Effective Date: 1st June 2026
Introduction
-
Vegacart (“Vegacart”, “Company”, “we”, “us”, or “our”) recognises the importance of protecting personal data and maintaining your trust. This Privacy Policy describes how the Company collects, receives, uses, stores, processes, transfers, discloses, and safeguards personal data in connection with its website, Shopify integrations, mobile application platform, merchant mobile applications, onboarding, communications, support operations, analytics, and related services (collectively, the “Services”).
- Vegacart provides technology solutions that enable Shopify merchants to create, manage, publish, and operate branded mobile commerce applications and related customer engagement features for iOS and Android platforms.
-
For the purposes of this Privacy Policy, “Merchant” means any business, retailer, brand, store owner, agency, reseller, client, or commercial entity using the Services directly or indirectly.
-
This Privacy Policy applies to website visitors, Merchants, authorised users, prospective customers, Merchant representatives, and individuals whose personal data is processed by the Company (collectively referred to as “Data Principals”).
-
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy.
Applicability of Law
-
This Privacy Policy is intended to comply with applicable privacy and data protection laws, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”), together with globally recognised privacy and data protection standards relevant to the Services and the Company’s operations.
- Where personal data relating to individuals located outside India is collected, transferred, stored, or otherwise processed, the Company shall take reasonable steps to ensure such processing is undertaken in accordance with applicable legal requirements and recognised industry practices.
Personal Data We Collect
- The Company may collect personal data directly from you, automatically through your use of the Services, or through integrations, APIs, and third-party platforms authorised by Merchants.
-
Personal data voluntarily provided by you may include your name, email address, phone number, business address, company name, designation, billing information, Shopify store details, onboarding information, developer account details, support requests, communications, and business or professional contact information associated with Merchants, employees, representatives, or authorised users.
-
In connection with your use of the Services, the Company may automatically collect technical and usage-related information including IP address, browser type, operating system, device information, session activity, app interaction data, referral information, analytics information, cookies, crash diagnostics, and similar tracking information.
-
In the course of providing the Services within the Shopify ecosystem, the Company may access, receive, store, synchronise, transmit, or otherwise process Merchant and customer-related data made available through Shopify APIs, integrations, or permissions granted by Merchants.
-
Such data may include customer account information, order information, loyalty or rewards information, wishlist activity, cart information, push notification engagement data, analytics data, and related store information necessary for operation of the Services.
-
Vegacart processes such data solely for the purpose of providing, operating, maintaining, supporting, securing, or improving the Services on behalf of Merchants.
-
Vegacart does not sell Merchant customer data and does not use such data for unrelated advertising purposes, third-party behavioural advertising, profiling unrelated to the Services, or independent commercial exploitation unrelated to the Services.
-
The Company collects and processes only such personal data as is reasonably necessary for the lawful purposes described in this Privacy Policy.
Purpose of Processing
- The Company processes personal data only for specified, lawful, and legitimate business purposes connected with the Services, including operation and improvement of the Services, synchronisation of Merchant store data with mobile applications, onboarding Merchants, providing implementation and support services, managing subscriptions and billing, enabling customer engagement functionality, monitoring platform security and performance, detecting fraud or misuse, complying with legal obligations, enforcing agreements and policies, and developing or improving products, integrations, and operational functionality.
-
Certain features of the Services may use automated systems, analytics technologies, or artificial intelligence tools to provide operational insights, recommendations, analytics, personalisation, or customer engagement functionality related to the Services.
-
The Company does not use Merchant customer data to train artificial intelligence models unrelated to the Services without appropriate legal basis or authorisation.
Legal Basis for Processing
- The Company processes personal data on lawful grounds recognised under applicable law, including consent, performance of contractual obligations, compliance with legal obligations, lawful business purposes and legitimate operational interests permitted under applicable law, fraud prevention, security protection, and protection or enforcement of legal rights.
-
Where processing is based on consent, the Data Principal has the right to withdraw such consent at any time. Withdrawal of consent shall not affect the lawfulness of processing undertaken prior to such withdrawal. Upon withdrawal of consent, certain features or functionalities of the Services dependent on such processing may become unavailable.
Statutory Roles of the Parties
- Vegacart acts as a Data Fiduciary under the DPDP Act, or equivalent controller concept under applicable law, for personal data collected directly from website visitors, Merchants, prospective customers, Merchant representatives, and users in connection with onboarding, subscriptions, communications, support, and related business activities.
-
For personal data processed on behalf of Merchants, including Shopify store data and customer-related data, the relevant Merchant remains the Data Fiduciary, or equivalent controller under applicable law, and Vegacart acts solely as a Data Processor, or equivalent processor or service provider concept under applicable law, processing such data in accordance with the Merchant’s documented instructions, applicable contractual arrangements, and applicable law.
-
Merchants remain responsible for lawful collection and use of customer data, maintaining compliant privacy disclosures, obtaining legally required consents or permissions, and ensuring compliance with applicable privacy, telecom, consumer protection, platform, app store, and marketing laws or policies.
-
All Merchant store data and customer-related data processed through the Services remain under the ownership and control of the relevant Merchant, subject to applicable law and contractual arrangements.
