basecartDPDP Act 2023 Compliant
Return to Basecart
Data Protection & Privacy Rights

Basecart Platform Privacy Policy

Effective Date: August 24, 2026 • Compliant with Digital Personal Data Protection Act, 2023 (DPDP Act, India) & IT Rules

Basecart Inc. ("Basecart", "We", "Us", or "Our") is committed to protecting the privacy and security of Personal Data collected from Merchant owners and storefront end-customers. This Privacy Policy details our data collection, processing, encryption, and Data Principal rights under the Digital Personal Data Protection Act, 2023 (DPDP Act, India) and applicable global data privacy regulations.


1. Data Fiduciary & Data Processor Roles

Under the DPDP Act 2023:

  • Basecart as Data Fiduciary: For Merchant Account registration details (Merchant Name, GSTIN, Email, Phone, Subscription History), Basecart determines the purpose of processing and acts as Data Fiduciary.
  • Basecart as Data Processor: For Customer Order Data (end-customer delivery names, addresses, shopping carts) collected on Merchant storefronts (`subdomain.basecart.app`), the Merchant acts as Data Fiduciary and Basecart acts strictly as Data Processor executing per-tenant Durable Object storage operations.

2. Personal Data We Collect & Purpose

We collect and process only the minimal Personal Data necessary to operate your storefront and merchant services:

  • Merchant Account Data: Full Legal Name, Email Address, Business Address, Phone Number, GSTIN/PAN for legal invoicing.
  • Payment Gateway Credentials: Merchant Razorpay Key ID & Key Secret, which are encrypted at rest using AES-256-GCM Web Crypto helpers before database persistence.
  • Storefront Checkout Data: End-customer Name, Delivery Address, Phone Number (for WhatsApp dispatch notifications & Shiprocket AWBs), and Order Line Items.
  • Technical Session Logs: Masked IP Address, browser type, and request tracing IDs (`X-Request-ID`).

3. Data Protection Rights of Data Principals

Under Section 11–14 of the DPDP Act 2023, Data Principals (Merchants and End-Customers) possess the following statutory rights:

  • Right to Access Summary: Request a summary of Personal Data being processed by Basecart.
  • Right to Correction & Complete Update: Correct, update, or complete inaccurate Personal Data.
  • Right to Erasure ("Right to be Forgotten"): Request full deletion of Personal Data and tenant Durable Object storage unless retention is mandated by tax or legal statutes (e.g. GST invoice retention rules).
  • Right to Withdraw Consent: Revoke consent for optional communications or marketing alerts at any time.

4. Authorized Sub-Processors & Data Transfer

Basecart does not sell, rent, or trade Personal Data to data brokers or third-party ad networks. Data is shared exclusively with audited infrastructure sub-processors:

  • Cloudflare Inc. (Global Edge Network, Workers Compute, D1 Central Registry & Per-Tenant Durable Objects).
  • Razorpay Software Pvt. Ltd. (Encrypted Payment Gateway Verification & Direct Settlement).
  • Shiprocket / Delhivery (Merchant-initiated Logistics & Doorstep AWB Dispatch).
  • Resend API (Transactional Email Verification & Order Confirmation Receipts).

Data Protection Officer (DPO) & Grievance Mechanism

Pursuant to Section 10 of DPDP Act 2023 & Section 79 of Information Technology Act 2000:

Data Protection Officer: Chief Data Privacy Desk
Basecart SaaS Platform • Kochi, Kerala, India
Official DPO Email: [email protected]
Response SLA for Data Requests: Within 48 hours • Statutory Resolution: 30 days