Privacy Policy

Sebretail India Private Limited (operating the MarCat brand) Last updated: 9 June 2026

1. Introduction

This Privacy Policy explains how Sebretail India Private Limited ("Sebretail", "we", "us", "our"), the company that owns and operates the MarCat brand and the MarCat suite of products, collects, uses, stores, shares, and protects personal data when you use:

  • The MarCat marketing website at marcat.in
  • The MarCat Retailer Portal — accessible as a web application at app.marcat.in and as the MarCat Retailer Android application (package in.marcat.retailer) distributed via Google Play — including the in-portal point-of-sale, inventory, purchase, promotions, shop management, reporting, and WhatsApp campaign modules
  • The consumer Shop experience — accessible at app.marcat.in/shop/... and as the MarCat Android application (package in.marcat.app) distributed via Google Play
  • The MarCat Brand Intelligence Portal, Leotor Supplier Portal, Salesman SFA application, and Admin tooling
  • Any WhatsApp Business messaging delivered through MarCat infrastructure on behalf of a retailer that has connected a WhatsApp Business Account

Sebretail acts as a Data Fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") for personal data we collect directly. For personal data we process on behalf of our retailer customers (the data of their own end-customers), we act as a Data Processor on the retailer's documented instructions.

By using the MarCat services you agree to the practices described in this Policy.

2. Who we are and how to contact us

Sebretail India Private Limited is the legal entity providing these services. MarCat, Pantrix, Leotor, and the related portal names are product brands operated by Sebretail.

For privacy questions, data principal requests, or grievance redressal, contact our Grievance Officer at:

  • Email: privacy@marcat.in
  • Registered address: Shop G.F-06, Prahladnagar, B/H Titanium City Center, Jivraj Park, Ahmadabad City, Ahmedabad - 380051, Gujarat, India
  • Grievance Officer: Swarbhanu Gupta, Director, Sebretail India Private Limited

We acknowledge grievances within 7 days and resolve them within 30 days as required by §13 of the DPDP Act.

3. The personal data we collect

3.1 Retailer account data

When a retailer signs up to use the MarCat Retailer Portal, we collect:

  • Business name, legal entity type, GSTIN, and registered address
  • Authorised user names, email addresses, phone numbers, and passwords (stored only as salted hashes)
  • Store configuration including SKU catalog, opening hours, payment methods accepted, and chosen subscription tier
  • Hardware-tier signals (whether a point-of-sale workstation has registered with the account) used for billing slot enforcement
  • Subscription, invoice, and payment status

3.2 End-customer data captured through retailer use

Through a retailer's use of MarCat — at the point of sale, on the consumer Shop portal, or via WhatsApp campaigns — we process personal data of the retailer's own customers. This may include:

  • Phone number, name, and optional date of birth provided at billing or signup
  • Purchase history (bill items, totals, payment mode, store, timestamp)
  • Loyalty balances and redemption records
  • Delivery addresses, where provided for shop orders
  • WhatsApp opt-in status and consent records

The retailer is the Data Fiduciary for this data. Sebretail processes it strictly as a Data Processor on the retailer's documented instructions, except where Indian law requires us to retain or disclose it.

3.3 WhatsApp Business Platform data

If a retailer connects a WhatsApp Business Account ("WABA") to MarCat — either by entering an access token, or, going forward, through Meta's Embedded Signup flow once Sebretail is a confirmed Meta Tech Provider — we receive and process:

  • The retailer's WABA identifier, registered phone number identifiers, and business display name
  • System-user access tokens, refresh tokens, and webhook verification tokens issued by Meta
  • Message templates the retailer creates, including template content and Meta-assigned approval status
  • Inbound and outbound WhatsApp messages associated with the WABA: message identifiers, timestamps, sender and recipient phone numbers in E.164 format, message body, media URLs (Meta-hosted), template payloads, button payloads, message status events (sent / delivered / read / failed), and conversation-billing attributions returned by Meta

Message content and metadata are stored in the Sebretail-operated MarCat database to power retailer-facing features (campaign reporting, the message inbox, conversion attribution). Retailers may configure shorter retention windows for message content via the Retailer Portal administration screens.

3.4 Payment and billing data

For subscription billing and consumer order checkout, we use Razorpay Software Private Limited ("Razorpay") as our payment processor. Sebretail does not store full card numbers or CVVs. We retain Razorpay transaction identifiers, transaction amounts, payment statuses, payment-method category (UPI / card / netbanking), and the last four digits of cards purely for transaction reconciliation and any refund required by law or by these terms.

