On this page
1. Who we are
This Privacy Policy explains how Growvior Software Private Limited (CIN: U58200KL2025PTC095633), which operates the "Bhaksh" surplus-food marketplace app and website (together, the "Platform"), collects, uses, stores, shares and protects your personal data. "We", "us" and "Bhaksh" mean Growvior Software Private Limited; "you" means any user — a customer or a restaurant partner.
For the personal data whose purposes and means of processing we determine, we are the Data Fiduciary under the DPDP Act. Our registered office is 39/2475-B1, LR Towers, South Janatha Road, Palarivattom, Ernakulam - 682025, Kerala and you can reach us at bhaksh@growvior.com. By using the Platform you acknowledge this Policy; where the law requires your consent, we obtain it separately.
2. Scope & definitions
This Policy covers the app, the website and related services, and should be read with our Terms of Service. In line with the DPDP Act: "personal data" is any data about an identifiable individual; you are the "Data Principal"; we are the "Data Fiduciary"; a service provider that processes data on our instructions is a "Data Processor"; and a "child" is anyone under 18 years of age.
3. Personal data we collect
We collect only what we need for the purposes in section 4 (purpose limitation), and we do not collect special-category data beyond what is listed here:
- Identity & contact — your name, mobile number (for OTP verification) and email.
- Google Sign-In basics — your name, email, profile photo and Google account ID (basic profile scopes only), if you choose Google sign-in.
- Precise location — to show surplus listings near you, enable pickup/delivery and calculate distance. Collected with your device permission and only while you use location-based features.
- Order & transaction data — items reserved or purchased, pickup/delivery details and order history.
- Payment data — processed by our payment gateway (Razorpay). We receive the transaction status and reference, not your full card or UPI credentials.
- Device & diagnostic data — device model, operating system, IP address, app version, crash logs and usage analytics.
- Restaurant-partner data — business name, FSSAI licence, GSTIN/PAN, address, settlement/bank details and KYC documents.
4. Why we process your data
Each purpose maps to the data above. We process personal data to: create and authenticate your account; show you surplus food nearby; process reservations, pickups, deliveries, payments and refunds; provide customer support and grievance redressal; prevent fraud and misuse and support food-safety traceability; and comply with legal obligations (tax, FSSAI, consumer law). Only with your separate consent do we send promotional messages. We will not use your data for a new, incompatible purpose without fresh notice and consent.
5. Consent & legal basis
We process your personal data on the basis of your consent — obtained through a clear affirmative action at the point of collection — and, where applicable, for the "legitimate uses" permitted under s.7 of the DPDP Act (such as providing a service you have asked for). Our consent request is accompanied by this notice in clear, plain language, and is made available in English and other languages as required.
6. Withdrawing consent & Consent Managers
You may withdraw your consent at any time, and doing so is as easy as giving it — through in-app settings or by writing to our Grievance Officer (section 12). On withdrawal we will stop the relevant processing within a reasonable time, unless retention is required by law. Withdrawal does not affect processing done before it. Once the DPDP Consent Manager framework is operational, you may also review and withdraw consents through a Board-registered Consent Manager. Some services may not function if core consents are withdrawn.
7. How we share your data
We share personal data only as needed, with these categories of recipients:
- Restaurant partners — to fulfil your order (your name, order details, and for delivery, your contact and location).
- Delivery personnel / logistics providers — where you choose delivery.
- Payment gateway (Razorpay) — to process payments and refunds.
- Cloud hosting, analytics and communication providers — as Data Processors, bound by contract and DPDP-compliant safeguards.
- Government or law-enforcement authorities — where legally required.
We do not sell your personal data. Data Processors act only on our instructions.
8. Your rights as a Data Principal
Under the DPDP Act you have the right to:
- Access (s.11) — a summary of your personal data, the processing we carry out, and the parties we have shared it with.
- Correction & erasure (s.12) — correct inaccurate or incomplete data and erase data no longer needed, unless retention is legally required.
- Grievance redressal (s.13) — a readily available way to raise complaints (section 12).
- Nominate (s.14) — nominate another person to exercise your rights if you die or become incapacitated.
To exercise any right, contact our Grievance Officer (section 12) or use in-app account settings; we will respond within the timelines under the DPDP Rules. As a Data Principal you also agree not to file false or frivolous complaints and to provide authentic information.
9. Children's data
The Platform is intended for users aged 18 and above. We do not knowingly collect the personal data of children. Where processing a child's data (or that of a person with a disability who has a lawful guardian) is unavoidable, we will obtain the verifiable consent of the parent or lawful guardian, and we will not undertake tracking, behavioural monitoring or targeted advertising directed at children, nor process such data in a way likely to harm a child's well-being (DPDP s.9).
10. Data retention
We keep personal data only as long as necessary for the purposes stated, or as required by law (for example, tax records, FSSAI traceability, and consumer-dispute limitation periods). When the purpose is served and no legal retention applies, we erase or anonymise the data. Order and invoice records may be retained for the statutory period required under tax and accounting laws.
11. Data security
We implement reasonable security practices and procedures — managerial, technical, operational and physical controls proportionate to the data, such as encryption in transit, access controls and secure infrastructure — to protect your data against unauthorised access, loss or disclosure (IT Act s.43A; SPDI Rule 8; DPDP s.8(5)). If a personal-data breach occurs, we will notify the Data Protection Board of India and affected Data Principals as required. No method of transmission or storage is perfectly secure.
12. Grievance Officer & data-protection contact
For any question, request to exercise your rights, withdrawal of consent, or complaint about your personal data, contact our Grievance Officer:
We will acknowledge complaints within the timelines under the IT Rules, 2021 (acknowledge within 24 hours; resolve within 15 days) and the DPDP Rules. If you are not satisfied, you may escalate to the Data Protection Board of India.
13. Cross-border data transfer
Some of our service providers (for example, cloud hosting and analytics) may process data outside India. We transfer personal data outside India only in compliance with s.16 of the DPDP Act, never to a territory restricted by the Central Government, and subject to appropriate contractual safeguards. Our infrastructure runs on Google Cloud in the Mumbai (asia-south1) region.
14. Cookies & tracking technologies
Our website and app use cookies, SDKs and analytics for functionality, session management and understanding usage. You can control cookies through your browser or device settings; disabling some may affect functionality. We do not carry out behavioural tracking of children.
15. Third-party services
The Platform integrates Google Sign-In, Razorpay and mapping/geolocation services, each governed by its own privacy policy. We are not responsible for the privacy practices of third parties; please review their policies.
16. Changes to this policy
We may update this Policy from time to time. Material changes will be notified in-app or by email, and the "Last updated" date will be revised. Continued use after changes constitutes acknowledgement.