GAINKAT

Privacy Policy

Last updated 30 September 2026

GAINKAT is an analytics product for online stores, operated by Cyberrig Private Limited. This policy explains what we collect, why, who it is shared with, and what you can ask us to do with it. It covers both the merchants who use GAINKAT and the visitors to their stores.

1. Who is responsible for your data

Our role depends on whose data it is, and the distinction matters for your rights.

For merchant account information — the details of the person and business using GAINKAT — we are the data controller. We decide what is collected and why.

For store data and store-visitor data — orders, products, customers and website activity belonging to a merchant’s shop — we act as a data processor on that merchant’s instructions. The merchant is the controller. If you shopped at a store and want your data removed, the merchant is the right first contact, and we will act on their instruction.

2. Information about merchants

WhatWhy we hold it
Email addressSigning in, and account and service notices
Name and phone number, if providedIdentifying you in the account and support
Organisation nameNaming your workspace
Authentication dataPasswords are handled by our authentication provider and stored hashed. We never see or store your password
Business details provided at signupWebsite, revenue band, industry and role, used to set sensible defaults. Optional
Usage and diagnostic logsKeeping the service working and investigating faults
A record of changes to your workspaceWho changed a setting or a connection, what it was before and after, and changes Billy made that you approved. Shown to your workspace under Settings → Activity and downloadable there. It records changes, not what you looked at
Devices you sign in fromThe browser and operating system, and the country and city your connection reports, shown to you under Settings → Devices so you can spot a sign-in you do not recognise. Your IP address is read to derive the location and is not stored
Emails you send to supportEach email to our support address becomes a ticket: your address, name, the subject and the text of the message, our replies, and the names of any attachments. Kept so we can answer you and see the history of a problem. The files themselves stay with our email provider
A demo request, if you send oneYour name, business, email, and any phone number, store address and message you give on the Book a demo form, with the page and campaign that brought you there. Used to contact you about a demo; kept as a sales record, and you can ask us to delete it

GAINKAT gives each browser a first-party identifier so the same machine is not listed twice. It is not a fingerprint: clearing your cookies clears it, and that browser then appears as a new one because at that point we genuinely cannot tell it is the same.

3. Store data we process

When a merchant connects a store, we read the following through that platform’s official API, using access the merchant explicitly grants and can revoke at any time.

SourceWhat we read
ShopifyOrders (amounts, dates, discounts, taxes, shipping, refunds, delivery status), products and variants, inventory costs, fulfilment status, and shipping country and postcode
Shopify customersA customer identifier and their order count only — used to tell new customers from returning ones
Meta Ads, where connectedAdvertising spend, impressions, clicks and platform-reported conversions, at ad level. We can also pause a campaign or change a daily budget, and only ever after you approve that specific change
Costs entered by the merchantProduct costs, fees and expenses typed into GAINKAT

Reading is the default and covers almost everything above. GAINKAT makes a change only where you have approved that specific change: recording a product cost back to Shopify, adding a tag to an order, creating a discount code you asked for, pausing a Meta campaign, or changing a daily budget.

Each of those arrives as a proposal describing exactly what will happen. Nothing is carried out until you approve it, the approved wording is what executes, and the result is recorded so you can see afterwards what was done. GAINKAT never creates campaigns, edits targeting or creative, deletes anything, or acts without being asked.

4. Store visitors and the site pixel

Merchants may install our first-party analytics script on their storefront. Where they do, we collect the following about visits to that merchant’s store, on the merchant’s behalf:

WhatWhy
A randomly generated visitor identifier, stored in a first-party cookieRecognising a returning browser so a visit and a later purchase can be connected. It is random and is not derived from any personal detail
Session identifier, page paths, page titles and timestampsUnderstanding which pages a visit included
Referring website, UTM parameters and advertising click identifiersEstablishing which advertisement, campaign or partner a visit came from
Actions such as product views, add-to-cart and checkout startMeasuring where visits progress or stop
Browser, operating system and device categoryDiagnosing tracking problems specific to a browser
Country, derived from network informationCoarse geographic reporting. We do not store IP addresses

This data belongs to the merchant whose store it was collected on. It is never combined across different merchants, and never sold, rented, or used to build advertising profiles or audiences.

5. What we never collect

These are deliberate design choices, not omissions. The application is built so that:

  • We do not copy shopper names, email addresses, phone numbers or street addresses out of a merchant’s store.
  • We never receive payment card numbers, bank details or any payment credentials. Payments are handled entirely by the store’s own provider and never pass through GAINKAT.
  • We do not use special category data such as health, biometric, religious or political information.
  • We do not track individuals across websites we do not operate for a merchant, and we do not participate in third-party advertising networks.

6. Why we use it

  • Providing the analytics, reporting and attribution the merchant asked for.
  • Calculating revenue, costs, profitability and advertising performance.
  • Answering a merchant’s questions about their own store through our assistant.
  • Keeping accounts secure and preventing abuse.
  • Diagnosing faults and improving reliability.
  • Sending service messages about the account.

We do not use merchant or visitor data to train machine learning models, and we do not sell data to anyone, for any purpose.

