Skip to content
Gudnet
Worldwide (EU/EEA, UK, United States, India & APAC)Version 3.2

Global Privacy Policy

How Gudnet and independent marketplace suppliers collect, use, safeguard, and respect your personal information across international borders.

Last updated: September 13, 2026Effective worldwide: September 13, 2026
Contact Legal

At a Glance — Executive Summary

Gudnet operates a multi-vendor e-commerce marketplace connecting global shoppers with independent suppliers as well as platform-curated essentials. We believe privacy is a fundamental human right. We do not sell your personal information, we enforce strict supplier data isolation so vendors never receive general access to our customer database, and we employ military-grade encryption and automated security controls to protect your identity.

No Selling of Personal Data

We never sell, rent, or trade your personal information or browsing history to third-party data brokers or advertisers.

Strict Supplier Data Isolation

Independent vendors only receive the exact delivery information required to pack and ship your order. Vendors have zero access to your broader profile, payment cards, or other store orders.

Bank-Grade Security

All credentials are protected by one-way bcrypt hashing (cost factor 12), encrypted HTTP-only session cookies, automated brute-force lockouts, and TLS 1.3 transport encryption.

Full Global Rights

Whether you are protected by GDPR (Europe/UK), CCPA/CPRA (California), or the DPDP Act (India), you enjoy seamless rights to access, rectify, export, and permanently delete your personal data.

01

Scope & Data Controllership

Summary: Explains who is responsible for your data when you browse, create an account, or place orders on the marketplace.

This Privacy Policy applies to the Gudnet website (http://localhost:3000), our customer storefront, vendor storefronts, mobile experiences, and associated commerce services.

Gudnet Computers Pvt. Ltd. ('Gudnet', 'we', 'us', or 'our') acts as the primary Data Controller for your marketplace user account, browsing activity, central order checkout records, payment authorizations, platform dispute resolution, and security infrastructure.

When you purchase products from independent third-party vendors listed on our marketplace ('Sold by [Vendor Name]'), that vendor acts as a separate, limited data controller strictly for the purpose of picking, packaging, shipping, and fulfilling the specific sub-order items placed with their store.

International Legal Representation

For customers residing in the European Economic Area (EEA) and the United Kingdom, our processing strictly complies with Regulation (EU) 2016/679 (GDPR) and the UK Data Protection Act 2018. For United States residents, this policy complies with the California Consumer Privacy Act (CCPA) as amended by the CPRA, and state privacy statutes. For residents of India, this policy complies with the Digital Personal Data Protection Act, 2023 (DPDP Act).

02

Information We Collect About You

Summary: Details the specific categories of data we gather directly from you, automatically through your device, or via authorized marketplace interactions.

We adhere to the principle of data minimization: we only request and process personal data that is strictly necessary to provide an exceptional, reliable, and secure shopping experience.

A. Account & Identity Information

Information provided when you register an account, update your customer profile, or save delivery addresses:

  • Full legal name and preferred display name.
  • Verified primary email address (used as your unique sign-in identifier).
  • Contact telephone number for order verification and carrier delivery updates.
  • Encrypted password credentials (stored exclusively via irreversible bcrypt hashing with cost factor 12; Gudnet never stores or possesses plaintext passwords).
  • Saved shipping and billing postal addresses, recipient names, and delivery phone numbers.

B. Commercial & Transaction Data

Information generated through marketplace browsing and checkout transactions:

  • Shopping cart items, wishlist selections, and saved preferences.
  • Order records, sub-order splits per vendor, line items, and quantities.
  • Payment method metadata (e.g. payment token, issuing bank, card brand, transaction ID, and masked last 4 digits). Gudnet does NOT store raw credit card numbers or CVV codes; all card transactions are processed by certified Level 1 PCI-DSS payment gateways.
  • Invoicing, taxation records (GST/VAT/Sales Tax), customs declaration notes, and shipping zone classifications.
  • Return requests, replacement history, dispute communications, and platform settlement ledger entries.

