Skip to main content
15% OFF Flat 15% off on your first order
Unlimited Digital Downloads • Secure Checkout
Shop Now

Legal Information

Privacy Policy

This policy explains exactly what AllDigitalCart records when you use the store, why we record it, how long we keep it, and what you can ask us to do with it. It is written to be read, not to be skimmed past.

In effect from
1 September 2026
No tracking
No advertising or cross-site trackers
Also read
Terms and Refund Policy

The short version

Four things are worth knowing before you read the rest.

  • No advertising trackers No Google or Facebook pixel, no data broker, no cross-site profiling. Three first-party cookies only. Clause 8.
  • IP addresses are hashed Analytics stores a salted hash of your IP, not the address itself, so we cannot read it back. Clause 6.
  • We never sell your data Not for money, not for advertising, not for anyone. Clause 11.

1. Who We Are and Scope

AllDigitalCart is a digital storefront that sells downloadable products. This Privacy Policy describes what happens to your personal information when you visit AllDigitalCart, create an account, place an order, or download a file.

The store is operated as a Sole proprietorship.

This policy applies to the website and to the support and transactional email we send. It does not apply to a third-party site you reach by following a link out from ours, or to a payment provider's own checkout screens, which have their own policies.

2. What This Policy Covers

Personal information means anything that identifies you, or could be used to identify you when combined with other information we hold. Your name, email address, IP address and the products you bought are all personal information. A product page you viewed is not, on its own, unless you are signed in and we attach it to your account.

We apply this policy to everyone who uses the store, whether or not you have an account. Browsing without an account still creates analytics records, which is why clause 5 is as long as it is.

3. Information We Collect

We collect three categories: what you type into a form, what the website records as you use it, and what a payment provider tells us about a transaction. The table below is the complete list, and the names in the first column are the names used in our database, so you can quote them back to us in a request.

Stored as What it records Why
first_name, last_name Your name, split into two fields Order invoices and to address you properly
email Your email address Sign-in, receipts, download access, security notices
password_hash A one-way hash of your password. We never store the password itself To verify a sign-in attempt
phone, country Your phone number and country, both optional Order records and tax handling
marketing_consent Whether you opted in to marketing email To only send marketing to those who agreed
last_login_at, last_login_ip When you last signed in and the IP used Security alerts and account takeover detection
otp_verifications A hash of your one-time code, the purpose it was issued for, your attempt count, IP, and expiry Verifying email signup, password reset, and email change. A change is only applied once the code sent to the new address is confirmed.
orders, order_items Order number, what you bought, prices, discounts, totals, status, and the IP and browser used Fulfilment, invoicing and accounting
payments Amount, currency, status, PayPal order, capture and transaction IDs, and the email PayPal returns Confirming payment and handling disputes
download_entitlements, download_logs Which files you are entitled to, how many times you downloaded, and each attempt with IP and browser Enforcing purchase limits and investigating abuse
analytics_visitors, analytics_pageviews, analytics_events Hashed IP, browser, device, operating system, country, referrer, campaign parameters, pages viewed, scroll depth and time on page Understanding how the store is used so we can improve it
search_logs What you searched for, how many results, IP and country Finding products customers cannot find
reviews Your rating, title, review text, and any note an administrator adds Publishing customer reviews and moderating them
wishlists Which products you saved Providing the wishlist feature
Your cart Products and quantities, held in your own browser session rather than in an account record Completing your order
marketing_subscribers Your email, subscription status, consent flag, and the IP and page you subscribed from Sending marketing you asked for and proving you asked
email_logs Recipient, message type, subject, delivery status and any error Diagnosing mail that failed to arrive
coupon_usages Which coupon you used on which order Preventing coupon abuse and fraud

Administrator accounts are stored separately in admin records covering sign-ins and actions taken in the admin panel, with IP and browser details. These are not customer records and are not used to profile you.

4. Information You Give Us

Most of what we hold, you typed into a form. That includes your name, email address, optional phone number and country when you register; the address details on an order; a review you write; a review reply if you leave one; and anything you write in the contact form.

If you contact us, you are choosing to send us that message. Please do not include payment card numbers, passwords, or identity documents in a message: we do not need them, and email is not the right channel for them.

Anything you post publicly, such as a product review, is visible to other visitors. Do not include personal information in a review. We may remove a review that does, and clause 16 explains how to ask us to.

5. Information Collected Automatically

The store records how it is used. This happens for signed-in customers and for visitors browsing without an account, and it is the largest category of information we hold.

5.1 What is recorded

  • Your IP address, in the form described in clause 6.
  • Your browser string, device type, operating system, and the approximate country derived from your IP.
  • The pages you open, how long you stay on them, how far you scroll, and whether it was your last page in the visit.
  • The page you arrived from, and campaign parameters such as utm_source when you arrived from a link.
  • Searches you run and how many results came back.
  • Products you viewed, added to your cart, and purchased.
  • Events such as a signup, an order, or a download.

5.2 How visitors are identified

A random identifier is placed in a first-party cookie when you first arrive. It is not derived from anything about your device, it is not a fingerprint, and it does not follow you to another website. If you clear your cookies, you read as a new visitor and the previous visit is no longer linked to you.

