Privacy Policy
Effective date: 20 August 2026 · Version: 2026.08.20
This Privacy Policy explains how HOSPIVERSE INNOVATIONS (OPC) PRIVATE LIMITED, CIN U78100HR2026OPC148919 ("Hospiverse", "we", "us", or "our"), collects, uses, shares, protects and retains personal data in connection with the Hospiverse Platform.
1. Who Is Responsible
Data-handling entity: HOSPIVERSE INNOVATIONS (OPC) PRIVATE LIMITED
Registered office: 306/5, Sector 5, Railway Road, Gurugram, Haryana 122006, India
Privacy and Grievance Contact: Jigar Chanana · Email: jigar.chanana@hospiverse.in · Telephone: +91 98102 00872
We act as the body corporate/data fiduciary for personal data processed for our own Platform purposes. A buyer, supplier, brand or consultant may separately be responsible for data it receives and uses for its own business.
2. Scope
This Policy applies to website visitors; registered buyers, suppliers, brands and consultants; prospective customers; people submitting RFQs, enquiries or grievances; representatives and staff of business accounts; and individuals whose information is provided in connection with verification or a transaction.
It does not govern an independent supplier's, consultant's, payment provider's or external website's processing for its own purposes.
3. Personal Data We Collect
Depending on how you use the Platform, we may collect:
- Identity and contact data: Name, job title, organisation, business address, city, state, email, telephone/WhatsApp number, account role and authorised-user status.
- Business and verification data: Company/firm name, registration details, GST status, FSSAI number, licences, dealership/brand authority, certifications, business references, website, service area, bank-account verification status and copies or extracts of supporting documents. We avoid collecting Aadhaar or other government identifiers unless necessary and lawful; sensitive verification documents are restricted and not published in full.
- Account and authentication data: User ID, login records, encrypted credential data or authentication tokens, account preferences, accepted policy versions, permissions, team members and security events.
- Marketplace activity: Listings, profiles, RFQs, specifications, quantity, city, timeline, quotations, comparisons, introductions, saved items, enquiries, messages, review activity, lead status and related records.
- Subscription and billing data: Plan, price, billing frequency, trial/renewal dates, invoices/receipts, payment status, Razorpay customer/mandate/transaction reference and limited payment metadata. Complete card numbers, CVV and UPI credentials are processed by the authorised payment provider and are not intentionally stored by Hospiverse.
- Hospiverse-owned product orders: Where Hospiverse is expressly identified as seller — product, quantity, delivery/contact details, order status, payment reference, invoice, delivery proof, support, return and warranty information.
- Communications and support: Emails, forms, call/WhatsApp records supplied to us, support requests, feedback, survey responses, complaints, legal notices and grievance/takedown evidence.
- Technical, usage and cookie data: IP address, device/browser type, operating system, approximate location derived from IP, referring page, page views, search/click/scroll events, session timing, crash/security logs, cookie/local-storage choices and analytics identifiers.
- Marketing preferences: Newsletter subscription, campaign interests, consent/opt-out records and engagement with permitted communications.
4. Sources
We receive data:
- directly from you;
- from an authorised representative of your organisation;
- from another user when necessary for an RFQ, quote, introduction or complaint;
- from service providers supporting hosting, payment, analytics, communication, verification or security; and
- from lawful public business registries, manufacturer/brand confirmation or sources we are authorised to use.
We do not treat public availability as permission to republish personal data or copyrighted material.
5. Why We Process Personal Data
We process data to: create, authenticate and administer accounts; verify businesses, licences, authority and badges; publish authorised profiles/listings; route RFQs, quotations, messages and introductions; provide plans, trials, recurring billing and customer support; fulfil and support products expressly sold by Hospiverse; personalise search, ranking and user experience; measure performance with permitted analytics; send service notices and marketing chosen by the recipient; prevent fraud, abuse, infringement and cybersecurity incidents; investigate grievances, preserve evidence and enforce agreements; comply with tax, accounting, corporate, food, consumer, IT, court and lawful government requirements; and establish, exercise or defend legal claims.
Where consent is the appropriate basis, you may withdraw it. Where processing is necessary for an account, requested service, contract, legal obligation, emergency, fraud prevention or other legally recognised use, withdrawal may not require deletion of data still needed for that purpose.
6. Notice and Consent
We provide notice at or before collection through this Policy, form-level explanations and account/checkout screens. We do not obtain consent through silence, inactivity or an unrelated bundled choice where a separate choice is required.
You may decline optional data or marketing. A field required to provide an account, RFQ, payment, delivery or legal response will be identified or apparent from context; without it, that service may not be available.
