ApexMart
HomeShopAboutContactLoginGet Started

Privacy Policy

How ApexMart handles your personal data, and the rights you have over it.

Last updated: 29 July 2026

This Privacy Policy explains what personal data ApexMart collects when you use the ApexMart platform, why we collect it, who we share it with, how long we keep it, how we protect it and what you can ask us to do with it. It is published under the Digital Personal Data Protection Act, 2023(the "DPDP Act"), the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the "SPDI Rules").

We never see your card number, CVV or UPI PIN

Online payments are processed end to end by our third-party payment gateway on its own PCI-DSS compliant infrastructure. ApexMart does not collect, receive, process or store your full card number, card expiry, CVV, card PIN, UPI PIN, net banking password or any OTP. Those details are entered on the gateway's own secure screen and never reach our servers or our database. We receive only the outcome of the transaction — success, failure or pending — the method used, the amount, and a gateway reference identifier.

Nobody from ApexMart will ever ask you for those details by phone, email or message. If somebody does, they are not us. Report it to our Grievance Officer using the details in clause 17.

1. Who we are — the Data Fiduciary

For the purposes of the DPDP Act, ApexMart is the Data Fiduciary — the person that determines the purpose and the means of processing your personal data on the ApexMart platform. You are the Data Principal. Wherever this policy says "we", "us" or "our", it means ApexMart.

Data Fiduciary
ApexMart
Brand name
ApexMart
Website
https://apexmart.in
Privacy contact
support@apexmart.in
Business hours
Monday to Saturday, 10:00 AM to 7:00 PM IST

2. What this policy covers

This policy applies to the ApexMart website and every part of it — the catalogue, your account and dashboard, the cart and checkout, the seller area, the wallet, the affiliate referral programme, our transactional emails and our support channels.

It does not apply to:

  • third-party websites you reach through a link on our platform, which have their own privacy policies;
  • what an independent Seller does with your data after we pass it to them for fulfilment, beyond the restrictions we impose on them in clause 8; or
  • the payment gateway's own processing of the payment credentials you enter on its screen, which is governed by its policy and by the Reserve Bank of India's requirements for payment aggregators.

3. The personal data we collect

3.1 Data you give us directly

  • Account details — your name, email address, mobile number, the username you choose, your password (stored only as a one-way hash, see clause 11) and the referral code, if any, that you entered when registering.
  • Verification records — the six-digit one-time code we email you at registration, the number of attempts made on it, and the date and time your email address was verified.
  • Delivery addresses — recipient name, full postal address, PIN code and a contact number, for each address you save in your address book.
  • Order data — the items and quantities you buy, prices and taxes, invoices, order and payment status, and any cancellation, return or refund on the order.
  • Payout details — only if you withdraw a wallet balance: bank account number, IFSC code, bank name and/or UPI ID. A UPI ID (VPA) is an address, not a credential; we never ask for and never accept your UPI PIN.
  • Correspondence — the content of emails, contact-form messages, grievances and anything you attach to them.
  • Seller details — if you are onboarded as a Seller: business name, GSTIN and tax particulars, listing content, and settlement details.

3.2 Data we generate about your account

  • your unique referral code, and your account status — registered, or activated by a first paid order;
  • your wallet balance, the transaction ledger behind it, and referral reward entries recording which settled order a reward arose from;
  • referral relationships — the account whose referral code you used when registering, and the accounts that registered using yours. We hold these solely to attribute referral rewards under our affiliate programme correctly and to detect abuse of it. Referral relationships are not published, sold or shared with any third party.

3.3 Technical and usage data, collected automatically

  • your IP address, browser type and version, device type, operating system, and language and display settings;
  • the pages and API endpoints you request, the date and time, the referring page, and error and diagnostic logs used to keep the service running;
  • Our server access logs deliberately mask secrets: any token, password, API key or secret appearing in a request URL is redacted before the line is written.
  • We do not track your precise device location, and we do not access your camera, microphone, contacts or photo library.

3.4 Sensitive personal data

Under the SPDI Rules, passwords and financial information count as sensitive personal data. We hold your password only as a salted one-way hash that cannot be reversed, and we hold payout bank or UPI details only where you have supplied them for a withdrawal. We do not collect Aadhaar numbers, biometric data, health records, caste, religion, sexual orientation or political affiliation — please never send them to us.

