This policy explains how we collect, use, share, store and delete personal data when you use the Shopify app "ReguCart: India Compliance", the website regucart.com, our emails and our support (the Service). It is written for merchants and their staff, for people who contact us, and for people whose data reaches us through a merchant's store.
1. Who we are and how to contact us
1.1 The Service is provided by Shivam Bector, trading as Debug Ninja, a sole proprietorship based in Panchkula, Haryana, India (Debug Ninja, we, us). "ReguCart" is our brand.
1.2 General contact: support@regucart.com.
1.3 Grievance Officer and contact person for personal data questions:
- Name: Shivam Bector
- Designation: Founder
- Email: support@regucart.com (subject line "Privacy" or "Grievance")
- Location: Panchkula, Haryana, India
- Telephone: +91 98888 17142
This person acts as our Grievance Officer under rule 5 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 (SPDI Rules), and as the person who answers questions about our processing of personal data under the Digital Personal Data Protection Act 2023 (DPDP Act) and the Digital Personal Data Protection Rules 2025 (DPDP Rules). We are not a Significant Data Fiduciary and have not appointed a Data Protection Officer.
2. Our two roles
2.1 We decide (Data Fiduciary). For data about merchants, their staff, website visitors and people who contact us, we decide why and how the data is used. We are the Data Fiduciary under the DPDP Act and the body corporate collecting the information under the SPDI Rules. This policy covers that data.
2.2 We act for the merchant (Data Processor). Some personal data reaches us because a merchant uses the Service to handle it. Examples:
- complaints that customers submit through a merchant's grievance form, and replies to them;
- details that a marketplace's vendors submit through the seller details form;
- personal data that appears in a merchant's store content or in documents the merchant uploads (for example a reviewer's name shown on a product page, or a buyer's name on a sample invoice);
- the name and designation of the person who signs a merchant's self-audit certificate page.
For this data, the merchant is the Data Fiduciary and we are its Data Processor. We process it only on the merchant's instructions, under our Data Processing Addendum (regucart.com/dpa). If you submitted a complaint or details to a store, please read that store's privacy notice and contact the store first. Section 12 explains how we help.
3. Which laws apply, and when
3.1 Until 13 May 2027, section 43A of the Information Technology Act 2000 and the SPDI Rules apply to our handling of personal data.
3.2 From 13 May 2027, the main duties of the DPDP Act and DPDP Rules take effect, and section 43A and the SPDI Rules stop applying. This policy is written to meet both regimes. Where they differ, we explain which applies.
4. What we collect
4.1 From Shopify, when a merchant installs the app
Through Shopify's Admin API, with the permissions the merchant approves on install, we read:
- shop details: store name, domain, contact email, address and phone, currency, timezone and plan;
- products, variants, prices, inventory quantities, country of origin, collections and selling plans;
- product and other metafields and metaobjects that the Service needs;
- online store pages, shop policies (for example refund and privacy policies), navigation menus and theme settings files;
- discounts, markets and privacy settings.
This is mostly business data. It may include personal data where a merchant has put it there (for example a proprietor's name and address in a policy).
We do not request access to Shopify order or customer records. We do not ask for the read_orders, read_customers or read_users permissions.
We also receive the merchant's plan status (Free or Pro) from Shopify. Shopify handles payment. We never see card or bank details.
4.2 From the storefront, through our crawler
Our crawler, ReguCartBot, visits the merchant's public storefront like a shopper (see regucart.com/bot). It records page addresses, page code, visible text, screenshots, cookies and scripts loaded, and pop-ups shown. It never submits forms or orders and never enters personal data. Screenshots and page text may contain personal data that the store displays publicly, such as reviewer names.
4.3 From merchants and their staff
- Terms acceptance: name and work email of the person who accepts our Terms, Shopify staff user ID where available, IP address, browser user agent, time, the Terms version and a hash of the text shown.
- Store profile: legal name, entity type, GSTIN, PAN (stored masked except the last 4 characters), Udyam and CIN numbers, addresses, customer care contacts, and the names and contacts of the grievance officer, data protection contact and similar officers.
- Declarations and self-audits: answers, explanations and signatory details (name, designation, date).
- Uploads: licences, certificates and other documents for the evidence vault, and sample invoices for the invoice checker.
- Settings: alert recipients' email addresses and preferences.
- Feedback: false-positive reports and comments.
4.4 Through features merchants run on their stores (as Data Processor)
- Grievance desk: complainant's name, email, phone (optional), order number (optional), complaint category and description, photos (optional, up to 3), ticket history and replies.
- Seller details form: a vendor's business name, addresses, contacts, GSTIN, PAN (masked), Udyam number, grievance officer details and similar information.
4.5 When you contact us or visit our website
- Emails you send to support and our replies.