3.5 Technical and usage data

When you use MarCat we automatically collect device type, browser identifier, IP address, session timestamps, feature interaction events, and error traces. This data is used for security, abuse prevention, capacity planning, and product improvement.

3.6 Cookies and similar technologies

The MarCat Retailer Portal and Shop portal use first-party session cookies and browser local storage to keep you signed in and to remember your in-app preferences. We do not use third-party advertising cookies. We do not track you across unrelated websites. We do not use cross-site tracking pixels.

3.7 Mobile application device permissions

The MarCat Android applications request device permissions only as needed to deliver the features described below. Each permission is requested at the time the corresponding feature is first invoked; you may decline or later revoke any permission via Android Settings → Apps without losing access to other features that do not require that permission.

MarCat Retailer Android application (in.marcat.retailer)

Permission What it is used for
Internet, Network state Communicating with MarCat servers; detecting connectivity for the offline-resilient point-of-sale mode
Camera Scanning product barcodes at the point of sale and during purchase receipt; capturing product master images and purchase-receipt photos. Barcode scans are decoded on-device and only the decoded value is transmitted; product master photos and purchase-receipt photos, when the cashier explicitly captures one, are uploaded to MarCat servers and associated with the corresponding record
Bluetooth (scan, connect) Discovering and connecting to paired Bluetooth thermal printers for printing customer bills. The neverForLocation declaration is set so this permission is not used to derive location
Location (coarse and fine) Capturing the store's location during owner onboarding ("drop a pin where I am standing") and, in future versions, attaching delivery driver location to dispatched orders. We do not continuously track device location
Notifications, Notification policy Delivering incoming-order alerts and other operational notifications. Notification-policy access is requested so the retailer may grant our "incoming order" channel permission to bypass Do-Not-Disturb — this is necessary because an unmissed order is a contractual expectation between the retailer and the consumer
Vibrate, Wake lock, Foreground service (data sync type) Sustaining the audible alarm pattern of the OrderAlertService and maintaining the Firebase Cloud Messaging data-message handler in the foreground until the cashier acknowledges the incoming order

MarCat Shop Android application (in.marcat.app)

Permission What it is used for
Internet Communicating with MarCat servers
Location (coarse and fine) Filtering the discovery feed to stores that deliver to your area. We do not continuously track device location. Shop location data is processed in-app and on MarCat servers only; it is not shared with third parties for advertising or analytics
Notifications, Vibrate Delivering order status updates (confirmed, dispatched, delivered, cancelled). Today these are local in-app notifications triggered by the application's polling of MarCat servers; a future release may migrate to Firebase Cloud Messaging under the handling rules described in Section 3.8

In addition to the device permissions above, the MarCat Shop application collects personal data described in Section 3.2 (order data, including delivery address), Section 3.4 (payment metadata via Razorpay), and Section 3.9 (Google account identity, where you sign in with Google).

3.8 Push notifications via Firebase Cloud Messaging

The MarCat Retailer Android application uses Google Firebase Cloud Messaging ("FCM"), operated by Google LLC, to deliver server-initiated push messages. When the application is first launched on a device, Google issues a device-bound FCM token; Sebretail stores this token associated with the retailer's user account so that order, payment, and inventory alerts can be addressed to the correct device.

FCM message payloads we send are limited to operational metadata (alert type, the identifier of the affected order or inventory item, and a short human-readable label) — not personal data of end-customers, not message content, and not financial data beyond an amount label. When a token is revoked or replaced by Android, the prior token is deleted from our store within seven days of the next token refresh.

The MarCat Shop Android application may, in future releases, use FCM for transactional order-status notifications under the same handling rules.

3.9 Third-party authentication providers

The MarCat Shop Android application and the consumer Shop web experience allow you to sign in using Google. If you choose to do so, Google shares with Sebretail your email address, display name, profile picture URL, and a unique Google account identifier. We use this information solely to create or sign you in to your MarCat Shop account on the retailer's storefront you are visiting. We do not request access to your Google contacts, calendar, drive, or any other Google service data. You may revoke MarCat's access at any time from your Google account at myaccount.google.com → Security → Third-party access.

