Privacy Policy
Last Updated: October 4, 2026
Welcome to Kapda Pasal Seller App ("the App"). This application is owned by Kapda Pasal and operated by Infiloop ("we", "our", or "us"). We are committed to protecting your privacy and ensuring the security of the personal and business information you entrust to us.
This Privacy Policy explains how we collect, use, store, share, and protect your information when you use our vendor management mobile application ("the App") to manage your clothing business on the Kapda Pasal multi-vendor marketplace.
⚠️ IMPORTANT: By using the Kapda Pasal Seller App, you consent to the collection and use of your information as described in this policy, including the processing of your business documents, bank details, and product images for AI-powered editing.
1. Information We Collect
To facilitate your vendor operations and provide our marketplace services, we collect the following types of information:
A. Account and Authentication Information
- Email address and phone number for account creation and login.
- Login credentials (email and password, encrypted at rest).
- Authentication tokens for secure session management.
B. Business Profile Information
- Owner name, shop name, and store nickname.
- Seller type (Individual or Business).
- Business email address and phone number.
- Store logo and profile images.
C. Shop Address and Location Information
- Complete shop address including district, municipality/rural, ward, city, street/tole, and nearest landmark.
- GPS coordinates (latitude/longitude) when you use the map location picker or current location feature.
- City/country level location data for delivery coordination.
D. Identity and Bank Verification Information
- Government-issued identity documents for seller verification.
- Bank account details including bank holder name, account number, bank name, and branch.
- QR code images for payment processing.
- Business registration documents (for Business seller type).
🔒 SENSITIVE DATA: Bank account details and identity documents are encrypted at rest using flutter_secure_storage and are only accessed for verification and payment processing purposes.
E. Product and Inventory Information
- Product names, descriptions, categories, subcategories, brands, and SKUs.
- Product images (original and AI-edited versions).
- Product variants including color, size, price, and stock levels.
- Pricing information including base prices, discount prices, and stock thresholds.
- Product status (draft, active, inactive, out of stock).
F. Order and Transaction Information
- Customer order details including products, quantities, prices, and order status.
- Customer information (name, email, phone number) for order fulfillment.
- Shipping and billing addresses provided by customers.
- Payment method and payment status information.
- Shipping tracking numbers and provider information.
- Order notes and special instructions.
G. Discount and Voucher Information
- Voucher names, discount types (percentage or fixed amount), and discount values.
- Minimum spend requirements and discount limits.
- Voucher validity periods (start and end dates).
- Products eligible for discounts.
H. AI Image Processing Data
- Product images uploaded for AI-powered editing (background removal, ghost mannequin, flat lay, model selection, photo recomposition, and image enhancements).
- Original and processed images are temporarily transmitted to third-party AI services (PhotoRoom) for processing.
- AI editing parameters and presets selected by you.
🤖 AI PROCESSING: When you use AI image editing features, your product images are sent to PhotoRoom's API for processing. Images are processed temporarily and not permanently stored by the AI service provider.
I. Communications and Customer Interaction
- Product Q&A messages exchanged with customers.
- Customer inquiries and your responses.
- Support tickets and communications with our support team.
- Bug reports, feature requests, and app feedback.
J. Device and Technical Information
- Device UUID, device name, device model/brand, operating system version, and timezone.
- Device location (city/country level) for authentication and security purposes.
- App feature usage patterns and preferences.
- Push notification tokens for delivering alerts.
K. Notification Preferences
- Your preferences for order updates, customer messages, stock alerts, promotional content, and account notifications.
- Notification scheduling and delivery preferences.
2. How We Use Your Information
We use the collected information for the following core purposes:
- Account Management: Creating and managing your vendor account, authenticating your identity, and providing secure login options.
- Business Verification: Verifying your identity and business details to ensure marketplace integrity and compliance with regulations.
- Product Management: Enabling you to create, edit, and manage your product listings, inventory, and pricing.
- Order Processing: Facilitating order management, customer communication, shipping coordination, and delivery tracking.
- Payment Processing: Processing payments, managing payouts, and coordinating with payment providers.
- AI Image Editing: Providing AI-powered image editing services including background removal, ghost mannequin effects, flat lay composition, and model selection.
- Customer Communication: Facilitating Q&A messages between you and customers for product inquiries.
- Discount Management: Creating and managing vouchers, discounts, and promotional offers.
- Analytics and Insights: Providing sales analytics, performance metrics, and business insights through charts and reports.
- Communications: Sending push notifications for order updates, customer messages, stock alerts, and account updates based on your preferences.
- Support and Improvement: Responding to support inquiries, processing bug reports and feature requests, analyzing usage patterns to improve the App.
- Security: Detecting fraudulent activity, protecting vendor accounts, and ensuring platform integrity.
- Location Services: Using your shop location for delivery coordination and customer address verification.
3. AI Image Processing
🎨 THE APP USES AI TO EDIT YOUR PRODUCT IMAGES FOR PROFESSIONAL LISTINGS.
Our App includes AI-powered image editing features to help you create professional product listings. When you use these features:
- Background Removal: Your product image is sent to PhotoRoom's API to remove the background and optionally replace it with a solid color or AI-generated scene.
- Ghost Mannequin: Your product image is processed to create a 3D hollow mannequin effect for a professional look.
- Flat Lay: Your product image is transformed into a flat lay composition suitable for e-commerce listings.
- Model Selection: Your product image is processed to display it on AI-generated models.
- Photo Recomposition: Your product image is recomposed with AI-generated backgrounds or scenes.
- Image Enhancements: Your product images may be adjusted for brightness, contrast, and other visual improvements.
