This Privacy Policy explains what personal data ApexMart collects when you use the ApexMart platform, why we collect it, who we share it with, how long we keep it, how we protect it and what you can ask us to do with it. It is published under the Digital Personal Data Protection Act, 2023(the "DPDP Act"), the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the "SPDI Rules").
1. Who we are — the Data Fiduciary
For the purposes of the DPDP Act, ApexMart is the Data Fiduciary — the person that determines the purpose and the means of processing your personal data on the ApexMart platform. You are the Data Principal. Wherever this policy says "we", "us" or "our", it means ApexMart.
- Data Fiduciary
- ApexMart
- Brand name
- ApexMart
- Website
- https://apexmart.in
- Privacy contact
- support@apexmart.in
- Business hours
- Monday to Saturday, 10:00 AM to 7:00 PM IST
2. What this policy covers
This policy applies to the ApexMart website and every part of it — the catalogue, your account and dashboard, the cart and checkout, the seller area, the wallet, the affiliate referral programme, our transactional emails and our support channels.
It does not apply to:
- third-party websites you reach through a link on our platform, which have their own privacy policies;
- what an independent Seller does with your data after we pass it to them for fulfilment, beyond the restrictions we impose on them in clause 8; or
- the payment gateway's own processing of the payment credentials you enter on its screen, which is governed by its policy and by the Reserve Bank of India's requirements for payment aggregators.
3. The personal data we collect
3.1 Data you give us directly
- Account details — your name, email address, mobile number, the username you choose, your password (stored only as a one-way hash, see clause 11) and the referral code, if any, that you entered when registering.
- Verification records — the six-digit one-time code we email you at registration, the number of attempts made on it, and the date and time your email address was verified.
- Delivery addresses — recipient name, full postal address, PIN code and a contact number, for each address you save in your address book.
- Order data — the items and quantities you buy, prices and taxes, invoices, order and payment status, and any cancellation, return or refund on the order.
- Payout details — only if you withdraw a wallet balance: bank account number, IFSC code, bank name and/or UPI ID. A UPI ID (VPA) is an address, not a credential; we never ask for and never accept your UPI PIN.
- Correspondence — the content of emails, contact-form messages, grievances and anything you attach to them.
- Seller details — if you are onboarded as a Seller: business name, GSTIN and tax particulars, listing content, and settlement details.
3.2 Data we generate about your account
- your unique referral code, and your account status — registered, or activated by a first paid order;
- your wallet balance, the transaction ledger behind it, and referral reward entries recording which settled order a reward arose from;
- referral relationships — the account whose referral code you used when registering, and the accounts that registered using yours. We hold these solely to attribute referral rewards under our affiliate programme correctly and to detect abuse of it. Referral relationships are not published, sold or shared with any third party.
3.3 Technical and usage data, collected automatically
- your IP address, browser type and version, device type, operating system, and language and display settings;
- the pages and API endpoints you request, the date and time, the referring page, and error and diagnostic logs used to keep the service running;
- Our server access logs deliberately mask secrets: any token, password, API key or secret appearing in a request URL is redacted before the line is written.
- We do not track your precise device location, and we do not access your camera, microphone, contacts or photo library.
3.4 Sensitive personal data
Under the SPDI Rules, passwords and financial information count as sensitive personal data. We hold your password only as a salted one-way hash that cannot be reversed, and we hold payout bank or UPI details only where you have supplied them for a withdrawal. We do not collect Aadhaar numbers, biometric data, health records, caste, religion, sexual orientation or political affiliation — please never send them to us.
4. What we never collect
Being explicit about this matters more than any assurance we could give, so the list is short and absolute. ApexMart does not collect, request or store:
- your full card number, card expiry date or CVV;
- your card PIN, UPI PIN, or net banking username and password;
- any OTP issued to you by your bank, card issuer or UPI application;
- your account password in readable form — only an irreversible hash of it;
- Aadhaar numbers, biometric identifiers or any government ID scan from a shopper;
- your precise geolocation, or any cross-site advertising or behavioural profile; or
- personal data of anyone we know to be under 18 (clause 13).