4. How we use personal data

We use personal data for the following purposes:

Purpose Legal basis (DPDP Act)
Providing the MarCat platform features you signed up for Performance of contract
Processing payments and managing subscriptions Performance of contract
Sending WhatsApp messages from a retailer's WABA to that retailer's end-customers Performance of the retailer's documented instruction; MarCat acts as Processor
Sending transactional emails (receipts, account alerts, security notifications) Performance of contract and legitimate use
Sending push notifications via Firebase Cloud Messaging about orders, payments, and inventory events to the MarCat Android applications Performance of contract
Authenticating users who choose to sign in with Google on the MarCat Shop application Performance of contract; consent for the Google account connection
Marketing communications about new MarCat features Consent — withdrawable at any time
Detecting fraud and abuse, and securing the platform Legitimate interest in the integrity of the service
Complying with tax, GST, and regulatory obligations Legal obligation
Producing anonymised, aggregated analytics for internal product decisions Legitimate interest

We do not sell personal data. We do not use personal data, including WhatsApp message content, to train foundation AI models or for advertising purposes. We do not share one retailer's customer list with another retailer.

5. WhatsApp Business Platform — specific data handling

This section describes how Sebretail, operating the MarCat platform, handles data flowing through the Meta WhatsApp Business Platform, as required for our role as a Meta Tech Provider.

5.1 What Meta sends us

When a retailer connects their WABA to MarCat — and only with that retailer's explicit consent — Meta provides Sebretail with system-user access tokens, the WABA identifier, phone number identifiers, business verification status, and webhook events about messages and account changes.

Sebretail's WhatsApp Business Platform integration requests the following Meta permissions: whatsapp_business_messaging (to send and receive messages on the retailer's behalf), whatsapp_business_management (to manage templates, phone-number profiles, and related WABA configuration), and business_management (to read the connected Business Manager assets the retailer has authorised). We do not request access to a retailer's commerce catalogs, ad accounts, or other business assets beyond the connected WABA.

5.2 What we store

We store the tokens necessary to send messages and receive webhooks on the retailer's behalf, encrypted at rest. We store message metadata and content as described in Section 3.3 of this Policy.

5.3 What we do not do

  • We do not send WhatsApp messages from a retailer's WABA except in response to actions initiated by that retailer (either directly via the Retailer Portal interface, or via automated rules the retailer has configured).
  • We do not access message threads from WABAs the retailer has not connected to MarCat.
  • We do not share one retailer's WhatsApp data with another retailer.
  • We do not use WhatsApp message content to train foundation AI models. Where AI features process message content (for example, to suggest a reply or summarize a conversation), Sebretail uses Anthropic PBC's commercial large-language-model inference API; message payloads are sent per-request and, under Anthropic's commercial terms, are not retained beyond what is needed to return the response and are not used for model training.
  • We do not sell WhatsApp data to any third party.

5.4 Retailer revocation

A retailer may disconnect MarCat from their WABA at any time, either from inside the MarCat Retailer Portal, or directly via Meta Business Manager → Connected Apps. On revocation:

  • Sebretail ceases all sending from that WABA immediately
  • We delete stored access tokens within 7 days
  • We retain historical message records only for the period required for billing reconciliation (typically up to 90 days), unless the retailer requests earlier deletion

5.5 End-Customer deletion requests

An End-Customer who has exchanged WhatsApp messages with a retailer through MarCat may request deletion of their WhatsApp message history with that retailer. Because the retailer is the Data Fiduciary for End-Customer data, the End-Customer should write to the retailer in the first instance. Sebretail will support the retailer in fulfilling such requests within the timelines under the DPDP Act. If the retailer does not respond within 30 days, the End-Customer may escalate to privacy@marcat.in and Sebretail will, in coordination with the retailer or where Sebretail's own role permits, give effect to the deletion request.

6. Sharing of personal data

We share personal data only with the following categories of recipients:

  • Meta Platforms Ireland Limited — for the operation of WhatsApp Business Platform messaging that the retailer has authorised
  • Razorpay Software Private Limited — for payment processing
  • Google LLC — for Firebase Cloud Messaging push delivery to the MarCat Retailer Android application (device token and operational message metadata only), and for Google Sign-In authentication on the MarCat Shop application (email, display name, profile picture URL, and Google account identifier only)
  • Anthropic PBC — for per-request large-language-model inference on selected MarCat features (including WhatsApp reply suggestions and conversation summaries that a retailer has explicitly enabled); message payloads sent to Anthropic are not retained beyond the response and are not used for model training under Anthropic's commercial terms
  • Supabase Inc. — our infrastructure provider, which hosts the MarCat database, authentication, and storage services
  • Vercel Inc. — which hosts the MarCat application frontends
  • Service providers under written contract with Sebretail — for narrowly scoped and necessary support, deliverability, and security functions
  • Government, regulators, and law enforcement — where required by a legally valid order under Indian law

We do not share personal data with advertisers. We do not sell personal data to data brokers or list-purchasers.

