • Ask us to correct, complete or update your data.
  • Ask us to erase your data, where it is no longer needed for the purpose it was collected for (subject to our legal and billing retention duties).
  • Withdraw consent at any time.
  • Nominate someone to exercise your rights in the event of your death or incapacity.
  • File a grievance with our Grievance Officer.

To exercise any of these rights, write to our Grievance Officer at support@karto.site. We will respond within the time required by law. If you are not satisfied, you may complain to the Data Protection Board of India.

11. End customers: data controlled by Merchants

When you buy from a storefront on Karto, the Merchant is the Data Fiduciary for your data; Karto processes it on the Merchant's behalf. To access, correct or delete your personal data, or to withdraw consent, please contact the store or Merchant first - they can raise the request with us.

We will act on the Merchant's instructions and as required by law. Some records may need to be retained for billing, support and compliance reasons even after an erasure request.

12. Children

The Services are meant for businesses and are not directed at children under 18. We do not knowingly process a child's data without verifiable consent from a parent or lawful guardian. If you believe a child's data has been provided to us, contact us and we will take appropriate action.

13. Cookies and similar technologies

We use essential cookies and browser local storage to run the Services - for example, to remember your theme, the storefront template, your store identity, your cart and your consent choices. You can clear cookies or local storage from your browser, but essential ones may be required for the Services to work.

15. Changes to this policy

We may update this policy from time to time. We will post the new version with a revised effective date and, where the law requires it, ask for fresh consent.

16. Grievance Officer and contact

For any questions or requests about this policy, or to exercise your rights, contact our Grievance Officer:

  • Name: [To be updated]
  • Designation: [To be updated]
  • Email: support@karto.site
  • Phone: [To be updated]
  • Address: [To be updated]
Questions? Email support@karto.site.