SKARTIO AI Cloud
Business Cloud

Digitalize your business. Operate everything from one cloud.

Launch a professional business website, manage customer relationships, automate sales and organize finance, operations and services through one connected business platform.

Partners

Connect, build and grow across the SKARTIO Eco-System.

A connected ecosystem for business partners, developers and investors contributing to customer growth, platform innovation and SKARTIO's global expansion.

Privacy Policy.

This Policy explains how SKARTIO collects, uses, shares, protects, stores and otherwise processes Personal Data when you visit our websites, use our cloud services or mobile applications, operate a business on SKARTIO, interact with Agentic AI, use APIs and integrations, participate in trials, or otherwise engage with us.

Last updated · August 2026Applies across SKARTIO cloud servicesIncludes AI and security telemetry
Different roles, different responsibilitiesSKARTIO may act as Controller for its own business data and as Processor for customer-controlled data such as Shopper or workforce information.
Cloud and AI are coveredPrompts, outputs, files, knowledge sources, tool calls, API activity, telemetry and security events are addressed in this Policy.
Security requires visibilityAudit logs, authentication records and service telemetry may be processed to protect accounts, investigate abuse and maintain platform reliability.
You retain privacy choicesDepending on applicable law, you may have rights to access, correct, delete, restrict, object, withdraw consent or raise a complaint.

Privacy follows the role SKARTIO is performing.

When SKARTIO manages its own accounts, billing, website, marketing, security and business relationships, SKARTIO generally determines why Personal Data is processed. When a customer uses SKARTIO to run commerce, CRM, workforce, finance, support or other business operations, the customer may determine the purposes of processing and SKARTIO processes that data on the customer’s behalf, subject to applicable agreements and law.

Privacy at a glance.

Collect what is relevant

We collect account, contact, device, browser, transaction, support, payment, usage and security information as needed to operate the Services.

Use it for defined purposes

Data supports service delivery, billing, support, personalization, fraud prevention, security, analytics, communication and legal compliance.

Protect customer-controlled data

Merchant, shopper, employee and business records are processed according to the role SKARTIO performs and the customer’s configuration and instructions.

Share only when needed

Information may be shared with affiliates, processors, service providers, integrations, financial institutions or authorities where necessary and lawful.

Who this Policy covers.

The categories below help explain when SKARTIO is acting for itself and when it is processing information on behalf of another business.

Merchants & business customers

Businesses and authorized users who create accounts, subscribe to SKARTIO services, operate cloud solutions, contact support or use APIs and applications.

Shoppers, end users & workforce users

People whose data is processed through a SKARTIO customer’s store, CRM, HR, LMS, support, finance or other business workflows.

Partners & developers

Partners, developers, consultants, resellers, implementation providers, integration providers and prospective ecosystem participants.

Visitors & prospects

People who browse SKARTIO websites, request information, attend events, submit forms, interact with marketing or otherwise communicate with SKARTIO.

Full Privacy Policy.

1. Scope and definitions

This Privacy Policy applies to Personal Data processed by SKARTIO in connection with our websites, mobile applications, cloud services, software, APIs, support channels, events, marketing, Agentic AI capabilities and other interactions with SKARTIO.

It does not govern independent websites, applications or services that SKARTIO does not control, including third-party products selected by customers or independent websites operated by SKARTIO customers.

Key information categories

  • Account Information: account identifiers, tenant, organization, roles, permissions, subscription and feature use.
  • Contact Information: name, business, email, phone, postal address and related contact details.
  • Browser and Device Information: IP address, browser, operating system, device identifiers, network details and approximate region.
  • Payment Information: billing and payment-related information used to process charges and prevent fraud.
  • Security Information: credentials, authentication events, access logs, MFA events, risk signals and security metadata.
  • Support Information: tickets, chats, troubleshooting details, diagnostic data and communications with support.
  • Transaction Information: orders, products, payments, shipping, fulfilment and related transactional records.
  • Usage Information: pages, features, workflows, API activity, clicks, sessions and service interactions.
  • AI Interaction Data: prompts, messages, instructions, files, retrieval context, outputs, feedback and tool activity associated with AI features.

