Privacy Policy
This Privacy Policy explains how APKHOST PRIVATE LIMITED ("we", "us", or "our") collects, uses, stores, discloses, and protects personal data when you use FrontMart, our hosted online store and e-commerce software platform.
By using FrontMart, you acknowledge that personal data may be processed as described in this Privacy Policy and as otherwise permitted by applicable law.
1. Our Different Privacy Roles
Our role may differ depending on how FrontMart is being used.
- Merchant account information: when you create and use a Merchant account, we generally determine the purposes for which account, billing, technical, security, and support information is processed.
- Merchant-customer information: when a customer purchases from or interacts with a Store operated by a Merchant, the Merchant generally determines the purposes for which customer information is collected and used. We process such information to provide, secure, maintain, and support the FrontMart platform, subject to applicable law and the Merchant's instructions or configuration.
The exact legal role of each party may depend on the nature of the data, the processing activity, applicable law, and the specific service being provided.
2. Personal Data We Collect From Merchants
- Account information: name, email address, mobile number, business name, store name, and chosen store subdomain
- Billing information: subscription plan, payment status, payment references, transaction identifiers, invoice history, and related billing records
- Technical information: IP address, browser type, device information, operating-system information, pages or features accessed, timestamps, and technical diagnostic information
- Support information: information you provide when contacting us or requesting technical or account assistance
- Business information: information voluntarily provided for configuring or operating your Store
We do not intentionally store your full card number, CVV, or UPI PIN. Payment credentials are handled by the applicable payment provider. We may receive payment references, transaction identifiers, payment status, and other information necessary to reconcile and administer payments.
3. Information Processed Through Merchant Stores
Merchants may place information into FrontMart including product catalogues, orders, delivery addresses, customer names, phone numbers, email addresses, and other information required to operate their Stores.
We process and store such information as reasonably necessary to provide the FrontMart service, including hosting Stores, processing orders, providing administrative functionality, maintaining security, providing support, and maintaining operational backups.
We do not sell Merchant customer data as a commercial data product.
Where a customer wishes to exercise a privacy right concerning information collected by a Merchant, the customer should generally contact that Merchant first because the Merchant generally determines the purposes and means of the relevant customer-data processing.
4. Why We Use Personal Data
- To create, operate, and support Merchant accounts and Stores
- To authenticate account users
- To send one-time passwords and account-security messages
- To process subscription payments
- To issue invoices and receipts
- To send service and billing notices
- To provide customer and technical support
- To detect abuse, fraud, and security attacks
- To apply technical and security rate limits
- To maintain and improve platform reliability and security
- To troubleshoot errors and technical issues
- To comply with applicable legal and tax obligations
- To establish, exercise, or defend legal claims where appropriate
Service, security, account, and billing notices are operational communications relating to the use of the Service.
We do not sell personal data for advertising or unrelated commercial profiling.
5. Cookies and Similar Technologies
We use cookies and similar technologies that are necessary for the Service to function, including maintaining authentication sessions, remembering relevant Store or account configuration, and protecting against security threats such as cross-site request forgery.
Authentication cookies may be configured with security attributes such as HttpOnly and Secure where technically appropriate.
We do not use advertising or cross-site tracking cookies on https://frontmart.in as part of our core platform.
Individual Merchant Stores may independently use analytics, cookies, pixels, or other technologies. Merchants are responsible for providing appropriate disclosures and obtaining any consent required by applicable law for technologies they independently configure or control.
6. Who We Share Personal Data With
We use a limited number of third-party service providers to operate and secure FrontMart. Depending on the service involved, providers may process information necessary to perform their respective functions.
- Razorpay — payment processing and payment-related services
- Brevo — transactional email and one-time-password delivery
- Vercel — hosting and delivery of applicable frontend services
- DigitalOcean — application servers and database infrastructure
- Cloudflare — DNS, CDN, storage, network, and security services
- Sentry — error reporting, monitoring, and application diagnostics
We may also disclose personal data to professional advisers, auditors, legal advisers, governmental authorities, courts, regulators, law enforcement agencies, or other parties where disclosure is required or reasonably necessary under applicable law.
Some service providers may process information outside India. Where applicable, such processing will be subject to appropriate contractual, technical, organizational, or other safeguards required by applicable law.
7. Business Transfers
If FrontMart or substantially all of its assets are involved in a merger, acquisition, restructuring, financing, sale, or similar transaction, personal data may be transferred or disclosed as reasonably necessary for that transaction, subject to applicable law.
8. How We Protect Personal Data
We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, misuse, or destruction.
- HTTPS is used for applicable service communications
- Security controls are applied to platform infrastructure
- Merchant data is logically separated between Stores
- Sensitive credentials are protected using appropriate security measures
- Authentication cookies may use security attributes such as HttpOnly
- Rate limiting is applied to relevant authentication endpoints
- Database backups are maintained for operational recovery
- Application errors may be monitored through diagnostic tooling
No online system or method of transmission can be guaranteed to be completely secure. If a security incident materially affects personal data, we will take appropriate measures and provide notifications where required by applicable law.
9. How Long We Keep Personal Data
- Active Merchant accounts: for as long as reasonably necessary to operate the account and provide the Service
- After cancellation: 30 days, subject to applicable legal, security, dispute, fraud-prevention, and operational requirements
- Invoices and payment records: for as long as required by applicable tax, accounting, financial, or legal requirements
- Security and server logs: for a limited operational retention period and then rotated, anonymized, or deleted according to applicable practices and requirements
- Backups: backup copies may remain for a limited period after deletion from active systems as part of normal backup rotation and disaster-recovery processes
10. Your Privacy Rights
Subject to applicable law, you may have rights to request access to, correction of, export of, or deletion of personal data we hold about you. Depending on the legal basis for processing, you may also have rights to withdraw consent or object to certain processing.
Requests should be sent from your registered email address to support@frontmart.in.
We may need to verify your identity before fulfilling a request. Some requests may be subject to legal exceptions, technical limitations, or retention obligations.
If your request concerns customer data held by a Merchant through its FrontMart Store, you should generally contact that Merchant directly. Where appropriate, we may assist the Merchant in responding to a valid request in accordance with applicable law.
11. Children's Privacy
FrontMart is a business software service and is not directed at children. We do not knowingly seek to collect personal information from children through the core Service.
If you believe that a child has provided personal information to us in a manner that may violate applicable law, please contact us so that we can review and take appropriate action.
12. Legal Basis and Applicable Law
Depending on the applicable law and the nature of the processing, we may process personal data where necessary to provide the Service, perform a contract, comply with legal obligations, protect legitimate interests, prevent fraud or abuse, maintain security, or where consent or another lawful basis is required and has been obtained.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our services, technology, business practices, security measures, or applicable law.
The latest version will be published on this page. Significant changes may be communicated to account holders where appropriate or required by applicable law.
14. Contact and Grievance
APKHOST PRIVATE LIMITED
Private Limited Company
Khasra 1153/3/2, Village Senduri, Infront of Petrol Pump, Jaithari Road, Anuppur, Madhya Pradesh – 484224, India
Email: support@frontmart.in
Grievance Officer
Email: grievance@frontmart.in