Privacy Policy

Last updated: 26 June 2026

This Privacy Policy explains how DigitalShop collects, uses, discloses and safeguards personal data when you use our e-commerce platform and related services.

Template notice: This Privacy Policy is a template provided for convenience and general guidance. It should be reviewed and adapted by qualified legal counsel before you rely on it in production.

DigitalShop (“DigitalShop”, “the Platform”, “we”, “us” or “our”) is a multi-tenant e-commerce platform operated as a joint venture of two companies: UnfoldCRO, which provides the technical and product engineering for the Platform, and ICraftAds, which provides financial and management support for the product. Privacy and data security are jointly managed by UnfoldCRO and ICraftAds, who together act as the data fiduciary for personal data processed through DigitalShop.

This Policy is framed in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), and other applicable Indian law.

1. Who this Policy applies to

DigitalShop serves two broad groups of individuals, and the way we process data differs for each:

  • Merchants — business owners and their staff who sign up for and operate a store on DigitalShop. For merchant account data, DigitalShop acts as a data fiduciary.
  • Store customers (shoppers) — the end customers who buy from a merchant’s store. For this data, the merchant is the data fiduciary who determines the purpose of processing, and DigitalShop acts as a data processor on the merchant’s behalf.

2. Data we collect

From merchants

  • Identity and contact details: name, business name, email, phone number, address.
  • Account and KYC-related details required to operate a store and receive payouts, including GSTIN, PAN and bank/UPI settlement details (handled in conjunction with our payment partner).
  • Billing data: subscription plan, add-ons, invoices and e-mandate references (card data is not stored by us).
  • Usage and device data: log-ins, IP address, browser/device type, pages used and feature activity.
  • Communications: support tickets, emails and feedback you send us.

From store customers (processed for the merchant)

  • Order details: name, shipping and billing address, email, phone number and order contents.
  • Payment status and references returned by the payment gateway (we do not store card numbers or CVV).
  • Account credentials where a store offers customer log-in, and order/communication history.
  • Browsing and analytics data such as cookies, device identifiers and pages viewed on the store.

3. Why we process data and the legal basis

Under the DPDP Act, we process personal data on the following bases:

  • Performance of service / contract: to create and operate merchant stores, process orders, enable payments and shipping, generate GST invoices and provide support.
  • Consent: for marketing communications, optional cookies and any processing that is not necessary to deliver the core service. Consent may be withdrawn at any time.
  • Legal obligation and legitimate uses: to comply with tax, accounting, fraud-prevention and other statutory requirements, and to secure the Platform.

4. How we share data and sub-processors

We do not sell personal data. We share it only with trusted service providers (sub-processors) who help us deliver the service, under contractual confidentiality and security obligations. Key sub-processors include:

Sub-processorPurposeData shared
Razorpay (PCI-DSS payment gateway)Payment processing, subscriptions and e-mandate auto-debitPayment amount, contact details and order references. Card data is captured and stored by Razorpay, not by DigitalShop.
Shiprocket and shipping partnersOrder fulfilment, courier allocation and trackingRecipient name, shipping address, phone and order details.
Cloud hosting and infrastructure providersHosting, storage and delivery of the PlatformAll Platform data, stored securely.
Email, SMS and analytics providersTransactional messages and aggregated usage analyticsContact details and event/usage data as required.

We may also disclose data where required by law, a valid order of a court or government authority, or to protect the rights, safety and security of users and the Platform.

5. Data retention

We retain personal data only for as long as necessary to provide the service and to meet legal, tax and accounting obligations. Merchant billing and invoice records are retained for the period required under Indian tax law. When data is no longer required and there is no legal obligation to retain it, it is deleted or anonymised. Store customer data is retained on the merchant’s instruction and is removed in line with our deletion processes when a merchant closes their store.

6. Security measures

Information security is jointly managed by UnfoldCRO and ICraftAds. We implement reasonable security practices and procedures designed to protect personal data, including:

  • Encryption of data in transit (TLS/HTTPS) and encryption of sensitive data at rest.
  • Logical tenant isolation so each merchant’s data is segregated within the multi-tenant platform.
  • Role-based access controls, least-privilege access and audit logging.
  • Use of PCI-DSS compliant payment partners so that card data never touches our servers.
  • Regular backups, monitoring and review of security controls.

While we take security seriously, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Your rights

Subject to applicable law, individuals have the right to:

  • Access the personal data we hold about you and obtain a summary of processing.
  • Request correction, completion or updating of inaccurate or incomplete data.
  • Request erasure of your data where it is no longer required and not subject to a legal retention obligation.
  • Withdraw consent for processing that is based on consent.
  • Nominate another individual to exercise your rights in the event of death or incapacity.
  • Raise a grievance with our Grievance Officer and escalate to the Data Protection Board of India.

Store customers should direct requests about their data to the merchant whose store they purchased from, as the merchant is the data fiduciary; we will support merchants in fulfilling such requests.

8. Cookies and tracking

DigitalShop and merchant storefronts use cookies and similar technologies for essential functions (such as log-in sessions and cart state) and, with consent, for analytics and marketing. You can control non-essential cookies through your browser settings or any consent banner shown to you. Disabling essential cookies may affect core functionality.

9. Children

DigitalShop is intended for business users and is not directed at children. In line with the DPDP Act, we do not knowingly process the personal data of children (individuals under 18) without verifiable parental consent. If you believe a child’s data has been collected, please contact us so we can take appropriate action.

10. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified through the Platform or by email. The “Last updated” date at the top reflects the latest revision. Continued use of the Platform after changes take effect constitutes acceptance of the revised Policy.

11. Grievance Officer and contact

In accordance with the DPDP Act and the Information Technology Act, 2000, you may contact our Grievance Officer for any questions, requests or complaints regarding your personal data:

Grievance Officer, DigitalShop
A joint venture of UnfoldCRO & ICraftAds
Email: hello@digitalshop.cloud

We aim to acknowledge grievances promptly and resolve them within the timelines required by law.