5. Why we use your data, and on what basis
We process personal data only for the purposes below, and only with the data each purpose actually needs. Under the DPDP Act our basis is your consent, given for a specific purpose when you register, place an order or make a request, or a legitimate use — principally performing the contract you asked us to perform and complying with Indian law.
| Purpose | Personal data used | Basis |
|---|---|---|
| Creating, verifying and securing your account | Name, email, mobile, username, password hash, verification records | Consent at registration; performance of our contract with you |
| Processing your order, arranging dispatch within 1-2 business days and delivery within 3-7 business days of dispatch | Delivery address and contact number, order contents, payment status | Performance of our contract with you |
| Cancellations (any time before your order is dispatched), returns within 7 days from delivery, and refunds processed in 5-7 business days | Order records, payment status, wallet and transaction ledger | Performance of our contract; obligations under consumer law |
| Collecting payment and reversing it when a refund is due | Order reference, amount, the transaction outcome returned by the gateway | Performance of our contract with you |
| Attributing referral rewards under the affiliate programme | Referral code, referral relationships, settled order data | Consent given when you enrol; performance of the programme terms |
| Paying out a wallet withdrawal | Bank account and IFSC or UPI ID, withdrawal amount, tax identifiers where a deduction applies | Performance of our contract; legal obligation (tax) |
| Issuing invoices and filing tax returns | Name, billing address, order value and tax, your GSTIN where you supply one | Legal obligation |
| Sending service messages — one-time codes, order, dispatch and refund updates | Email address, mobile number, order status | Performance of our contract with you |
| Answering support queries and handling grievances | Your message, order reference and account details | Performance of our contract; legal obligation under the IT Rules, 2021 |
| Preventing fraud, duplicate accounts and abuse of promotions or referral rewards | IP and device data, access logs, account and order history | Legitimate use; legal obligation |
| Keeping the platform reliable and improving it | Aggregated, non-identifying usage and error statistics | Legitimate use |
We do not sell your personal data. We do not share it with advertising networks, data brokers or any third party for their own marketing, and we do not use it to build an advertising profile of you.
6. Cookies, local storage and similar technologies
We use as little browser storage as the service can work with, and the platform carries no third-party advertising or cross-site tracking cookies. Your session and your cart are kept in your browser's local storage on your own device rather than in a tracking cookie:
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
apexmart_token | Local storage | Holds the signed session token that keeps you logged in and authorises your requests to our API. Strictly necessary. | Until you log out, the session expires, or you clear site data |
apexmart_user | Local storage | Caches your name, email, role and account status so your dashboard renders without an extra round trip. Strictly necessary. | Until you log out, or you clear site data |
apexmart_cart_v1 | Local storage | Keeps the items in your cart on this device so they survive a page reload. Strictly necessary. | Until the cart is emptied, or you clear site data |
Because these live in your browser rather than on a tracking network, logging out or clearing site data removes them completely from that device. Please log out on shared or public computers. Where our hosting provider or image CDN sets a strictly necessary cookie for load balancing or security, it is used for that purpose alone. If we ever introduce analytics or marketing cookies, we will ask for your consent first and update this policy before doing so.
7. Who we share your data with
We share personal data only with the categories of recipient below, only to the extent each one needs it, and only under a contract requiring them to keep it confidential, to use it solely for the purpose we engaged them for, and to apply appropriate security measures.
| Recipient, by role | What they receive | Why |
|---|---|---|
| Payment gateway (PCI-DSS compliant payment aggregator) | Your name, email, phone, the order amount and an order reference. Your card or UPI credentials go to it directly from your browser and never pass through us. | To collect payment and to process refunds, reversals and chargebacks |
| Courier and logistics partners | Recipient name, delivery address and PIN code, contact number, parcel reference | To dispatch, track and deliver your order, and to collect returns |
| Independent Sellers on the platform | Only the fulfilment data listed in clause 8 | To pack, invoice and dispatch the item you bought from them |
| Email delivery provider | Your email address, your name, and the content of the transactional message | To deliver one-time codes, order confirmations and service notices |
| Cloud hosting and managed database provider | The platform data stored and backed up on their infrastructure | To run, host and back up the service |
| Image and file storage / content delivery network | Product media and any image you upload | To store images and serve them quickly |
| Accountants, auditors, tax advisers and our bankers | Transaction, invoice and settlement records | Accounting, audit, statutory filings and payouts |
| Law enforcement, courts, regulators | Only what is specifically required | Where compelled by Indian law, or to establish, exercise or defend a legal claim |
| A successor in a business transfer | Records forming part of the business transferred | Merger, acquisition or reorganisation — subject to this policy continuing to apply to the transferred data |
8. Sharing with Sellers
Where an item is sold by an independent Seller, that Seller receives strictly what it needs to fulfil your order: the recipient's name, the delivery address and PIN code, a contact number for the delivery, the items and quantities ordered, and the order reference.
