Privacy & Data Protection

Privacy Policy

Effective08 Dec 2024Last Updated08 Dec 2024

This Privacy Policy explains how we collect, use, share, store, and protect personal data across SuprX’s e-commerce, hyperlocal, services, and mobility offerings.

0

Overview

Kartten Internet Pvt. Ltd. (“SuprX,” “we,” “our”) operates the SuprX mobile application and related websites (collectively, the “Platform”). This Privacy Policy (“Policy”) explains how we collect, use, share, store, and protect your personal data when you use the Platform or our services.

This Policy is intended to be consistent with the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, which govern processing of digital personal data related to individuals in India, including where goods or services are offered to them.

Regulatory Alignment
We aim to align our practices with guidance from relevant authorities such as MeitY and other competent regulators in India.
1

Scope

This Policy applies to the processing of personal data of the following categories of individuals:

  • Customers/Users who browse, order, book, or pay on SuprX.
  • Merchants/Service Providers who list products/services on SuprX.
  • Delivery/Rider/Driver Partners who fulfill orders or rides.
  • Visitors to our websites, support channels, and marketing pages.

If you use third-party platforms linked from SuprX, their privacy policies apply to data they collect independently.

2

What We Collect

We collect information in three ways: (a) you provide it, (b) we collect it automatically, and (c) we receive it from partners where permitted by law.

2.1 Customer/User Data
  • Account data: name, phone number, email, password/OTP verification.
  • Profile data (optional): photo, addresses, preferences.
  • Order & service data: items purchased, service bookings, cart, refunds, ratings, support chats.
  • Location data: precise or approximate location for delivery, ride pick-up/drop, fraud prevention, and service availability (subject to your device permissions).
  • Device & usage data: device ID, IP, app version, crash logs, cookie identifiers, click/scroll patterns.
  • Communications: calls/chats/emails with support and (where enabled) masked calls with delivery/rider partners.
2.2 Merchant/Provider Data
  • Business information: entity name, owner details, shop address, GST (if applicable), bank settlement details.
  • Listing data: catalog, pricing, stock, service descriptions, images.
  • Operational data: order acceptance times, cancellation metrics, service quality signals.
2.3 Delivery/Rider/Driver Partner Data
  • Identity & KYC: government ID (as required), license/vehicle documents for ride/logistics.
  • Safety & compliance data: background check status where legally required.
  • Real-time location: while on duty for dispatching, routing, safety and fraud control.
3

E-commerce & Hyperlocal Marketplace-Specific Data

When you purchase goods on SuprX, we may process additional details such as:

  • Delivery instructions, gate/landmark notes, recipient details.
  • Substitution preferences (e.g., out-of-stock alternatives).
  • Returns/refund reasons, photos of damaged items (if you submit them).
4

Services & Mobility-Specific Data

For ride-hailing, on-demand help, or logistics, we may process:

  • Trip details: pick-up/drop, route metadata, timestamps, fare breakdown.
  • Safety events: emergency alerts, incident reports.
5

Payments, UPI, Cards & Wallet

We may support UPI, cards, net-banking, and wallet/credits.

We do not intend to store full card numbers, CVV, or sensitive authentication data on our servers. Card transactions are processed via regulated payment gateways/partners.

Tokenisation
For safer card payments, the ecosystem uses tokenisation, which replaces actual card details with a token instead of sharing real card data with merchants, as guided by the Reserve Bank of India.
Data Localisation
Where SuprX operates or integrates with authorised payment system operators, payment system data storage may be required to be in India under applicable RBI directions.
  • Payment references: transaction IDs, UPI VPA (masked when possible), payment status, timestamps.
  • Billing info: name, address, tax invoice data.
  • Fraud signals: device risk, unusual order/payment patterns.
6

How We Use Your Data

We use personal data for the following purposes:

  • Create and manage accounts.
  • Enable browsing, ordering, booking, and fulfillment.
  • Provide customer support and dispute resolution.
  • Improve product search, recommendations, and local availability.
  • Ensure platform safety, prevent fraud, and enforce policies.
  • Comply with legal and regulatory obligations.
  • Send service communications (order updates, OTPs, receipts).
  • Send marketing messages only where permitted and with opt-out options.
7

Lawful Basis & Consent

We process data for specific, lawful purposes. Where required, we rely on your free, specific, informed, unconditional, and unambiguous consent, and you can withdraw it with comparable ease to giving it.

Withdrawal of certain permissions (like location) may limit some features.

8

How We Share Your Data

Merchants/Service Providers

To fulfill your order/booking (name, phone, address, order details).

Delivery/Rider/Driver Partners

To complete delivery or a trip (name, contact, pickup/drop and order information).

Payment Gateways & Financial Partners

To process payments, refunds, chargebacks, and risk checks.

Service Providers (Processors)

Cloud hosting, analytics, customer support tools, messaging/OTP services, and fraud prevention. We require reasonable confidentiality and security commitments from them.

Legal & Safety Disclosures

When required by law, court orders, or to protect users and the Platform.

Business Transfers

In case of merger, acquisition, or restructuring, with appropriate safeguards.

9

Data Storage & Cross-Border Transfers

We primarily store data in India. Where cross-border processing occurs (e.g., use of global cloud tools), we implement contractual and technical safeguards consistent with applicable law.

10

Data Retention

We retain data only as long as necessary for:

  • Service delivery.
  • Tax/accounting requirements.
  • Fraud prevention and dispute handling.
  • Legal compliance.

After this, we delete or anonymize it unless retention is required by law.

11

Your Rights

Subject to applicable law, you may have the right to:

  • Access your account information.
  • Correct or update your data.
  • Request deletion of your account.
  • Manage marketing preferences.
  • Withdraw consent for optional processing.

We may need to verify your identity before fulfilling certain requests.

12

Children’s Privacy

SuprX is not intended for children unless a parent/guardian has provided consent where required. We may restrict certain features (e.g., payments and ride services) to users 18+.

13

Security

We use reasonable security safeguards including:

  • Encryption in transit where feasible.
  • Access controls and audit logs.
  • Fraud monitoring and anomaly detection.
  • Secure SDLC practices.

No system is 100% secure, but we work to prevent unauthorized access and misuse.

14

Cookies & Tracking (Web)

Our websites may use cookies and similar technologies for:

  • Session management.
  • Analytics.
  • Security.
  • Personalization.

You can control cookies via your browser settings.

15

Grievance & Contact

For privacy-related queries or complaints, you may contact our Grievance Officer / Privacy Contact:

Grievance Officer / Privacy Contact
Name: Shubham Verma
Email: shubhamverma@kartten.com
Address: Robertsganj, Sonbhadra, Uttar Pradesh

Response timelines will be consistent with applicable law.

16

Updates to This Policy

We may update this Policy to reflect changes in law, technology, or our services. We will post the updated version with a revised “Last Updated” date. Where required by law, we may also notify you through the Platform or other channels.

Your data. Your city. Your control.

SuprX is designed to be transparent and responsible with your data. If you have questions, we’re here to help.