YOUR DATA, SECURED
Privacy Policy
This Privacy Policy explains how Rixcart collects, uses, stores, shares, and protects personal information. We are committed to transparency and aligning with global privacy standards, including India’s DPDP and GDPR.
Scope & Applicability
This Policy applies to all visitors, customers, and users of Rixcart worldwide. It covers personal data collected online and any offline data later digitized.
Key Definitions
- Personal Data: Identifies you (name, email, etc.).
- Data Controller: Rixcart.
- Processing: Collection, storage, use, etc.
Information We Collect
Directly Provided
- Account Details (Name, Email)
- Order Info (Product, Address)
- Support Content
- Marketing Preferences
Payment & Billing
Tokenized card IDs via PCI-compliant gateways.
We do NOT store raw card numbers.
Automated Data
- IP Address & Device Info
- Usage Data & Session Logs
- Cookies & Pixels
Third-Party Sources
- Social Logins (Google/FB)
- Delivery Confirmations
- Fraud Prevention Services
Why We Collect Data
Perform contract: process orders & shipping.
Comply with legal obligations (Tax/Fraud).
Improve services & fix bugs.
Provide targeted content (with consent).
Cookies & Tracking
Manage via Cookie Preferences.
Data Sharing
We do NOT sell your personal information.
Your Rights
Storage & Transfer
Data transfer outside India is protected by standard contractual clauses.
Retention:
- Order records: 6-7 years (Tax)
- Marketing: Until withdrawn
- Support: 12-36 months
Security
Encryption (TLS), Access Controls, and Regular Audits.
Children's Data
Services for adults only. We delete data of minors if found.
Automated Decisions
Used for fraud & recommendations. Right to human review available.
Breach Response
Incident response plan in place. Notification as per law.
Contact & Grievance Officer
For any privacy concerns or to exercise your rights.
Common Questions
Click "unsubscribe" in emails or update account preferences.
Yes, email us. We verify and delete subject to legal retention.
Only shipping partners and internal fulfillment teams.
No, handled entirely by PCI-DSS secure gateways.
* We maintain records of processing activities to demonstrate compliance with Indian DPDP, GDPR, and other applicable laws.