4. What we never collect

Being explicit about this matters more than any assurance we could give, so the list is short and absolute. ApexMart does not collect, request or store:

  • your full card number, card expiry date or CVV;
  • your card PIN, UPI PIN, or net banking username and password;
  • any OTP issued to you by your bank, card issuer or UPI application;
  • your account password in readable form — only an irreversible hash of it;
  • Aadhaar numbers, biometric identifiers or any government ID scan from a shopper;
  • your precise geolocation, or any cross-site advertising or behavioural profile; or
  • personal data of anyone we know to be under 18 (clause 13).

5. Why we use your data, and on what basis

We process personal data only for the purposes below, and only with the data each purpose actually needs. Under the DPDP Act our basis is your consent, given for a specific purpose when you register, place an order or make a request, or a legitimate use — principally performing the contract you asked us to perform and complying with Indian law.

PurposePersonal data usedBasis
Creating, verifying and securing your accountName, email, mobile, username, password hash, verification recordsConsent at registration; performance of our contract with you
Processing your order, arranging dispatch within 1-2 business days and delivery within 3-7 business days of dispatchDelivery address and contact number, order contents, payment statusPerformance of our contract with you
Cancellations (any time before your order is dispatched), returns within 7 days from delivery, and refunds processed in 5-7 business daysOrder records, payment status, wallet and transaction ledgerPerformance of our contract; obligations under consumer law
Collecting payment and reversing it when a refund is dueOrder reference, amount, the transaction outcome returned by the gatewayPerformance of our contract with you
Attributing referral rewards under the affiliate programmeReferral code, referral relationships, settled order dataConsent given when you enrol; performance of the programme terms
Paying out a wallet withdrawalBank account and IFSC or UPI ID, withdrawal amount, tax identifiers where a deduction appliesPerformance of our contract; legal obligation (tax)
Issuing invoices and filing tax returnsName, billing address, order value and tax, your GSTIN where you supply oneLegal obligation
Sending service messages — one-time codes, order, dispatch and refund updatesEmail address, mobile number, order statusPerformance of our contract with you
Answering support queries and handling grievancesYour message, order reference and account detailsPerformance of our contract; legal obligation under the IT Rules, 2021
Preventing fraud, duplicate accounts and abuse of promotions or referral rewardsIP and device data, access logs, account and order historyLegitimate use; legal obligation
Keeping the platform reliable and improving itAggregated, non-identifying usage and error statisticsLegitimate use

We do not sell your personal data. We do not share it with advertising networks, data brokers or any third party for their own marketing, and we do not use it to build an advertising profile of you.

6. Cookies, local storage and similar technologies

We use as little browser storage as the service can work with, and the platform carries no third-party advertising or cross-site tracking cookies. Your session and your cart are kept in your browser's local storage on your own device rather than in a tracking cookie:

NameTypePurposeLifetime
apexmart_tokenLocal storageHolds the signed session token that keeps you logged in and authorises your requests to our API. Strictly necessary.Until you log out, the session expires, or you clear site data
apexmart_userLocal storageCaches your name, email, role and account status so your dashboard renders without an extra round trip. Strictly necessary.Until you log out, or you clear site data
apexmart_cart_v1Local storageKeeps the items in your cart on this device so they survive a page reload. Strictly necessary.Until the cart is emptied, or you clear site data

Because these live in your browser rather than on a tracking network, logging out or clearing site data removes them completely from that device. Please log out on shared or public computers. Where our hosting provider or image CDN sets a strictly necessary cookie for load balancing or security, it is used for that purpose alone. If we ever introduce analytics or marketing cookies, we will ask for your consent first and update this policy before doing so.

7. Who we share your data with

We share personal data only with the categories of recipient below, only to the extent each one needs it, and only under a contract requiring them to keep it confidential, to use it solely for the purpose we engaged them for, and to apply appropriate security measures.

Recipient, by roleWhat they receiveWhy
Payment gateway (PCI-DSS compliant payment aggregator)Your name, email, phone, the order amount and an order reference. Your card or UPI credentials go to it directly from your browser and never pass through us.To collect payment and to process refunds, reversals and chargebacks
Courier and logistics partnersRecipient name, delivery address and PIN code, contact number, parcel referenceTo dispatch, track and deliver your order, and to collect returns
Independent Sellers on the platformOnly the fulfilment data listed in clause 8To pack, invoice and dispatch the item you bought from them
Email delivery providerYour email address, your name, and the content of the transactional messageTo deliver one-time codes, order confirmations and service notices
Cloud hosting and managed database providerThe platform data stored and backed up on their infrastructureTo run, host and back up the service
Image and file storage / content delivery networkProduct media and any image you uploadTo store images and serve them quickly
Accountants, auditors, tax advisers and our bankersTransaction, invoice and settlement recordsAccounting, audit, statutory filings and payouts
Law enforcement, courts, regulatorsOnly what is specifically requiredWhere compelled by Indian law, or to establish, exercise or defend a legal claim
A successor in a business transferRecords forming part of the business transferredMerger, acquisition or reorganisation — subject to this policy continuing to apply to the transferred data

8. Sharing with Sellers

Where an item is sold by an independent Seller, that Seller receives strictly what it needs to fulfil your order: the recipient's name, the delivery address and PIN code, a contact number for the delivery, the items and quantities ordered, and the order reference.

