LEGAL TRANSPARENCY
Privacy Policy
We sell luxury streetwear, not your personal data. Here is exactly how we collect, encrypt, and respect your information.
Last Updated: August 2026
1. Core Commitment: Zero Data Monetization
GERKINK does not sell, rent, or trade your personal information to third-party data brokers or advertising networks. We collect only what is strictly required to fulfill orders, process multi-currency payments, prevent fraud, and calculate affiliate commissions.
2. Information We Collect
When you interact with the GERKINK storefront, we collect the following categories of information:
- Account Credentials: Email address, display name, avatar URL, and encrypted authentication tokens.
- Order & Fulfillment Data: Full recipient name, shipping address, city, state, postal code, country, phone number, and purchased product line items.
- Encrypted Payout Details: For affiliates claiming referral rewards, submitted bank account numbers, IFSC/routing codes, UPI IDs, or PayPal emails.
- Technical Metadata: Anonymized IP addresses for rate limiting, device headers for Content Security Policy compliance, and referral query attribution (e.g.
?ref=GK-XXXX).
3. Bank-Level PII Encryption (AES-256-GCM)
All sensitive financial credentials submitted by affiliates for commission payouts are encrypted server-side using AES-256-GCM (Galois/Counter Mode) authenticated encryption with random initialization vectors before being written to our database. Decryption occurs strictly in-memory by authorized admin operators when approving payouts.
4. Third-Party Fulfillment & Payment Processors
To deliver our streetwear globally, we securely share order parameters with vetted infrastructure partners:
- Printify API: Receives customer shipping addresses and item SKU blueprints for print-on-demand fulfillment and tracking dispatch.
- Razorpay & PayPal: Process credit card, UPI, and digital wallet transactions over encrypted TLS tunnels. We do not store raw card numbers on GERKINK servers.
- Firebase (Google Cloud): Provides secure authentication, encrypted cloud database storage, and session token verification.
5. Session Cookies & Local Storage
We utilize HttpOnly, Secure, SameSite=Strict cookies for authentication sessions (valid for 5 days) to eliminate cross-site scripting (XSS) and cross-site request forgery (CSRF) vulnerabilities. Local storage is used exclusively to retain your shopping cart items and currency preference across browser reloads.
6. Your Rights: Right to Access & Right to Deletion (GDPR / CCPA)
You maintain full sovereignty over your data. At any time, you may:
- Request an export of all referral and order activity stored under your account.
- Permanently delete your user profile, encrypted payout details, and authentication record via our automated account deletion tools or by contacting support.
7. Contact & Data Privacy Requests
For privacy inquiries, GDPR data deletion requests, or questions regarding our cryptographic safeguards, reach out directly to our privacy desk:
GERKINK Privacy & Data Protection Desk
Email: gerkinkofficial@gmail.com
Support Portal: Visit Support Center →