Privacy Policy
Last updated: 26 June 2026
This Privacy Policy explains how DigitalShop collects, uses, discloses and safeguards personal data when you use our e-commerce platform and related services.
DigitalShop (“DigitalShop”, “the Platform”, “we”, “us” or “our”) is a multi-tenant e-commerce platform operated as a joint venture of two companies: UnfoldCRO, which provides the technical and product engineering for the Platform, and ICraftAds, which provides financial and management support for the product. Privacy and data security are jointly managed by UnfoldCRO and ICraftAds, who together act as the data fiduciary for personal data processed through DigitalShop.
This Policy is framed in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), and other applicable Indian law.
1. Who this Policy applies to
DigitalShop serves two broad groups of individuals, and the way we process data differs for each:
- Merchants — business owners and their staff who sign up for and operate a store on DigitalShop. For merchant account data, DigitalShop acts as a data fiduciary.
- Store customers (shoppers) — the end customers who buy from a merchant’s store. For this data, the merchant is the data fiduciary who determines the purpose of processing, and DigitalShop acts as a data processor on the merchant’s behalf.
2. Data we collect
From merchants
- Identity and contact details: name, business name, email, phone number, address.
- Account and KYC-related details required to operate a store and receive payouts, including GSTIN, PAN and bank/UPI settlement details (handled in conjunction with our payment partner).
- Billing data: subscription plan, add-ons, invoices and e-mandate references (card data is not stored by us).
- Usage and device data: log-ins, IP address, browser/device type, pages used and feature activity.
- Communications: support tickets, emails and feedback you send us.
From store customers (processed for the merchant)
- Order details: name, shipping and billing address, email, phone number and order contents.
- Payment status and references returned by the payment gateway (we do not store card numbers or CVV).
- Account credentials where a store offers customer log-in, and order/communication history.
- Browsing and analytics data such as cookies, device identifiers and pages viewed on the store.
3. Why we process data and the legal basis
Under the DPDP Act, we process personal data on the following bases:
- Performance of service / contract: to create and operate merchant stores, process orders, enable payments and shipping, generate GST invoices and provide support.
- Consent: for marketing communications, optional cookies and any processing that is not necessary to deliver the core service. Consent may be withdrawn at any time.
- Legal obligation and legitimate uses: to comply with tax, accounting, fraud-prevention and other statutory requirements, and to secure the Platform.
4. How we share data and sub-processors
We do not sell personal data. We share it only with trusted service providers (sub-processors) who help us deliver the service, under contractual confidentiality and security obligations. Key sub-processors include:
| Sub-processor | Purpose | Data shared |
|---|---|---|
| Razorpay (PCI-DSS payment gateway) | Payment processing, subscriptions and e-mandate auto-debit | Payment amount, contact details and order references. Card data is captured and stored by Razorpay, not by DigitalShop. |
| Shiprocket and shipping partners | Order fulfilment, courier allocation and tracking | Recipient name, shipping address, phone and order details. |
| Cloud hosting and infrastructure providers | Hosting, storage and delivery of the Platform | All Platform data, stored securely. |
| Email, SMS and analytics providers | Transactional messages and aggregated usage analytics | Contact details and event/usage data as required. |
We may also disclose data where required by law, a valid order of a court or government authority, or to protect the rights, safety and security of users and the Platform.
5. Data retention
We retain personal data only for as long as necessary to provide the service and to meet legal, tax and accounting obligations. Merchant billing and invoice records are retained for the period required under Indian tax law. When data is no longer required and there is no legal obligation to retain it, it is deleted or anonymised. Store customer data is retained on the merchant’s instruction and is removed in line with our deletion processes when a merchant closes their store.
6. Security measures
Information security is jointly managed by UnfoldCRO and ICraftAds. We implement reasonable security practices and procedures designed to protect personal data, including:
- Encryption of data in transit (TLS/HTTPS) and encryption of sensitive data at rest.
- Logical tenant isolation so each merchant’s data is segregated within the multi-tenant platform.
- Role-based access controls, least-privilege access and audit logging.
- Use of PCI-DSS compliant payment partners so that card data never touches our servers.
- Regular backups, monitoring and review of security controls.
While we take security seriously, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Your rights
Subject to applicable law, individuals have the right to:
- Access the personal data we hold about you and obtain a summary of processing.
- Request correction, completion or updating of inaccurate or incomplete data.
- Request erasure of your data where it is no longer required and not subject to a legal retention obligation.
- Withdraw consent for processing that is based on consent.
- Nominate another individual to exercise your rights in the event of death or incapacity.
- Raise a grievance with our Grievance Officer and escalate to the Data Protection Board of India.
Store customers should direct requests about their data to the merchant whose store they purchased from, as the merchant is the data fiduciary; we will support merchants in fulfilling such requests.
8. Cookies and tracking
DigitalShop and merchant storefronts use cookies and similar technologies for essential functions (such as log-in sessions and cart state) and, with consent, for analytics and marketing. You can control non-essential cookies through your browser settings or any consent banner shown to you. Disabling essential cookies may affect core functionality.
9. Children
DigitalShop is intended for business users and is not directed at children. In line with the DPDP Act, we do not knowingly process the personal data of children (individuals under 18) without verifiable parental consent. If you believe a child’s data has been collected, please contact us so we can take appropriate action.
10. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified through the Platform or by email. The “Last updated” date at the top reflects the latest revision. Continued use of the Platform after changes take effect constitutes acceptance of the revised Policy.
11. Grievance Officer and contact
In accordance with the DPDP Act and the Information Technology Act, 2000, you may contact our Grievance Officer for any questions, requests or complaints regarding your personal data:
Grievance Officer, DigitalShop
A joint venture of UnfoldCRO & ICraftAds
Email: hello@digitalshop.cloud
We aim to acknowledge grievances promptly and resolve them within the timelines required by law.