Privacy Policy
Last updated: September 2026
This Privacy Policy describes how KRITO ("we," "us," or "our") collects, processes, stores, and protects personal information when you visit our website, communicate with us, or purchase our digital music products. We are committed to protecting your privacy in full compliance with the Information Technology Act, 2000, the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011, and the Digital Personal Data Protection (DPDP) Act.
1. Information We Collect
When you browse or purchase from our website, we collect only the necessary information required to process and fulfill your order:
- Contact Information: Your name and email address (mandatory for sending digital download links and purchase receipts).
- Order & Billing Details: Billing country, state, city, and PIN code required for digital invoicing, taxation, and transaction accounting.
- Technical & Log Data: Internet Protocol (IP) address, browser specifications, operating system, and timestamp data captured automatically for fraud prevention, server security, and system stability.
2. Payment Information & Direct UPI Security
We do NOT collect, store, or process any sensitive financial credentials (such as your private UPI PIN, net banking passwords, or bank passwords) on our servers. You complete transactions directly inside your authorized UPI application (Google Pay, PhonePe, Paytm, BHIM) on your own device.
All transactions are verified using official 12-digit NPCI/UPI transaction UTR reference numbers. Website communications and payment instructions are protected with industry-standard 256-bit SSL encryption to ensure end-to-end data security.
3. How We Use Your Information
We use your personal data strictly for legitimate business purposes:
- To execute transactions and deliver your digital download links instantly via email
- To provide dedicated customer service regarding download issues, license rights, or inquiries
- To send order confirmation receipts, payment invoices, and essential product updates
- To monitor website performance, detect security incidents, and prevent fraudulent transactions
4. Data Sharing & Third-Party Services
We respect your privacy. We do NOT sell, rent, or trade your personal information to advertisers or data brokers. We share personal data solely with trusted third-party service providers who help us operate our store under strict data confidentiality obligations:
- Direct Banking & UPI Rails: For direct interbank UPI settlement verification and order authorization
- Secure Cloud Hosting & Email Infrastructure: For delivering high-speed digital audio files and automated confirmation receipts
- Law Enforcement / Regulatory Authorities: Only when strictly required by applicable Indian laws or valid court orders
5. Cookies & Tracking Technologies
Our website utilizes essential first-party cookies necessary for core shopping functionalities (such as maintaining items in your shopping cart across sessions). We do not deploy intrusive third-party cross-site advertising trackers.
6. Data Retention & Security Measures
We retain transactional data only for the period necessary to comply with our legal, accounting, and tax obligations under Indian law. We implement rigorous administrative, technical, and physical safeguards to prevent unauthorized access, loss, or alteration of your personal data.
7. Your Legal Data Rights
Under applicable Indian data protection laws, you have the right to request access to, review, correct, or request deletion of your personal data held by us. To exercise any of these rights, please contact us at kritoxd499@gmail.com.
8. Grievance Redressal Officer
In accordance with the Information Technology Act, 2000 and rules made thereunder, the contact details of our Grievance Officer are:
- Designation: Grievance & Compliance Officer
- Entity: KRITO Beat Store
- Email: kritoxd499@gmail.com (Subject: Attention Grievance Officer)
- Address: Sector 70, Mohali, Punjab — 160055, India
- Response SLA: Inquiries are acknowledged within 48 hours and addressed within 30 days.
