Privacy Policy

Last updated: 6 July 2026

1. Who we are and what this policy covers

Quickmerce (operated by Quickmerce Internet Pvt. Ltd., registered office [registered address]) is a commerce platform on which merchants build and run their own online stores. This policy explains how we handle personal data on quickmerce.in, in the merchant dashboard, and in our platform services, in line with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Information Technology Act, 2000.

2. Two roles: fiduciary and processor

Quickmerce plays two distinct roles, and your rights run to the right party:

  • Data fiduciary - merchants and visitors. For personal data of merchants, their staff, and visitors to this website (account details, billing information, support conversations, usage data), Quickmerce decides the purposes of processing and is the data fiduciary under the DPDP Act. This policy governs that data.
  • Data processor - shoppers on merchant stores. When you buy from a store built on Quickmerce, the merchant is the data fiduciary for your order data (name, address, phone, order history). We process that data on the merchant's instructions to run their store - hosting, checkout, order updates, delivery tracking. For requests about your data on a merchant's store, contact that merchant first (their privacy policy is on their store); we assist merchants in honouring such requests.

3. Personal data we collect

  • Account data - name, email, phone number, password (stored hashed)
  • Business data - store name, logo, product catalog, GST details you provide, bank/payout details for settlements
  • Billing data - plan, invoices, and payment method references. Card/UPI credentials are collected directly by our PCI-DSS Level 1 payment provider; we never receive or store card numbers, CVVs, or UPI PINs
  • Content you upload - products, pages, media, customer lists you import
  • Usage and device data - pages visited, actions taken, browser type, IP address, collected via cookies (see our Cookie Policy)
  • Support data - messages you send our support and AI assistants

4. Purposes and lawful basis

We process personal data with your consent and for these purposes:

  • Providing, maintaining, securing, and improving the platform
  • Processing subscription payments, commissions, and settlements
  • Sending transactional and security messages (these are part of the service and cannot be opted out of while your account is active)
  • Sending product updates and marketing you can opt out of at any time - withdrawing consent is as easy as giving it
  • Detecting and preventing fraud and abuse
  • Complying with law - tax, accounting, KYC, and lawful requests from authorities

5. AI features

Features such as Bullu, Magic Write, and Ask AI send your prompts and relevant store data to our AI infrastructure provider (Anthropic) to generate the response or plan. This data is processed to provide the feature, is subject to the provider's enterprise data commitments, and is not used by us to train AI models. AI actions that change your store execute only after you approve them.

6. Who we share data with

We do not sell personal data. We share it only with processors we contract to run the platform:

  • Cloud hosting - Amazon Web Services (data stored in India)
  • Payments and settlements - Razorpay (PCI-DSS Level 1)
  • Logistics - Shiprocket and courier partners, to ship merchant orders
  • Messaging - email/SMS/WhatsApp providers (including Meta's WhatsApp Business Platform) to deliver transactional messages
  • AI infrastructure - Anthropic, for the AI features above
  • Authorities - where required by law, or to protect rights, safety, or the integrity of the platform

Each provider is bound by contract to use the data only to provide their service to us and to protect it. Some providers process data outside India; where they do, we transfer it in accordance with the DPDP Act.

7. Retention

We keep account and store data while your account is active. After cancellation or deletion we retain your store data for [30] days so you can export it, then delete or anonymise it - except records we must keep longer by law (tax, invoicing, and financial records are retained for the statutory period). Backups are purged on their rotation schedule.

8. Security

All traffic runs over TLS; passwords are hashed; merchant secrets are encrypted at rest; access to production data is restricted and logged. No internet service can guarantee absolute security, but if a personal data breach affecting you occurs, we will notify you and the Data Protection Board of India as the DPDP Act requires.

9. Your rights

Under the DPDP Act you may:

  • Access a summary of your personal data and how it has been processed
  • Have inaccurate or incomplete data corrected or updated
  • Request erasure of data we are not required to retain by law
  • Nominate a person to exercise your rights in case of death or incapacity
  • Withdraw consent for optional processing (like marketing) at any time
  • Export your store data at any time from Settings

To exercise any right, email us (Section 12). If you are not satisfied with our response, you may complain to the Data Protection Board of India.

10. Children

The platform is for people 18 and over. We do not knowingly process children's personal data, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.

11. Changes

We may update this policy as our practices or the law change. Material changes are notified in the dashboard or by email, and the date above is always current. Continued use after a change takes effect constitutes acceptance.

12. Contact & grievance officer

Privacy questions and data-principal requests: help@quickmerce.in.

Grievance Officer (IT Act, 2000 / DPDP Act, 2023): [name, designation], help@quickmerce.in, Quickmerce Internet Pvt. Ltd., [registered address]. We acknowledge grievances within 48 hours and resolve them within the statutory period.