Data Integrity

Privacy
Policy

Last Updated • April 2026
1

1. INTRODUCTION

Culinary Compass Advisors LLP ("Company", "we", "us", or "our") is a Limited Liability Partnership incorporated under the laws of India, providing technology-driven analytics solutions and business consulting services to restaurants and food service businesses.

We operate a Software-as-a-Service (SaaS) analytics platform that enables businesses to integrate operational and transactional data from third-party systems, including point-of-sale (POS) platforms and food delivery aggregators, and to generate insights through dashboards, reports, and performance analytics.

In addition to our technology platform, we provide strategic consulting and advisory services aimed at improving business growth, delivery performance, dining operations, and profitability.

This Privacy Policy explains how we collect, use, process, store, and protect personal data in connection with:

  • Our SaaS platform
  • Our consulting and advisory services
  • Our website and related communications

In most cases, we process personal data on behalf of our business clients in our capacity as a data processor. In certain situations (such as account management, website usage, and direct communications), we may act as a data fiduciary under applicable Indian law.

This Privacy Policy is issued in accordance with the Digital Personal Data Protection Act, 2023 and other applicable laws.

2

2. INFORMATION WE COLLECT

We collect information necessary to provide our SaaS platform, consulting services, onboarding support, and integration with third-party systems.

2.1 Account & User Information

We collect information relating to authorized users of our platform, including:

  • Name (if provided)
  • Email address
  • Contact number
  • Company/restaurant name
  • Login credentials for access to our dashboard

This information is used to create and manage user accounts and provide access to our services.

2.2 Business Platform Access & Integration Information

To provide our analytics and consulting services, we may obtain authorized access to our clients' accounts on third-party operational platforms, including but not limited to:

  • Zomato
  • Swiggy
  • Point-of-Sale (POS) systems
  • Other food aggregators or operational platforms integrated in the future

Aggregator Platform Access (e.g., Zomato, Swiggy)

In certain cases, clients may grant us authorized access to their business accounts by adding our designated company account as an authorized user or administrator on such platforms. We do not collect or store the primary login passwords of these aggregator accounts. Access is used solely for the purpose of retrieving operational and transactional data necessary to provide analytics, reporting, and consulting insights.

POS System Credentials

For certain POS integrations, clients may provide login credentials or access details to enable system connectivity and data synchronization. Such credentials are:

  • Used solely for integration purposes
  • Stored securely using appropriate safeguards
  • Accessible only to authorized personnel
  • Not shared with third parties except as required to provide services

2.3 Business & Compliance Documents

As part of onboarding, compliance verification, or consulting services, we may collect:

  • PAN card details
  • FSSAI registration/license
  • GST registration certificate
  • Cancelled cheque
  • Banking documents
  • Other regulatory or financial documentation

These documents are collected for legitimate business purposes, including compliance verification, onboarding, and operational coordination.

2.4 Operational & Transactional Data

Through integrations with client systems, we may process:

  • Order history
  • Revenue data
  • Menu information
  • Customer information (such as name, phone number, and delivery address, where available through client systems)
  • Performance metrics
  • Other business data

In most cases, such data is processed on behalf of our business clients in our capacity as a data processor.

2.5 Uploaded Files

Clients may upload files such as:

  • Excel spreadsheets
  • PDF reports
  • Operational documents

These files are processed solely for the purpose of delivering our services.

3

3. HOW WE USE THE INFORMATION

We use the information we collect strictly for legitimate business purposes related to providing our SaaS platform and consulting services.

3.1 To Provide Access to Our Platform

We use account and contact information to:

  • Create and manage user accounts
  • Provide secure access to our dashboard and services
  • Authenticate authorized users
  • Communicate service-related updates

3.2 To Deliver Analytics & Consulting Services

We use operational and aggregator data (including order, revenue, and performance data) to:

  • Generate dashboards and performance reports
  • Analyze sales, customer trends, and operational efficiency
  • Provide growth recommendations and strategic consulting
  • Improve delivery and dining performance
  • Identify revenue optimization opportunities

Such data is processed on behalf of our business clients to support their business decision making and growth strategies.

