Data Protection & Privacy

Privacy Policy

Last Updated: August 20, 2026• Effective Date: August 20, 2026

Transparent Data Use

We collect only essential data needed to provision merchant storefronts, process buyer orders, and provide secure services.

Secure Storage

Your assets and media are safely stored across encrypted databases and isolated S3/MinIO Object Storage buckets.

Merchant Ownership

Merchants retain full ownership of their store data, customer records, and product assets hosted on Malicc.

1Introduction & Scope

Welcome to Malicc ("Company", "we", "our", or "us"). This Privacy Policy explains how Malicc collects, uses, discloses, and safeguards personal data when you visit our platform domain (tiny.malicc.com), use our merchant management dashboard, access customer storefront subdomains (e.g., <subdomain>.tiny.malicc.com), or interact with our API services.

By accessing or using the Malicc platform as a Merchant, Buyer, Affiliate Agent, or Visitor, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with any terms of this policy, please discontinue use of our services immediately.

2Information We Collect

We collect information to provide, maintain, and improve our multi-tenant e-commerce ecosystem. The categories of information we collect include:

A. Information Provided by Merchants & Agents

  • Account Credentials: Name, email address, password hash (encrypted via bcrypt), and contact details.
  • Store Information: Store display names, store subdomains, logos, descriptions, and custom domain configurations.
  • Payment & Payout Credentials: Razorpay Linked Account IDs (`acc_xxx`), credit transaction history, and billing invoices.

B. Information Provided by Buyers (Customers)

  • Order & Checkout Details: Customer full name, email address, physical shipping address (for physical items), and order item breakdown.
  • Payment Metadata: Transaction verification signatures, Razorpay payment IDs, and payment status (we do not store raw credit card or banking PIN numbers).

C. Automatically Collected Technical Data

  • Device & Network Data: IP address, browser type, operating system, referrer URLs, and HTTP header tenant identifiers (`x-tenant-host`).
  • Log Data & Telemetry: Timestamp logs, API request payloads, HTTP status responses, and performance metrics.

3How We Use Your Information

We process personal data for legitimate business purposes, including:

  • Provisioning and maintaining isolated merchant storefronts and databases.
  • Processing customer orders and securely delivering digital goods via presigned S3 object URLs.
  • Verifying Razorpay payments and settling direct payouts to merchant accounts.
  • Managing the affiliate agent referral network and calculating valid commission payouts.
  • Sending transactional emails (order confirmations, digital access links, invoice receipts) via Resend.
  • Enforcing system security, detecting fraud, and preventing unauthorized access or abuse.

4Data Sharing & Third-Party Service Providers

We do not sell, rent, or trade your personal information. We share data only with trusted third-party infrastructure providers necessary to run Malicc:

Razorpay

Processes payments, generates checkout sessions, and routes merchant payouts.

Resend API

Delivers transactional emails, order receipts, and digital download notifications.

MinIO / S3 Storage

Stores public product images (`tiny-public`) and secure private digital assets (`tiny-private`).

PostgreSQL & Redis

Hosts relational data, merchant records, order ledgers, and background job queues.

5Data Security & Retention

Malicc employs industry-standard administrative, technical, and physical security measures to protect personal data against unauthorized access, loss, alteration, or disclosure.

  • All web traffic is encrypted in transit using SSL/TLS protocols.
  • Merchant passwords are hashed using high-cost bcrypt salt rounds.
  • Digital product files are stored in private storage buckets and accessible only via time-restricted presigned S3 tokens (`expiresIn = 900s`).
  • We retain merchant and customer transaction logs for as long as necessary to fulfill contractual obligations, resolve disputes, and comply with tax and legal requirements.

6Cookies & Tracking Technologies

We use essential cookies and local storage tokens (`auth_token`) to maintain merchant session authentication, shopping cart state, and tenant domain routing. We do not use third-party cross-site tracking cookies.

7Your Data Rights & Choices

Depending on your jurisdiction (including rights under India's Digital Personal Data Protection Act and GDPR principles), you have the right to:

  • Access and receive a copy of your personal data stored on Malicc.
  • Request correction or updating of inaccurate personal data.
  • Request deletion of your merchant account and associated store data (subject to statutory record-keeping obligations).

Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or data protection practices at Malicc, please contact our Data Protection team at:

Company: Malicc

Support Email: support@tiny.malicc.com

Governing Jurisdiction: Bengaluru, Karnataka, India