Data Processing: Images are temporarily transmitted to PhotoRoom's servers for AI processing. The processed images are returned to your device. Original images are not permanently stored by the AI service provider after processing is complete.
Camera and Gallery Permission: The App will request access to your camera and photo gallery only when you choose to upload or edit product images. You can revoke these permissions at any time from your device settings.
4. Location Data
📍 THE APP USES YOUR DEVICE LOCATION TO HELP YOU SET YOUR SHOP ADDRESS.
Our App includes location features to help you set your shop address. When you use these features:
- Your device's GPS location is accessed to show your current position on the map.
- You can manually select or search for a location on the map.
- The selected coordinates (latitude/longitude) are stored along with your shop address.
- Location data is used for delivery coordination and customer address verification.
Location Permission: The App will request location access only when you use the map location picker or current location feature. You can revoke this permission at any time from your device settings.
5. Data Storage, Security, and Protection
Your privacy is our priority. We employ industry-standard measures to ensure security:
- Encryption in Transit: All communications between the App and our backend servers are encrypted using Secure Socket Layer (SSL/TLS) technology.
- Encryption at Rest: Sensitive tokens, authentication credentials, bank details, and identity documents are stored using secure encrypted local storage (flutter_secure_storage).
- Server Security: Your data is stored on secure servers with restricted access limited to authorized personnel.
- Data Retention: We retain your account and business data for as long as your vendor account is active. Upon account deletion, your personal data is permanently removed from our servers after a brief grace period. Transaction records may be retained for legal and accounting requirements.
- Offline Data: The App caches certain data locally (product catalog, order data) for offline functionality. This data is stored in encrypted local databases (sqflite).
- Draft Data: Business and bank details forms are saved locally as drafts using encrypted SQLite databases to prevent data loss during the verification process.
6. Third-Party Services
We use the following third-party services in our App. Each service has its own privacy policy governing data handling:
- Firebase Cloud Messaging (Google): Used for push notifications. FCM registration tokens are collected, together with device information supplied by Google, in order to deliver notifications to your device.
- PhotoRoom: Used for AI-powered image editing services including background removal, ghost mannequin, flat lay, model selection, and photo recomposition. Product images are temporarily sent to PhotoRoom's API for processing.
- BugSnag: Used for error tracking and crash reporting. When a crash or a handled error occurs, the App sends diagnostic information to BugSnag. This may include your device model, operating system version, app version, the error stack trace, and technical breadcrumbs describing recent network requests made by the App. Authentication tokens, passwords and other credentials are redacted before transmission. Product images, identity documents and bank details are not included in crash reports.
- OpenStreetMap and Nominatim (OpenStreetMap Foundation): Used for the map location picker feature that helps you set your shop address. Map tiles are loaded from tile.openstreetmap.org, and the coordinates you select or type are sent to nominatim.openstreetmap.org to convert between an address and its latitude/longitude. Your location queries, the coordinates you select, and your device's IP address are therefore visible to the OpenStreetMap Foundation, which handles this data under its own privacy policy. We do not send your identity or business documents to OpenStreetMap.
- On-device location access: Reading your current GPS position uses your device's built-in location services directly. This does not involve an additional third party.
7. Data Sharing and Third-Party Disclosure
We do not sell, trade, or rent your personal or business information to third parties. We only share information with:
- Customers: Your shop name, product information, and order-related details are shared with customers who purchase from your store.
- Payment Processors: Transaction information is shared with payment providers (ConnectIPS, eSewa, Khalti, bank transfers) for payment processing and payouts.
- Delivery Partners: Shipping addresses and contact information are shared with delivery partners to complete order deliveries.
- AI Service Providers: Product images are temporarily shared with PhotoRoom for AI image processing. Images are not permanently stored by the service provider.
- Map and Geocoding Provider: The coordinates you select in the map picker, and the address text you type to search for a location, are sent to the OpenStreetMap Foundation (nominatim.openstreetmap.org) to perform geocoding. Map tile requests are also made to tile.openstreetmap.org, which necessarily reveals your IP address and the area of the map being viewed. We do not share your name, identity documents or bank details with OpenStreetMap.
- Service Providers: Trusted third-party vendors who assist us in operating the App (cloud hosting, error monitoring, push notifications), subject to contractual obligations to protect your data.
- Legal Compliance: Government authorities and law enforcement when required by applicable law or to protect our legal rights.
8. Your Rights and Choices
You retain full control over your personal and business data:
- Access & Correction: You can access, review, and update your business profile, shop details, and bank information directly in the App under the Profile section.
- Notification Preferences: You can customize which push notifications you receive by category (Orders, Messages, Stock Alerts, Promotions, Account) in the App's notification settings.
- Account Deletion: You may request the permanent deletion of your vendor account and all associated data from our servers at any time through the Account Deletion option in your Profile, or by contacting our support team at [email protected]. Note: Some transaction data may be retained for legal and accounting requirements.
- Data Portability: You can request a copy of your personal and business data by contacting us.
- Order History: You can view your complete order history and transaction details from the App.
- Product Data: You can export your product listings and inventory data at any time.
- Holiday Mode: You can pause your store operations temporarily using the Holiday Mode feature.
9. Children's Privacy
Our App is not intended for use by children under the age of 13. We do not knowingly collect personal data from anyone under 13 years of age. If we learn that we have collected personal information from a child under 13, we will delete that information immediately. If you believe a child under 13 has provided us with personal data, please contact us.
10. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page, updating the "Last Updated" date, and sending a notification through the App. We encourage you to review this policy periodically.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us at:
Infiloop
Kathmandu, Bagmati, Nepal
Email: [email protected]
Website: infiloop.co