C. Technical, Device & Telemetry Data

Information automatically collected when accessing our web servers and APIs:

  • Internet Protocol (IP) address and approximate geographic location (country/city level).
  • Browser type, version, language preferences, and HTTP referrer headers.
  • Device category (mobile handset, tablet, or desktop), operating system, and screen viewport dimensions.
  • Platform session identifiers, security tokens, and server event logs.
03

Marketplace Architecture & Vendor Data Boundaries

Summary: Our core architectural commitment: vendors only receive the data necessary for fulfillment and cannot access our general customer base.

In a multi-supplier marketplace, your privacy depends on strict data segregation between different merchants. Gudnet enforces hard isolation boundaries within our database architecture and API endpoints:

  • Need-to-Know Fulfillment Disclosure: When an order contains items from an independent seller, that seller only receives the customer's recipient name, delivery address, contact phone number, and the specific items purchased from their catalog.
  • Zero Access to Other Vendor Data: A vendor cannot see items you ordered from any other vendor in the same unified cart, nor can they view your payment cards or platform order history.
  • No General Customer Database Access: Independent vendors do not have search, export, or directory access to Gudnet's registered customer base.
  • Contractual Prohibition on Off-Platform Marketing: Marketplace seller agreements strictly prohibit suppliers from using shopper delivery information for marketing, solicitation, or disclosure to external third parties. Violators face immediate account termination and legal forfeiture of vendor balances.

Shopper Protection Standard

If a seller contacts you outside of delivery coordination or attempts to solicit direct off-platform payments, report them immediately to privacy@gudnet.in. Gudnet will investigate and enforce sanctions.

04

Chat Ordering (WhatsApp / Telegram) Data Processing

Summary: How data is handled when you check local delivery eligibility and order via chat channels.

Gudnet provides a streamlined chat ordering service for designated products where suppliers offer localized Cash on Delivery (COD) fulfillment via WhatsApp or Telegram.

  • PIN Code & City Availability Verification: When you query delivery availability on a product page, your entered 6-digit PIN code or city name is checked securely on our server against the seller's configured service area. This query does not store personal identity records and is rate-limited to prevent automated scraping.
  • Chat Redirection: If the service area is supported and you click 'Order on WhatsApp' or 'Order on Telegram', you are redirected to the respective third-party messaging platform with a prefilled product reference message.
  • Third-Party Messaging Privacy: Once you transition to WhatsApp (Meta Platforms) or Telegram, their respective privacy policies and end-to-end encryption standards govern communications. We advise shoppers not to share sensitive financial credentials over chat channels.
06

Cookies, Session Storage & Local Data

Summary: Details on how we use essential cookies and browser storage technologies.

Gudnet uses a clean, privacy-conscious cookie architecture. We prioritize functional necessity and do not deploy invasive third-party cross-site tracking pixels.

You can configure your browser to block or alert you about cookies. However, blocking essential session cookies will prevent account login, checkout, and wishlist synchronization.

Cookie & Storage Inventory
Cookie / Token NameCategoryDurationPurpose
ecom.session-token.v1 (__Secure- in production)Strictly Necessary7 DaysEncrypted Auth.js JWT session token maintaining your secure logged-in state across pages.
next-auth.csrf-tokenSecuritySessionCryptographic cross-site request forgery prevention token.
gudnet_dataset / preview_modeFunctional30 DaysStores mock dataset preferences during development and preview modes.
gudnet_langPreferences1 YearStores your preferred storefront language selection.
07

Data Retention & Erasure Policies

Summary: How long we retain different categories of data and when information is securely purged.

We store personal data only as long as necessary to satisfy the purposes outlined in this policy or to comply with statutory statutory retention mandates:

  • Customer Account Data: Retained for the lifetime of your active account. If you request account closure, personal profile information is deleted or anonymized within 30 days.
  • Financial & Tax Ledgers: Retained for 7 years from the transaction date to comply with global commercial laws, tax inspection requirements (GST/VAT/IRS), and anti-money laundering regulations.
  • Security & Authentication Logs: Failed login attempts, lockout counters, and IP audit trails are retained for 90 days before automated rotation.
  • Customer Service Communications: Inquiries and dispute records are preserved for 2 years following resolution to manage warranty claims and repeat disputes.
08

Information Security & Technical Safeguards

Summary: The technical and organizational measures deployed to protect your personal information.

