๐Ÿ”Privacy Policy

Privacy Policy

We believe privacy is a right, not a feature. Here's exactly what data Krato collects, why we need it, and how you stay in control.

Effective: April 25, 2026GDPR ยท DPDP Act 2023Terms of Service โ†’Refund Policy โ†’
๐Ÿšซ
Never sold
Your data to third parties
๐Ÿ”
AES-256
Encryption at rest
๐Ÿ‡ฎ๐Ÿ‡ณ
Azure India
Data stored locally
๐Ÿ—‘๏ธ
30-day
Deletion on account close
โœ‰๏ธ
Delete request?
support@mahanx.in
๐Ÿ“ฅ
Section 01

Information We Collect

๐Ÿ‘คAccount Information
Name, email address, and password (hashed โ€” never stored in plain text).
๐ŸชStore Information
Your Shopify store URL, product catalog, collections, and inventory data.
๐Ÿ“ŠUsage Data
Pages visited, features used, conversation logs, and analytics from Krato sessions.
๐Ÿ’ณPayment Information
Billing details processed by Razorpay. Raw card numbers are never stored on our servers.
๐Ÿ’ฌConversation Data
Messages between your store visitors and Krato, plus purchase intent signals.
๐ŸŒTechnical Data
IP address, browser type, device information, and session identifiers.
โš™๏ธ
Section 02

How We Use Your Information

๐Ÿค–Provide, operate, and improve Krato and the MahanX platform
๐ŸŽฏPersonalise the AI experience for your store and customers
๐Ÿ’ฐProcess transactions and send related GST tax invoices
๐Ÿ””Send technical notices, security alerts, and support messages
๐Ÿ“ˆGenerate analytics and insight reports for your dashboard
๐Ÿ”Monitor and analyse trends to improve our services
๐Ÿ›ก๏ธDetect, investigate, and prevent fraudulent transactions and illegal activities
โš–๏ธComply with our legal obligations under applicable law
๐Ÿ”’
We do not use your data for advertisingKrato data is used exclusively to operate the service and improve AI performance for your specific store. We never serve ads or share data for advertising purposes.
๐Ÿค
Section 03

Data Sharing & Disclosure

โœ…
We do not sell your dataWe never sell, trade, or rent your personal information to third parties for commercial purposes.
โ˜๏ธ
Service Providers
Cloud hosting (Azure), payment processing (Razorpay), AI (OpenAI), vector search (Pinecone). All bound by confidentiality obligations.
๐Ÿ›๏ธ
Shopify Integration
Data shared with your Shopify store is governed by your Shopify merchant agreement. We access only what is necessary to operate Krato.
โš–๏ธ
Legal Requirements
We may disclose information if required by law, court order, or to protect our rights and prevent fraud.
๐Ÿข
Business Transfers
In the event of a merger or acquisition, your data may be transferred with prior notice and continued privacy protections.
๐Ÿ”
Section 04

Data Storage & Security

Your data is stored on secure servers (Microsoft Azure, India region). We implement industry-standard security measures:

๐Ÿ”‘
TLS/SSL
All data encrypted in transit
๐Ÿ›ก๏ธ
AES-256 Fernet
Sensitive data encrypted at rest
๐Ÿ”
Security Audits
Regular vulnerability assessments
๐Ÿ‘ค
RBAC
Role-based internal access controls
โฑ๏ธ
Rate Limiting
Protection on all API endpoints
๐Ÿงน
Input Sanitization
SQL injection & XSS prevention
โ„น๏ธ
While we take reasonable precautions, no method of internet transmission is 100% secure. We will notify you of any breach that affects your personal data within 72 hours as required by law.
โณ
Section 05

Data Retention

We retain your account information while your account is active. If you close your account, your personal data is removed within 30 days, except where:

โ€บWe are required to retain it by applicable law (e.g., GST records for 7 years)
โ€บIt is necessary to resolve active disputes or enforce agreements
โ€บConversation analytics have been anonymised and aggregated (may be retained indefinitely)
๐Ÿ“ง
Request deletion anytimeEmail support@mahanx.in to request immediate deletion of your personal data. We respond within 30 days.
๐Ÿช
Section 06

Cookies & Tracking

We use cookies and similar technologies on our dashboard platform:

Essential Cookies
Required for authentication and platform function. These cannot be disabled as the platform depends on them.
Analytics Cookies
Help us understand how our dashboard is used so we can improve the product experience.
Preference Cookies
Remember your settings such as dark/light mode and notification preferences.
โœ…
No cross-site tracking in the widgetThe Krato chat widget deployed on your storefront uses session cookies only. Your customers are not tracked across third-party websites.
โš–๏ธ
Section 07

Your Rights

Under GDPR and India's DPDP Act 2023, you have the following rights regarding your personal data:

๐Ÿ‘๏ธAccess
Request a copy of the personal data we hold about you
โœ๏ธCorrection
Request correction of inaccurate or incomplete data
๐Ÿ—‘๏ธDeletion
Request deletion of your personal data (subject to legal obligations)
๐Ÿ“ฆPortability
Request a machine-readable export of your data (ZIP format)
๐ŸšซObjection
Object to how we use your data for marketing purposes
โธ๏ธRestriction
Request that we restrict processing of your data
๐Ÿ“ง
Exercising your rightsEmail support@mahanx.in to exercise any right. We respond within 30 days. We comply with GDPR and the DPDP Act 2023.
๐Ÿ‘ถ
Section 08

Children's Privacy

Krato is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors.

๐Ÿšจ
If we learn a minor has provided dataWe will delete it promptly upon discovery. If you believe your child's data has been collected, contact us immediately at support@mahanx.in.
๐Ÿ’ฌ
Privacy questions?
Email support@mahanx.in ยท We respond within 24h on business days.
Terms of ServiceRefund Policy