5.3 Why we do it this way

Analytics runs on a queue that never blocks a page load, and a failure to record an event is never allowed to interfere with checkout. The purpose is to find the pages that confuse people and the products nobody looks at, so we can fix the store. It is not used to build a profile of you for advertising, because we do not run advertising.

6. Analytics and Hashed IP Addresses

Storing a full IP address is more than most of this data needs. So analytics records do not store your address. They store a salted hash: a short, one-way value computed from your IP address and a fixed secret before storage.

This means we can count unique visitors and spot suspicious patterns, but we cannot read an IP address back out of the analytics tables, because the transformation cannot be reversed. The same IP produces the same hash every time, which is what makes unique-visitor counts work.

Where a real IP address is still stored

Hashed addresses cover analytics only. A real IP address is still recorded where there is a specific reason to keep it: your last sign-in, orders, and download attempts. Those are the records we would need to show you if you asked whether someone else used your account, or whether a download was made from your order by someone who should not have had access.

7. How We Use Your Information

We use your information to run the store and nothing else. Specifically, to:

  • Create and manage your account, and sign you in.
  • Verify that you own an email address or asked for a password change, using one-time codes.
  • Process orders, take payment, and issue receipts and invoices.
  • Decide which files you may download, and enforce the download limits in our Refund Policy.
  • Send transactional email: confirmations, receipts, download links, download-ready notices, security alerts, and password resets.
  • Answer your questions and handle support requests.
  • Publish a review you have written, and moderate reviews for abuse or unlawful content.
  • Prevent fraud, abuse, and unauthorised access, including downloads outside the limits in our Refund Policy.
  • Understand which parts of the store are used and which are not, so we can improve them.
  • Keep records we are required to keep for tax, accounting, and legal purposes.
  • Send marketing email, but only if you asked for it.

We do not use your information to build advertising profiles, and we do not make automated decisions that have a significant effect on you. There is no scoring, no credit assessment, and no profiling used to decide whether you get a product or a price.

8. Cookies We Set

The store sets three first-party cookies. There are no advertising cookies, no social media pixels, and nothing from a third party embedded on the site. Here is the complete list:

Cookie Purpose Lifetime
adc_vid A random visitor identifier used to group a visit's page views into one analytics session 365 days
adc_sid Identifies the current visit for analytics Expires when the browser closes
adc_sa Timestamp of the last activity, used to decide whether a visit is still the same one Expires when the browser closes

A fourth cookie, PHPSESSID, is set when you sign in. It holds a random session identifier; what you are signed in as is kept server-side, not in the cookie, so the cookie itself does not contain your name, email address, or any readable personal information. It is marked HttpOnly, so scripts cannot read it, and it is marked Secure when the site is served over HTTPS.

All of these are set on our own domain, are marked SameSite=Lax, and are marked Secure when the site is served over HTTPS. Because the analytics cookies are not needed for the store to function, clearing your cookies stops analytics without affecting your account, your cart, or your ability to order. Clearing your cookies does sign you out, because that cookie is what keeps you signed in.

9. Payments and PayPal

Payments are processed by PayPal. When you pay, you are taken to PayPal to complete the transaction, and PayPal collects your payment details under its own privacy policy. We never see or store your full card number or card security code.

PayPal sends us back confirmation of the transaction, which we store: the order ID, capture ID, transaction ID, the amount, the currency, the status, and the email address associated with the payment. We reconcile our records against PayPal's on a recurring basis, but we do not keep a copy of PayPal's account records beyond those transaction identifiers.

Where you are taken to PayPal, their policy applies from that point on, not this one. We have no control over what PayPal does with your details once you are on their site.

10. Digital Files and Cloud Storage

Purchased files are held in cloud object storage operated by Amazon Web Services. The files themselves are not public: a download is only served after the request is checked against your purchase entitlement.

That check records who downloaded what, when, how many times, from which IP address and browser. This is in the store's interest as much as yours: a digital file cannot be returned once delivered, so the download log is the only way to tell a customer who downloaded a file once from someone redistributing it. We do not use the log to build a profile of you.

We do not ask for, and have no way to obtain, the contents of a file you have purchased. We cannot recover it, delete it from your device, or prevent you from copying it.

11. Who We Share Information With

We share the minimum needed to run the store, and only with these categories of recipient:

Recipient What they receive Why
PayPal Your email, order details, and transaction amount To process and confirm payment
Amazon Web Services Your account and order identifiers, so a download can be authorised To store the files and serve them to the right person
Email delivery provider Your email address and the content of the message To send confirmations, receipts and security notices
Web hosting provider Whatever is technically required to serve the website To run the site

We do not sell your personal information. Not for money, not in exchange for anything, and not for advertising. We do not share it with data brokers, and we do not allow any of the recipients above to use it for their own purposes.