3.3 To Enable System Integration

We use authorized access to third-party platforms (Zomato, Swiggy, POS systems) to retrieve relevant business data necessary to provide analytics and consulting services. This access is used solely for service delivery purposes and not for independent commercial use.

3.4 Business Verification & Compliance

We collect PAN, GST certificates, FSSAI licenses, cancelled cheques, and banking documents for:

  • Verifying the identity and legitimacy of the business
  • Regulatory and compliance requirements
  • Onboarding and contractual documentation
  • Facilitating financial transactions between us and the client
  • Invoicing and payment processing

Such documentation is collected only where necessary and is handled with appropriate safeguards.

3.5 Service Improvement & Security

We may use limited data to:

  • Improve platform functionality
  • Monitor system performance
  • Detect and prevent fraud or unauthorized access
  • Ensure security of our systems

Where possible, analytics for improvement purposes may use aggregated or anonymized data.

3.6 Legal & Regulatory Obligations

We may process information where required to:

  • Comply with applicable laws
  • Respond to lawful government requests
  • Enforce our contractual rights
4

4. DATA SHARING & DISCLOSURE

We do not sell personal data. We do not rent, trade, or commercially distribute client data to third parties. We share information only in the limited circumstances described below.

4.1 Internal Access

Access to client data is restricted to authorized personnel within our organization who require such access for platform maintenance, data integration, analytics generation, consulting services, and customer support. Access is controlled through role-based permissions and security safeguards.

4.2 Cloud Infrastructure & Service Providers

Our platform is hosted on infrastructure provided by Amazon Web Services, including services such as EC2 and RDS for server hosting and database storage. We also use Google Workspace for internal communication and business operations. These service providers may process data on our behalf solely for the purpose of providing infrastructure or operational support services and are bound by their respective security and data protection obligations.

We may engage additional service providers in the future (such as email services, analytics tools, CRM systems, or accounting software) to support our business operations. Any such providers will be required to implement appropriate data protection safeguards.

4.3 Third-Party Platform Integration

Where clients authorize integration with third-party platforms such as Zomato, Swiggy, or POS systems, data may be accessed, retrieved, or synchronized between systems as part of service delivery. We do not independently disclose client data to these platforms beyond what is required for integration and operational functionality.

4.4 Legal & Regulatory Disclosure

We may disclose information where required to:

  • Comply with applicable laws or regulations
  • Respond to lawful requests by government authorities
  • Comply with court orders or legal processes
  • Protect our legal rights

Such disclosures are made only when legally necessary.

5

5. DATA SECURITY & SAFEGUARDS

We implement appropriate technical and organizational measures to protect personal and business data against unauthorized access, alteration, disclosure, or destruction.

Our security measures include, but are not limited to:

5.1 Infrastructure Security

Our platform is hosted on secure cloud infrastructure provided by Amazon Web Services. Security measures include:

  • Encrypted database storage
  • Secure server environments
  • Network-level security controls
  • Identity and Access Management (IAM)-based access control
  • Role-based internal access restrictions

5.2 Data Transmission Security

All data transmitted between users and our platform is encrypted using HTTPS/TLS protocols to protect information in transit.

5.3 Credential Protection

  • User account passwords are securely hashed.
  • POS system credentials are stored using appropriate encryption safeguards.
  • Access to integration credentials is restricted to authorized personnel only.

We do not store primary passwords for third-party aggregator platforms where access is granted through authorized account permissions.

5.4 Access Controls

Access to personal and business data is limited to authorized team members. We implement role-based permissions, the principle of least privilege, and controlled internal access management.

5.5 Backup & Availability

We rely on automated infrastructure-level backup mechanisms provided by our cloud hosting provider to support data resilience and system availability.

