Last updated: June 2026
Commerce56 Tech India Private Limited ("Commerce56", "we", "our") operates a commerce infrastructure platform for brands and sellers. Our registered office is in Bangalore, India.
For questions about this policy, contact us at hello@commerce56.com.
This policy describes how Commerce56 collects, uses, stores, and disposes of information in connection with:
The Commerce56 seller platform (www.commerce56.com)
Zapigo, our celebration platform (zapigo.com)
Our owned brand stores (balloonistics.in, habba.shop, jodi.gifts)
Orders fulfilled through Amazon Multi-Channel Fulfilment on behalf of sellers
Consumer terms and privacy for Zapigo are governed separately at zapigo.com.
From Amazon sellers who connect to our platform: We access seller account data through Amazon's Selling Partner API (SP-API), authorized by the seller through Amazon's standard OAuth flow. This includes product catalog data, inventory information, order data, and fulfilment details. We use this data solely to provide the services described on this website.
From buyers placing orders through Commerce56 channels: When an order is placed through a Commerce56 channel (such as Zapigo), we collect the information necessary to fulfil that order — including name, delivery address, phone number, and email address. This constitutes Personally Identifiable Information (PII).
From visitors to our website: Standard server logs, analytics data, and any information you voluntarily provide via contact forms.
We use the information we collect to:
Operate and improve the Commerce56 platform
Route and fulfil orders through Amazon Multi-Channel Fulfilment and Amazon Seller Flex
Provide sellers with operational dashboards and analytics
Communicate with sellers and buyers regarding orders and platform updates
Comply with applicable laws and Amazon's Selling Partner API policies
We do not sell, rent, or share seller operational data or buyer PII with third parties, partner channels, or other sellers on the platform.
Partner channels (such as creator storefronts) receive only the public product information necessary to display items — product titles, descriptions, images, and pricing. No operational or personal data is shared with partners.
We retain order-level PII for more than 180 days following shipment, as required for fulfilment operations, dispute resolution, settlement reconciliation, and regulatory compliance.
When a seller revokes their platform authorization, their data is deleted in accordance with Amazon's data handling requirements.
Long-term analytics and reporting use anonymised or aggregated data only.
Commerce56 hosts all data on Microsoft Azure infrastructure. Key protections include:
Encryption at rest using AES-256 across all databases and storage
Encryption in transit using TLS 1.2 or higher for all data transfers
Private network isolation — no database or file server is exposed to the public internet
Access controls using role-based permissions tied to individual identities
Azure Key Vault for management of encryption keys and API credentials
Audit logging with minimum 12-month retention
Regular vulnerability scanning and annual penetration testing
Our full security practices are described at www.commerce56.com/security.
Commerce56 integrates with Amazon's Selling Partner API in accordance with Amazon's Acceptable Use Policy. Data accessed through the SP-API is:
Used only to provide services to the seller who authorized the connection
Never shared with other sellers, partners, or external organizations
Retained and disposed of in accordance with Amazon's data handling requirements
If you are a seller or buyer whose data we hold, you may contact us at hello@commerce56.com to:
Request access to the data we hold about you
Request correction of inaccurate data
Request deletion of your data, subject to operational and legal requirements
We will respond to all requests within 30 days.
If we identify a security incident involving Amazon data, we will notify Amazon at security@amazon.com within 24 hours of detection. Affected individuals will be notified in accordance with applicable law.
Our incident management point of contact is reachable at hello@commerce56.com.
We may update this policy from time to time. The "last updated" date at the top of this page will reflect any changes. Continued use of our platform following an update constitutes acceptance of the revised policy.