8. Service Providers and Recipients
We may disclose limited data to providers that support:
- cloud/database and authentication, such as Supabase;
- identity/OAuth providers, such as Google, when a user chooses that sign-in method;
- website hosting and performance, such as Vercel;
- payment and recurring mandates, such as Razorpay;
- analytics, such as Google Analytics and Vercel Analytics, only in accordance with cookie choices;
- email and communications, such as Brevo and WhatsApp/Meta;
- audio or AI-feature providers, such as ElevenLabs, only where that feature is enabled and requested;
- customer support, security, verification, professional advice and audit; and
- delivery/logistics for Hospiverse-owned product sales.
We may also disclose data to an acquiring/restructured entity subject to confidentiality; to courts, regulators, law-enforcement or government bodies on a lawful request; and to protect rights, safety, security or investigate fraud.
We do not sell personal data. We do not permit a provider to use Platform data for its unrelated advertising merely because it processes the data for us.
9. International Processing
Some providers may process or support data from locations outside India, which may include Singapore, the European Union, the United States or other service locations. We use contractual and security controls and comply with applicable Indian transfer restrictions. We may change provider locations over time and will not transfer personal data to a country or territory prohibited by the Central Government under applicable law.
11. Marketing Communications
We send promotional email, SMS, WhatsApp or calls only where permitted and using appropriate consent/preferences. Service messages — such as security, payment, RFQ, mandate, support and policy notices — are not marketing merely because they concern an account.
Marketing messages identify Hospiverse and provide an unsubscribe/opt-out mechanism. Withdrawal does not stop essential service or legal communications. We retain a minimal suppression record so an opted-out address or number is not accidentally re-added.
12. Retention
We keep data only as long as reasonably needed for the stated purpose, including:
- Active account/profile: While active
- Registration data after account cancellation: At least 180 days, and longer if lawfully required
- Removed/restricted content and associated records: At least 180 days for investigation, or longer under lawful direction
- ICT/security logs covered by CERT-In directions: At least the legally required rolling period, maintained in the required jurisdiction
- Subscription, invoice, payment and accounting records: Up to 8 financial years or longer if required for proceedings
- RFQ, quote and business-communication records: Normally up to 3 years after closure, subject to dispute/legal needs
- Verification evidence: While badge/account is active and normally 3 years after expiry/removal
- Hospiverse-owned product order/warranty records: Warranty period plus applicable accounting/claim period
- Grievances, notices and legal claims: Resolution plus normally 3 years, or longer for proceedings
- Marketing consent and suppression: Until withdrawal; suppression record as needed to honour withdrawal
- Analytics: According to the configured period in the Cookie Policy
We may retain anonymised statistics that no longer identify an individual. We suspend routine deletion for a legal hold, fraud, safety or active dispute and resume when the need ends.
13. Security
We use proportionate safeguards such as encryption in transit, access controls, role-based database rules, authentication controls, backups, logging, provider due diligence, restricted KYC access and incident procedures. No system is completely secure. Users must protect credentials and report suspicious activity.
If a personal-data breach occurs, we will contain and assess it and make notifications to affected individuals and authorities within the timelines required by applicable law, including applicable CERT-In and, when operative, DPDP requirements.
14. Your Choices and Rights
Subject to applicable law and identity/authority verification, you may request:
- a summary/access to personal data processed about you;
- correction, completion or updating;
- erasure where retention is no longer necessary or legally required;
- withdrawal of consent;
- account closure;
- marketing opt-out;
- grievance redressal; and
- nomination of another individual to exercise applicable rights in the event of death or incapacity once that right becomes operative.
Submit requests to jigar.chanana@hospiverse.in. We aim to respond within 30 days and will not exceed a shorter or longer statutory period where applicable. We may refuse or limit a request with reasons where necessary to protect another person, preserve evidence, comply with law, exercise legal rights or prevent fraud.
Before approaching the Data Protection Board under the DPDP framework once the relevant provisions are operative, a person should use our grievance process as required by applicable law.
15. Business Administrators and Other Individuals
If you provide another person's information, you represent that you have authority and have given them any required notice. Business administrators may control authorised users but may not access personal communications or data beyond their lawful organisational authority.
16. Children
The Platform is not intended for anyone under 18. We do not knowingly create child accounts or target children. If we learn that a child's data was submitted without lawful authority, we will take appropriate steps to restrict or delete it, subject to evidence and legal requirements.
17. External Links
External websites and independent suppliers have their own privacy practices. Review them before providing data. Hospiverse is not responsible for their independent processing.
18. Changes
We will publish updates with a new effective date. Material changes will be notified through appropriate channels. We will request fresh consent where required rather than treating continued use as consent for a materially new optional purpose.
19. Contact and Grievance
Complaints are handled under the Grievance, Notice and Takedown Policy.