A Seller does not receive your password, any payment credential, your wallet balance or transaction ledger, your referral data, or your order history with any other seller. It may use what it receives only to pack, dispatch, invoice and handle the return of that order and to meet its own statutory record-keeping duties. Using your data for its own marketing is a breach of its seller agreement — tell us and we will act on it.

9. Where your data is stored, and transfers outside India

Our database and file storage are operated for us by cloud providers. Some of those providers, and some of the payment, email and content delivery providers listed in clause 7, run infrastructure outside India. Where personal data is processed outside India, we transfer it only to a country that has not been restricted by the Central Government under section 16 of the DPDP Act, and only under a contract imposing protection equivalent to this policy.

Payment transaction data is held by our payment gateway in accordance with the Reserve Bank of India's data storage requirements that apply to it as a payment aggregator. Books of account, invoices and tax records are retained as required by Indian law.

10. How long we keep your data

We keep personal data only for as long as the purpose it was collected for requires, or for longer where a law requires us to. When a retention period ends we delete the data or irreversibly anonymise it so that it can no longer identify you.

DataRetention period
Account profile — name, email, mobile, saved delivery addressesWhile your account is open, and for 90 days after you ask us to close it, so that a closure requested in error can be reversed
Order records, invoices, GST and other tax dataAt least 8 years from the end of the relevant financial year, as required by the Companies Act, 2013, the Income-tax Act, 1961 and the Central Goods and Services Tax Act, 2017. These cannot be erased on request while that period runs.
Wallet balance, transaction ledger and referral reward entriesThe same period as order records — they form part of the financial audit trail
Payout bank account or UPI detailsWhile withdrawals are enabled on your account, and thereafter for the statutory record period applicable to the payments already made
Support and grievance correspondence3 years from the date the matter was closed
Server, access, security and error logsUp to 12 months, after which they are deleted or aggregated
Marketing opt-out recordsFor as long as needed to keep honouring your opt-out

11. How we protect your data

We apply reasonable security practices and procedures appropriate to the data we hold, as required by section 8(5) of the DPDP Act and Rule 8 of the SPDI Rules. In practice that means:

  • Encryption in transit. The platform is served over HTTPS/TLS, and every request between your browser and our API is encrypted.
  • Passwords are hashed, never stored. We keep only a salted, one-way bcrypt hash. We cannot read your password, we will never email it to you, and we will never ask you for it.
  • Verified email, rate-limited codes. Registration is confirmed by a time-limited one-time code with a hard cap on attempts, so a code cannot be guessed by brute force.
  • Signed, expiring sessions. Session tokens are cryptographically signed; a rejected or expired token immediately logs that device out and clears the cached account data from the browser.
  • Role-based access control. Shopper, seller and administrative areas are separated, and every administrative action requires an authenticated admin session.
  • Least-privilege access. Access to production data is limited to the small number of people who need it to operate the service, and is removed when it is no longer needed.
  • Auditable money movements. Wallet credits, refunds and withdrawals are written inside database transactions with an accompanying ledger entry, so every change to a balance is traceable.
  • Secrets redacted from logs. Tokens, passwords, API keys and secrets are masked before any access log line is written.
  • Payment credentials are out of scope by design. We cannot lose what we never hold.

No system can be guaranteed perfectly secure. Please play your part: use a password unique to this platform, never share your one-time codes with anyone, and log out on shared devices.

12. Your rights as a Data Principal

  • Right to information and access. A summary of the personal data we hold about you, how we are processing it, and the identities of the other Data Fiduciaries and processors with whom it has been shared.
  • Right to correction, completion and updating. Most of this you can do yourself from your dashboard profile and address book. Write to us for anything you cannot edit there.
  • Right to erasure. You may ask us to delete your personal data and close your account. We will do so unless a law requires us to keep specific records — see clause 10 — in which case we will tell you exactly what we must retain and for how long, and we will stop using it for anything else.
  • Right to withdraw consent. You may withdraw consent as easily as you gave it. Withdrawal takes effect going forward; it does not undo processing already carried out, and it may mean we can no longer provide part of the service — we cannot deliver an order without a delivery address, for example.
  • Right to grievance redressal. A readily available means of raising a complaint with us, set out in clause 17.
  • Right to nominate. You may nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
  • Right to opt out of marketing. See clause 15.

