LEGAL TRANSPARENCY

Privacy Policy

We sell luxury streetwear, not your personal data. Here is exactly how we collect, encrypt, and respect your information.

Last Updated: August 2026

1. Core Commitment: Zero Data Monetization

GERKINK does not sell, rent, or trade your personal information to third-party data brokers or advertising networks. We collect only what is strictly required to fulfill orders, process multi-currency payments, prevent fraud, and calculate affiliate commissions.

2. Information We Collect

When you interact with the GERKINK storefront, we collect the following categories of information:

  • Account Credentials: Email address, display name, avatar URL, and encrypted authentication tokens.
  • Order & Fulfillment Data: Full recipient name, shipping address, city, state, postal code, country, phone number, and purchased product line items.
  • Encrypted Payout Details: For affiliates claiming referral rewards, submitted bank account numbers, IFSC/routing codes, UPI IDs, or PayPal emails.
  • Technical Metadata: Anonymized IP addresses for rate limiting, device headers for Content Security Policy compliance, and referral query attribution (e.g. ?ref=GK-XXXX).

3. Bank-Level PII Encryption (AES-256-GCM)

All sensitive financial credentials submitted by affiliates for commission payouts are encrypted server-side using AES-256-GCM (Galois/Counter Mode) authenticated encryption with random initialization vectors before being written to our database. Decryption occurs strictly in-memory by authorized admin operators when approving payouts.

4. Third-Party Fulfillment & Payment Processors

To deliver our streetwear globally, we securely share order parameters with vetted infrastructure partners:

  • Printify API: Receives customer shipping addresses and item SKU blueprints for print-on-demand fulfillment and tracking dispatch.
  • Razorpay & PayPal: Process credit card, UPI, and digital wallet transactions over encrypted TLS tunnels. We do not store raw card numbers on GERKINK servers.
  • Firebase (Google Cloud): Provides secure authentication, encrypted cloud database storage, and session token verification.

5. Session Cookies & Local Storage

We utilize HttpOnly, Secure, SameSite=Strict cookies for authentication sessions (valid for 5 days) to eliminate cross-site scripting (XSS) and cross-site request forgery (CSRF) vulnerabilities. Local storage is used exclusively to retain your shopping cart items and currency preference across browser reloads.

6. Your Rights: Right to Access & Right to Deletion (GDPR / CCPA)

You maintain full sovereignty over your data. At any time, you may:

  • Request an export of all referral and order activity stored under your account.
  • Permanently delete your user profile, encrypted payout details, and authentication record via our automated account deletion tools or by contacting support.

7. Contact & Data Privacy Requests

For privacy inquiries, GDPR data deletion requests, or questions regarding our cryptographic safeguards, reach out directly to our privacy desk:

GERKINK Privacy & Data Protection Desk

Email: gerkinkofficial@gmail.com

Support Portal: Visit Support Center →