Legal Information
Privacy Policy
This policy explains exactly what AllDigitalCart records when you use the store, why we record it, how long we keep it, and what you can ask us to do with it. It is written to be read, not to be skimmed past.
- In effect from
- 1 September 2026
- No tracking
- No advertising or cross-site trackers
- Also read
- Terms and Refund Policy
The short version
Four things are worth knowing before you read the rest.
- No advertising trackers No Google or Facebook pixel, no data broker, no cross-site profiling. Three first-party cookies only. Clause 8.
- IP addresses are hashed Analytics stores a salted hash of your IP, not the address itself, so we cannot read it back. Clause 6.
- We never sell your data Not for money, not for advertising, not for anyone. Clause 11.
1. Who We Are and Scope
AllDigitalCart is a digital storefront that sells downloadable products. This Privacy Policy describes what happens to your personal information when you visit AllDigitalCart, create an account, place an order, or download a file.
The store is operated as a Sole proprietorship.
This policy applies to the website and to the support and transactional email we send. It does not apply to a third-party site you reach by following a link out from ours, or to a payment provider's own checkout screens, which have their own policies.
2. What This Policy Covers
Personal information means anything that identifies you, or could be used to identify you when combined with other information we hold. Your name, email address, IP address and the products you bought are all personal information. A product page you viewed is not, on its own, unless you are signed in and we attach it to your account.
We apply this policy to everyone who uses the store, whether or not you have an account. Browsing without an account still creates analytics records, which is why clause 5 is as long as it is.
3. Information We Collect
We collect three categories: what you type into a form, what the website records as you use it, and what a payment provider tells us about a transaction. The table below is the complete list, and the names in the first column are the names used in our database, so you can quote them back to us in a request.
| Stored as | What it records | Why |
|---|---|---|
| first_name, last_name | Your name, split into two fields | Order invoices and to address you properly |
| Your email address | Sign-in, receipts, download access, security notices | |
| password_hash | A one-way hash of your password. We never store the password itself | To verify a sign-in attempt |
| phone, country | Your phone number and country, both optional | Order records and tax handling |
| marketing_consent | Whether you opted in to marketing email | To only send marketing to those who agreed |
| last_login_at, last_login_ip | When you last signed in and the IP used | Security alerts and account takeover detection |
| otp_verifications | A hash of your one-time code, the purpose it was issued for, your attempt count, IP, and expiry | Verifying email signup, password reset, and email change. A change is only applied once the code sent to the new address is confirmed. |
| orders, order_items | Order number, what you bought, prices, discounts, totals, status, and the IP and browser used | Fulfilment, invoicing and accounting |
| payments | Amount, currency, status, PayPal order, capture and transaction IDs, and the email PayPal returns | Confirming payment and handling disputes |
| download_entitlements, download_logs | Which files you are entitled to, how many times you downloaded, and each attempt with IP and browser | Enforcing purchase limits and investigating abuse |
| analytics_visitors, analytics_pageviews, analytics_events | Hashed IP, browser, device, operating system, country, referrer, campaign parameters, pages viewed, scroll depth and time on page | Understanding how the store is used so we can improve it |
| search_logs | What you searched for, how many results, IP and country | Finding products customers cannot find |
| reviews | Your rating, title, review text, and any note an administrator adds | Publishing customer reviews and moderating them |
| wishlists | Which products you saved | Providing the wishlist feature |
| Your cart | Products and quantities, held in your own browser session rather than in an account record | Completing your order |
| marketing_subscribers | Your email, subscription status, consent flag, and the IP and page you subscribed from | Sending marketing you asked for and proving you asked |
| email_logs | Recipient, message type, subject, delivery status and any error | Diagnosing mail that failed to arrive |
| coupon_usages | Which coupon you used on which order | Preventing coupon abuse and fraud |
Administrator accounts are stored separately in admin records covering sign-ins and actions taken in the admin panel, with IP and browser details. These are not customer records and are not used to profile you.
4. Information You Give Us
Most of what we hold, you typed into a form. That includes your name, email address, optional phone number and country when you register; the address details on an order; a review you write; a review reply if you leave one; and anything you write in the contact form.
