Privacy Policy
Last updated 3 August 2026
This explains what personal data GoOak handles, why, and what you can do about it. GoOak is operated by OAKSOL TECHNOLOGIES PRIVATE LIMITED.
1. Two different relationships
This matters, because it decides who answers to you:
- If you run a store on GoOak, we hold your data as the controller. This policy describes what we do with it.
- If you bought something from a store on GoOak, the merchant is the controller of your data. We process it on their instructions, as their service provider. For requests about your orders, contact the merchant first; we will help them respond.
2. What we collect
From merchants
- Name, email address, phone number and password (stored only as a bcrypt hash — we cannot read it).
- Business details: trading name, registered company name, business address, tax registration number, declared annual turnover.
- Store configuration, product catalogue, and the content you publish.
- Billing and subscription records.
From shoppers
- Name, email address, phone number, and delivery and billing addresses.
- Order history, and any tax registration number given for a business purchase.
- Account credentials, where an account was created (again, the password only as a hash).
Automatically
- Technical data needed to serve and secure a request: IP address, browser type, timestamps and error logs.
- Cookies — see section 6.
We never receive card numbers.Payment details are entered with the payment provider and do not pass through our servers. What we store against an order is the provider’s transaction reference and the method used, so the order can be reconciled and refunded.
3. Why we use it
- To provide the service — hosting the store, processing orders, moving stock, arranging shipping. This is performance of our contract with you.
- To meet legal obligations — issuing tax invoices, keeping accounting records, and reporting invoices to a tax authority where the law requires it.
- To keep the platform safe — detecting fraud, abuse and unauthorised access. This is our legitimate interest in a service that is not being attacked.
- To support you — answering the messages you send us.
- To improve the product — aggregated usage patterns, where analytics are enabled.
We do not sell personal data, and we do not share it for anyone else’s advertising.
4. Who else sees it
- Payment providers — Razorpay and Stripe, to take payment and handle refunds and disputes.
- Delivery partners — the courier a merchant chooses, given the address needed to deliver the parcel.
- Infrastructure providers — hosting and email delivery, under contracts that bind them to confidentiality.
- Tax authorities — where a merchant’s country requires invoices to be reported.
- Authorities and advisers — where we are legally required to disclose, or need to establish or defend a legal claim.
5. Where it is kept, and how it is separated
Data is stored on servers in India. Where a payment provider or delivery partner operates elsewhere, that transfer is covered by the safeguards in our agreement with them.
Every store’s data lives in its own separate database schema.One merchant’s customers, orders and products are not in a shared table with another merchant’s, and a request is bound to a single store before it can read anything. That is an architectural boundary, not a filter applied after the fact.
6. Cookies
- Session cookie — set when you sign in. It is httpOnly, so no script can read it, and it is what keeps you signed in. The service cannot work without it.
- Session hint — a companion cookie holding the value
1and nothing else. It exists so a page can tell whether to bother checking your session, and it identifies no one. - Cart and preferences — remembering a basket and a chosen currency.
- Analytics — only when a merchant or the platform has configured a Google tag. Not set otherwise.
7. How long we keep it
- Account and store data — while the store is open, and for a limited period afterwards so it can be exported or restored.
- Orders and invoices — for the period tax and accounting law requires, which is longer than the account itself and is not something we can shorten on request.
- Logs — a short rolling window, for security and debugging.
8. Your rights
Depending on where you live, you can ask us to:
- tell you what data we hold about you, and give you a copy;
- correct data that is wrong or incomplete;
- delete data, where we are not required to keep it;
- restrict or object to particular uses;
- withdraw consent you previously gave, without affecting what was done before.
Shoppers should ask the merchant they bought from, since the merchant controls that data. If you are a merchant, or the merchant cannot be reached, write to us at support@gooak.shop.
If you are in India, the Digital Personal Data Protection Act 2023 applies and you may complain to the Data Protection Board. If you are in the EEA or UK, the GDPR applies and you may complain to your local supervisory authority.
9. Security
Passwords are hashed, sessions use httpOnly cookies, traffic is encrypted in transit, and access to production systems is restricted. No system is perfectly secure, but if a breach affects your data we will notify you and the relevant authority as the law requires.
10. Children
GoOak is for businesses and adult shoppers. We do not knowingly collect data from children. If you believe a child has given us data, write to us and we will remove it.
11. Changes
We will post any update here and change the date at the top. Where a change materially affects you, we will give notice before it takes effect.
12. Contact
Write to support@gooak.shop for any question about this policy or about data we hold.