2. When SKARTIO is a Controller and when SKARTIO is a Processor

SKARTIO generally acts as a Controller when it determines the purposes of processing for account registration, website analytics, billing, fraud prevention, security, direct support, business communications, marketing, partner management, legal compliance and internal operations.

SKARTIO generally acts as a Processor or service provider when a business customer uses SKARTIO to process Shopper, customer, workforce, lead, partner, order, catalog, finance, learning, support or other business data according to that customer’s instructions.

Some processing may involve both roles.For example, SKARTIO may process customer-controlled transaction data to provide the service, while separately using limited security and fraud signals as a Controller to protect the platform.

3. Categories of Personal Data we may process

CategoryExamplesTypical purpose
Identity & contactName, business, email, phone, addressAccount setup, support, billing, communication
Account & accessUser ID, organization, roles, permissions, login historyAuthentication, authorization, service delivery
Device & browserIP, device, OS, browser, cookies, approximate regionSecurity, analytics, personalization
Commerce & transactionOrders, products, shipping, customer and payment-related recordsMerchant service delivery, fulfilment, fraud controls
Business solution dataCRM, HR, LMS, finance, partner, support and operational recordsCustomer-configured cloud workflows
AI interactionPrompts, files, retrieval context, outputs, tool callsAI feature delivery, safety, troubleshooting
SupportTickets, chat, diagnostics, screenshots, technical detailsCustomer support and incident resolution
Security & telemetryAudit logs, risk signals, API events, usage metricsSecurity, reliability, fraud and abuse prevention

4. Merchants, prospective merchants and business customers

When you create an account, request a trial, subscribe, contact us, use a mobile application, access an API or use SKARTIO cloud services, we may collect Account, Contact, Browser, Device, Payment, Security, Support, Transaction and Usage Information.

We use this information to provide and improve services, authenticate users, manage subscriptions, invoice customers, provide support, detect fraud, manage risk, secure accounts, administer contracts, communicate with customers, personalize experiences and meet legal obligations.

5. Shoppers, end users and other customer-controlled individuals

When a Shopper or other individual interacts with a SKARTIO-powered business, SKARTIO may process Personal Data on behalf of the relevant customer. Depending on the solution, this may include contact, order, browser, support, transaction, profile, employment, learning or other business information.

The customer is generally responsible for deciding why this information is collected and used, providing appropriate notices, obtaining required consent and responding to privacy requests.

6. Partners, developers and prospective ecosystem participants

SKARTIO may process Account, Contact, Payment, Browser, Security, Support and Usage Information for partners, developers, consultants, resellers, implementation providers and other ecosystem participants.

This information may be used for onboarding, account administration, program operations, referrals, marketplace or integration enablement, support, billing, fraud prevention, communications, compliance and management of the partner relationship.

7. Website visitors, prospects and event participants

When you visit a SKARTIO website, submit a form, attend an event, request a consultation, download content or communicate with us, we may collect Contact, Browser, Device, Cookie and Usage Information.

This information may be used to respond to requests, personalize website experiences, understand site performance, manage events, provide requested communications and market SKARTIO where permitted by law.

8. Why we process Personal Data

Depending on the context, SKARTIO may process Personal Data to:

  • Provide, operate, maintain, support and improve SKARTIO Services.
  • Create accounts, authenticate users and manage permissions.
  • Process orders, transactions, workflows and customer-configured business operations.
  • Manage subscriptions, invoicing, payments, credits and account administration.
  • Detect fraud, misuse, abuse, suspicious access and cybersecurity threats.
  • Monitor platform availability, performance, capacity and reliability.
  • Provide Agentic AI, search, analytics, recommendations and automation.
  • Provide support, investigate incidents and resolve technical issues.
  • Personalize communications and service experiences.
  • Conduct marketing and event communications where permitted.
  • Comply with contractual, tax, legal, regulatory and law-enforcement obligations.
  • Establish, exercise or defend legal claims and enforce SKARTIO Terms.

10. Agentic AI, AI assistants, models and generated content

SKARTIO may provide AI assistants, agents, content generation, recommendations, knowledge retrieval, model routing, automated workflows and tool-enabled actions.