7. International transfers

Some of the providers listed in Section 6 operate infrastructure outside India. Where personal data is transferred outside India, Sebretail relies on the lawful transfer exceptions under §16 of the DPDP Act and on contractual safeguards with the receiving provider. The MarCat primary database is hosted on Supabase infrastructure in the AWS ap-south-1 (Mumbai) region. Vercel edge functions that serve marketing-website and portal traffic may execute in multiple regions worldwide based on the requesting user's proximity; no end-customer personal data is stored at Vercel edge nodes.

8. Retention

We retain personal data for the periods listed below, unless a longer period is required by law:

Category Retention period
Retailer account and subscription records Lifetime of the account + 7 years after closure (tax and GST compliance)
End-customer purchase and bill records Lifetime of the retailer's MarCat account + 7 years (the retailer's statutory tax-record obligation)
WhatsApp message content and metadata 90 days by default; the retailer may configure this lower; retained longer only where required for active billing reconciliation
Meta access tokens and webhook secrets While the integration is active; deleted within 7 days of revocation
Firebase Cloud Messaging device tokens (MarCat Retailer Android app) While the app remains installed and signed in; rotated tokens replace prior tokens within 7 days
Google Sign-In identity records (Shop) Until the customer deletes their MarCat Shop account or revokes MarCat's Google access
Application logs and error traces 30 days
Marketing email subscriber list Until consent is withdrawn

When the retention period ends, we either delete personal data or irreversibly anonymise it.

9. Your rights as a data principal

If you are a data principal under the DPDP Act, you have the rights to:

  • Access the personal data we hold about you and information about how we use it
  • Correct, complete, or update inaccurate personal data
  • Erase personal data, subject to the retention requirements in Section 8
  • Withdraw consent at any time where processing is based on consent
  • Nominate another individual to exercise these rights in the event of your death or incapacity — to register a nominee, write to privacy@marcat.in with the nominee's full name and contact details; we will acknowledge the nomination within 7 days and record it against your account
  • Grievance redressal through our Grievance Officer (Section 2)

To exercise these rights, write to privacy@marcat.in from the email address associated with your account. We will respond within the statutory timeframes.

If you are a customer of a retailer that uses MarCat (for example, you shop at a kirana that uses MarCat to issue your bill or send you WhatsApp updates), please direct your data requests in the first instance to that retailer. Sebretail will support the retailer's response to your request in our capacity as Data Processor.

10. Security

Sebretail protects personal data through the following measures:

  • TLS encryption in transit for all client-server and server-Meta communications
  • Encryption at rest for the primary database and backups
  • Row-Level Security policies enforcing per-tenant isolation across retailers
  • Salted and hashed password storage; we never store plaintext passwords
  • Restricted, audited access for MarCat personnel to production systems
  • Webhook signature validation for all inbound Meta events
  • Regular security review of source code and third-party dependencies

No security control is absolute. In the unlikely event of a personal data breach affecting your data, we will notify the affected data principal, the Retailer (where the breach concerns End-Customer data the Retailer is the Data Fiduciary for), and the Data Protection Board of India, in each case without undue delay and in any event within 72 hours of becoming aware of the breach, in line with §8(6) of the DPDP Act and the DPDP Rules.

11. Children

The MarCat services are not directed to children under the age of 18. Sebretail does not knowingly collect personal data from children. If you believe we hold personal data of a child, write to privacy@marcat.in and we will delete it.

12. Changes to this Policy

Sebretail may update this Policy from time to time. The "Last updated" date at the top reflects the current version. Material changes will be notified in-app or by email to the registered account contact at least 30 days before they take effect.

13. Contact

For any question about this Privacy Policy or the personal data Sebretail holds about you, write to privacy@marcat.in.

The canonical version of this Privacy Policy is published at https://marcat.in/legal/privacy. The version dated at the top of this document replaces all prior versions.