Privacy Policy

Effective Date: 17/07/2026 · Last Updated: 09/08/2026

CyberCartNow ("we," "us," or "our") respects your privacy and is committed to protecting the personal data of everyone who visits our website or uses our Services, regardless of where in the world you are located. This Privacy Policy explains what data we collect, why we collect it, how we use it, and the rights you have over it.

By using https://cybercartnow.com ("Website") or purchasing our Services, you acknowledge the practices described in this policy.

1. Who We Are (Data Controller)

  • Legal Entity Name: Magellanix Technology Solutions Private Limited
  • Registered Address: 2/534, Sundeep Road, Neelangarai, Chennai - 600115, India
  • Contact Email (Privacy/Data Protection): privacy@cybercartnow.com

2. What Data We Collect

We collect the following categories of personal data:

(a) Information you provide directly:

  • Name, email address, phone number
  • Billing/company address and business details
  • Account login credentials
  • Payment-related information (processed by Razorpay; we do not store full card numbers)
  • Bank transfer payment proof documents you upload
  • Project scoping information (e.g., domain names, IP ranges, application URLs) that you submit for engagement purposes
  • Messages sent via our contact form
  • Email address submitted for newsletter/marketing signup

(b) Information collected automatically:

  • IP address, browser type, device information
  • Pages visited, time spent, referring URLs (via cookies/analytics tools)
  • General location inferred from IP address

(c) Information from third parties:

  • Payment confirmation data from Razorpay
  • Currency exchange rate data (non-personal)

3. How We Use Your Data

We use your data to:

  • Create and manage your account
  • Process orders, payments, and deliver contracted Services
  • Communicate with you about your order, engagement status, or support requests
  • Verify manual bank transfer payments
  • Send marketing communications, where you have opted in (you can unsubscribe anytime)
  • Improve our website, Services, and security
  • Comply with legal, tax, and regulatory obligations
  • Detect and prevent fraud or abuse

4. Legal Basis for Processing (GDPR — applicable to EU/UK/EEA residents)

Where GDPR applies, we rely on the following legal bases:

  • Contractual necessity — to process your order and deliver Services you've purchased
  • Legitimate interest — to improve our Services, prevent fraud, and for direct marketing to existing customers
  • Consent — for newsletter subscriptions and non-essential cookies (you may withdraw consent at any time)
  • Legal obligation — to comply with tax, accounting, and regulatory requirements

5. Cookies & Tracking

We use cookies and similar technologies to:

  • Keep you logged in and remember your cart contents
  • Understand website usage via analytics
  • Support currency/locale preferences

You can control cookies through your browser settings. Disabling certain cookies may affect website functionality (e.g., cart persistence). Where required by law (e.g., EU/UK), we will request your consent via a cookie banner before setting non-essential cookies.

6. How We Share Your Data

We do not sell your personal data. We share data only with:

  • Razorpay — to process payments (subject to Razorpay's own privacy policy)
  • Supabase — our backend infrastructure and hosting provider, which stores account data, order records, and uploaded files
  • Email/communication service providers — to send transactional and marketing emails
  • Professional advisors (legal, accounting) where necessary, under confidentiality obligations
  • Law enforcement or regulators — where legally required to do so

Any sub-processor we use is contractually obligated to protect your data to a standard consistent with this policy.

7. International Data Transfers

Since we serve clients globally, your data may be processed or stored in countries outside your own, including the United States, India, and the European Union. Where we transfer personal data from the EU/UK/EEA to a country without an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs), as required under GDPR/UK GDPR.

8. Data Retention

We retain personal data only as long as necessary to:

  • Fulfill the purposes described in this policy,
  • Comply with legal, tax, or accounting obligations for financial records,
  • Resolve disputes and enforce our agreements.

Engagement-related sensitive data (e.g., scoping details, vulnerability findings) is retained only as long as necessary for delivery, audit, and legal defense purposes, after which it is securely deleted or anonymized in accordance with our internal data handling procedures.

9. Data Security

Given the nature of our business, we take data security seriously. Measures include:

  • Encryption of data in transit (TLS) and at rest where supported by our infrastructure providers
  • Role-based access controls limiting internal access to client data
  • Secure credential storage (payment secrets, API keys) via environment-level secrets management
  • Regular access reviews

No system is 100% secure, and we cannot guarantee absolute security, but we take reasonable and industry-appropriate steps to protect your information.

10. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Delete your data ("right to be forgotten"), subject to legal retention obligations
  • Restrict or object to certain processing
  • Data portability — receive your data in a structured, machine-readable format
  • Withdraw consent at any time where processing is based on consent

To exercise any of these rights, contact us at privacy@cybercartnow.com. We will respond within the timeframe required by applicable law.

Region-Specific Notes:

  • EU/UK/EEA residents: GDPR/UK GDPR rights as described above apply.
  • California residents (CCPA/CPRA): You have the right to know what personal data is collected, request deletion, and opt out of the sale/sharing of personal data. We do not sell personal data.
  • India (DPDP Act): You may request access, correction, or erasure of your personal data, and may withdraw consent for processing where applicable.
  • Other jurisdictions: If your local law grants you additional rights, we will honor them to the extent legally required.

11. Children's Privacy

Our Services are intended for business/professional use and are not directed at individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

12. Marketing Communications

If you subscribe to our newsletter or opt into marketing emails, you can unsubscribe at any time via the link in any marketing email or by contacting support@cybercartnow.com. Transactional emails (order confirmations, payment status) are not affected by this opt-out, as they are necessary to deliver your purchased Services.

13. Third-Party Links

Our website may contain links to third-party sites. We are not responsible for the privacy practices of those sites. We encourage you to review their privacy policies independently.

14. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Material changes will be communicated via email or a notice on our website. The "Last Updated" date at the top reflects the most recent revision.

15. Contact Us

For any privacy-related questions, requests, or complaints, contact us at: support@cybercartnow.com