Khojj ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and safeguard your information when you use the Khojj platform, including our website and mobile applications.
1. Information We Collect
Information You Provide
- Account information: Name, email address, phone number, and password when you create an account.
- Profile information: Profile photo, bio, location, and language preferences.
- Seller information: Business name, tax identification numbers, bank account or payment details for payouts.
- Transaction information: Purchase history, shipping addresses, billing details, and payment method information.
- Communications: Messages between buyers and sellers, support requests, and feedback.
Information We Collect Automatically
- Device information: IP address, browser type, operating system, device identifiers.
- Usage data: Pages visited, search queries, items viewed, click patterns, and time spent on pages.
- Location data: Approximate location based on IP address; precise location only with your consent.
2. How We Use Your Information
- To provide, maintain, and improve the Khojj platform and its features.
- To process transactions, including payments and refunds.
- To personalize your experience, including product recommendations and search results.
- To communicate with you about orders, account updates, and promotional offers (with opt-out options).
- To detect and prevent fraud, abuse, and security threats.
- To comply with legal obligations and enforce our Terms of Service.
- To analyze usage patterns and improve our services.
3. How We Share Your Information
We do not sell your personal information. We may share it in these circumstances:
- With other users: Seller information is visible to buyers on store pages; buyer shipping details are shared with sellers to fulfill orders.
- Service providers (sub-processors): See the table below for the third parties we currently rely on to operate the Platform. They process data only on our behalf under contract.
- Legal requirements: When required by law, court order, or government request, or to protect the rights and safety of Khojj and its users.
- Business transfers: In the event of a merger, acquisition, or sale of assets, user data may be transferred as part of the transaction.
| Sub-processor | Purpose | Region |
|---|
| Stripe, Inc. | Payments, payouts, fraud prevention | US, global |
| Vercel, Inc. | Hosting, edge delivery, request logs | US, global |
| Neon (Databricks) | Managed PostgreSQL database | US |
| Resend | Transactional email (verification, receipts, refund updates) | US |
| Google LLC | OAuth sign-in (only when you choose "Sign in with Google") | US, global |
4. Data Retention
We retain your personal information for as long as your account is active or as needed to provide services. After account deletion, we may retain certain data for up to 3 years to comply with legal obligations, resolve disputes, and enforce agreements. Transaction records may be retained longer as required by tax and financial regulations in the applicable jurisdiction.
5. Legal Bases (GDPR)
If you are in the EEA, UK, or Switzerland, we process your personal data under these legal bases:
- Performance of a contract — to operate your account, process orders, issue tickets, deliver refunds.
- Legitimate interests — to keep the Platform secure, prevent fraud, improve features, and communicate transactional updates.
- Consent — for optional analytics cookies, marketing email, and any precise-location data.
- Legal obligation — to comply with tax, accounting, anti-money-laundering, and regulator requirements.
You may withdraw consent at any time without affecting prior processing.
6. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of your personal data.
- Correction: Update or correct inaccurate information.
- Deletion: Request deletion of your personal data, subject to legal retention requirements.
- Portability: Receive your data in a structured, machine-readable format. Use the "Download your data" button on the Account page.
- Opt-out: Unsubscribe from marketing emails and adjust notification preferences.
- Restriction / objection: Limit or object to processing of your data in certain circumstances.
- California residents (CCPA/CPRA): You have the right to know what we collect, delete it, correct it, and to opt out of any "sale" or "sharing" — Khojj does not sell or share personal information for cross-context behavioural advertising. We honour Global Privacy Control (GPC) signals.
- Right to lodge a complaint: EEA/UK users may complain to their local data-protection authority.
To exercise any of these rights, contact us at privacy@khojj.com. We respond within 30 days (45 days for CCPA, with one allowed extension where necessary).
7. Cookies & Tracking Technologies
We use cookies and similar technologies to:
- Essential cookies: Keep you logged in and enable core platform functionality.
- Analytics cookies: Understand how users interact with the Platform to improve our services.
- Preference cookies: Remember your settings, language, and currency preferences.
- Marketing cookies: Deliver relevant advertisements (with your consent where required).
You can manage cookie preferences through your browser settings or the consent banner. See our Cookie Policy for the full list. Disabling strictly-necessary cookies will break sign-in and checkout.
8. International Data Transfers
Khojj operates across multiple countries including the United States, United Kingdom, Australia, and Nepal. Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) for transfers from the EEA/UK, and compliance with applicable data protection laws in each jurisdiction.
9. Children's Privacy
Khojj is not intended for children under 18. We do not knowingly collect personal information from children. If you believe a child under 18 has provided us with personal information, please contact us at privacy@khojj.com, and we will promptly delete such information.
10. Security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, access controls, and regular security audits. However, no method of transmission or storage is 100% secure. We encourage you to use strong passwords and enable two-factor authentication.
11. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, contact us at: