KINETEX LLP ("Kinetex", "we", "us") is committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use it, how we protect it, and the rights you have under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and other applicable Indian laws.
This policy applies to all Kinetex products including the website at kinetex.co.in, in-store kiosks, the customer mobile app, the operator admin dashboard, and the welcome-display screen.
1. Data Fiduciary details
2. What we collect
(a) Account information
- Name
- Mobile number (verified via OTP)
- Email address (if registered via Google)
- Avatar (if provided by Google)
(b) Transaction information
- Items purchased, quantities, prices, taxes, and timestamps
- Payment method used (UPI, wallet, card) and the masked transaction reference
- Store and kiosk where the transaction took place
- Loyalty points earned and redeemed
- Wallet top-ups and balance changes
(c) Biometric data (face recognition) — only if you opt in
- When you choose to enrol your face for store entry recognition, a single photograph is captured on the kiosk.
- The image is processed locally and converted into a 128-dimensional mathematical embedding — an irreversible numeric fingerprint.
- The original photograph is discarded immediately and never leaves the kiosk.
- Only the embedding is transmitted (over HTTPS) and stored, encrypted at rest, on our servers.
- The embedding cannot be reverse-engineered to reconstruct your face.
(d) Technical & device data
- Device identifiers, IP address, browser/app version, operating system
- Crash reports and diagnostic logs
- Push notification tokens (for the mobile app)
3. How we use your data
- To deliver the Service — process payments, generate receipts, credit loyalty points, fulfil orders.
- To identify you in-store — match a face capture at the entrance against your enrolled embedding, only for stores you have opted into.
- For account security — verify OTPs, detect fraud, prevent unauthorised access.
- For customer support — investigate refund requests, transaction disputes, and complaints.
- For service improvements — aggregated, de-identified analytics on usage patterns.
- For legal compliance — meet our obligations under tax, anti-money-laundering, and consumer protection laws.
We do not sell your personal data to third parties. We do not use your data for behavioural advertising.
4. Lawful bases (DPDP Act §6 & §7)
- Consent — for marketing communications and biometric (face) enrolment.
- Legitimate use — for transaction processing, account management, fraud prevention, and legal compliance.
5. Sharing & disclosure
We share data only with:
- Payment processors (PhonePe Payment Gateway) — to settle transactions. They receive only the data necessary to process the payment.
- SMS / OTP gateway providers (Fast2SMS) — to deliver verification messages.
- Cloud hosting providers (Hostinger, AWS, or equivalent) — who host our infrastructure under standard data-processing agreements.
- The operating Merchant for stores you transact at — they see your name, phone, purchase history at their store, and loyalty status (so they can serve you).
- Law enforcement or regulators — only when legally compelled by a valid order, summons, or DPDP Board notice.
6. Data retention
- Transaction records — retained for 8 years to meet GST/Income Tax record-keeping requirements.
- Account profile — retained while the account is active and for 1 year after deletion request, then purged.
- Biometric embeddings — retained while enrolled; deleted within 7 days of withdrawal of consent.
- Diagnostic logs — retained for 90 days, then automatically purged.
7. Your rights (DPDP Act §11–§14)
As a Data Principal under the DPDP Act, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Correct — request correction of inaccurate or incomplete data.
- Erase — request deletion of your data (subject to legal retention obligations).
- Withdraw consent — for any processing that relies on consent, with effect from the date of withdrawal.
- Grievance redressal — escalate concerns to our Grievance Officer.
- Nominate — designate another individual to exercise your rights in the event of death or incapacity.
You can exercise most rights directly from the Kinetex mobile app (Settings → Privacy → Delete my data / Download my data). For other requests, email grievance@kinetex.co.in. We will acknowledge within 48 hours and resolve within 30 days.
8. Security
We employ industry-standard safeguards including TLS 1.2+ encryption in transit, AES-256 encryption at rest for sensitive fields (face embeddings, payment tokens), Sanctum-based session authentication, role-based access control on the operator dashboard, and a full audit log of all administrative actions. We periodically review our security practices, but no system is perfectly secure — please notify us immediately at grievance@kinetex.co.in if you suspect unauthorised access to your account.
9. Children
The Service is not directed at children under 18. We do not knowingly collect data from minors. If we become aware that we have collected data from a minor without verifiable parental consent, we will delete it.
10. International transfers
Your data is primarily stored on servers located in India. We do not transfer personal data to jurisdictions notified as restricted by the Central Government under §16 of the DPDP Act.
11. Cookies
Our website uses only essential cookies for session management. We do not use third-party advertising or tracking cookies.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified through the mobile app or by email. The "Last updated" date at the top of this page reflects the most recent revision.
13. Contact
Questions, requests, or grievances: grievance@kinetex.co.in · See the full Contact page for postal address and phone.