Skip to content
GK Smart Book

Privacy Policy

Effective:
22 August 2026
Last updated:
22 August 2026
Version:
1.0

This policy explains what personal data GK Smart Book actually collects, why we collect it, who it is shared with, how long it is kept and the rights you have over it.

1. Who we are

GK Smart Book is operated by [LEGAL BUSINESS NAME — TO BE PROVIDED] ([ENTITY TYPE: PROPRIETORSHIP / LLP / PRIVATE LIMITED — TO BE PROVIDED]), [REGISTERED BUSINESS ADDRESS — TO BE PROVIDED]. For the purposes of India's Digital Personal Data Protection Act, 2023 (DPDP Act), we are the Data Fiduciary for personal data processed through this Website. Registration details: [BUSINESS REGISTRATION / CIN / UDYAM DETAILS, IF APPLICABLE — TO BE PROVIDED]. GSTIN: [GSTIN, IF APPLICABLE — TO BE PROVIDED].

2. Scope

This policy covers personal data processed through gksmartbook.in: account creation and login, browsing and cart use, checkout and orders, payments, digital delivery, seller/publisher applications and customer support. It does not cover independent websites you reach from links here, including the payment provider's own pages, which operate under their own notices.

3. Personal data we collect

We only list what this application actually processes today.

CategoryExamplesPurpose
Account dataEmail address, authentication identifier, password (stored only as a salted hash by our authentication provider), account creation and sign-in timestampsCreating and securing your account, showing your orders and digital library
Order and contact dataName, email address, mobile number, order number, items, quantities, prices, coupon used, order and fulfilment statusProcessing, fulfilling and supporting your order; tax and accounting records
Delivery dataShipping address including address lines, landmark, city, state and PIN code (collected only when the order contains a printed book)Delivering printed books
Payment-related dataPayment status, gateway order/payment reference identifiers and any failure message returned to usVerifying payment, releasing fulfilment, refunds, reconciliation and fraud prevention
Digital access recordsWhich titles you have access to, the account/email linked to that access, download counts and last download timeGranting your digital library access and detecting misuse of files
Cart and preference dataCart contents, wishlist and interface preferences stored in your own browser's local storageKeeping your cart between visits on the same device
Seller / publisher application dataName, brand, email, mobile, business address, seller type, PAN, GSTIN (optional), bank account name/number/IFSC, UPI ID (optional), title and rights information, website and notesEvaluating an application to supply books (see section 6)
Support communicationsThe content of emails or messages you send us and our repliesAnswering your query and keeping a record of the issue
Technical and security dataIP address, request metadata, browser/device information and error logs generated automatically by our hosting and backend providersSecurity, abuse prevention, debugging and service reliability

4. What we do NOT collect

  • We never receive or store card numbers, CVV, UPI PINs, net-banking passwords or OTPs — those are entered on the payment provider's own hosted checkout.
  • No advertising, behavioural-tracking or analytics SDK is integrated in this Website at present.
  • We do not buy personal data from data brokers and we do not sell your personal data.

5. How we collect it

  • Directly from you: account sign-up and login, checkout, coupon entry, seller/publisher application, emails and calls to support.
  • Automatically: essential browser storage for your cart and login session, and server/security logs generated by our hosting and backend providers.
  • From our payment provider: payment success/failure status and reference identifiers, returned to us and through a signed webhook.

6. Seller / publisher application data

The Seller / Partner form collects business and financial identifiers including PAN and bank details. Marketplace functionality is not active: at present the form is an expression of interest, and submitted details are not persisted in our database or transmitted to any third-party service from this Website. Before seller onboarding goes live we will implement encrypted storage with access restricted to authorised reviewers, and this policy will be updated to describe that processing, its purpose and its retention period. Please do not submit financial identifiers you are not comfortable sharing at an application stage.

7. Purposes of processing

  • Creating and administering your account and authenticating your logins.
  • Taking, validating, pricing and fulfilling your orders, including shipping printed books and granting access to digital books.
  • Processing payments, refunds and reconciliation through the payment provider.
  • Providing customer support and handling grievances.
  • Preventing fraud, piracy and abuse, and securing the platform.
  • Meeting legal, tax, accounting and record-keeping obligations.
  • Maintaining, debugging and improving the service.

We process personal data with your consent, and for uses that are necessary to perform the contract you enter with us, to comply with law, and for the legitimate purposes permitted under the DPDP Act, 2023 (for example fulfilling an order you placed, or preventing fraud). Consent requests are kept specific, understandable and separate from other text. We do not bundle marketing consent into the purchase flow. The Digital Personal Data Protection Rules, 2025 are being brought into force in stages; we are aligning our practices with them as their provisions commence, and this policy will be updated as that happens.

You can withdraw consent at any time: sign out and clear your browser's site data to remove locally stored cart data, close your account from the Account page or by contacting us, and email [GRIEVANCE OFFICER EMAIL — TO BE PROVIDED] to withdraw consent for any other specific processing. Withdrawal is not retrospective, and where processing is necessary to complete an order already placed or to meet a legal obligation we may need to continue that specific processing.