5.6 Security Monitoring & Protection

We implement reasonable safeguards to monitor system activity and protect against unauthorized access, misuse, or data breaches. While we take commercially reasonable measures to protect data, no system can guarantee absolute security.

6

6. DATA RETENTION

We retain personal and business data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

6.1 Active Client Accounts

For active clients, we retain account information, operational and transactional data, integration data, and uploaded files for the duration of the service relationship.

6.2 Upon Termination of Services

Upon termination of a client’s account:

  • Access to systems and integrations is revoked.
  • Operational and aggregator data stored within our systems is deleted within 2 business days, unless otherwise required by law.
  • Integration access credentials are removed or invalidated.

Clients are advised to revoke our authorized access from third-party platforms and update their credentials upon termination.

6.3 Financial & Compliance Documents

Certain business and financial documents (such as invoices, payment records, and regulatory documentation) may be retained for a longer period where required for legal compliance, taxation and accounting obligations, contractual dispute resolution, or regulatory record-keeping. Such data is retained only for the minimum period required under applicable law and is not used for operational analytics after termination.

6.4 Backup Systems

Data may temporarily remain in secure backup systems for a limited retention cycle before automatic deletion, in accordance with our infrastructure provider's backup policies.

7

7. YOUR RIGHTS

In accordance with applicable data protection laws, including the Digital Personal Data Protection Act, 2023, individuals whose personal data is processed through our services may have the following rights:

7.1 Right to Access

You may request information regarding the personal data we process about you, the purpose of processing, and the categories of data processed.

7.2 Right to Correction

You may request correction of inaccurate, incomplete, or outdated personal data.

7.3 Right to Erasure

You may request deletion of personal data where the data is no longer necessary for the purpose collected, consent has been withdrawn, or the processing is no longer legally required. Certain information may be retained where required by law (such as accounting or regulatory obligations).

7.4 Right to Withdraw Consent

Where processing is based on consent, you may withdraw your consent at any time by contacting us. Withdrawal of consent may affect the availability of certain services.

7.5 Grievance Redressal

If you have any questions, concerns, or complaints regarding the processing of your personal data, please contact us at contact@culinarycompass.in. We will acknowledge and respond to requests within a reasonable timeframe in accordance with applicable law.

7.6 Data Processed on Behalf of Clients

Where we process personal data on behalf of our business clients, requests relating to such data may be directed to the respective client as the primary data fiduciary.

8

8. COOKIES & AUTHENTICATION TECHNOLOGIES

Our platform uses limited cookies and similar technologies solely for authentication, session management, and security purposes. These cookies are essential for:

  • Maintaining user login sessions
  • Authenticating API requests
  • Securing access to the dashboard
  • Preventing unauthorized access

We do not use cookies for advertising, behavioral tracking, or third-party marketing purposes. Users may configure their browser settings to block or delete cookies; however, disabling essential cookies may affect the functionality and accessibility of our platform.

9

9. INTERNATIONAL DATA TRANSFERS

Our primary infrastructure is currently hosted in India (AWS ap-south-1 region). In the future, we may store or process data in additional jurisdictions where we operate or maintain infrastructure, including through cloud service providers or authorized service partners. Where personal data is transferred outside India, we will ensure that such transfers are conducted in accordance with applicable data protection laws and subject to appropriate safeguards.

10

10. Children's Privacy

Our services are intended for use by businesses and authorized representatives of business entities. We do not knowingly collect or process personal data of individuals under the age of 18. If we become aware that personal data of a minor has been inadvertently collected, we will take reasonable steps to delete such information.

11

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or operational practices. Any updates will be posted on our website with a revised "Effective Date." Continued use of our services after such updates constitutes acceptance of the revised Privacy Policy.

12

12. Contact Information

If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of personal data, please contact us. We will respond in accordance with applicable law.

Questions on Privacy?

Our data protection officer is available for any clarification regarding your rights and our storage protocols.

contact@culinarycompass.in