AI Interaction Data may include:

  • Prompts, messages, instructions and conversation content.
  • Files, images, documents and other content submitted for processing.
  • Knowledge-base material and retrieved context used to answer a request.
  • Generated outputs, recommendations, summaries and classifications.
  • Tool calls, API actions, workflow steps and execution metadata.
  • User feedback, ratings and corrections associated with an AI interaction.

AI Interaction Data may be processed to provide the requested feature, maintain security, troubleshoot failures, evaluate quality, enforce usage policies and improve the operation of SKARTIO Services.

Do not submit Personal Data to AI features unless you are authorized to do so.Customers remain responsible for the lawfulness of Personal Data, confidential information and customer-controlled data they choose to provide to AI-enabled workflows.

SKARTIO may use different model families, service providers or private model infrastructure. Where a third-party model provider processes Personal Data on SKARTIO’s behalf, the provider is handled under applicable contractual and security controls.

11. Knowledge bases, documents and uploaded files

Customers may upload documents, catalogs, policies, product information, FAQs, business records and other materials into knowledge or retrieval features. These materials may be indexed, transformed, embedded or otherwise processed to enable search, retrieval and AI-assisted responses.

Access to customer knowledge sources is governed by customer account permissions and applicable tenancy controls. Customers are responsible for ensuring they have lawful rights to upload and use such material.

12. Commerce Cloud, Business Cloud and other customer business data

Depending on the SKARTIO solution selected by a customer, the platform may process data relating to products, catalogs, orders, shoppers, leads, employees, learning, finance, partners, support, operations, websites, communications and other business functions.

SKARTIO does not independently determine the business purpose for customer-controlled records merely because they are hosted on SKARTIO. Customers are responsible for privacy notices, permissions, retention instructions and lawful processing associated with their business use.

13. Service usage, logs, audit trails and telemetry

SKARTIO may collect operational telemetry including authentication events, API requests, feature usage, system events, errors, performance metrics, network information, security events, audit records, capacity information and other diagnostic data.

This information supports service delivery, billing, reliability, troubleshooting, abuse prevention, fraud detection, threat detection, incident response, capacity planning and enforcement of service limits.

Where practical, SKARTIO may aggregate or de-identify telemetry for analytics, performance analysis and product improvement.

14. Cybersecurity trials, security products and evaluation data

If you use a SKARTIO cybersecurity feature, scanner, monitoring agent, assessment service or security trial, we may process technical information about the authorized systems being evaluated, including host, network, endpoint, domain, configuration, event, vulnerability and security findings.

Security evaluation data may be used to provide the assessment, generate findings, investigate security events, maintain the integrity of the service and comply with lawful obligations.

Customers must only submit or scan systems they own, control or are expressly authorized to assess. Unauthorized third-party security testing is prohibited by the SKARTIO Terms of Service.

15. Payments, billing and financial information

SKARTIO may collect billing contacts, invoice details, transaction references and payment-related information. Payment credentials may be processed by financial institutions, payment gateways or other payment providers.

SKARTIO may use payment and transaction information for invoicing, reconciliation, taxation, fraud prevention, charge management, customer support and compliance.

16. Promotional, service and account communications

Promotional communications

SKARTIO may send product updates, offers, event invitations, surveys and other promotional communications where permitted by law. You can opt out of promotional communications through the method provided in the message or through available preference settings.

Essential service communications

Billing notices, account changes, legal notices, security alerts, service-impacting updates and other operational communications may be necessary for active accounts and may not be subject to marketing opt-out.

17. Cookies and similar technologies

SKARTIO may use cookies, pixels, local storage, SDKs and similar technologies to operate websites and applications, remember preferences, maintain sessions, protect accounts, measure usage and support marketing where permitted.

TypePurpose
EssentialAuthentication, security, sessions and core site functionality.
FunctionalPreferences, chat, media and enhanced user experiences.
AnalyticsUnderstanding website and application performance and usage.
AdvertisingMarketing measurement, audience creation or targeted advertising where permitted.

