Privacy Policy
Last updated 22 August 2026
This policy explains what personal data Bhagavatha Groups ("we", "us") collects when you use The Organic Bengaluru mobile application and website, why we collect it, how long we keep it, and the choices you have.
We do not sell your personal data, and we do not share it for advertising.
1. Who we are
The Organic Bengaluru is an organic grocery delivery service operating in Bengaluru, Karnataka, India. The data controller (the "Data Fiduciary" under India's Digital Personal Data Protection Act, 2023) is:
Bhagavatha Groups
94/16, Annasandrapalya Nanjappa Colony, Annasandrapalya Extension, Vimanapura, HAL, Bengaluru, Karnataka 560017
GSTIN: [[GSTIN — registration pending]]
Email: support@theorganicbengaluru.com
Phone: +91 93538 42258
2. What we collect
We collect only what the service needs to work. Nothing below is optional decoration — each item is used for the purpose stated beside it.
| Data | Why we hold it | When it is collected |
|---|---|---|
| Mobile number | It is your account identity and how we sign you in. We also use it to reach you about an order in progress. | When you first sign in |
| Name, email address, date of birth | To address you correctly, send order receipts, and apply any age-restricted or birthday offers. | Optional; only if you enter them in your profile |
| Delivery addresses — recipient name and phone, address lines, landmark, area, city, state, PIN code, and the map coordinates you pick | To determine whether we deliver to you, to calculate the delivery fee and time, and to get the order to your door. | When you add an address |
| Approximate or precise device location | Only to pre-fill the address form and to check serviceability. The app asks permission first, and you can decline and type your address instead. | Only while you are choosing a delivery location, and only with permission |
| Order history — items, quantities, prices, taxes, coupons, delivery slot and status | To fulfil and support your orders, to show you your past orders, and to meet tax and accounting obligations. | Each time you place an order |
| Payment status and gateway reference | To confirm that an order is paid and to process refunds. We never receive or store your card number, UPI PIN, CVV or bank credentials — those go directly to our payment gateway. | At checkout, for online payments |
| Device information — push notification token, platform, device identifier, app version and locale | To send order-status notifications to the right device, and to diagnose crashes and version-specific bugs. | When the app starts |
| Sign-in records — last sign-in time, and one-time-code request counts | Security: to detect and rate-limit abuse of the sign-in system. | At each sign-in attempt |
We do not collect your contacts, photos, microphone, camera, calendar, SMS messages, or the list of other apps on your device.
3. App permissions
The Android app requests these permissions and no others:
- Internet and network state — to reach our servers and to tell you when you are offline.
- Location (coarse and fine) — only to pre-fill and verify a delivery address. Declining it does not stop you from ordering; you can enter the address manually.
- Notifications — to tell you when your order is confirmed, packed, dispatched and delivered. You can turn these off in your device settings at any time.
The app does not track your location in the background.
4. Why we are allowed to use it
We process your data on these grounds:
- To perform our contract with you — taking, fulfilling and delivering your order, and handling returns and refunds.
- Your consent — location access and push notifications. You may withdraw either at any time through your device settings, without affecting anything you have already ordered.
- Legal obligation — tax invoices, GST records and financial reporting.
- Legitimate business interest — preventing fraud and abuse, securing accounts, and keeping the service working.
5. Who else sees it
We share the minimum necessary, only with parties who need it to deliver the service:
- Delivery partners — your name, delivery address, phone number and the items to hand over. They do not receive your email address, date of birth or order history.
- Payment gateway (Razorpay) — the order amount and reference. They handle the payment instrument directly under their own privacy policy.
- Notification and hosting providers — Google Firebase Cloud Messaging for push notifications, and our hosting provider for the servers that run the service.
- Government authorities — where we are required by law to disclose, and only to the extent required.
We do not sell personal data. We do not share it with advertisers or data brokers.
6. Where it is stored
Your data is stored on servers operated by our hosting provider, Hostinger, in [[DATA CENTRE REGION — confirm in hPanel]]. Some of our service providers may process data outside India; where that happens we rely on the provider's contractual data-protection commitments.
7. How long we keep it
| Data | Kept for |
|---|---|
| Account profile and addresses | While your account is open, then deleted in line with section 8 |
| Order, invoice and payment records | 8 financial years, because tax law requires it |
| One-time sign-in codes | Five minutes. They are stored hashed and are never readable by us or written to a log. |
| Push notification tokens | Until the app is uninstalled or you sign out |
| Server and security logs | 14 days |
8. Your rights
You may, at any time:
- See and correct your data — your profile and saved addresses are editable in the app under Account.
- Ask for a copy of the personal data we hold about you.
- Delete your account — Account → Delete account in the app, or email us. When you ask, we immediately deactivate the account and sign out every device.
- Withdraw consent for location or notifications, through your device settings.
- Complain to us first, and then to the Data Protection Board of India if you are not satisfied.
One honest caveat about deletion. When you delete your account we remove your profile and addresses, but we cannot erase invoices, payment records and order history, because tax and accounting law requires us to retain them for the period in the table above. Those retained records are kept only for that purpose and are not used to contact you or to build a profile.
9. Children
The service is not intended for anyone under 18. We do not knowingly create accounts for children. If you believe a child has an account with us, write to us and we will remove it.
10. How we protect it
- All traffic between the app and our servers is encrypted with HTTPS.
- Sign-in codes are stored hashed, never in plain text, and are never written to a log or returned in a response.
- Sign-in attempts are rate-limited per phone number, per IP address and per device.
- Staff access to the dashboard requires a password and a second factor, and is limited by role — most staff cannot see customer contact details at all.
- Access to customer records by staff is logged.
No system is perfectly secure. If a breach affects your data we will notify you and the Data Protection Board of India as the law requires.
11. Changes to this policy
If we change this policy materially we will update the date at the top and notify you in the app before the change takes effect. Continuing to use the service after that means you accept the updated policy.
12. Contact us
For any privacy question, or to exercise a right above, contact our Grievance Officer:
Grievance Officer: Yasash Prasad
Email: support@theorganicbengaluru.com
Phone: +91 93538 42258
Address: 94/16, Annasandrapalya Nanjappa Colony, Annasandrapalya Extension, Vimanapura, HAL, Bengaluru, Karnataka 560017
We acknowledge every request within 48 hours and resolve it within 30 days.