MySoMart Privacy Policy

MySoMart is currently operated by the verified individual developer shown on the MySoMart Google Play listing, as an individual developer. This policy explains the actual information handling for the customer website and Android application.

Effective: 21 August 2026

Information we handle

We handle the name, mobile number, PIN hash and verification status used to create and secure a customer account; saved home, society and delivery address details; and location coordinates when a customer grants location access so that we can determine service availability and nearby stores.

When an order is placed, we handle its products, quantities, prices, delivery address and coordinates, store, status, notes, payment method, payment status and any payment reference submitted by the customer. We also handle cancellation reasons, store responses and request timestamps, profile changes, product suggestions, feedback and support communications.

Authentication cookies and rotating session records contain identifiers, expiry information, IP address and browser user-agent. Web Push, when enabled, stores a browser/device subscription endpoint. Security controls may temporarily process OTP or verification codes, failed-login counters and rate-limiting identifiers.

Analytics and device information

When Google Analytics is configured, the website sends page views and app interactions such as searches, product views, cart actions, checkout, purchase and location-set events to Google. Precise location coordinates are not included in analytics events. The current implementation may send a customer identifier, and Google may process device, browser, network and approximate-location information under its own terms. MySoMart also records limited campaign interactions in its own systems.

How information is used and disclosed

Information is used to authenticate customers, determine nearby availability, fulfil and support orders, provide payment and refund status, deliver notifications, prevent abuse and fraud, resolve disputes, improve the service, and meet accounting, tax and legal duties.

Order and contact details are available to the store and staff responsible for fulfilment and support. Information is also processed by infrastructure and service providers needed to operate the service, including hosting/database providers, Google Analytics when enabled, browser push services, and payment applications or providers chosen during checkout. We do not describe operational disclosure to stores or processors as a sale of personal information.

Cookies, permissions and choices

Strictly necessary HTTP-only cookies maintain signed-in sessions. Analytics may use browser storage or cookies when enabled. Location and notification access are optional device/browser permissions; denying them limits nearby-store detection or alerts but does not grant MySoMart access. Permissions can be changed in browser or Android settings.

Retention and security

Active profile and order information is kept while needed to provide the service. Completed orders and associated payment, refund, settlement, Platform Fee, invoice and other financial records may be retained up to 8 years from the end of the relevant financial year where necessary for accounting, tax, fraud prevention, dispute resolution, audit or law.

That period does not apply to all customer data. OTPs and verification codes expire quickly; sessions and rate-limit records use shorter security-based lifetimes; temporary checkout/location state is retained only as operationally required. A legal hold may extend relevant records during an active dispute, chargeback, investigation, audit, tax proceeding or legal matter.

MySoMart uses HTTPS in production, access controls, hashed PINs and restricted session cookies. No internet service can promise absolute security.

Account and data deletion

Customers can permanently delete their account in Customer Profile or request deletion at /account-deletion. Deletion revokes sessions and removes profile, contact, address, location, push and non-required support data. Retained order/financial records are detached from the customer’s identity and delivery details are anonymized, while minimum transaction fields may remain for the purposes above. Deletion is not account suspension and cannot be undone.

Customer requests and grievances

Subject to applicable law, customers may request information about their personal data, correction of inaccurate profile details, deletion of data that is no longer required, or review of a privacy grievance. We may verify account ownership before acting on a request and may retain limited records where law, fraud prevention, accounting or an active dispute requires it.

Contact and policy changes

For privacy, personal-data and deletion matters, email privacy@mysomart.com. For application and order support, email support@mysomart.com. Platform grievances may be sent to MySoMart grievance support at support@mysomart.com.

We will update this page when practices or the legal operator change and revise the effective date where appropriate.