You may control non-essential cookies through available cookie settings, your browser or device. Disabling certain cookies may affect features. SKARTIO may honor Global Privacy Control or similar legally recognized signals where applicable and technically supported.

18. Information sharing, service providers and subprocessors

SKARTIO may disclose Personal Data to:

  • Cloud, hosting, security, support, analytics and infrastructure providers.
  • Payment processors, banks and financial-service providers.
  • Messaging, communication, CRM, support and productivity providers used to operate SKARTIO.
  • AI model or AI infrastructure providers used to deliver requested AI features.
  • Partners or implementation providers involved in services requested by a customer.
  • SKARTIO affiliates and entities in the SKARTIO family for legitimate business operations.
  • Professional advisers, auditors and insurers where necessary.
  • Government, regulatory or law-enforcement authorities where required by applicable law or valid legal process.

Service providers are expected to process Personal Data under applicable contractual, confidentiality, security and data-protection requirements.

19. Third-party integrations and customer-enabled products

Customers may choose to connect SKARTIO with third-party applications, marketplaces, payment providers, logistics systems, social platforms, AI services or other integrations.

Enabling an integration may allow the third party to receive Personal Data from SKARTIO or send information into SKARTIO. Third-party products are governed by their own privacy practices and terms.

Customer choice matters.SKARTIO is not responsible for the independent privacy or security practices of third-party products selected and enabled by a customer.

20. Automated decision-making, fraud screening and personalization

SKARTIO may use automated systems to detect fraud, suspicious access, spam, abuse, security threats and other platform risks. Automated systems may also support recommendations, personalization, routing, classification or marketing where permitted.

Where applicable law provides a right concerning solely automated decisions with significant effects, you may request available information, human review or another remedy as required by law.

21. How we protect Personal Data

SKARTIO uses administrative, organizational and technical safeguards designed to protect Personal Data from unauthorized access, alteration, disclosure, loss or misuse.

Measures may include encryption in transit, access controls, authentication protections, logging, network controls, monitoring, backup procedures, vulnerability management, tenant isolation and other controls appropriate to the nature of the Services.

No security measure or transmission method can guarantee absolute security. Customers are responsible for protecting credentials, configuring users and permissions, securing integrations and following reasonable security practices.

22. Security incidents and breach response

SKARTIO maintains processes to investigate suspected security incidents and take appropriate remedial action. Where a Personal Data breach triggers legal or contractual notification obligations, SKARTIO will provide notifications in accordance with the applicable role, law and agreement.

Where SKARTIO acts as a Processor, SKARTIO may notify the relevant customer so that the customer can meet its own obligations to affected individuals or authorities.

23. Data retention, backups and deletion

SKARTIO retains Personal Data for as long as reasonably necessary for service delivery, account administration, support, security, fraud prevention, billing, legal obligations, dispute resolution, business continuity and other purposes described in this Policy.

Retention periods may differ by data category, solution, customer instruction, regulatory obligation, backup cycle and contractual requirement.

Customer-controlled data may be deleted or returned following account termination according to the applicable product capability, retention schedule, backup cycle and contractual terms. Some records may be retained where legally required or necessary to establish, exercise or defend legal claims.

24. International and cross-border data transfers

SKARTIO may process or store Personal Data in countries other than the country in which it was collected, depending on cloud region, service configuration, customer choice, support operations and service providers.

Where applicable law requires transfer safeguards, SKARTIO may use approved contractual mechanisms, data-processing agreements, Standard Contractual Clauses, the UK International Data Transfer Addendum or other legally recognized measures.

Transfers involving Personal Data originating in India are handled subject to applicable Indian data-protection law, including any restrictions or requirements issued by the Government of India.

25. Your privacy rights

Depending on your jurisdiction, role and applicable law, you may have rights to:

  • Request information about Personal Data we process about you.
  • Access or obtain a copy of Personal Data.
  • Correct inaccurate or incomplete Personal Data.
  • Request deletion where legally available.
  • Withdraw consent where processing is based on consent.
  • Object to or restrict certain processing.
  • Opt out of certain marketing, targeted advertising or legally defined sharing.
  • Request portability where applicable.
  • Request review of certain automated decisions where applicable.
  • Nominate another person to exercise rights where applicable law provides such a right.
  • Raise a grievance or complain to an appropriate supervisory or data-protection authority.

