Privacy Policy

Your privacy is our priority. Learn how we collect, use, and protect your information.

Last updated: 1 August 2026

Introduction

Welcome to Kadaikodi ("we," "our," or "us"). Kadaikodi is operated by Headshot Marketing Pvt. Ltd., a company incorporated in India and part of the Burdenoff Group. We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and website (collectively, the "Platform"), and it is our notice under India's Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 (and the SPDI Rules made under it), the GDPR / UK GDPR, and the California CPRA.

By using Kadaikodi, you consent to the data practices described in this policy. If you do not agree with our policies and practices, please do not use our Platform.

Information We Collect

Personal Information

  • Account Information: Name, email address, phone number, and password
  • Profile Information: Profile picture, address, and preferences
  • Business Information: For merchants — business name, PAN, GSTIN (where applicable), licence details (e.g., FSSAI for food carts), and bank-account information, subject to RBI KYC norms
  • Investment Information: The investment marketplace is an illustrative preview only and not yet accepting investments. When it launches (subject to SEBI, Companies Act and RBI regulatory clearance), we will collect KYC documents, PAN card details, and investment/suitability preferences from investors before onboarding them
  • Payment Information: Credit/debit card details, UPI IDs, digital wallet information (held by our PCI-DSS payment partners as tokenised references — we do not store full card or bank-account numbers)

Usage Information

  • Location Data: GPS location for finding nearby carts and delivery services
  • Device Information: Device type, operating system, unique device identifiers
  • Usage Data: Search queries, order history, interaction with carts
  • Communication Data: In-app messages, customer support interactions

How We Use Your Information

  • Service Delivery: To facilitate connections between customers and merchants
  • Payment Processing: To process transactions securely
  • Communication: To send order updates, promotional offers, and important notifications
  • Personalization: To provide customized recommendations and improve user experience
  • Safety & Security: To verify identities (KYC/AML), prevent fraud, and ensure platform safety
  • Analytics: To understand usage patterns and improve our services
  • Legal Compliance: To comply with applicable laws and regulations, including RBI, SEBI, GST/tax, and DPDP obligations

We do not sell your personal data, and we do not use your personal data, order content, messages or reviews to train, fine-tune or evaluate any generally available machine-learning or large-language model in a way that identifies you.

Information Sharing and Disclosure

We do not sell, trade, or rent your personal information. We may share your information in the following circumstances:

  • With Service Providers (subprocessors): Payment processors, cloud infrastructure, analytics, and KYC/verification services. The full, up-to-date list is published on our Subprocessors page
  • Between Users: Limited information shared between customers and merchants for order fulfillment
  • For Legal Reasons: When required by law, a lawful court/CERT-In order, or to protect our rights and safety
  • Business Transfers: In case of merger, acquisition, or sale of assets
  • With Consent: When you explicitly agree to share your information

Data Security

We implement industry-standard security measures to protect your information:

  • • Encryption in transit (TLS) and at rest for primary data stores
  • • Secure SSL/TLS connections
  • • Regular security audits and penetration testing
  • • Payment processing handled by a PCI-DSS-compliant payment provider
  • • Access controls (role-based) and authentication mechanisms
  • • Regular employee training on data protection

Breach notification. We notify affected customers of a confirmed personal-data breach without undue delay, and in any event within 72 hours of becoming aware. Where required, we report qualifying incidents to CERT-In within 6 hours of becoming aware, per Indian cybersecurity directions.

Your Rights and Choices

You have the following rights regarding your personal information:

  • Access: Request a copy of your personal data and a summary of processing
  • Correction: Update, complete, or correct inaccurate information
  • Deletion / Erasure: Request deletion of your account and associated data (subject to legal-hold exceptions below)
  • Portability: Receive your data in a structured, machine-readable format
  • Opt-out: Unsubscribe from marketing communications
  • Consent Withdrawal: Withdraw consent for data processing where applicable
  • Nomination (DPDP Act): Nominate another person to exercise your rights in the event of your death or incapacity
  • Grievance redressal: Raise a complaint with our Grievance Officer (below); if unresolved, you may escalate to the Data Protection Board of India under the DPDP Act, your local Data Protection Authority under GDPR/UK GDPR, or the California Privacy Protection Agency under CPRA

We respond within the timeframe local law requires — typically 30 days under the DPDP Act and GDPR/UK GDPR, and 45 days under CPRA. Some data (e.g., KYC, AML, and tax/transaction records) we must retain by law and cannot delete on request — see Data Retention below.

Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience. See our full Cookie Policy for the exact cookies we set, their purpose, and how to control them. In short:

  • Essential Cookies: Required for platform functionality
  • Analytics Cookies: Help us understand usage patterns (self-hosted analytics — we do not sell this data)
  • Preference Cookies: Remember your settings and preferences
  • Marketing Cookies: Measure the effectiveness of our own marketing campaigns

You can manage cookie preferences through our cookie preferences centre, your browser settings, or by sending a Global Privacy Control (GPC) signal, which we honour as a US opt-out signal.

Children's Privacy

Kadaikodi is intended for users aged 18 and over to transact, sell, work or invest, and 13 and over for browse-only features. We do not knowingly create accounts for children under 13. For users aged 13 to the age of majority, we collect a parent or lawful guardian's email address and send a notification email to the guardian. Transactional, selling, working and investing features are not enabled for known minor users. If you are a parent or guardian and believe we hold a child's account without your awareness, please contact us immediately.

International Data Transfers

All Customer Data is stored in India by default — backend services and frontend assets are hosted in Indian cloud regions. Some operational metadata (e.g., connection metadata routed through Cloudflare's edge, and international billing data processed by Stripe) may leave India.

For transfers out of the EEA, UK or Switzerland, we rely on the EU Standard Contractual Clauses (Module 2), the UK International Data Transfer Addendum, and the Swiss FDPIC-approved variant, incorporated into our Data Processing Addendum. For India, we comply with cross-border transfer rules under Section 16 of the DPDP Act, 2023 and any restrictions the Central Government notifies from time to time.

Data Retention

We retain your personal information only as long as necessary to provide our services and comply with legal obligations. Typical retention periods:

  • • Account profile data: while the account is active, plus 90 days
  • • KYC / AML records: as required by RBI / PMLA rules — typically up to 5 years after the relationship ends, or longer if law requires
  • • Billing and tax records: 8 years (Indian Income-tax Act / Companies Act / GST retention requirements)
  • • Investment records (where applicable): as required by securities / tax law
  • • Security and abuse investigations: up to 7 years if needed to establish or defend legal claims

When information is no longer needed, we securely delete or anonymize it.

Updates to This Policy

We may update this Privacy Policy periodically. For material changes that reduce your rights, we give at least 30 days' notice through the Platform or via email. Your continued use of Kadaikodi after changes indicates acceptance of the updated policy. Statutory consumer protections under the Consumer Protection Act, 2019 are preserved.

Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

Headshot Marketing Pvt. Ltd.
CIN: U74999TN2022PTC155849
PAN: AAGCH5173C
GSTIN: 33AAGCH5173C1ZW
DPIIT certificate no.: DIPP121325
Privacy: [email protected]
General: [email protected]
Phone: +91-7358445777
Address: "VISWAM", Plot No.43, Veeramani Nagar, 2nd Cross Street
Nanmangalam, Chennai - 600117, Tamil Nadu, India

Grievance Officer & Nodal Contact

In accordance with the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, and the Consumer Protection (E-Commerce) Rules, 2020, the name and contact details of the Grievance Officer and the E-Commerce Rules Nodal Contact are provided below:

Grievance Officer (DPDP Act §8(10) / IT Act / E-Commerce Rules)
Vignesh T.V., Founder & CEO
Headshot Marketing Pvt. Ltd.
Email: [email protected]
Phone: +91-7358445777

Nodal Contact / Chief Grievance Officer (E-Commerce Rules)
Vignesh T.V., Founder & CEO
Headshot Marketing Pvt. Ltd.
Email: [email protected]
Phone: +91-7358445777

If your complaint is not resolved to your satisfaction, you may escalate it to the Data Protection Board of India once operational under the DPDP Act.