If you contact us, you are choosing to send us that message. Please do not include payment card numbers, passwords, or identity documents in a message: we do not need them, and email is not the right channel for them.
Anything you post publicly, such as a product review, is visible to other visitors. Do not include personal information in a review. We may remove a review that does, and clause 16 explains how to ask us to.
5. Information Collected Automatically
The store records how it is used. This happens for signed-in customers and for visitors browsing without an account, and it is the largest category of information we hold.
5.1 What is recorded
- Your IP address, in the form described in clause 6.
- Your browser string, device type, operating system, and the approximate country derived from your IP.
- The pages you open, how long you stay on them, how far you scroll, and whether it was your last page in the visit.
-
The page you arrived from, and campaign parameters
such as
utm_sourcewhen you arrived from a link. - Searches you run and how many results came back.
- Products you viewed, added to your cart, and purchased.
- Events such as a signup, an order, or a download.
5.2 How visitors are identified
A random identifier is placed in a first-party cookie when you first arrive. It is not derived from anything about your device, it is not a fingerprint, and it does not follow you to another website. If you clear your cookies, you read as a new visitor and the previous visit is no longer linked to you.
5.3 Why we do it this way
Analytics runs on a queue that never blocks a page load, and a failure to record an event is never allowed to interfere with checkout. The purpose is to find the pages that confuse people and the products nobody looks at, so we can fix the store. It is not used to build a profile of you for advertising, because we do not run advertising.
6. Analytics and Hashed IP Addresses
Storing a full IP address is more than most of this data needs. So analytics records do not store your address. They store a salted hash: a short, one-way value computed from your IP address and a fixed secret before storage.
This means we can count unique visitors and spot suspicious patterns, but we cannot read an IP address back out of the analytics tables, because the transformation cannot be reversed. The same IP produces the same hash every time, which is what makes unique-visitor counts work.
Hashed addresses cover analytics only. A real IP address is still recorded where there is a specific reason to keep it: your last sign-in, orders, and download attempts. Those are the records we would need to show you if you asked whether someone else used your account, or whether a download was made from your order by someone who should not have had access.
7. How We Use Your Information
We use your information to run the store and nothing else. Specifically, to:
- Create and manage your account, and sign you in.
- Verify that you own an email address or asked for a password change, using one-time codes.
- Process orders, take payment, and issue receipts and invoices.
- Decide which files you may download, and enforce the download limits in our Refund Policy.
- Send transactional email: confirmations, receipts, download links, download-ready notices, security alerts, and password resets.
- Answer your questions and handle support requests.
- Publish a review you have written, and moderate reviews for abuse or unlawful content.
- Prevent fraud, abuse, and unauthorised access, including downloads outside the limits in our Refund Policy.
- Understand which parts of the store are used and which are not, so we can improve them.
- Keep records we are required to keep for tax, accounting, and legal purposes.
- Send marketing email, but only if you asked for it.
We do not use your information to build advertising profiles, and we do not make automated decisions that have a significant effect on you. There is no scoring, no credit assessment, and no profiling used to decide whether you get a product or a price.
8. Cookies We Set
The store sets three first-party cookies. There are no advertising cookies, no social media pixels, and nothing from a third party embedded on the site. Here is the complete list:
| Cookie | Purpose | Lifetime |
|---|---|---|
| adc_vid | A random visitor identifier used to group a visit's page views into one analytics session | 365 days |
| adc_sid | Identifies the current visit for analytics | Expires when the browser closes |
| adc_sa | Timestamp of the last activity, used to decide whether a visit is still the same one | Expires when the browser closes |
A fourth cookie, PHPSESSID, is set when
you sign in. It holds a random session identifier;
what you are signed in as is kept server-side, not in
the cookie, so the cookie itself does not contain your
name, email address, or any readable personal
information. It is marked HttpOnly, so
scripts cannot read it, and it is marked
Secure when the site is served over
HTTPS.