- Basic technical data that our hosting providers log when you visit regucart.com or app.regucart.com (for example IP address and browser type). We use Cloudflare Web Analytics to count visits to regucart.com. It does not use cookies, does not track you across other websites and does not build a profile of you. We do not use advertising cookies.
4.6 Usage and service records
- Records of scans, Findings, Fixes and their before and after values, AI usage and costs, emails sent, and internal events (for example "scan completed"). We do not use third-party analytics in the app.
- Delivery records from our email provider (recipient address, time, delivery status).
- Application and error logs. Our logs are designed not to contain access tokens or personal data.
5. What we do not collect
5.1 We do not collect Shopify order or customer records, payment card or bank details, passwords, or biometric data.
5.2 We do not ask for sensitive personal data. A complaint, photo or uploaded document may contain it (for example health information in a complaint about a medicine). We treat such content with the security described in section 10 and use it only to provide the feature.
6. Why we use personal data, and on what basis
| Purpose | Data | Basis (SPDI Rules, until 13 May 2027) | Basis (DPDP Act, from 13 May 2027) |
|---|---|---|---|
| Provide the Service: run Checks, show Findings, prepare and apply Fixes, generate drafts and reports | 4.1 to 4.4 | Necessary to perform our contract; information provided voluntarily for that purpose | Legitimate use: data voluntarily provided for a specified purpose (s.7(a)); otherwise consent |
| Record acceptance of our Terms, and defend legal claims | 4.3 (Terms acceptance) | As above | As above; and to comply with law |
| Send service emails (scan complete, alerts, digests, grievance notices) | Emails in 4.1, 4.3, 4.4 | As above | As above |
| Handle complaints and vendor details for merchants | 4.4 | Merchant's instructions under the DPA | Processing on the merchant's behalf (s.8(2)) |
| Support and grievances | 4.5 | As above | As above |
| Security, fraud prevention, debugging and keeping logs | 4.5, 4.6 | Reasonable security practices (s.43A) | Security safeguards and log duties (s.8(5); DPDP Rules) |
| Improve our Checks (for example, from false-positive reports) | 4.3 (feedback), 4.6 | Consent given by sending the report | Legitimate use (s.7(a)); otherwise consent |
| Meet legal obligations and respond to lawful requests | Any | Required by law | Required by law (s.7) |
6.1 Where we rely on consent, you may withdraw it at any time by writing to support@regucart.com. Withdrawal does not affect processing already done. If you withdraw consent needed to provide the Service, you may need to stop using it.
6.2 We do not sell personal data. We do not use personal data for advertising. We do not use your data to train AI models.
7. AI processing
7.1 The Service uses AI models provided by Anthropic (Claude API) to classify products, review store text and images, check invoices, read uploaded licences, draft text and write summaries.
7.2 We send Anthropic only the content needed for each task (for example a product description, a page, a screenshot crop or an uploaded invoice). Anthropic processes it under its commercial terms to return a result to us. Under those terms, Anthropic does not use this data to train its models, and it deletes API inputs and outputs automatically within 30 days, except where content is flagged for a breach of its usage policy (kept for up to 2 years) or the law requires it to keep data longer.
7.3 AI results are stored with the scan so we do not send the same content twice. They are deleted with the rest of your Store's data.
7.4 AI results are never applied to a store automatically. Merchants review every draft and Fix before applying it.
8. Who we share personal data with
8.1 Subprocessors. We use the service providers listed at regucart.com/subprocessors to host, store, email and process data for us. In summary: Railway (app hosting, database), Cloudflare (website hosting, DNS, cookieless website analytics and file storage), Anthropic (AI processing), Amazon Web Services (email delivery through Amazon SES), Porkbun (domain registration and email forwarding), Google (the mailbox that receives support email) and, when we start using it, Sentry (error monitoring). Each acts only on our instructions under its contract terms.
8.2 Shopify. Shopify provides the platform the app runs on and bills merchants. Shopify receives data under its own terms and privacy policy.
8.3 The merchant. Complaints and vendor details submitted through a store's features are shared with that store's merchant, who decides how they are used.
8.4 Legal requirements. We may disclose personal data where the law requires it, to a government agency authorised by law, or to protect our rights, our users or the public, as permitted by law.
8.5 Business transfer. If the Service is transferred to a company or other entity (for example, one formed by our owner), personal data will transfer with it, under this policy. We will tell merchants before this happens.
9. Where data is stored, and transfers outside India
9.1 Our main servers and database are hosted by Railway in its Southeast Asia (Singapore) region. Files such as screenshots, reports and uploads are stored in Cloudflare R2 in its Asia-Pacific location. Emails are sent through Amazon SES in the Mumbai (ap-south-1) region. AI processing by Anthropic takes place in the United States and other countries where Anthropic and its providers operate.
