Flipkart Marketplace Platform  ·  View 10 of 25  ·  4 · Data

Data Architecture and Ownership

Which store is the record, which is authored, which is derived — and therefore what has to be backed up.

Editable source SVG draw.io All views
Systems of record — strongly consistent, never rebuilt from anything else Orders Citus · shard by order Payments and refunds Citus · PCI scope Inventory ledger Citus · append only Settlement ledger Citus · double entry Identity and consent PostgreSQL Authored masters — eventually consistent, owned by a person or a feed Catalog and listings Cosmos DB NoSQL Prices and promotions Cosmos DB + Redis Seller profile and KYC PostgreSQL + Blob Media and documents ADLS Gen2 Derived — rebuildable from the record or the log, so never backed up Search index OpenSearch · 150M docs Online features Feast on Redis Seller analytics Apache Pinot Read caches Redis · PDP, cart Analytical estate — the lakehouse Bronze · raw Raw topic landing Iceberg · 30 d Silver · conformed Conformed entities Iceberg · 3 y Gold · marts Business marts GMV, funnel, supply Training sets point in time Regulatory archive immutable · 8 y CDC · Debezium index rebuild upsert stream WORM export Data Architecture — Ownership and Rebuildability Data store event / async batch The classification decides the backup bill: only the top two boxes are backed up and point-in-time restorable. Everything in the derived box is rebuilt from Kafka or the record within an hour. v 1.0 · owner Data Architecture · date 2026-09

The classification is the decision

  • Systems of record are strongly consistent, backed up and point-in-time restorable: orders, payments, inventory ledger, settlement, identity
  • Derived stores — search index, features, seller analytics, caches — are never backed up; they are rebuilt from Kafka or from the record
  • Rebuild time is the SLA that replaces backup for the derived tier: full search index rebuild in under an hour

Polyglot, with a reason each

  • Citus (Cosmos DB for PostgreSQL) where a transaction must be atomic and shardable by tenant or order
  • Cosmos DB NoSQL for the catalog, where the document shape varies per category and multi-region writes matter
  • Redis where the access pattern is a counter or a hot key, not a query

Retention and residency

  • Bronze 30 days, silver 3 years, gold indefinite; financial records exported WORM for 8 years
  • All data in Indian regions; PII tokenised before it leaves the owning service
  • PSP statements are reconciled against the settlement ledger daily — the reconciliation job is drawn on the actors view, not here