All of these are set on our own domain, are marked
SameSite=Lax, and are marked
Secure when the site is served over
HTTPS. Because the analytics cookies are not needed for
the store to function, clearing your cookies stops
analytics without affecting your account, your cart,
or your ability to order. Clearing your cookies does
sign you out, because that cookie is what keeps you
signed in.
9. Payments and PayPal
Payments are processed by PayPal. When you pay, you are taken to PayPal to complete the transaction, and PayPal collects your payment details under its own privacy policy. We never see or store your full card number or card security code.
PayPal sends us back confirmation of the transaction, which we store: the order ID, capture ID, transaction ID, the amount, the currency, the status, and the email address associated with the payment. We reconcile our records against PayPal's on a recurring basis, but we do not keep a copy of PayPal's account records beyond those transaction identifiers.
Where you are taken to PayPal, their policy applies from that point on, not this one. We have no control over what PayPal does with your details once you are on their site.
10. Digital Files and Cloud Storage
Purchased files are held in cloud object storage operated by Amazon Web Services. The files themselves are not public: a download is only served after the request is checked against your purchase entitlement.
That check records who downloaded what, when, how many times, from which IP address and browser. This is in the store's interest as much as yours: a digital file cannot be returned once delivered, so the download log is the only way to tell a customer who downloaded a file once from someone redistributing it. We do not use the log to build a profile of you.
We do not ask for, and have no way to obtain, the contents of a file you have purchased. We cannot recover it, delete it from your device, or prevent you from copying it.
12. Legal and Security Disclosures
We will disclose personal information only where we are legally required to, which means:
- To comply with a court order, subpoena, or a lawful request from a law enforcement or regulatory authority.
- To establish, exercise, or defend legal claims, or to protect the rights, safety, and property of the store, our users, or others.
- To investigate fraud, abuse, or a security incident involving your account.
We will tell you, unless we are legally prohibited from doing so, if we are asked to disclose your information in response to a legal process.
13. How Long We Keep Information
We keep information for as long as we need it for the purpose it was collected, and no longer. In practice:
| Information | Kept for |
|---|---|
| Account and profile | Until you close the account, then for the period in clause 17 |
| Orders, payments, invoices | As long as tax and accounting law requires. These records cannot be deleted on request. |
| Download records | For as long as the order exists, so download limits can be enforced |
| Last sign-in details | Retained on your account so we can spot a sign-in that does not look like yours |
| Analytics records | Aggregated and pruned as the data ages. Hashed IP addresses mean old records cannot be traced back to you. |
| Search logs | Short term, used to improve search results |
| One-time codes and reset tokens | Until they expire, which is shortly after they are issued |
| Unsubscribed marketing records | Retained in suppressed form so we do not accidentally email you again |
| Published reviews | Until you ask us to remove them, then removed from public view |
14. How We Protect Information
Passwords are stored as a one-way hash, so a copy of our user table does not reveal your password. One-time codes, reset tokens, and email-change tokens are also stored hashed rather than in plain text. Signing in uses a server-side session: the cookie in your browser carries a random identifier only, and what you are signed in as is held on the server.
Pages that change data require a valid session and a single-use anti-forgery token, so a third-party site cannot submit a request as if it came from you. Administrative pages require their own separate sign-in. Purchased files are not served from a public URL; access is checked against your purchase record on every request, and requests without a valid session are refused.
Access to customer records is limited to those who need it to run the store. Administrative actions are logged with the administrator's identity, so there is a record of who looked at what.
No system is perfectly secure. If a breach affects your information, we will tell you and the relevant authority as required by law, and we will tell you what we know and what we are doing about it.
15. Marketing Email and Consent
We send two kinds of email. Transactional email covers confirmations, receipts, invoices, download links, security alerts, and password resets. It is sent because you asked for something, and you cannot switch it off while keeping your account working.
Marketing email is anything promoting products or offers. We send it only if you opted in, either at registration, on your profile, or through the newsletter form. We record that you opted in, when, and from which page, so that the consent is provable rather than assumed.
You can change your marketing preference at any time from your account profile, and every marketing email contains an unsubscribe link. Unsubscribing stops marketing email and does not affect your account, orders, or the transactional email you still need.
