Legal · CommerceOS by Bizzar Marketing

Privacy Policy

This policy explains what data CommerceOS collects, why, and how it is handled — both for merchants who run stores on the platform and for shoppers who buy from those stores.

Last updated July 13, 2026

1. Who we are

The CommerceOS platform at commerceos.online is operated by Bizzar Marketing, Murgasole, Asansol – 713303, West Bengal, India. For a merchant’s own account data we act as the data controller. For shopper data inside a merchant’s store (customers, orders) we act as a processor on the merchant’s behalf — the merchant is the controller of their store’s data.

2. Data we collect

  • Merchant accounts — name, email, password (stored as a salted hash), store settings.
  • Store data — catalog, content, media, themes, orders, and customer records created by the store.
  • Shopper data — when you buy from a store: name, email, shipping address, order contents; when you create a customer account: your sign-in details.
  • Usage data — page views and basic analytics for a store, collected first-party for the merchant’s own dashboard. We do not sell analytics data or share it across stores.

3. Payments

Card details never touch our servers. Payments are processed by payment providers (such as Stripe or Razorpay) through their hosted, PCI-compliant fields; we receive only the transaction result and reference, never the card number or CVV.

4. Cookies

We use strictly necessary cookies: session cookies to keep merchants and shoppers signed in, and cart/wishlist state on storefronts. We do not use third-party advertising cookies.

5. How data is used

  • To provide and operate the service — rendering storefronts, processing orders, sending transactional email (order confirmations, sign-in codes).
  • To secure the platform — fraud and abuse prevention, audit logs of dashboard actions.
  • To improve the product — aggregate, non-identifying usage measurement.

We do not sell personal data.

6. Isolation and security

Every store’s data is isolated at the database layer (row-level security per tenant). Access is encrypted in transit (TLS everywhere). Backups run automatically. Staff access to production data is restricted and logged.

7. Retention

Store data is kept for as long as the store exists. When a store is deleted, its data is removed from production systems and ages out of backups on the backup rotation schedule. Legal or accounting records may be retained where required by law.

8. Your rights

Merchants can export their data and request account deletion. Shoppers should contact the store they purchased from for requests about their order data; if you contact us directly we will route the request to the merchant and assist where we are the processor.

9. Data location

Production data is hosted on servers operated by our infrastructure providers; content is delivered through a global CDN. We choose providers with strong security practices and process data only to provide the service.

10. Changes

We will update this policy as the product evolves and announce material changes on the website. The “last updated” date above reflects the current version.

11. Contact & grievances

Privacy questions, requests, or grievances: [email protected] or +91 97492 96134. By post:

Bizzar Marketing
Murgasole, Asansol – 713303
West Bengal, India