Privacy Policy
Effective date: 3 October 2026 · Questions? support@storenest.in
Your privacy matters to us. This Privacy Policy explains what personal data StoreNest collects, why we collect it, how we protect it, and the choices you have. It is written to align with the Information Technology Act, 2000, the rules made under it, and the Digital Personal Data Protection Act, 2023 (as applicable).
1. Who we are and our role
StoreNest provides software that lets merchants run their own online stores. We act in two roles:
- As a data fiduciary (controller) for the information of merchants and their staff who use StoreNest: account, billing and platform-usage data.
- As a data processor for the shopper data (customers, addresses, orders) that a merchant collects through their store. The merchant decides why and how that data is used; we process it on their instructions to provide the service.
2. Information we collect
2.1 From merchants
- Identity and contact details: name, business name, email address, phone number.
- Business and tax details: GSTIN, registered address, state.
- Subscription and invoice records. We do not store card numbers; payments are handled by payment gateways.
- Gateway credentials you add so you can accept payments. These are encrypted at rest and are never shown back in full or written to logs.
2.2 From shoppers (processed for the merchant)
- Name, email, phone number, delivery and billing addresses.
- Order, payment-status, shipment and return history.
- Optional account details such as a password (stored only as a salted hash).
2.3 Technical information
IP address, browser type, device information, pages viewed, and security events such as sign-in attempts. We use a small number of cookies that are necessary to keep you signed in, hold your cart and protect against forged requests.
3. How we use information
- To create and operate stores, process orders and deliver the features of your plan.
- To bill subscriptions and issue GST-compliant invoices.
- To send service messages such as order confirmations, receipts and important account notices.
- To secure the platform, detect abuse and fraud, and enforce our Terms of Service.
- To meet legal, accounting and tax obligations.
- To improve reliability and performance, using aggregated or de-identified data where possible.
We do not sell personal data. We do not use shopper data for our own marketing.
4. Tenant isolation and security
Each merchant's data is logically separated from every other merchant's, and is accessible only to that merchant and the staff they authorise. We use encryption in transit, encryption of sensitive credentials at rest, hashed passwords, role-based access control, request forgery protection, rate limiting on sign-in, and audit logs of important actions. No system is perfectly secure; if we become aware of a personal data breach affecting you we will notify you and the relevant authority as required by law.
5. Sharing and disclosure
We share personal data only as needed to run the service:
- With the merchant whose store you purchased from.
- With service providers such as payment gateways, shipping and logistics partners, email and SMS providers, and hosting and infrastructure providers, who may process data only for these purposes and under appropriate obligations.
- When required by law, court order or a lawful request from a government authority, or to protect rights, safety and the integrity of the platform.
- In a business transfer, such as a merger or acquisition, subject to this policy continuing to apply.
6. Retention
We keep data for as long as your account is active and as needed to provide the service. Invoices, tax and transaction records are kept for the period required by applicable law (for example, GST and company law). When a store is closed, data is deleted or anonymised after the applicable retention period, unless the law requires us to keep it longer.
7. Your rights and choices
Subject to applicable law, you may ask to access, correct, update or erase your personal data, withdraw consent where processing relies on consent, nominate another person to exercise your rights in the event of death or incapacity, and raise a grievance. Shoppers should send requests to the merchant they bought from; we will support the merchant in fulfilling them. Merchants and others can write to support@storenest.in. We will respond within a reasonable time and in line with the law.
8. Children
StoreNest is intended for businesses and is not directed at children. A store that sells to or collects data from minors is responsible for obtaining any verifiable parental consent the law requires.
9. International processing
Data is primarily stored and processed in India. If a service provider processes data elsewhere, we will do so only as permitted by applicable law.
10. Changes to this policy
We may update this policy from time to time. We will post the new version here with a new effective date and, for material changes, notify merchants by email or within the admin.
11. Grievance and contact
For privacy questions, requests or complaints, contact our grievance contact at support@storenest.in with the subject line “Privacy”.