Learn what personal data we collect, how it is used, and your rights over that data.
This Privacy Policy describes what personal data Commerce.lk collects, how it is used, and the choices you have regarding that data. We have written this policy to be direct and readable — not to obscure anything behind legal complexity.
By using this platform you agree to the practices described here. If you do not agree, please do not use the platform.
When you create an account, we collect your name, email address, and a password (stored as a one-way cryptographic hash — we never store your password in plain text).
You may choose to provide additional details — phone number, school name, district, medium of instruction, A/L year, gender, and date of birth. These fields are entirely optional. They are used only to personalise your experience on the platform.
If you are signed in, we record your download history (up to 200 entries) and the resources you bookmark. This data powers your profile page and is not used for any other purpose.
Like all web servers, ours logs basic request data — IP address, browser type, pages visited, and timestamps. This data is used to maintain and improve the platform and is not linked to your account.
We use the data we collect to:
We do not use your data for advertising targeting, profiling, or any purpose not listed above.
We do not sell, rent, or share your personal data with third parties for their commercial purposes.
Your data may be processed by the following categories of service provider, strictly as necessary to operate the platform:
These providers process data only on our instructions and are not permitted to use it for their own purposes.
We retain your personal data for as long as your account is active. If you delete your account, your personal data — name, email, profile information, download history, and bookmarks — is permanently deleted from our database. Anonymised aggregate data (e.g. total download counts per resource) may be retained.
Server access logs are retained for up to 90 days for security and diagnostic purposes.
You have the right to:
To exercise any of these rights, use the settings in your profile page or write to hello@commerce.lk.
Passwords are hashed using bcrypt with a work factor of 12 before storage. Connections to the platform are encrypted via TLS. We apply standard security practices throughout the application. No system is perfectly secure, and we cannot guarantee that a breach will never occur, but we take reasonable and proportionate measures to protect your data.
We may update this policy from time to time. When we do, the “last updated” date at the top of this page will change. For significant changes, we will notify registered users by email. Continued use of the platform after a change constitutes acceptance of the updated policy.
For privacy-related questions or requests, write to hello@commerce.lk.