Legal

Privacy Policy

How Khodi Mart collects, uses, stores, and protects seller, supplier, marketplace, and visitor data.

Last updated: July 2026

1. Introduction

Khodi Mart ("we", "our", "us") operates a multi-channel B2B product discovery, order, inventory, warehouse, and marketplace operations platform from Surat, Gujarat, India. This Privacy Policy explains how we handle personal and business information when you use our public website, Docs, Help Center, seller dashboard, supplier dashboard, warehouse tools, MAYA AI assistant, ShipSmart, SPIE, Global OPS, Meesho operations features, Trust Center, and related APIs.

By creating an account or using our services, you agree to this Policy. If you do not agree, please do not use the platform. This Policy is designed for Indian law (including the Digital Personal Data Protection Act, 2023) and enterprise / marketplace partner due diligence.

2. Information we collect

We collect only what is needed to run B2B commerce and platform features:

  • Account & identity: name, email, phone, password (hashed), role (seller, supplier, warehouse, admin).
  • Business profile: trade name, GSTIN where provided, city, address, KYC / onboarding documents.
  • Usage & technical: IP address, device/browser, session identifiers, approximate location from IP, diagnostic and security logs.
  • Support: Contact Us form submissions, emails, and ticket content.
  • Billing: subscription plan, invoices, payment references (card data is handled by payment processors — we do not store full card numbers).

3. Marketplace data we access

When you connect Amazon, Flipkart, Meesho, or similar marketplaces via official OAuth / partner APIs, we access only the scopes you authorise. Typical categories:

  • Orders, shipments, cancellations, and returns metadata required for ops dashboards.
  • Inventory and listing fields needed for sync and health scoring.
  • Settlement / fee summaries where the partner API exposes them for P&L tools.
  • OAuth access and refresh tokens — encrypted at rest; never shown in the browser; never stored as marketplace passwords.

Khodi Mart never asks for your Amazon, Flipkart, or Meesho seller account passwords. Disconnecting an integration stops sync and removes stored credential material.

4. Customer (end-buyer) data

Marketplace end-customer personal data (names, addresses, phone numbers on retail orders) may appear in API payloads you sync. We process that data solely as a processor / service provider to operate features you enable (order ops, returns, shipping helpers). We do not sell end-customer data, use it for unrelated marketing, or expose it to other sellers.

You remain responsible for complying with marketplace policies and applicable privacy law for your retail customers. Prefer minimum necessary fields in exports and MAYA prompts.

5. Business data

  • Catalogue & sourcing: product views, saved items, cart/orders, MOQ, wholesale pricing, pickup preferences.
  • Supplier catalogue and fulfilment records (supplier identity is hidden from sellers in product discovery views).
  • Warehouse inward, QC, pack, and pickup verification events.
  • Operations analytics: Meesho / multi-channel P&L style metrics, ads/return signals, shipping history when you use Meesho Ops, Global OPS, ShipSmart, or SPIE.
  • MAYA AI context: chat messages, feedback, seller memory snippets, and tool-call logs scoped to your account.

6. How we use data

  • Provide product discovery, margin intelligence, city-wise sourcing, and structured B2B ordering.
  • Protect supplier anonymity — sellers see anonymised catalogue views.
  • Run warehouse and pickup workflows.
  • Power marketplace integrations and operational tools you connect.
  • Operate MAYA AI with seller-scoped context and validated tools (no raw SQL from the model).
  • Process subscriptions, entitlements, and invoices.
  • Send transactional updates (orders, pickups, security alerts) and, where permitted, product announcements.
  • Improve search relevance, Docs, safety, fraud prevention, and platform reliability.
  • Meet legal, tax, dispute, and audit obligations.

7. AI data usage (MAYA)

MAYA is a seller business assistant. Prompts may be sent to third-party LLM providers (e.g. via OpenRouter) to generate answers. We scope context to your seller account, apply tool allowlists, and store structured responses and feedback for quality review. We do not use LLM output to invent or disclose supplier identities. Do not paste unrelated personal data of third parties into MAYA chats. AI outputs are advisory — verify critical finance, compliance, and listing decisions yourself.

  • Training: we do not sell your chat data to train public foundation models.
  • Feedback (thumbs up/down) may be reviewed by our team to improve prompts and knowledge — not for uncontrolled self-training.
  • You may request deletion of MAYA conversation history subject to retention and security logs.

8. Cookies

We use essential session cookies for authentication and OAuth state, preference cookies, optional analytics cookies, and (on public marketing pages) Google AdSense advertising cookies. See our Cookie Policy for details and controls.

9. Third-party services

We do not sell personal data. We share limited information only when required to operate the service:

  • Cloud hosting, database, email, and infrastructure vendors under confidentiality and data-processing controls.
  • Payment processors for authorised payments and refunds.
  • Marketplace APIs (Amazon, Flipkart, Meesho, shipping partners) solely for integrations you connect and actions you trigger.
  • LLM / AI providers for MAYA responses you request.
  • Legal or regulatory authorities when required by Indian law, court order, or to protect platform integrity.

10. Data storage

  • Primary application and database hosting in secure cloud environments with restricted access.
  • Sensitive integration credentials encrypted at rest (AES-256-GCM).
  • Passwords hashed with modern one-way algorithms — never stored in plaintext.
  • HTTPS / TLS for data in transit.

11. Data retention

We retain account, order, billing, and compliance records for as long as your account is active and as needed for legal, tax, dispute, and audit obligations. Chat logs and routine diagnostics may be retained for a shorter operational window unless linked to a support, security, or safety case.

12. Data deletion

You may request account closure and deletion of personal data by emailing support@khodimart.com from your registered address. We will verify identity and delete or anonymise data that is not required for legal retention, fraud prevention, or ongoing disputes. Marketplace disconnect removes encrypted tokens promptly; historical order sync rows may be retained in anonymised or aggregated form where required for audit.

13. User rights

Subject to applicable Indian law (including the DPDP Act, 2023 and rules as notified), you may request access, correction, or deletion of personal data, or withdraw consent where processing is consent-based. Contact us at the email below. We may verify identity and refuse requests that conflict with legal retention, fraud prevention, or another user's rights.

14. Security measures

We apply HTTPS everywhere in production, JWT session authentication, role-based access control, seller-scoped queries, encrypted marketplace tokens, audit logs for sensitive actions, rate limiting, and operational monitoring. See our Security Policy and Security Center for details. No method of transmission over the internet is 100% secure — keep credentials confidential and log out on shared devices.

15. International transfers

Primary operations are in India. Some subprocessors (cloud, email, LLM providers) may process data in other jurisdictions. Where transfers occur, we use appropriate contractual and technical safeguards consistent with applicable law and our vendor reviews.

16. Children's privacy

Khodi Mart is a B2B platform for businesses. It is not directed at children under 18. We do not knowingly collect personal data from minors.

17. Policy updates

We may update this Policy as features evolve (new marketplaces, AI tools, or fulfilment flows). The “Last updated” date at the top will change. Material changes may also be notified in-dashboard or by email.

18. Contact information

Privacy questions: support@khodimart.com. Security reports: security@khodi.in. Office: Surat, Gujarat, India. Phone: +91 98765 43210. Or use the Contact Us page.

Also see Trust Center, Privacy, Terms, Security, Compliance, Cookies, DPA, Disclosure, and Help.