How to exercise a right

Write to support@apexmart.in from the email address registered on your account, saying which right you wish to exercise and giving enough detail for us to find your records — your registered email, and an order number where the request concerns an order. We may ask you to verify your identity before we act; that check exists to stop someone else obtaining or deleting your data. We respond within 30 days of receiving a valid request, and there is no charge for making one.

Section 15 of the DPDP Act also places duties on you: give authentic information, do not impersonate anyone else when registering or ordering, do not suppress material information where you are legally required to disclose it, and do not raise a false or frivolous grievance.

13. Children's data

The platform is not intended for children. You must be at least 18 years old to register an account, place an order, sell, or take part in the affiliate referral programme. We do not knowingly collect personal data from anyone under 18, and we carry out no tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has given us personal data, write to our Grievance Officer and we will delete it and close any account concerned.

14. Automated decision-making

We do not take decisions about you that produce legal effects by purely automated means. Automated checks may flag an order or an account for review — for suspected fraud, duplicate accounts, or abuse of a promotion or of referral rewards — but any suspension, withheld payout or cancelled order that follows is reviewed by a person, and you can contest the outcome through the grievance route in clause 17.

15. Service messages and marketing

  • Service messages — one-time codes, order confirmations, dispatch and delivery updates, refund confirmations and security notices — are part of the service and are sent for as long as you hold an account. They cannot be switched off while your account is open.
  • Promotional messages are sent only where you have opted in. Every one carries an unsubscribe link, and you can also opt out by writing to us. Opting out of marketing does not stop service messages.
  • We do not pass your email address or phone number to any third party for that third party's own marketing.

16. Personal data breaches

We maintain procedures to detect, investigate and contain a personal data breach. If one occurs, we will notify the Data Protection Board of India and every affected Data Principal in the form and within the timelines prescribed under the DPDP Act, and will report the incident to CERT-In where its directions require it. The notice will describe, so far as we know it at the time, the nature and extent of the breach, its likely consequences, the measures we have taken and propose to take, and what you should do to protect yourself.

17. Grievance Officer

If you are unhappy with how we have handled your personal data, or you have exercised a right and are not satisfied with our response, contact our Grievance Officer, appointed under the DPDP Act and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

Designation
Grievance Officer
Email
grievance@apexmart.in
Business hours
Monday to Saturday, 10:00 AM to 7:00 PM IST

We acknowledge every grievance within 24 hours and resolve it within 15 days of receipt. The full escalation path, and what to do if you remain dissatisfied, is set out on our Grievance Redressal page. If your grievance about your personal data is still unresolved after that, you may complain to the Data Protection Board of India under the DPDP Act.

18. Changes to this policy

We may update this policy when our services, our processors or the law change. The current version is always published on this page with the "Last updated" date shown at the top. Where a change materially affects how we use your personal data, we will tell you by email or through a prominent notice on the platform before it takes effect. Continuing to use the platform after that date means you accept the updated policy.

19. Contact us

For anything in this policy — a question, a request under clause 12, or a correction to your records — reach us at the details below or through our Contact page.

Legal entity
ApexMart
Email
support@apexmart.in
Business hours
Monday to Saturday, 10:00 AM to 7:00 PM IST
Data protection queries
grievance@apexmart.in

This Privacy Policy forms part of, and should be read with, our Terms & Conditions and the Grievance Redressal procedure. Where this policy and any other document conflict on how personal data is handled, this policy prevails.

Terms & ConditionsCancellation & RefundsOrder CancellationShipping & DeliveryPricing & ChargesGrievance Redressal
ApexMart

India's most rewarding shop-and-earn affiliate platform.

Quick Links

  • Member Perks
  • How it Works
  • Shop
  • Join Now

Company

  • About Us
  • Contact

Legal

  • Terms & Conditions
  • Privacy Policy
  • Cancellation & Refunds
  • Order Cancellation
  • Shipping & Delivery
  • Pricing & Charges
  • Grievance Redressal

Get in Touch

  • support@apexmart.in
© 2026 ApexMart. All rights reserved. Built with ❤️ in India.