GAINKAT
Privacy Policy
Last updated 30 September 2026
GAINKAT is an analytics product for online stores, operated by Cyberrig Private Limited. This policy explains what we collect, why, who it is shared with, and what you can ask us to do with it. It covers both the merchants who use GAINKAT and the visitors to their stores.
1. Who is responsible for your data
Our role depends on whose data it is, and the distinction matters for your rights.
For merchant account information — the details of the person and business using GAINKAT — we are the data controller. We decide what is collected and why.
For store data and store-visitor data — orders, products, customers and website activity belonging to a merchant’s shop — we act as a data processor on that merchant’s instructions. The merchant is the controller. If you shopped at a store and want your data removed, the merchant is the right first contact, and we will act on their instruction.
2. Information about merchants
| What | Why we hold it |
|---|---|
| Email address | Signing in, and account and service notices |
| Name and phone number, if provided | Identifying you in the account and support |
| Organisation name | Naming your workspace |
| Authentication data | Passwords are handled by our authentication provider and stored hashed. We never see or store your password |
| Business details provided at signup | Website, revenue band, industry and role, used to set sensible defaults. Optional |
| Usage and diagnostic logs | Keeping the service working and investigating faults |
| A record of changes to your workspace | Who changed a setting or a connection, what it was before and after, and changes Billy made that you approved. Shown to your workspace under Settings → Activity and downloadable there. It records changes, not what you looked at |
| Devices you sign in from | The browser and operating system, and the country and city your connection reports, shown to you under Settings → Devices so you can spot a sign-in you do not recognise. Your IP address is read to derive the location and is not stored |
| Emails you send to support | Each email to our support address becomes a ticket: your address, name, the subject and the text of the message, our replies, and the names of any attachments. Kept so we can answer you and see the history of a problem. The files themselves stay with our email provider |
| A demo request, if you send one | Your name, business, email, and any phone number, store address and message you give on the Book a demo form, with the page and campaign that brought you there. Used to contact you about a demo; kept as a sales record, and you can ask us to delete it |
GAINKAT gives each browser a first-party identifier so the same machine is not listed twice. It is not a fingerprint: clearing your cookies clears it, and that browser then appears as a new one because at that point we genuinely cannot tell it is the same.
3. Store data we process
When a merchant connects a store, we read the following through that platform’s official API, using access the merchant explicitly grants and can revoke at any time.
| Source | What we read |
|---|---|
| Shopify | Orders (amounts, dates, discounts, taxes, shipping, refunds, delivery status), products and variants, inventory costs, fulfilment status, and shipping country and postcode |
| Shopify customers | A customer identifier and their order count only — used to tell new customers from returning ones |
| Meta Ads, where connected | Advertising spend, impressions, clicks and platform-reported conversions, at ad level. We can also pause a campaign or change a daily budget, and only ever after you approve that specific change |
| Costs entered by the merchant | Product costs, fees and expenses typed into GAINKAT |
Reading is the default and covers almost everything above. GAINKAT makes a change only where you have approved that specific change: recording a product cost back to Shopify, adding a tag to an order, creating a discount code you asked for, pausing a Meta campaign, or changing a daily budget.
Each of those arrives as a proposal describing exactly what will happen. Nothing is carried out until you approve it, the approved wording is what executes, and the result is recorded so you can see afterwards what was done. GAINKAT never creates campaigns, edits targeting or creative, deletes anything, or acts without being asked.
4. Store visitors and the site pixel
Merchants may install our first-party analytics script on their storefront. Where they do, we collect the following about visits to that merchant’s store, on the merchant’s behalf:
| What | Why |
|---|---|
| A randomly generated visitor identifier, stored in a first-party cookie | Recognising a returning browser so a visit and a later purchase can be connected. It is random and is not derived from any personal detail |
| Session identifier, page paths, page titles and timestamps | Understanding which pages a visit included |
| Referring website, UTM parameters and advertising click identifiers | Establishing which advertisement, campaign or partner a visit came from |
| Actions such as product views, add-to-cart and checkout start | Measuring where visits progress or stop |
| Browser, operating system and device category | Diagnosing tracking problems specific to a browser |
| Country, derived from network information | Coarse geographic reporting. We do not store IP addresses |
This data belongs to the merchant whose store it was collected on. It is never combined across different merchants, and never sold, rented, or used to build advertising profiles or audiences.
5. What we never collect
These are deliberate design choices, not omissions. The application is built so that:
- We do not copy shopper names, email addresses, phone numbers or street addresses out of a merchant’s store.
- We never receive payment card numbers, bank details or any payment credentials. Payments are handled entirely by the store’s own provider and never pass through GAINKAT.
- We do not use special category data such as health, biometric, religious or political information.
- We do not track individuals across websites we do not operate for a merchant, and we do not participate in third-party advertising networks.
