Privacy Policy
Effective 10 August 2026Cratus NextGen ("Cratus", "we", "us") is a warehouse and order-management operating system used by order-fulfilment companies and brands to run e-commerce operations across multiple sales channels, including Amazon, Flipkart, WooCommerce, ONDC and JioMart. This policy describes how we collect, process, store, use, share and dispose of data — including order and buyer data received from connected marketplaces on behalf of our account holders — and explains the rights available to individuals whose data passes through the platform, in line with India's Digital Personal Data Protection Act, 2023 ("DPDP Act").
Cratus is a business-to-business platform. We do not sell directly to consumers, and the individuals whose personal data we process (buyers on a connected marketplace) are not our own customers — they are customers of the brands and fulfilment companies who use Cratus.
What we collect
To operate order fulfilment, reconciliation and tax compliance, we collect order, shipment and settlement data from the marketplaces and channels a Cratus account connects: order and item identifiers, quantities, amounts, HSN/tax data, and the buyer information needed to ship and invoice an order — typically name, shipping address, and (where the channel provides it) phone number or email address. This data is pulled only for our own account holders' own transactions, directly from each channel's official API or from manually uploaded reports the account holder provides.
Why we collect it (purposes)
- Order fulfilment — dispatch, pick/pack, shipping labels, courier handoff and delivery tracking.
- Tax compliance — generating GST-compliant invoices, e-invoicing (IRN) where legally required, and filing statutory returns.
- Reconciliation — matching what a marketplace paid an account holder against what was actually owed.
- Operational analytics — inventory, margin, and channel-performance reporting, scoped to the account holder's own data.
- Fraud and returns protection — detecting patterns such as label-strip pilferage, weight-tampered returns, and RTO abuse.
We do not use marketplace or buyer data for advertising, and we do not build cross-account or cross-brand profiles of individual buyers.
How we store and protect it
Buyer contact details (phone and email) are encrypted at the field level using AES-256-GCM before storage, with a unique initialization vector and authentication tag per record. Buyer name and shipping address are stored in readable form because couriers and tax invoices require them on every shipment, but are masked by default on every screen and revealed only on an explicit, individually logged action. Data is isolated per account through database-level access controls, and access to any account's data is restricted to that account's own authorised, individually attributed users through role-based logins. All data in transit is encrypted (TLS 1.2 or higher).
Amazon marketplace data — additional commitments
Where an account connects Amazon via the Selling Partner API (SP-API), we handle any data returned as "Restricted Data" (buyer name, address, phone number, email alias, gift messages and similar) under Amazon's own Data Protection Policy for SP-API applications, in addition to this policy. In particular:
- Amazon buyer personal data is retained no longer than is necessary to fulfil the order and applicable legal/tax retention obligations, and is not retained beyond what Amazon's own policy permits for non-shipping purposes.
- All such data is encrypted at rest using AES-256 (or equivalent) and in transit using TLS 1.2+, matching or exceeding Amazon's minimum key-strength requirements.
- Access is restricted to the systems and personnel that need it to fulfil orders for the connected account — never shared with a separate application or third party without the account holder's authorisation.
- We do not use Amazon buyer data to build marketing lists, and we do not use it to contact buyers outside of order fulfilment.
Who we share it with
We do not sell buyer or marketplace data, and we do not share it for marketing or advertising purposes. Data is shared only where operationally necessary, with the processors below:
| Processor | Role | What they receive |
|---|---|---|
| Supabase | Database & application hosting | The full operational database, under standard hosting/processor terms; not used for their own purposes. |
| Vercel | Application hosting | Application runtime only; no direct database access. |
| Anthropic | AI assistant features | Non-identifying order metadata only (counts, status, category, region) — never buyer name, address, phone, or email. |
| Shiprocket | Courier aggregation | Buyer name and address, only for orders fulfilled outside a marketplace's own logistics network (e.g. not for Amazon FBA/Easy Ship, which ship through Amazon's own system). |
| Cloudflare | Hosting, DNS, edge network | Standard web traffic metadata for the marketing site and application delivery. |
| NIC / Invoice Registration Portal (IRP) | Statutory GST e-invoicing | Invoice-level data for business-to-business sales that legally require an e-invoice under Indian GST law. |
How long we keep it
Operational order and buyer data is retained for as long as needed to run fulfilment and reconciliation for the account holder, and thereafter for as long as Indian tax and accounting law requires — currently up to 8 years for books of account (Companies Act) and up to 6 years for GST and income-tax records. Data that is no longer required for either purpose is deleted or securely disposed of. Where a data principal's erasure request would conflict with one of these statutory retention obligations, we retain only what the law requires and tell the requester which part of their data could not be erased, and why.
Your rights
If you are a buyer whose order was fulfilled using Cratus and you have a question about how your data was handled, you can contact the brand you purchased from directly, or reach us at the address below and we will route your request appropriately. Under the DPDP Act, you may request:
- Access — a summary of the personal data we hold about you in connection with an order.
- Correction — correction of inaccurate or incomplete personal data.
- Erasure — deletion of your personal data, subject to the statutory retention limits described above.
- Grievance redressal — a way to raise a complaint about how your data has been handled.
- Nomination — naming another individual to exercise these rights on your behalf in the event of death or incapacity.
We aim to acknowledge a request within 7 business days and resolve it within 30 days, except where a longer statutory retention obligation applies to part of the request.
Grievance Officer
For any question about this policy, to exercise a right described above, or to report a suspected data-security incident, contact subhadevi@cratus.in.
Changes to this policy
We may update this policy as our practices or applicable law change. The effective date at the top of this page reflects the most recent revision. Material changes will be reflected here before they take effect.
Contact
Questions about this policy can be sent to subhadevi@cratus.in.