9.2 This means personal data is transferred outside India. Until 13 May 2027 we make these transfers because they are necessary to perform our contract with merchants, and our providers are bound by contract terms that protect the data. From 13 May 2027 we will transfer data only to countries the Central Government has not restricted under section 16 of the DPDP Act.
10. How we protect personal data
10.1 We use reasonable security practices, including:
- encryption in transit (TLS) for all connections;
- encryption at rest with AES-256-GCM for Shopify access tokens and for the name, email, phone and complaint text of grievance records;
- keyed hashing (HMAC-SHA256) of complainant emails, so we can find records for deletion requests without reading the data;
- the minimum Shopify permissions needed, and no access to Shopify order or customer records;
- signature (HMAC) verification of all webhooks and storefront form requests from Shopify;
- access to production systems and provider accounts limited to our owner;
- logs designed to exclude tokens and personal data;
- daily database backups.
10.2 No system is perfectly secure. If you believe your data has been exposed, contact us at once (section 1.3).
11. Personal data breaches
11.1 If a personal data breach affects data for which we are the Data Fiduciary, we will:
- tell affected people without delay, describing what happened, the likely consequences, what we are doing and what they can do, and how to contact us;
- from 13 May 2027, inform the Data Protection Board of India without delay and send a detailed report within 72 hours, as the DPDP Rules require;
- report the incident to CERT-In where the law requires it.
11.2 If a breach affects data we process for a merchant, we notify the merchant as set out in the DPA, so the merchant can meet its own duties.
12. How long we keep data
| Data | How long |
|---|---|
| Storefront crawl evidence (screenshots, page code) | 90 days on Pro; on Free, until the next scan replaces it |
| Readiness and self-audit reports | 2 years from creation |
| Grievance desk records | 3 years after the complaint is closed (a merchant may ask us for a shorter period), then deleted |
| Scan results, Findings, change history (for undo), declarations, store profile, price history | While the app is installed |
| Terms acceptance records | While the app is installed |
| Support emails | 3 years from the last message in the conversation |
| Security and access logs | At least 1 year from 13 May 2027, as the DPDP Rules require; until then, as our providers retain them |
| Database backups | Overwritten within 14 days |
On uninstall: Shopify sends us a "shop/redact" request 48 hours after a merchant uninstalls the app. When we receive it, we delete all data we hold about that store, including every item in the table above that relates to the store, and its stored files. A reinstall within those 48 hours keeps the data.
At any time: a merchant can delete all data we hold about its store from Settings ("Delete my data"), and can export Findings and declarations from Settings.
Customer requests through Shopify: when Shopify sends us a "customers/redact" request for a person, we delete grievance records linked to that person's email. When Shopify sends a "customers/data_request", we send the merchant the grievance records linked to that email so the merchant can respond.
13. Your rights
13.1 If we are the Data Fiduciary for your data, you can ask us to:
- give you a summary of the personal data we hold about you and how we use it, and the identities of those we have shared it with;
- correct, complete or update it;
- erase it, where we no longer need it for the purpose or the law does not require us to keep it;
- withdraw consent you have given;
- nominate another person to exercise your rights if you die or become unable to (from 13 May 2027).
13.2 Write to support@regucart.com (subject line "Privacy"). We may need to confirm your identity. We will acknowledge your request within 48 hours and respond within one month. That is within the one-month period under the SPDI Rules and the 90-day maximum under the DPDP Rules.
13.3 If you are not satisfied, you may escalate to our Grievance Officer (section 1.3). From 13 May 2027, after using our grievance process, you may complain to the Data Protection Board of India.
13.4 If you submitted a complaint or details through a store, the store is responsible for your request. Contact the store. If you contact us, we will pass your request to the store and help it respond, as the DPA requires.
14. Children
The Service is for businesses. It is not directed at anyone under 18, and we do not knowingly collect personal data from children as our own users. Merchants are responsible for children's data that reaches them through their store features.
15. Cookies and similar technology
15.1 The app runs inside the Shopify admin and authenticates with Shopify session tokens. It does not set advertising or tracking cookies. Shopify may set its own cookies under its policy.
15.2 The crawler accepts cookies that a storefront sets during its visit, within its own browser session, to test what shoppers see. It discards them after the visit.
15.3 regucart.com does not set cookies. Visits are counted with Cloudflare Web Analytics, which works without cookies. The tour video on the home page is hosted on YouTube. Nothing is loaded from YouTube until you press play; it then loads from youtube-nocookie.com, and Google (YouTube) receives your IP address and browser details and may store data on your device under Google's own privacy policy.
16. Changes to this policy
We may update this policy. We will post the new version at regucart.com/privacy with its version date. For material changes we will tell merchants in the app or by email before they take effect.
17. Contact
Questions, requests and complaints: support@regucart.com, or the Grievance Officer in section 1.3.