A Seller does not receive your password, any payment credential, your wallet balance or transaction ledger, your referral data, or your order history with any other seller. It may use what it receives only to pack, dispatch, invoice and handle the return of that order and to meet its own statutory record-keeping duties. Using your data for its own marketing is a breach of its seller agreement — tell us and we will act on it.
9. Where your data is stored, and transfers outside India
Our database and file storage are operated for us by cloud providers. Some of those providers, and some of the payment, email and content delivery providers listed in clause 7, run infrastructure outside India. Where personal data is processed outside India, we transfer it only to a country that has not been restricted by the Central Government under section 16 of the DPDP Act, and only under a contract imposing protection equivalent to this policy.
Payment transaction data is held by our payment gateway in accordance with the Reserve Bank of India's data storage requirements that apply to it as a payment aggregator. Books of account, invoices and tax records are retained as required by Indian law.
10. How long we keep your data
We keep personal data only for as long as the purpose it was collected for requires, or for longer where a law requires us to. When a retention period ends we delete the data or irreversibly anonymise it so that it can no longer identify you.
| Data | Retention period |
|---|---|
| Account profile — name, email, mobile, saved delivery addresses | While your account is open, and for 90 days after you ask us to close it, so that a closure requested in error can be reversed |
| Order records, invoices, GST and other tax data | At least 8 years from the end of the relevant financial year, as required by the Companies Act, 2013, the Income-tax Act, 1961 and the Central Goods and Services Tax Act, 2017. These cannot be erased on request while that period runs. |
| Wallet balance, transaction ledger and referral reward entries | The same period as order records — they form part of the financial audit trail |
| Payout bank account or UPI details | While withdrawals are enabled on your account, and thereafter for the statutory record period applicable to the payments already made |
| Support and grievance correspondence | 3 years from the date the matter was closed |
| Server, access, security and error logs | Up to 12 months, after which they are deleted or aggregated |
| Marketing opt-out records | For as long as needed to keep honouring your opt-out |
11. How we protect your data
We apply reasonable security practices and procedures appropriate to the data we hold, as required by section 8(5) of the DPDP Act and Rule 8 of the SPDI Rules. In practice that means:
- Encryption in transit. The platform is served over HTTPS/TLS, and every request between your browser and our API is encrypted.
- Passwords are hashed, never stored. We keep only a salted, one-way bcrypt hash. We cannot read your password, we will never email it to you, and we will never ask you for it.
- Verified email, rate-limited codes. Registration is confirmed by a time-limited one-time code with a hard cap on attempts, so a code cannot be guessed by brute force.
- Signed, expiring sessions. Session tokens are cryptographically signed; a rejected or expired token immediately logs that device out and clears the cached account data from the browser.
- Role-based access control. Shopper, seller and administrative areas are separated, and every administrative action requires an authenticated admin session.
- Least-privilege access. Access to production data is limited to the small number of people who need it to operate the service, and is removed when it is no longer needed.
- Auditable money movements. Wallet credits, refunds and withdrawals are written inside database transactions with an accompanying ledger entry, so every change to a balance is traceable.
- Secrets redacted from logs. Tokens, passwords, API keys and secrets are masked before any access log line is written.
- Payment credentials are out of scope by design. We cannot lose what we never hold.
No system can be guaranteed perfectly secure. Please play your part: use a password unique to this platform, never share your one-time codes with anyone, and log out on shared devices.
12. Your rights as a Data Principal
- Right to information and access. A summary of the personal data we hold about you, how we are processing it, and the identities of the other Data Fiduciaries and processors with whom it has been shared.