10. Who we share data with

  • Cashfree Payments — payment processing; receives your name, email, mobile number, order reference and amount.
  • Lovable Cloud (Supabase — managed Postgres, authentication and file storage) — hosting, database, authentication and encrypted file storage for the Website; processes all data stored by the application.
  • Courier / logistics partners for printed orders ([COURIER PARTNER NAMES — TO BE PROVIDED]) — receive the recipient name, address and phone number needed to deliver.
  • Professional advisers, accountants and auditors, where necessary and under confidentiality.
  • Law enforcement, courts, regulators or tax authorities where disclosure is legally required.
  • A seller or publisher, only where a marketplace order requires them to fulfil it — not applicable while marketplace functionality is inactive.

11. International transfers

Our backend, hosting and payment providers may process or replicate data on infrastructure located outside India, and their support teams may access it from other countries. We do not claim that all data is stored only in India. Transfers are made subject to the providers' contractual and security commitments and to any restrictions notified by the Central Government under the DPDP Act, 2023.

12. Retention

  • Order, invoice, payment and tax records: retained for the period required by tax, accounting and limitation laws.
  • Account and digital-access records: retained while your account is open, because they are what grants your library access.
  • Support correspondence: retained while needed for the issue and any related dispute.
  • Technical and security logs: retained for the short operational period set by our infrastructure providers.
  • Cart data in your browser: stays on your device until you clear it.
  • Specific retention durations: [RETENTION PERIOD TO BE CONFIRMED BY BUSINESS/LEGAL COUNSEL — TO BE PROVIDED].

13. Security

  • The site is served over HTTPS.
  • Passwords are handled and stored as hashes by our authentication provider; we never see them.
  • Database access is restricted by row-level security policies so customers can only read their own orders, order items and digital access records.
  • Digital book files and samples are kept in private storage and released only through short-lived signed links generated after payment verification.
  • Payment webhooks are verified with a signature check and processed only once, and order status is re-verified directly with the payment provider.
  • Administrative functions are restricted to accounts holding an admin role stored in a dedicated, server-checked roles table.
  • We do not claim any security certification or third-party audit standard.

14. Personal data breaches

We maintain a process to investigate and contain suspected security incidents, assess the personal data affected and mitigate the impact. Where a personal data breach occurs, we will notify the Data Protection Board of India and affected individuals in the manner and within the timelines required by applicable law, and will describe the nature of the breach and the steps you can take.

15. Your rights

Send requests to [GRIEVANCE OFFICER EMAIL — TO BE PROVIDED] from the email address on your account. We may need to verify your identity. We will respond within the timelines prescribed by applicable law and, where no statutory timeline applies, without undue delay.

  • Access — a summary of the personal data we process about you and who it has been shared with.
  • Correction — correct inaccurate or incomplete data, and complete or update it.
  • Erasure — request deletion of personal data we no longer need to retain for a legal or contractual purpose.
  • Withdraw consent — as described in section 9.
  • Grievance redressal — a first point of complaint with us, before approaching the Data Protection Board.
  • Nomination — nominate another individual to exercise your rights in the event of death or incapacity.

16. Children and students

This is an educational platform and some visitors will be school students. We do not knowingly process a child's personal data in a manner that is detrimental to their wellbeing, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children. Purchase accounts and orders are intended to be created by a parent or legal guardian, or with their verifiable involvement, and we rely on the account holder's confirmation of that. If you believe a child's data has been submitted without appropriate consent, contact us and we will delete it. As the verifiable parental-consent requirements under the DPDP framework commence, we will implement the corresponding technical flow rather than relying on this notice alone.

17. Cookies and local storage

The Website does not use advertising or analytics cookies. What it does use is limited to what is strictly necessary to make the site work.

TypeWhat it isConsent
Strictly necessaryLogin/session token stored by the authentication client so you stay signed inNo consent required — without it you cannot log in
FunctionalLocal storage holding your cart, wishlist and interface preferences on your own device; a cookie remembering a collapsed/expanded panelNo consent required — stores no identifiers about you and never leaves your browser except as part of an order you submit
AnalyticsNot used
Marketing / advertisingNot used

18. Marketing communications

We currently send only transactional messages relating to your account, order, payment and delivery. No marketing email, SMS or WhatsApp provider is integrated with this Website (no marketing provider configured). If we introduce marketing messages, they will be sent only with your separate opt-in consent, will never be a condition of purchase, and every message will carry a simple unsubscribe or opt-out.

19. Account deletion

You can request deletion of your account by emailing [GRIEVANCE OFFICER EMAIL — TO BE PROVIDED] from your registered address, or by using the deletion option in your Account page where available. On deletion we remove your profile and login credentials and revoke access to your digital library. Order, invoice, payment and tax records, and records needed for fraud prevention or to defend a legal claim, are retained for as long as the law requires and are then deleted. Deleting your account cannot restore access to previously purchased digital titles.

20. Grievance redressal

Grievance Officer: [GRIEVANCE OFFICER NAME — TO BE PROVIDED], [GRIEVANCE OFFICER DESIGNATION — TO BE PROVIDED]. Email: [GRIEVANCE OFFICER EMAIL — TO BE PROVIDED]. Address: [GRIEVANCE CORRESPONDENCE ADDRESS — TO BE PROVIDED]. Full escalation details are on the Grievance Redressal page. If you remain dissatisfied, you may complain to the Data Protection Board of India in relation to personal data, or use the consumer remedies described there.

21. Updates to this policy

We update this policy when our data practices or the law change. The effective date, last-updated date and version are shown at the top of this page. Current version: 1.0.

Items shown in square brackets are business details that must be filled in by the store owner before launch. They are intentionally left blank rather than guessed.