Legal

Privacy Policy

Effective 10 August 2026

Cratus NextGen ("Cratus", "we", "us") is a warehouse and order-management operating system used by order-fulfilment companies and brands to run e-commerce operations across multiple sales channels, including Amazon, Flipkart, WooCommerce, ONDC and JioMart. This policy describes how we collect, process, store, use, share and dispose of data — including order and buyer data received from connected marketplaces on behalf of our account holders — and explains the rights available to individuals whose data passes through the platform, in line with India's Digital Personal Data Protection Act, 2023 ("DPDP Act").

Cratus is a business-to-business platform. We do not sell directly to consumers, and the individuals whose personal data we process (buyers on a connected marketplace) are not our own customers — they are customers of the brands and fulfilment companies who use Cratus.

What we collect

To operate order fulfilment, reconciliation and tax compliance, we collect order, shipment and settlement data from the marketplaces and channels a Cratus account connects: order and item identifiers, quantities, amounts, HSN/tax data, and the buyer information needed to ship and invoice an order — typically name, shipping address, and (where the channel provides it) phone number or email address. This data is pulled only for our own account holders' own transactions, directly from each channel's official API or from manually uploaded reports the account holder provides.

Why we collect it (purposes)

We do not use marketplace or buyer data for advertising, and we do not build cross-account or cross-brand profiles of individual buyers.

How we store and protect it

Buyer contact details (phone and email) are encrypted at the field level using AES-256-GCM before storage, with a unique initialization vector and authentication tag per record. Buyer name and shipping address are stored in readable form because couriers and tax invoices require them on every shipment, but are masked by default on every screen and revealed only on an explicit, individually logged action. Data is isolated per account through database-level access controls, and access to any account's data is restricted to that account's own authorised, individually attributed users through role-based logins. All data in transit is encrypted (TLS 1.2 or higher).

Amazon marketplace data — additional commitments

Where an account connects Amazon via the Selling Partner API (SP-API), we handle any data returned as "Restricted Data" (buyer name, address, phone number, email alias, gift messages and similar) under Amazon's own Data Protection Policy for SP-API applications, in addition to this policy. In particular:

Who we share it with

We do not sell buyer or marketplace data, and we do not share it for marketing or advertising purposes. Data is shared only where operationally necessary, with the processors below:

ProcessorRoleWhat they receive
SupabaseDatabase & application hostingThe full operational database, under standard hosting/processor terms; not used for their own purposes.
VercelApplication hostingApplication runtime only; no direct database access.
AnthropicAI assistant featuresNon-identifying order metadata only (counts, status, category, region) — never buyer name, address, phone, or email.
ShiprocketCourier aggregationBuyer name and address, only for orders fulfilled outside a marketplace's own logistics network (e.g. not for Amazon FBA/Easy Ship, which ship through Amazon's own system).
CloudflareHosting, DNS, edge networkStandard web traffic metadata for the marketing site and application delivery.
NIC / Invoice Registration Portal (IRP)Statutory GST e-invoicingInvoice-level data for business-to-business sales that legally require an e-invoice under Indian GST law.

How long we keep it

Operational order and buyer data is retained for as long as needed to run fulfilment and reconciliation for the account holder, and thereafter for as long as Indian tax and accounting law requires — currently up to 8 years for books of account (Companies Act) and up to 6 years for GST and income-tax records. Data that is no longer required for either purpose is deleted or securely disposed of. Where a data principal's erasure request would conflict with one of these statutory retention obligations, we retain only what the law requires and tell the requester which part of their data could not be erased, and why.

Your rights

If you are a buyer whose order was fulfilled using Cratus and you have a question about how your data was handled, you can contact the brand you purchased from directly, or reach us at the address below and we will route your request appropriately. Under the DPDP Act, you may request:

We aim to acknowledge a request within 7 business days and resolve it within 30 days, except where a longer statutory retention obligation applies to part of the request.

Grievance Officer

Subha Devi
Grievance Officer, Cratus

For any question about this policy, to exercise a right described above, or to report a suspected data-security incident, contact subhadevi@cratus.in.

Changes to this policy

We may update this policy as our practices or applicable law change. The effective date at the top of this page reflects the most recent revision. Material changes will be reflected here before they take effect.

Contact

Questions about this policy can be sent to subhadevi@cratus.in.