- Right to correction, completion and updating. Most of this you can do yourself from your dashboard profile and address book. Write to us for anything you cannot edit there.
- Right to erasure. You may ask us to delete your personal data and close your account. We will do so unless a law requires us to keep specific records — see clause 10 — in which case we will tell you exactly what we must retain and for how long, and we will stop using it for anything else.
- Right to withdraw consent. You may withdraw consent as easily as you gave it. Withdrawal takes effect going forward; it does not undo processing already carried out, and it may mean we can no longer provide part of the service — we cannot deliver an order without a delivery address, for example.
- Right to grievance redressal. A readily available means of raising a complaint with us, set out in clause 17.
- Right to nominate. You may nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
- Right to opt out of marketing. See clause 15.
How to exercise a right
Write to support@apexmart.in from the email address registered on your account, saying which right you wish to exercise and giving enough detail for us to find your records — your registered email, and an order number where the request concerns an order. We may ask you to verify your identity before we act; that check exists to stop someone else obtaining or deleting your data. We respond within 30 days of receiving a valid request, and there is no charge for making one.
Section 15 of the DPDP Act also places duties on you: give authentic information, do not impersonate anyone else when registering or ordering, do not suppress material information where you are legally required to disclose it, and do not raise a false or frivolous grievance.
13. Children's data
The platform is not intended for children. You must be at least 18 years old to register an account, place an order, sell, or take part in the affiliate referral programme. We do not knowingly collect personal data from anyone under 18, and we carry out no tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has given us personal data, write to our Grievance Officer and we will delete it and close any account concerned.
14. Automated decision-making
We do not take decisions about you that produce legal effects by purely automated means. Automated checks may flag an order or an account for review — for suspected fraud, duplicate accounts, or abuse of a promotion or of referral rewards — but any suspension, withheld payout or cancelled order that follows is reviewed by a person, and you can contest the outcome through the grievance route in clause 17.
15. Service messages and marketing
- Service messages — one-time codes, order confirmations, dispatch and delivery updates, refund confirmations and security notices — are part of the service and are sent for as long as you hold an account. They cannot be switched off while your account is open.
- Promotional messages are sent only where you have opted in. Every one carries an unsubscribe link, and you can also opt out by writing to us. Opting out of marketing does not stop service messages.
- We do not pass your email address or phone number to any third party for that third party's own marketing.
16. Personal data breaches
We maintain procedures to detect, investigate and contain a personal data breach. If one occurs, we will notify the Data Protection Board of India and every affected Data Principal in the form and within the timelines prescribed under the DPDP Act, and will report the incident to CERT-In where its directions require it. The notice will describe, so far as we know it at the time, the nature and extent of the breach, its likely consequences, the measures we have taken and propose to take, and what you should do to protect yourself.
17. Grievance Officer
If you are unhappy with how we have handled your personal data, or you have exercised a right and are not satisfied with our response, contact our Grievance Officer, appointed under the DPDP Act and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
- Designation
- Grievance Officer
- Business hours
- Monday to Saturday, 10:00 AM to 7:00 PM IST
We acknowledge every grievance within 24 hours and resolve it within 15 days of receipt. The full escalation path, and what to do if you remain dissatisfied, is set out on our Grievance Redressal page. If your grievance about your personal data is still unresolved after that, you may complain to the Data Protection Board of India under the DPDP Act.
18. Changes to this policy
We may update this policy when our services, our processors or the law change. The current version is always published on this page with the "Last updated" date shown at the top. Where a change materially affects how we use your personal data, we will tell you by email or through a prominent notice on the platform before it takes effect. Continuing to use the platform after that date means you accept the updated policy.
19. Contact us
For anything in this policy — a question, a request under clause 12, or a correction to your records — reach us at the details below or through our Contact page.
- Legal entity
- ApexMart
- support@apexmart.in
- Business hours
- Monday to Saturday, 10:00 AM to 7:00 PM IST
- Data protection queries
- grievance@apexmart.in
This Privacy Policy forms part of, and should be read with, our Terms & Conditions and the Grievance Redressal procedure. Where this policy and any other document conflict on how personal data is handled, this policy prevails.