16. Your Rights
Depending on where you live, you may have the right to:
- Access — get a copy of the personal information we hold about you.
- Correction — have inaccurate information corrected. You can do most of this yourself from your profile.
- Deletion — ask us to delete your information. See clause 17 for what we must keep regardless.
- Restriction or objection — ask us to pause or stop a particular use, most often marketing email.
- Withdraw consent — where we rely on your consent, take it back, by changing your marketing preference or unsubscribing.
- Complain — raise a complaint with your local data protection authority.
- Data portability — receive your information in a structured, commonly used format where that right applies to you.
16.1 How to make a request
To exercise any of these rights, email alldigitalcart@gmail.com from the address on your account, or use the contact page. Tell us which right you are exercising and which account it concerns.
16.2 What happens next
We will confirm receipt, verify that the request really comes from you rather than from someone guessing your email address, and then respond within the period the applicable law requires. We do not charge for a request, and we will not treat you differently for making one.
We may ask for information to confirm your identity. That is to protect your account from someone else pretending to be you, not to obstruct you. If we ask, we will explain what we need and why.
17. Account Deletion and What We Must Keep
You can ask us to close your account at any time by emailing alldigitalcart@gmail.com . There is no self-service deletion button, so a request by email is how this is done. We will confirm the request with you before closing anything, because closing an account is not something we want you to do by accident.
Closing your account removes your profile, your sign-in session, your wishlist, your cart, and your marketing subscription. It does not remove your order history, invoices, or payment records, because tax and accounting law requires a business to keep those. Those records are retained for the period the law requires and then deleted. They are not used to contact you or to market to you, and they remain associated with your order rather than with an active account.
If you have placed orders, tell us whether you want your order history kept for your records or removed once the retention period expires, and we will confirm what we can and cannot do.
Purchased files cannot be reclaimed. Once a download has been delivered, deleting the account does not return it and does not entitle you to a refund. That is a separate question, covered by the Refund Policy.
18. Children
The store is not directed at children, and we do not knowingly collect personal information from anyone under the age at which they may lawfully consent to the data processing described here on their own. Our Terms set out the age at which you must be to hold an account.
If you believe a child has provided personal information to us, contact us and we will review it and delete it where we are able to.
19. Third-Party Links
The store may link to other websites, including product pages, author sites, and payment providers. Once you follow a link, you are on someone else's site and their privacy policy applies instead of this one. We are not responsible for how a third party handles your information.
20. International Transfers
Some of the service providers listed in clause 11 operate outside India. That means your information may be processed in another country, including the United States, through Amazon Web Services, the email delivery provider, or PayPal.
Where information is transferred outside its country of origin, the transfer is made under the safeguards those providers put in place, such as standard contractual clauses. If you want to know more about the safeguards that apply to a specific transfer, ask us using the details in clause 22.
21. Changes to This Policy
We will update this policy when what we collect or how we use it changes, or when the law requires it. The date at the top of this page is the date the current version took effect.
If a change materially affects how we use information you have already given us, we will tell you before it takes effect, by email or by a notice on the site. A change that reduces what we collect or how long we keep it does not need that notice.
Continuing to use the store after a change takes effect means you accept it. If you do not, stop using the store; your rights to your orders, receipts, and downloads are unaffected.
22. How to Contact Us
For any privacy question, to make a request under clause 16, or to close your account under clause 17, contact us and we will deal with it.
- Trading name
- AllDigitalCart
- Legal entity
- Sole proprietorship
- Support email
- alldigitalcart@gmail.com
- Governing law
- India
- Courts
- Kolkata, West Bengal
- Contact form
- https://alldigitalcart.com/pages/contact.php
- Orders and downloads
- Your order history, invoices and downloads are in your account, under My Account.
- Related policies
- Terms & Conditions and Refund Policy
This policy is governed by the laws of India, and the courts of Kolkata, West Bengal have jurisdiction over any dispute arising from it. Nothing in this paragraph removes any protection or right you have under the mandatory law of your own country.