We implement defense-in-depth security engineered into every architectural layer of the marketplace:

  • End-to-End Transport Security: All web traffic, API requests, and webhook payloads require TLS 1.3 encryption with modern cipher suites.
  • Bcrypt Password Cryptography: Account passwords are protected using bcrypt with a high work factor (12 rounds) and are never exposed in application logs or standard database queries.
  • Brute-Force Account Protection: Our authentication service monitors login attempts; 8 consecutive failed passwords trigger an automatic 15-minute account lock.
  • Session Invalidation: Every account mutation increments a server-side sessionVersion, instantly invalidating active JWT tokens across all devices upon password reset or role modification.
  • Encrypted Storage: Sensitive database volumes and cloud backup archives are encrypted at rest using AES-256.
09

Cross-Border Data Transfers

Summary: Safeguards governing the transfer of personal data across national borders.

As a global marketplace, your data may be processed in secure data centers located in India, the European Union, the United States, and regional cloud availability zones.

When transferring data out of the EEA, the UK, or Switzerland, Gudnet relies on European Commission Standard Contractual Clauses (SCCs), UK International Data Transfer Agreements (IDTAs), or statutory adequacy decisions to guarantee that your personal information receives equivalent protection.

10

Your Global Privacy Rights & How to Exercise Them

Summary: Comprehensive rights available to users in the EU, UK, US, India, Australia, and worldwide.

A. Rights for EEA, UK & Global Shoppers

  • Right of Access: Request a machine-readable copy of your personal data held by Gudnet.
  • Right to Rectification: Correct inaccurate or incomplete profile or address details directly via your account settings.
  • Right to Erasure ('Right to be Forgotten'): Request the permanent deletion of your account and personal identifiers, subject to statutory tax ledger retention.
  • Right to Restrict Processing: Ask us to pause processing your data during active disputes.
  • Right to Data Portability: Receive your transaction history and profile in a structured, commonly used JSON/CSV format.
  • Right to Object: Object at any time to processing based on legitimate interests or direct marketing.

B. California & US State Privacy Rights (CCPA / CPRA)

If you reside in California, Virginia, Colorado, Connecticut, or other US states with active privacy legislation:

  • We DO NOT sell your personal information or share it for cross-context behavioral advertising.
  • We do not collect or process sensitive personal information for inferring characteristics.
  • You have the right to non-discrimination: we will never deny goods, charge higher prices, or provide a lower quality of service because you exercised your privacy rights.

C. Rights under India's DPDP Act, 2023

  • Right to access a summary of personal data being processed and the identities of data fiduciaries/processors.
  • Right to correction, completion, and updating of personal data.
  • Right to grievance redressal regarding any act or omission of the data fiduciary.
  • Right to nominate another individual to exercise privacy rights in the event of death or incapacity.
11

Children's Privacy Protection

Summary: Our strict policy regarding underage users.

The Gudnet marketplace is not directed to, marketed to, or intended for use by individuals under the age of 18 (or the age of legal majority in your country of residence).

We do not knowingly collect personal data from minors. If we discover that a minor has provided us with personal information without verified parental consent, we will promptly terminate the account and purge the associated data.

12

Amendments to this Policy

Summary: How we notify you of modifications to our privacy practices.

We may update this Global Privacy Policy periodically to reflect changes in our commerce features, cloud architecture, or applicable legal standards.

When material modifications occur, we will update the 'Last Updated' date at the top of this document and post a prominent notice on the storefront banner or send an email notification to registered account holders before changes take effect.

13

Contact Us & Grievance Redressal Officer

Summary: Official channels to submit privacy requests, inquiries, or statutory grievances.

If you wish to exercise your privacy rights, request data deletion, or submit a formal grievance regarding how your data is handled by Gudnet or an independent marketplace supplier, contact our designated Data Protection & Grievance Officer:

Legal Identity & Grievance Redressal

Gudnet Computers Pvt. Ltd. (CIN: U72200MH2021PTC368921)

Designated Grievance Officer

Arpit Singh (Head of Data Governance & Compliance)

Email: privacy@gudnet.in

General Inquiries & Support

Support: support@gudnet.in

Legal Affairs: legal@gudnet.in

Corporate Headquarters

Gudnet Computers Pvt. Ltd., Tech Tower 4, Sector 18, Navi Mumbai, Maharashtra 400705, India

Statutory response within 30 days (or faster where required by local law).