This Privacy Policy explains how Nxcart (“Nxcart”, “we”, “us”) handles personal data when you use our platform (the “Service”). We follow India's Digital Personal Data Protection Act, 2023 (“DPDP Act”) and its Rules, and the Information Technology Act, 2000 with the SPDI Rules, 2011. It applies to merchants who sign up for an account and to the shoppers who visit our merchants' storefronts.
1. Who we are
Nxcart operates the Service from Mohali, Punjab, India. We are the Data Fiduciary for the personal data of our merchants (account holders). For the personal data of shoppers that merchants collect through their storefronts, the merchant is the Data Fiduciary and Nxcart acts as a Data Processor on the merchant's behalf (see § 4). For any question about this policy or your data, write to our Grievance Officer at contact@nxcart.io (§ 14).
2. Key terms
- Data Principal — the individual the personal data is about (you).
- Data Fiduciary — who decides why and how personal data is processed.
- Data Processor — who processes personal data on a Data Fiduciary's behalf.
- Personal data — any data about an identifiable individual.
3. Information we collect
From merchants (we are the Data Fiduciary)
- Account data — name, email, phone, business name, GSTIN/PAN, billing address.
- Payment data — collected via our payment processor (Razorpay); we store only the last 4 digits and card brand. Full card numbers never reach our servers.
- Store data — products, orders, and customer records you bring into or create within the Service.
- Usage & device data — pages viewed, features used, IP address, browser/device information, and log data.
From shoppers on merchant storefronts (we are the Data Processor)
- Contact & address — name, email, phone, shipping/billing address provided at checkout.
- Order data — items, totals, payment status (again, no raw card data).
- Analytics — first-party session data to help the merchant understand traffic and conversion.
4. Our two roles — fiduciary and processor
When you sign up as a merchant, we decide how your account data is used, so we are the Data Fiduciary for it. When a shopper buys from a merchant's store, the merchant is the Data Fiduciary for that shopper's data and Nxcart only processes it on the merchant's documented instructions to run the store (rendering checkout, processing orders, sending transactional email). The merchant's own privacy policy applies to shoppers first. Our role as processor is set out in our Data Processing Addendum.
5. Why we process data, and our legal basis
Under the DPDP Act we process personal data on the basis of your consent or for certain legitimate uses permitted by the Act. Purposes include:
- Providing and operating the Service — rendering the storefront, processing orders, sending transactional emails.
- Billing, fraud prevention, and account security.
- Improving the platform — performance, reliability, and new features.
- Powering AI features you choose to use (see § 6).
- Service communications — product updates, billing notices, security alerts.
- Complying with the law — GST and tax records, accounting, and responding to lawful requests.
Where we rely on consent, you may withdraw it at any time (§ 11); withdrawal does not affect processing already carried out.
6. AI features & your data
When you use AI features, your prompts and the relevant context (e.g. the product you're describing) are sent to our AI providers strictly to generate the output you requested. We do not permit your data to be used to train third-party foundation models. Outputs are stored alongside your store data and belong to you.
7. Cookies
We use essential cookies to keep you signed in, hold your cart, and protect against CSRF, and first-party analytics to understand product usage. For non-essential cookies we rely on your consent. See our Cookie Policy for the full list and how to control them.
8. Sharing & sub-processors
We share personal data only as needed to run the Service, with providers bound by contract to protect it:
- Payments — Razorpay (to charge cards and settle payouts).
- Shipping — Delhivery and similar carriers (to create labels and track parcels).
- Email — AWS SES and transactional email relays.
- Cloud hosting — Amazon Web Services (compute and storage).
- Authorities — when required by law, under valid legal process.
We do not sell personal data.
9. Cross-border transfers
Our infrastructure runs primarily in India (AWS Mumbai). Some sub-processors may operate outside India; where they do, transfers are made only to jurisdictions permitted under the DPDP Act and subject to appropriate contractual safeguards.
10. Security & data-breach response
We apply reasonable security safeguards as required by the DPDP Act and the SPDI Rules, including encryption in transit (TLS 1.2+) and at rest (AES-256), masking of sensitive fields, application-layer encryption of critical secrets with environment-specific keys, and least-privilege access control, access logging and monitoring. If a personal-data breach occurs, we will notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines required by law (currently without undue delay, and to the Board within 72 hours).
11. Your rights as a Data Principal
Subject to applicable law, you may:
- Access a summary of your personal data and how it is processed.
- Correct, complete, or update inaccurate or incomplete data.
- Erase your personal data where it is no longer needed for the purpose collected.
- Withdraw consent where processing is based on consent.
- Nominate another person to exercise your rights in the event of death or incapacity.
- Grievance redressal — raise a complaint with us and escalate to the Data Protection Board of India.
To exercise any right, email contact@nxcart.io. We respond within the timelines required by law. If your request concerns data we process for a merchant (shopper data), we will direct you to, or assist, that merchant as the Data Fiduciary.
12. Children's data
The Service is not directed to anyone under 18. We do not knowingly process a child's personal data without verifiable consent of a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child has provided data, contact us and we will delete it.
13. Data retention
We retain account data for as long as your account is open. If your subscription lapses or you cancel, your store becomes inactive — it stops selling, but your account and data are retained so you can resubscribe and pick up where you left off.
We delete data on account termination — when you close your account, or when we terminate it under our Terms. On termination you may request an export of your data for 30 days, after which data is deleted, except where we must retain records to comply with law (e.g. invoices and GST records are retained for the period required under tax law, generally up to 7 years). Shopper data processed for a merchant is retained per the merchant's instructions and our DPA.
14. Grievance Officer & complaints
If you have a concern about how your data is handled, contact our Grievance Officer:
Email: contact@nxcart.io
If you are not satisfied with our response, you may lodge a complaint with the Data Protection Board of India in the manner prescribed under the DPDP Act.
15. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email or in-app notice at least 14 days before they take effect.