Kanchuki ("we", "us") provides an AI-powered catalog platform for clothing retailers in India. This policy explains what we collect from retailers and their customers, why, and how it's handled.
What we collect
- Retailer account data: phone number (for OTP login, verified via our SMS provider MSG91), business name, address, and GST details (for invoicing).
- Shop location (optional): during onboarding a retailer may tap “Get Location” to capture their shop's GPS coordinates. This is a one-time foreground request — there is no background tracking. The coordinates are used to pre-fill the address and to show a “Get directions” link on the retailer's public catalog page. Skip the button and no location is collected.
- Product photos: uploaded by retailers to build their catalog. Photos are processed by AI vision providers (e.g. Anthropic Claude, OpenAI, Google Gemini) to auto-tag category, color, and fabric, and by AI image- and video-generation providers to remove or replace backgrounds, generate studio-style catalog images, and produce short promotional videos (photo slideshows or AI-generated motion) that a retailer may publish to their storefront or connected social accounts.
- Design reference photos: retailers may upload design images (for example “Suits Designs” and other design galleries) that are watermarked and shown on their public storefront. These are handled like product photos.
- KYC documents: GST certificates and Aadhaar card images you upload for seller verification. They are stored securely, used only for verification and GST invoicing, and visible only to you and our verification team.
- Customer data: name, phone number, and style/budget preferences captured by a retailer when adding a customer to their CRM, or when you share your details, submit a review, or send an enquiry on a store's Kanchuki catalog page.
- Shopper profile (optional): if you create a Kanchuki shopper profile, we store your phone number, style preferences, and which products you view and favourite, to personalise recommendations across participating stores. This is consent-based; you can turn off personalisation, export your data, or delete the profile at any time from My Profile.
- WhatsApp messages: if a retailer enables WhatsApp catalog sync or messaging, product updates are sent to you via Meta's WhatsApp Business Cloud API.
- Payment data: processed directly by Razorpay; Kanchuki does not store card or UPI credentials.
- AI Stylist conversations: messages you type to the AI Stylist chat are sent to Anthropic Claude to generate product recommendations. They are used only to answer that conversation and are not linked to your name unless you've shared it with the store.
- Reviews: a review you submit, including your name if you provide one, is displayed publicly on that product's page. Your phone number is never shown publicly.
How we use it
To operate the catalog, customer CRM, WhatsApp collection links, storefront, and AI features a retailer has enabled — and nothing beyond that. We do not sell personal data. Some AI processing (photo tagging, image generation, the AI Stylist chat) is performed by providers located outside India; we only send what's needed for that specific feature.
Cookies & local storage
We use your browser's local storage (not tracking cookies) to remember that you've already shared your details with a store, so you're not asked again, and to prefill forms like reviews and enquiries. Clearing your browser data resets this.
Your rights
You can ask us to access, correct, or delete the personal data we hold about you by emailing privacy@kanchuki.app. We will respond within a reasonable time, subject to the retention obligations described below. Kanchuki retailer accounts are for users 18 and older; if a minor's details were shared without a parent or guardian's consent, contact us to have them removed.
Third parties we share data with
- AI vision and image-generation providers, to tag product photos and generate background-cleaned and studio-style catalog images.
- Cloudflare R2, to store product and KYC images.
- Razorpay, to process payments.
- Supabase, for authentication and database hosting.
- MSG91, to send OTP and transactional SMS.
- Meta (WhatsApp Business Cloud API), where a retailer enables WhatsApp catalog sync or messaging.
- Where a retailer connects their own Google Business Profile, Facebook, or Google Ads account, product data may be sent to those platforms using the retailer's own credentials.
Deletion & retention
Deleted products, customers, and photos are soft-deleted immediately and permanently purged after 15 days. A copy is kept in a write-only backup vault for that period in case of accidental deletion, then it is purged too.
GST numbers, KYC documents, and invoicing records are retained as required by Indian tax law and our record-keeping obligations — including after account deletion — as described on our account deletion page.