TRUEHORECA PRIVACY POLICY & DATA PROTECTION GOVERNANCE
Entity: TRUEHORECA PRIVATE LIMITED
Website: www.truehoreca.com
Effective Date: January 1, 2026
DPO Contact: contact@truehoreca.com
Jurisdiction: Kolkata, West Bengal, India
PREAMBLE:
TRUEHORECA PRIVATE LIMITED ("TrueHoreca", "we", "us", or "our") is committed to protecting the privacy, confidentiality, and security of business information, commercial order data, and personal details of our B2B kitchen partners, restaurant buyers, hotel operators, and suppliers ("Merchant" or "you"). This Privacy Policy explains how we collect, process, store, share, and protect your information across the TrueHoreca Platform.
========================================================================
1. SCOPE & ACCEPTANCE
1.1 This Privacy Policy applies to all commercial buyers, procurement managers, hotel executives, catering owners, and suppliers accessing or using the TrueHoreca B2B e-procurement platform, web app, and mobile applications.
1.2 By registering an account, submitting business verification (KYC) documents, or placing procurement orders on TrueHoreca, you acknowledge having read and accepted the practices described in this Privacy Policy.
------------------------------------------------------------------------
2. INFORMATION WE COLLECT
2.1 Business & Account Identity Information: Business name, legal entity status, GSTIN, FSSAI license numbers, PAN details, bank account credentials for credit limits, and contact details of authorized kitchen procurement managers.
• Commercial entity name, trade name, and registered business address
• GSTIN and FSSAI mandatory food safety license documentation
• Authorized contact person's name, email address, phone number, and designation
2.2 Transaction & Procurement Data: Order histories, frequency of fresh produce purchases, grade preferences, weight logs, invoice records, payment settlement histories, credit facility utilization, and wallet balances.
2.3 Logistics & Delivery Location Data: Precise geolocation coordinates of kitchen loading bays, gate access instructions, delivery time window preferences, and driver hand-off signatures.
2.4 Technical & Device Telemetry: IP addresses, device hardware identifiers, operating system versions, browser types, session activity logs, and app interaction analytics.
------------------------------------------------------------------------
3. HOW WE USE YOUR INFORMATION
3.1 Fulfillment & Cold-Chain Logistics: Processing daily fresh produce orders, coordinating next-day morning delivery routes, managing crate dispatch/returns, and issuing real-time dispatch alerts.
3.2 Credit Underwriting & Risk Assessment: Evaluating B2B credit facility eligibility, determining credit limits (30-day floating window), and conducting automated fraud prevention checks.
3.3 Supply Chain & Farm Demand Forecasting: Analyzing aggregated purchasing trends to inform farm harvest schedules, contract farming allocations, and price optimization for bulk produce.
3.4 Compliance & Auditing: Fulfilling statutory requirements under Indian tax laws (GST e-invoicing), FSSAI food safety traceability, and anti-money laundering (AML) regulations.
------------------------------------------------------------------------
4. INFORMATION SHARING & THIRD PARTIES
4.1 Logistics & Transport Partners: Sharing necessary delivery bay addresses, contact details, and invoice summaries with vetted third-party cold-chain logistics providers for order execution.
4.2 Financial Institutions & Payment Gateways: Transmitting encrypted payment instruction data to PCI-DSS compliant payment processors, banking partners, and RBI-regulated credit underwriters.
4.3 No Sale of Commercial Data: TrueHoreca explicitly DOES NOT sell, rent, or trade your commercial order data, restaurant recipes, or buyer lists to third-party advertisers.
------------------------------------------------------------------------
5. DATA SECURITY & STORAGE SAFEGUARDS
5.1 Encryption Standards: All data in transit is protected using TLS 1.3 encryption, and sensitive KYC/payment credentials at rest are encrypted using AES-256 standards.
5.2 Access Controls: Strict role-based access control (RBAC) restricts internal employee access to Merchant data strictly on a need-to-know basis.
5.3 Infrastructure Location: Primary database servers and cold storage archives are hosted in ISO 27001 certified secure data centers located within India.
------------------------------------------------------------------------
6. DATA RETENTION & ACCOUNT DELETION
6.1 Retention Period: Active Merchant account data is retained for the duration of the commercial relationship plus 8 years thereafter to satisfy statutory tax and audit mandates under Indian law.
6.2 Account Termination: Merchants may request account closure by emailing contact@truehoreca.com, subject to clearance of all pending invoice dues and credit balances.
------------------------------------------------------------------------
7. YOUR RIGHTS & CONTACTS
7.1 Access & Rectification: Merchants have the right to inspect, update, or correct business profile details directly within the TrueHoreca portal settings.
7.2 Grievance Officer & DPO Contact: For any privacy inquiries, data deletion requests, or security concerns, contact our Data Protection Officer at contact@truehoreca.com.