13. How Long We Keep Information

We keep information for as long as we need it for the purpose it was collected, and no longer. In practice:

Information Kept for
Account and profile Until you close the account, then for the period in clause 17
Orders, payments, invoices As long as tax and accounting law requires. These records cannot be deleted on request.
Download records For as long as the order exists, so download limits can be enforced
Last sign-in details Retained on your account so we can spot a sign-in that does not look like yours
Analytics records Aggregated and pruned as the data ages. Hashed IP addresses mean old records cannot be traced back to you.
Search logs Short term, used to improve search results
One-time codes and reset tokens Until they expire, which is shortly after they are issued
Unsubscribed marketing records Retained in suppressed form so we do not accidentally email you again
Published reviews Until you ask us to remove them, then removed from public view

14. How We Protect Information

Passwords are stored as a one-way hash, so a copy of our user table does not reveal your password. One-time codes, reset tokens, and email-change tokens are also stored hashed rather than in plain text. Signing in uses a server-side session: the cookie in your browser carries a random identifier only, and what you are signed in as is held on the server.

Pages that change data require a valid session and a single-use anti-forgery token, so a third-party site cannot submit a request as if it came from you. Administrative pages require their own separate sign-in. Purchased files are not served from a public URL; access is checked against your purchase record on every request, and requests without a valid session are refused.

Access to customer records is limited to those who need it to run the store. Administrative actions are logged with the administrator's identity, so there is a record of who looked at what.

No system is perfectly secure. If a breach affects your information, we will tell you and the relevant authority as required by law, and we will tell you what we know and what we are doing about it.

16. Your Rights

Depending on where you live, you may have the right to:

  • Access — get a copy of the personal information we hold about you.
  • Correction — have inaccurate information corrected. You can do most of this yourself from your profile.
  • Deletion — ask us to delete your information. See clause 17 for what we must keep regardless.
  • Restriction or objection — ask us to pause or stop a particular use, most often marketing email.
  • Withdraw consent — where we rely on your consent, take it back, by changing your marketing preference or unsubscribing.
  • Complain — raise a complaint with your local data protection authority.
  • Data portability — receive your information in a structured, commonly used format where that right applies to you.

16.1 How to make a request

To exercise any of these rights, email alldigitalcart@gmail.com from the address on your account, or use the contact page. Tell us which right you are exercising and which account it concerns.

16.2 What happens next

We will confirm receipt, verify that the request really comes from you rather than from someone guessing your email address, and then respond within the period the applicable law requires. We do not charge for a request, and we will not treat you differently for making one.

We may ask for information to confirm your identity. That is to protect your account from someone else pretending to be you, not to obstruct you. If we ask, we will explain what we need and why.

17. Account Deletion and What We Must Keep

You can ask us to close your account at any time by emailing alldigitalcart@gmail.com . There is no self-service deletion button, so a request by email is how this is done. We will confirm the request with you before closing anything, because closing an account is not something we want you to do by accident.

What closing your account does not remove

Closing your account removes your profile, your sign-in session, your wishlist, your cart, and your marketing subscription. It does not remove your order history, invoices, or payment records, because tax and accounting law requires a business to keep those. Those records are retained for the period the law requires and then deleted. They are not used to contact you or to market to you, and they remain associated with your order rather than with an active account.

If you have placed orders, tell us whether you want your order history kept for your records or removed once the retention period expires, and we will confirm what we can and cannot do.

Purchased files cannot be reclaimed. Once a download has been delivered, deleting the account does not return it and does not entitle you to a refund. That is a separate question, covered by the Refund Policy.

18. Children

The store is not directed at children, and we do not knowingly collect personal information from anyone under the age at which they may lawfully consent to the data processing described here on their own. Our Terms set out the age at which you must be to hold an account.

If you believe a child has provided personal information to us, contact us and we will review it and delete it where we are able to.

20. International Transfers

Some of the service providers listed in clause 11 operate outside India. That means your information may be processed in another country, including the United States, through Amazon Web Services, the email delivery provider, or PayPal.

Where information is transferred outside its country of origin, the transfer is made under the safeguards those providers put in place, such as standard contractual clauses. If you want to know more about the safeguards that apply to a specific transfer, ask us using the details in clause 22.

21. Changes to This Policy

We will update this policy when what we collect or how we use it changes, or when the law requires it. The date at the top of this page is the date the current version took effect.

If a change materially affects how we use information you have already given us, we will tell you before it takes effect, by email or by a notice on the site. A change that reduces what we collect or how long we keep it does not need that notice.

Continuing to use the store after a change takes effect means you accept it. If you do not, stop using the store; your rights to your orders, receipts, and downloads are unaffected.

22. How to Contact Us

For any privacy question, to make a request under clause 16, or to close your account under clause 17, contact us and we will deal with it.

Trading name
AllDigitalCart
Legal entity
Sole proprietorship
Governing law
India
Courts
Kolkata, West Bengal
Orders and downloads
Your order history, invoices and downloads are in your account, under My Account.
Related policies
Terms & Conditions and Refund Policy

This policy is governed by the laws of India, and the courts of Kolkata, West Bengal have jurisdiction over any dispute arising from it. Nothing in this paragraph removes any protection or right you have under the mandatory law of your own country.