Privacy Policy
Effective 28 July 2026
KasiCart is a local multi-seller marketplace for browsing products and arranging pickup orders. This policy explains what information KasiCart processes, why it is used, how long it is kept, and the choices available to customers and sellers.
Information we collect
Customers
- Name, phone number, optional order note, selected products, quantities, pickup shop, and order status.
- A random order-tracking token used to limit access to the customer order page.
- Limited visit information such as source, time, pseudonymous visitor identifiers, and technical request data used for unique-view counting, security, and abuse detection.
Sellers and administrators
- Account name, email address, phone and WhatsApp details, password hash, verification status, login and lockout information, roles, and MFA status.
- Shop profile, pickup location, products, stock, orders, QR activity, moderation records, and administrator audit actions.
How we use information
- To create and track pickup orders and let the selected seller prepare them.
- To operate seller profiles, approved public shops, inventory, QR posters, and reports.
- To authenticate accounts, recover access, enforce MFA, prevent duplicate orders, rate-limit abuse, and investigate suspicious activity.
- To maintain service reliability, audit administrator decisions, and comply with applicable legal obligations.
Who receives information
Order contact details are provided to the seller selected by the customer. KasiCart may use hosting, database, email, backup, monitoring, and security providers that process information only to operate the service. Information is not sold. It may be disclosed when required by law, to protect users, or to investigate fraud or security incidents.
Retention
- Completed and cancelled order contact details are anonymized after 730 days. Product, quantity, status, and financial totals may remain in anonymized reports.
- Visitor-level page-view records are removed after 90 days.
- Operational events are normally retained for 90 days and administrator audit records for 365 days.
- Password reset links expire after 30 minutes. Email verification links expire after 24 hours. MFA recovery codes remain until used or replaced.
- Active seller and administrator account information is retained while the account and its legal or operational obligations remain active.
Security
KasiCart uses salted password hashing, administrator MFA, encrypted application secrets, persistent protected key storage, access controls, anti-forgery validation, rate limiting, audit records, TLS-enabled database connections, and encrypted backup procedures. No system can guarantee absolute security, so suspected account or data exposure should be reported promptly.
Your choices and rights
Depending on applicable law, a person may request access, correction, deletion, restriction, or an explanation of information associated with them. A customer should provide the order reference and the phone number used for the order. A seller should contact KasiCart through the support or administrator contact channel published for their account. Requests may require identity verification and may be limited where records must be retained for security, dispute, accounting, or legal reasons.
Cookies and local storage
KasiCart uses essential authentication and selected-shop cookies. Public shop pages use random identifiers for unique-view protection and order continuity. These mechanisms are used to provide and secure the service, not for third-party advertising.
Policy updates
Material changes will be published on this page with a revised effective date. Continued use after an update is subject to the updated policy.
See the KasiCart Terms of Use for marketplace and pickup-order rules.