6. Why we use it
- Providing the analytics, reporting and attribution the merchant asked for.
- Calculating revenue, costs, profitability and advertising performance.
- Answering a merchant’s questions about their own store through our assistant.
- Keeping accounts secure and preventing abuse.
- Diagnosing faults and improving reliability.
- Sending service messages about the account.
We do not use merchant or visitor data to train machine learning models, and we do not sell data to anyone, for any purpose.
7. Legal bases
Where the UK GDPR or EU GDPR applies, we rely on:
- Contract — providing the service a merchant has signed up for.
- Legitimate interests — keeping the service secure, reliable and free of abuse, balanced against the rights of the people concerned.
- Consent — where a merchant is required to obtain it for analytics on their storefront, that consent is collected by the merchant, and we process on their instruction.
- Legal obligation — where we must retain records to comply with law.
9. Use of AI models
GAINKAT includes an assistant that answers questions about a merchant’s own store. When it is used, the question and the figures needed to answer it are sent to our model provider.
The assistant retrieves aggregated figures — totals, counts and averages — through a fixed set of internal functions. It has no general access to the database and cannot query it freely. Shopper personal details are not present in what it receives, because we do not hold them.
Our model providers do not use data submitted through their APIs to train their models.
11. International transfers
Cyberrig Private Limited is established in India. Our service providers operate data centres in several countries, so information may be processed outside the country where it was collected.
Where data protected by the UK or EU GDPR is transferred outside those jurisdictions, we rely on the European Commission’s Standard Contractual Clauses, or an equivalent lawful mechanism, in our agreements with those providers.
12. How long we keep it
| Data | Retention |
|---|---|
| Merchant account information | For as long as the account is open, then up to 90 days after closure |
| Store and advertising data | For as long as the store remains connected. Disconnecting stops collection; deleting the store from the workspace removes its data |
| Store visitor and session data | Up to 25 months from collection, then deleted |
| Assistant conversations | Until the merchant deletes them, or the account closes |
| Diagnostic logs | Up to 90 days |
A workspace’s owner can delete it from Settings. It closes at once, and 14 days later its stores’ data, files, assistant conversations and the sign-ins that belong to it alone are erased, and GAINKAT is removed from its Shopify stores. Until then the owner can cancel. Its billing records are kept, as tax law requires.
We may retain information for longer where the law requires it, or where it is needed to establish or defend a legal claim.
13. Security
- All traffic is encrypted in transit using TLS, and data is encrypted at rest by our infrastructure providers.
- Every workspace’s data is isolated at the database level by row-level security policies, so one merchant’s records cannot be read by another.
- Platform access tokens are stored separately from ordinary data, in a location no client application can read.
- Access to production systems is limited to personnel who need it.
- Our support staff use a separate console with their own sign-in and a second factor. For each workspace it shows the plan, credits and AI usage; who signs in and when; the owner’s contact email; which stores and connections it has and whether they are syncing; and each store’s order count and revenue for the last 30 days, as totals. It does not show individual orders, customers or products. Staff can restart a sync, re-register live updates from Shopify, add credits, change a plan that is not billed through Stripe, and suspend or restore a workspace. Every visit and action there is logged, and every change appears in your Activity log as GAINKAT support. Staff also keep internal notes of their conversations with you. Each member of staff sees only what their role allows.
No system is perfectly secure. If a breach affects your information, we will notify you and the relevant regulator as required by law and without undue delay.
14. Your rights
Depending on where you live, you may have the right to access a copy of your information, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent where we rely on it.
If you are a California resident, you additionally have the right to know what is collected and to request deletion, and the right not to be discriminated against for exercising either. As stated above, we do not sell personal information.
To exercise any of these, contact us using the details below. We respond within 30 days. There is no charge unless a request is manifestly unfounded or excessive. You also have the right to complain to your local data protection authority.
15. If you shopped at a store using GAINKAT
We hold no name, email address or payment details for you. What we may hold, on behalf of the store, is a random identifier and a record of pages visited and actions taken on that store’s website.
The store is the controller of that information, so please contact the store first — they can instruct us to delete it. You may also contact us directly and we will pass the request on and act on it. Clearing your browser cookies for that store also ends the association immediately.
16. Children
GAINKAT is a business tool and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child’s information has reached us, contact us and we will delete it.
17. Changes to this policy
We will update this page when our practices change, and revise the date at the top. If a change materially affects how we handle your information, we will tell account holders by email or in the application before it takes effect.
18. Contact us
Cyberrig Private Limited
Operator of GAINKAT
- Contact
- SHM
- privacy@gainkat.com
- Phone
- +91 96332 21069
- Address
- 29, CWRDM Road, Netaji Nagar, Kottooli, Kozhikode, Kerala 673016, India
- Tax ID
- 32AAJCC2164M1ZM