Cookies and Tracking Technologies
- The Company may use cookies, SDKs, analytics tools, pixels, and similar technologies to operate, analyse, secure, improve, personalise, and support the Services.
-
Data Principals may disable or restrict certain tracking technologies through browser or device settings; however, portions of the Services may not function properly as a result
Push Notifications and Communications
- The Services may enable Merchants to send push notifications, transactional alerts, promotional communications, abandoned cart reminders, loyalty notifications, and customer engagement communications through Merchant-branded mobile applications.
-
Merchants remain solely responsible for ensuring that such communications comply with applicable law and for obtaining any permissions or consents required under applicable law.
Disclosure of Personal Data
- Vegacart does not sell personal data.
-
The Company may disclose personal data where reasonably necessary to service providers, cloud providers, hosting providers, infrastructure providers, analytics providers, payment providers, subprocessors, contractors, integration partners, professional advisers, auditors, insurers, financial institutions, regulatory authorities, law enforcement authorities, courts, governmental authorities, corporate affiliates, investors, acquirers, successors, or counterparties involved in financing, restructuring, mergers, acquisitions, or business transfers.
-
Such disclosures shall be subject to reasonable contractual, confidentiality, technical, organisational, or legal safeguards where applicable.
Third-Party Services and Integrations
- The Services may integrate with third-party platforms, APIs, plugins, applications, app stores, payment providers, analytics providers, communication tools, and external services including Shopify and related integrations.
-
The Company does not control and shall not be responsible for the privacy practices, security standards, availability, interoperability, continued functionality, or processing activities of independent third-party services or platforms.
-
Use of third-party services remains subject to their respective terms and privacy policies.
International Data Transfers
- Due to the global nature of the Services, personal data may be transferred to, processed in, or stored in jurisdictions outside the country in which the data was originally collected.
-
By using the Services, you understand that personal data may be processed in jurisdictions where privacy laws may differ from those applicable in your jurisdiction.
-
The Company shall take reasonable steps to implement appropriate safeguards for international data transfers where required under applicable law.
Data Security
- The Company implements reasonable technical, organisational, administrative, and security measures designed to protect personal data against unauthorised access, disclosure, misuse, alteration, loss, or destruction.
-
However, no method of transmission, storage, or electronic processing is completely secure, and the Company does not guarantee absolute security.
Data Retention
- The Company retains personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, performance of contractual obligations, compliance with legal obligations, enforcement of agreements, prevention of fraud or misuse, dispute resolution, security purposes, or legitimate business and operational requirements.
-
The Company shall take reasonable steps to delete, anonymise, or cease retention of personal data once the purpose for which such data was collected is no longer being served, unless retention is required under applicable law.
Aggregated and De-Identified Information
- The Company may generate, use, analyse, disclose, or retain aggregated, anonymised, statistical, or de-identified information derived from use of the Services for analytics, benchmarking, operational improvement, research, security, and product development purposes, provided such information does not reasonably identify any individual, Merchant or business entity.
Children’s Privacy
- The Services are intended for businesses and commercial users and are not directed toward children.
-
Vegacart does not knowingly collect or process personal data of children for its own independent purposes in violation of applicable law.
-
Merchants using the Services may independently collect or process personal data relating to children through their stores or mobile applications. In such cases, the relevant Merchant remains solely responsible for complying with applicable laws relating to children’s data, including obtaining any legally required parental or guardian consents.
Rights of Data Principals
- Subject to applicable law, Data Principals may have the right to obtain information regarding processing of their personal data, request correction or erasure of personal data, withdraw consent, seek grievance redressal, and exercise other rights available under applicable law.
-
Data Principals also have the right to nominate another individual to exercise rights on their behalf in the event of death or incapacity, in accordance with applicable law.
-
Requests relating to personal data may be submitted using the contact details provided below. The Company may require reasonable verification of identity before processing such requests.
Data Breach Response
-
In the event of a personal data breach or security incident affecting personal data processed by the Company, the Company shall take appropriate steps in accordance with applicable law, including investigation, mitigation, remediation, and notifications where legally required.
Changes to this Privacy Policy
- The Company may modify or update this Privacy Policy from time to time to reflect changes in legal, regulatory, operational, or technical requirements.
-
Updated versions shall be made available through the website or Services together with the revised Effective Date. Continued use of the Services following such updates constitutes acknowledgment of the revised Privacy Policy.
Grievance Redressal and Contact Information
- In accordance with applicable law, including the Digital Personal Data Protection Act, 2023, grievances or concerns relating to personal data may be addressed to:
Compliance Team,
Email: hello@vegacart.io -
If a Data Principal is not satisfied with the resolution provided by the Grievance Officer, the Data Principal may have the right to lodge a complaint with the appropriate statutory authority, including the Data Protection Board of India, in accordance with applicable law.
Governing Law and Jurisdiction
- This Privacy Policy shall be governed by and construed in accordance with the laws of India.
- Subject to applicable law, courts located in Surat, Gujarat shall have exclusive jurisdiction in relation to disputes arising out of or relating to this Privacy Policy.