Correction notice — published 2026-09-11. We corrected the description of our analytics and marketing defaults, and the payment records we receive and retain. This text clarifies behaviour already in operation; it does not represent a newly introduced consent setting.
Kundlit (“we”, “us”) is operated by DATCRAZY LLP (GSTIN 22AASFD4221E1ZU), with registered office at 105, MM Silver Plaza, G.E. Road, Raipur, Chhattisgarh - 492001. This policy explains what data we collect when you use https://kundlit.com, why we collect it, who we share it with, and the rights you have over it. This policy describes our data practices, and the rights available to you under the Digital Personal Data Protection Act, 2023 of India (the “DPDP Act”) and, where applicable, the EU General Data Protection Regulation (GDPR).
1. What we collect
Chart inputs — name, date of birth, time of birth, place of birth. Used to compute astrological results.
Account data — email address and a hashed password (we never see your plaintext password). Optional: phone number, display name.
Order data — service ordered, price, GST breakdown, billing address (for GST invoices), order status.
Payment data — Razorpay handles entry of card and UPI credentials, which never reach our servers. We do receive and store transaction records such as amount, currency, payment and order references, status, and the last four digits of the instrument, together with the verified webhook payload used to confirm and reconcile the payment. We do not store card numbers, UPI PINs, or CVVs.
Server logs — IP address, user agent, referrer, and request path, retained for security and abuse-prevention purposes.
Cookies — a strictly necessary session cookie for logged-in customers and your cart, plus optional analytics and marketing cookies that are enabled by default and remain under your control through the footer’s Cookie settings control (see the “Cookies & Analytics” subsection below).
1a. Cookies & Analytics
We use a small set of measurement tools to understand how the site is used and to measure the effectiveness of our advertising. These load by default. The consent banner does not auto-show; until you decline through the footer’s Cookie settings control, they remain enabled (Google Consent Mode v2, default-granted).
Google Analytics 4 (GA4) — governed by the Analytics consent category. Collects pseudonymous usage and behavioural data (pages viewed, events, approximate location, device and referrer) to help us improve the site.
Microsoft Clarity — also governed by the Analytics consent category. Provides aggregate heatmaps and pseudonymous session replays (clicks, scrolls and navigation) so we can find and fix usability problems. It loads by default unless you decline Analytics consent; form input is masked by default.
Google Ads and Meta Pixel and OpenAI Ads are advertising and attribution tools in the Marketing consent category. Used to measure ad conversions and reach relevant audiences. Google Enhanced Conversions and OpenAI Ads automatic advanced matching may read the contact details you enter on our forms so a conversion can be matched to an ad click; those details are SHA-256 hashed before they leave your browser — we never transmit your raw email, phone number, or other plaintext personal data to these advertising platforms. Reddit is a measurement platform used only when we have its measurement pixel enabled. Browser pixels load only while Marketing consent is enabled; our server may also process verified conversion events for applicable platforms.
Strictly necessary cookies (your login session and cart) are always on and are not part of these consent categories.
Referral cookie — if you reach us through an affiliate’s referral link (a link carrying a ref parameter), we store a kundlit_ref cookie holding only that affiliate’s numeric id, so their commission can be credited if you go on to buy. It lasts 90 days, cannot be read by scripts in your browser, is never used for advertising, profiling, or cross-site tracking, and is not set while you are on this page. The first referral link you arrive through keeps the credit; a later one does not replace it.
These tools are enabled by default, and you remain in control. The consent banner does not auto-show; it offers Accept all, Decline, and Customize. To withdraw or change consent at any time, open the footer’s Cookie settings control and choose Decline or adjust Analytics and Marketing. This updates Google Consent Mode v2 and the ad pixels.
2. Why we use it
Compute astrological results and deliver paid reports.
Authenticate you and keep your account and orders secure.
Process payments and issue tax invoices.
Provide customer support and process refunds.
Detect, prevent, and respond to fraud or abuse.
Comply with Indian tax, accounting, and consumer-protection law.
Under §6 of the DPDP Act, our lawful basis is the consent you give when you submit a form or place an order, together with the “legitimate use” ground for processing strictly necessary to fulfil the service you requested.
3. Who we share it with (data processors)
We do not sell your data. We share the minimum necessary data with the following processors:
Hosting and email infrastructure providers — required to operate the site and send transactional emails (order confirmations, password resets).
4. How long we keep it
Order and invoice records — eight (8) years, as required by the Indian GST Act and Companies Act.
Account data — until you ask us to delete it (see §6 below), subject to the invoice-retention rule above.
Chart inputs from one-off free-tool use — not stored on our servers beyond the immediate computation, unless you are signed in and explicitly save the result to your account.
Server logs — ninety (90) days, then deleted.
5. Where we store it
Our primary servers are located in India. Payment processors may process data in India, the United States, and the European Union. When data leaves India, it is governed by the contractual safeguards published by those processors and the cross-border transfer provisions of §16 of the DPDP Act.
6. Your rights
Under §11–§14 of the DPDP Act (and, where applicable, GDPR Arts. 15–22) you have the right to:
Access the personal data we hold about you.
Correct it if it is inaccurate.
Have it erased, subject to the retention obligations in §4 above.
Withdraw consent at any time, with future effect.
Nominate another person to exercise these rights on your behalf in the event of incapacity or death (§14 DPDP Act).
Lodge a grievance with us, and escalate to the Data Protection Board of India if unresolved.
To exercise any of these rights, email [email protected] from the address on your account. We respond within thirty (30) days.
7. Security
The site is served over HTTPS. Passwords are stored as one-way hashes. Razorpay handles card and UPI credential entry; those credentials never reach our servers. We receive and store transaction and webhook records, including amount, currency, payment and order references, status, the last four digits of the instrument, and the verified webhook payload used to confirm and reconcile the payment. If we ever suffer a data breach affecting your personal data, we will notify you and the Data Protection Board without undue delay, as required by §8(6) of the DPDP Act.
8. Children
We do not knowingly collect data from children under eighteen (18). If you are a parent or guardian and believe your child has provided us with personal data, contact us and we will delete it.
9. Changes
We may update this policy. Material changes will be announced on this page with a new effective date at least seven (7) days before they take effect.
10. Grievance officer
Under §10(2)(e) of the DPDP Act and Rule 5(9) of the IT (Intermediary Guidelines) 2021, our grievance officer is: