Privacy Policy for StarKart
Last updated: December 22, 2025
This Privacy Policy explains how StarKart ("StarKart", "we", "us") collects, uses, shares and protects personal data when you use the StarKart Service. The data controller is: StarKart, Registered Office: Near Main Market, Maudaha, Hamirpur, Uttar Pradesh, PIN 210507. Contact: support@gostarkart.com.
1. Personal data we collect
We collect the following categories of personal data:
- Account & identity data: name, mobile number, profile picture.
- Address data: delivery addresses, billing address.
- Order data: items ordered, order history, timestamps.
- Payment data: For COD we do not process card numbers; we may store transactional metadata (order IDs, amounts).
- Agent location data: For registered Delivery Agents only: real-time background location (latitude/longitude) while an active delivery is in progress; route data used for proof-of-delivery and dispute resolution.
- Device & usage data: device model, OS version, app logs, crash reports, analytics data for troubleshooting and improving the Service.
- KYC & verification documents (Sellers/Agents): government ID, driving licence, vehicle RC, GSTIN, FSSAI license where applicable.
2. Legal bases & purposes
We process personal data on the following bases:
- Contractual necessity: to provide the Service (process orders, arrange delivery, communicate updates).
- Consent: for background location tracking of Agents and marketing communications (users may opt-in/opt-out).
- Legal compliance: to comply with statutory obligations and to respond to lawful requests by authorities.
- Legitimate interests: for fraud prevention, platform security, and service improvement (balanced against user rights).
3. Location tracking — explicit consent & usage
Delivery Agents must provide explicit, informed consent in the app before any background or continuous location tracking begins. Agents will be asked to grant foreground and background location permissions; the app will store a timestamped record of the consent and a link to withdraw consent in settings. Withdrawal of consent may prevent the Agent from accepting delivery assignments that require live tracking.
We retain active-delivery GPS traces for 90 days for dispute resolution and fraud prevention unless extended for an ongoing investigation or if a different statutory retention applies.
4. Data sharing & processors
We may share personal data with:
- Sellers: delivery address and name are shared with the assigned Seller and assigned Agent only as necessary to fulfil an order.
- Delivery Agents: relevant details (delivery address, contact number) are shared with the assigned Agent.
- Service providers & processors: e.g., cloud providers, analytics providers (we use Firebase). We only share data with processors under written agreements and appropriate safeguards.
- Legal authorities: where required by law, court orders or regulatory obligations.
5. Cross-border transfers
If personal data is transferred outside India (e.g., to cloud subprocessors), we will ensure appropriate safeguards (standard contractual clauses, approved mechanisms) are in place.
6. Data retention
We retain personal data only as long as necessary for the purposes set out and to comply with legal obligations. Typical retention periods:
- Account & order data: 6 years (to comply with tax, audit and statutory recordkeeping obligations).
- Agent active-delivery GPS traces: 90 days (for dispute resolution), unless extended for an ongoing investigation.
- KYC documents: retained while the account is active and for 3 years after deactivation.
Agent active-delivery GPS traces: [90 days] (for dispute resolution) unless extended for an ongoing investigation.
KYC documents: [as long as the account is active + 3 years] after deactivation.
7. User rights & how to exercise them
Under applicable laws and best-practice data protection norms, you may have the right to:
- Access the personal data we hold about you.
- Correct or update inaccurate data.
- Request deletion or erasure of your personal data (subject to legal retention obligations).
- Object to processing for specific reasons (where applicable).
- Lodge a complaint with StarKart (DPO) or with the relevant supervisory authority.
To exercise rights, contact: dpo@gostarkart.com. We will respond within 30 days (or earlier if required by law).
Users can also request permanent deletion of their account and associated personal data by raising a help-line ticket in the StarKart app with the subject line “Account Deletion Request” or emailing us at support@gostarkart.com.
8. Security measures
We use industry-standard technical and organizational measures to protect data (encryption in transit, access controls, regular security audits). We cannot guarantee absolute security; users should use secure devices and keep credentials safe.
9. Changes to this policy
We may update this Privacy Policy. We will post changes with a revised "Last updated" date. For material changes, we will provide notice via the app.
10. Contact & Grievance
DPO / Privacy contact: dpo@gostarkart.com
Grievance Officer: grievance@gostarkart.com
Office: Near Main Market, Maudaha, Hamirpur, UP, PIN 210510