8. Who we share it with

We use a small number of service providers to run GAINKAT. Each acts on our instructions under a written agreement, and none may use the data for their own purposes.

ProviderPurpose
SupabaseDatabase and authentication
VercelApplication hosting and delivery
SentryReports of errors in the app — the page, the browser and what failed — so we can fix them. Sent without cookies or IP addresses
ResendSending our email, and receiving what is sent to our support and sales addresses — the message and its attachments
OpenAI and AnthropicPowering the in-app assistant, where a merchant uses it
Shopify, Meta and GoogleThe platforms a merchant connects. Data flows from them to us, at the merchant's instruction

We may also disclose information where required by law, to protect our rights or the safety of others, or to a successor entity in a merger or acquisition — in which case this policy continues to apply until you are told otherwise.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

9. Use of AI models

GAINKAT includes an assistant that answers questions about a merchant’s own store. When it is used, the question and the figures needed to answer it are sent to our model provider.

The assistant retrieves aggregated figures — totals, counts and averages — through a fixed set of internal functions. It has no general access to the database and cannot query it freely. Shopper personal details are not present in what it receives, because we do not hold them.

Our model providers do not use data submitted through their APIs to train their models.

10. Cookies and similar technology

On gainkat.com, we set cookies that are strictly necessary to keep you signed in. We do not use advertising or third-party tracking cookies on our own site.

On a merchant’s storefront, where they have installed our script, we set one first-party cookie containing a random visitor identifier, and use the browser’s session storage to hold the current session. These allow a visit to be connected to a later purchase. The cookie expires after twelve months.

Merchants are responsible for any consent banner their jurisdiction requires, and for honouring the choices their visitors make.

11. International transfers

Cyberrig Private Limited is established in India. Our service providers operate data centres in several countries, so information may be processed outside the country where it was collected.

Where data protected by the UK or EU GDPR is transferred outside those jurisdictions, we rely on the European Commission’s Standard Contractual Clauses, or an equivalent lawful mechanism, in our agreements with those providers.

12. How long we keep it

DataRetention
Merchant account informationFor as long as the account is open, then up to 90 days after closure
Store and advertising dataFor as long as the store remains connected. Disconnecting stops collection; deleting the store from the workspace removes its data
Store visitor and session dataUp to 25 months from collection, then deleted
Assistant conversationsUntil the merchant deletes them, or the account closes
Diagnostic logsUp to 90 days

A workspace’s owner can delete it from Settings. It closes at once, and 14 days later its stores’ data, files, assistant conversations and the sign-ins that belong to it alone are erased, and GAINKAT is removed from its Shopify stores. Until then the owner can cancel. Its billing records are kept, as tax law requires.

We may retain information for longer where the law requires it, or where it is needed to establish or defend a legal claim.

13. Security

  • All traffic is encrypted in transit using TLS, and data is encrypted at rest by our infrastructure providers.
  • Every workspace’s data is isolated at the database level by row-level security policies, so one merchant’s records cannot be read by another.
  • Platform access tokens are stored separately from ordinary data, in a location no client application can read.
  • Access to production systems is limited to personnel who need it.
  • Our support staff use a separate console with their own sign-in and a second factor. For each workspace it shows the plan, credits and AI usage; who signs in and when; the owner’s contact email; which stores and connections it has and whether they are syncing; and each store’s order count and revenue for the last 30 days, as totals. It does not show individual orders, customers or products. Staff can restart a sync, re-register live updates from Shopify, add credits, change a plan that is not billed through Stripe, and suspend or restore a workspace. Every visit and action there is logged, and every change appears in your Activity log as GAINKAT support. Staff also keep internal notes of their conversations with you. Each member of staff sees only what their role allows.

No system is perfectly secure. If a breach affects your information, we will notify you and the relevant regulator as required by law and without undue delay.

14. Your rights

Depending on where you live, you may have the right to access a copy of your information, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent where we rely on it.

If you are a California resident, you additionally have the right to know what is collected and to request deletion, and the right not to be discriminated against for exercising either. As stated above, we do not sell personal information.

To exercise any of these, contact us using the details below. We respond within 30 days. There is no charge unless a request is manifestly unfounded or excessive. You also have the right to complain to your local data protection authority.

15. If you shopped at a store using GAINKAT

We hold no name, email address or payment details for you. What we may hold, on behalf of the store, is a random identifier and a record of pages visited and actions taken on that store’s website.

The store is the controller of that information, so please contact the store first — they can instruct us to delete it. You may also contact us directly and we will pass the request on and act on it. Clearing your browser cookies for that store also ends the association immediately.

16. Children

GAINKAT is a business tool and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child’s information has reached us, contact us and we will delete it.

17. Changes to this policy

We will update this page when our practices change, and revise the date at the top. If a change materially affects how we handle your information, we will tell account holders by email or in the application before it takes effect.

18. Contact us

Cyberrig Private Limited

Operator of GAINKAT

Contact
SHM
Phone
+91 96332 21069
Address
29, CWRDM Road, Netaji Nagar, Kottooli, Kozhikode, Kerala 673016, India
Tax ID
32AAJCC2164M1ZM