SKARTIO may need to verify identity, authority and account relationship before fulfilling a request. Rights may be limited by law, security, confidentiality, legal obligations or the rights of others.

26. Shopper and customer-controlled data requests

If you are a Shopper, employee, learner, lead, partner contact or other person whose information is controlled by a SKARTIO customer, you should normally submit your privacy request directly to that customer.

SKARTIO may assist the customer in responding where required by our agreement and applicable law, but SKARTIO may not be able to independently alter customer-controlled data without the customer’s instruction.

27. Children and age-restricted data

SKARTIO websites and business services are not intended to be independently used by children where such use is prohibited or requires parental authorization under applicable law.

SKARTIO does not knowingly seek to collect children’s Personal Data for its own direct marketing. Customers using SKARTIO to provide services involving children are responsible for determining applicable age, notice, consent and parental-authorization requirements.

If you believe Personal Data relating to a child has been processed unlawfully, contact SKARTIO Support so the matter can be investigated.

28. Sale of data, targeted advertising and profiling

SKARTIO does not sell Personal Data in the ordinary meaning of selling personal information for monetary payment. Certain privacy laws may define “sale” or “sharing” more broadly, including some advertising or cross-context behavioral activities.

Where legally required, SKARTIO provides applicable choices regarding targeted advertising, profiling or legally defined sharing. SKARTIO does not intentionally use Sensitive Personal Data for targeted advertising in a manner prohibited by applicable law.

29. Corporate transactions and change of control

SKARTIO may disclose Personal Data to actual or prospective investors, acquirers, successors, lenders and advisers in connection with financing, mergers, acquisitions, restructuring, sale of assets, insolvency or other corporate transactions, subject to appropriate confidentiality and legal safeguards.

30. Customer responsibilities when using SKARTIO to process Personal Data

Customers that use SKARTIO to collect or process Personal Data are responsible for their own compliance with applicable privacy, employment, consumer, marketing and data-protection laws.

Customers should, as applicable:

  • Provide clear and accurate privacy notices.
  • Establish a lawful basis for collection and processing.
  • Obtain valid consent where required.
  • Collect only Personal Data appropriate for the business purpose.
  • Configure user access and permissions appropriately.
  • Manage retention and deletion in accordance with applicable law.
  • Respond to privacy rights requests from individuals.
  • Use Sensitive Personal Data only where authorized and legally permitted.
  • Ensure integrations and third-party products are appropriately assessed.
  • Do not use SKARTIO to process Personal Data for unlawful fraud, abuse, harassment, discrimination or other prohibited purposes.

31. Updates to this Privacy Policy

SKARTIO may update this Policy to reflect changes in our products, technology, legal requirements, security practices or business operations.

Where required, material changes will be communicated through the website, service, email or other appropriate method and additional consent will be obtained where applicable law requires it.

32. Contact, grievances and privacy requests

Questions about this Privacy Policy, privacy rights requests, complaints or concerns about how SKARTIO handles Personal Data can be directed to SKARTIO Support.

SKARTIO SupportEmail: support@skartio.ai
Phone / WhatsApp: +91 7012141500
SKARTIO AI Cloud Private Limited · India

If applicable law requires SKARTIO to designate or publish additional privacy, grievance or data-protection contact details, those details should be maintained in the production version of this Policy and applicable account or privacy interfaces.

Your privacy choices.

Access & understand

Ask what Personal Data SKARTIO controls about you and how it is being used, subject to applicable law.

Correct & delete

Request correction or deletion where the relevant privacy law provides that right and no lawful retention exception applies.

Control communications

Opt out of promotional communications and manage applicable cookie or advertising preferences.

Raise a concern

Contact SKARTIO about a privacy concern or exercise a right to complain to an applicable authority where available.

Privacy questions?

Contact SKARTIO Support.

For privacy requests, questions about Personal Data, AI data handling, customer-controlled data or cross-border processing, contact us through the channels below.