Menu

PRIVACY POLICY – VENDOR

Home / Privacy Policy- Vendor

  • (Compliant with IT Act, 2000 & DPDP Act, 2023)
    This Privacy Policy describes how VCO Job, having its registered office at No.903, 80 Feet Rd, 6th Block, Koramangala, Bengaluru, Karnataka 560095 (“Company”, “Platform”, “we”, “us”, or “our”), collects, processes, stores, uses, shares, and protects Personal Data of individuals registering or operating on the Platform as:

    Vendors (Restaurant Owners), (Collectively referred to as “Vendors” or “Data Principals”, as defined under the DPDP Act, 2023.)

    By registering, accessing, or using the Platform, you freely, specifically, informedly, unconditionally, and unequivocally consent to the processing of your Personal Data in accordance with this Privacy Policy.
  • LEGAL BASIS & APPLICABILITY
    This Privacy Policy is issued pursuant to:
    • • Section 43A of the Information Technology Act, 2000
    • • IT (Reasonable Security Practices & SPDI) Rules, 2011
    • • Digital Personal Data Protection Act, 2023 (India)
    • • This Policy applies only to Vendors / Restaurant Owners, data is governed by a separate privacy policy.
  • DEFINITIONS (DPDP ACT COMPLIANT)
    • • Personal Data: Any data about an individual who is identifiable by or in relation to such data.
    • • Sensitive Personal Data / Special Category Data: Financial information, government IDs, biometric data, etc., as applicable.
    • • Data Principal: Vendors / Restaurant Owners.
    Data Fiduciary: VCO Job.
    Data Processor: Third parties processing data on behalf of the Company.
  • CATEGORIES OF PERSONAL DATA COLLECTED
    Identity & Contact Data
    • • Full name
    • • Mobile number
    • • Email address
    • • Photograph
    • • Date of birth / age verification
    • • Residential or business address
    Business / Professional Data
    Vendors:
    • • Restaurant/business name
    • • Business address
    • • FSSAI, GST, trade license details
    • • Menu, pricing, operating hours
    Financial & Tax Data
    • • Bank account details
    • • PAN / GST
    • • Transaction, payout, commission records
    Note: Card details are not stored. Payments are processed via RBI-compliant third-party gateways. Location Data
    For Vendors (Restaurant Owners), the Platform may collect and process the following location-related information:
    • • Registered Business Location:
      Permanent location of the restaurant or food business as provided during onboarding and verification.
    • • Service Area / Delivery Radius:
      Geographic zones selected by the Vendor to define delivery coverage and order acceptance areas.
    • • Order Fulfilment Location:
      Location data linked to order preparation, pickup coordination, and logistics management.
    • • Compliance & Verification Purposes:
      Location information used for regulatory compliance, address verification, fraud prevention, and audit requirements.
    • • Operational Analytics:
      Aggregated and anonymized location data used to improve serviceability, demand forecasting, and platform efficiency.
    • Note:
      The Platform does not track real-time live movement of Vendors or Restaurant’s staff. Location data is collected only for operational, compliance, and service enablement purposes, strictly in accordance with the DPDP Act, 2023.
    Technical & Usage Data
    • • IP address
    • • Device identifiers
    • • App usage logs
    • • Crash diagnostics
  • PURPOSE OF PROCESSING OF PERSONAL DATA – RESTAURANT / VENDOR PARTNERS
    (Section 6, Digital Personal Data Protection Act, 2023)
    In a food delivery platform ecosystem, VCO Job acts as the Data Fiduciary for Restaurant/Vendor Partners. Personal Data of Vendors is processed only for specific, lawful, necessary, and clearly defined purposes, in accordance with Section 6 of the Digital Personal Data Protection Act, 2023, and the principles of purpose limitation and data minimization.
    A. Onboarding & Regulatory Compliance
    Data is processed to:
    • • Verify business ownership and authorized signatories
    • • Validate FSSAI registration, GST, trade licenses, and other statutory approvals
    • • Verify identity documents of restaurant owners or authorized representatives
    • • Ensure compliance with food safety, taxation, and local regulatory requirements
    • • This processing is necessary to determine the eligibility and legality of food business listings on the Platform.
    B. Restaurant Listing & Platform Enablement
    Data is processed to:
    • • Create and manage restaurant profiles on the Platform
    • • Display restaurant name, cuisine type, menu items, pricing, availability, and operating hours
    • • Enable order acceptance, preparation workflows, and serviceability configuration
    • • Only business-related information necessary for customer discovery and ordering is displayed.
    C. Order Management & Fulfilment
    Data is processed to:
    • • Share limited order-related information, including order ID, item details, quantities, and preparation instructions
    • • Enable real-time order preparation and coordination of B2B2C logistics
    • Data Minimization Assurance:
    • Customer Personal Data such as phone numbers, live location, or precise delivery addresses are not shared with Vendors, except where legally required or operationally necessary for order fulfilment.
    D. Financial Settlements & Tax Compliance
    Data is processed to:
    • • Calculate commissions, platform fees, and net payable amounts
    • • Process payouts to Vendor bank accounts
    • • Maintain transaction records for reconciliation and audit purposes
    • • Comply with statutory obligations including GST, TDS, invoicing, and financial reporting
    • • Payment processing is carried out through RBI-compliant third-party payment gateways.
    E. Business Communication & Support
    Data is processed to:
    • • Communicate order updates, settlement statements, policy changes, and operational alerts
    • • Provide customer support, dispute resolution, and grievance handling
    • • Share service-related notifications essential for Platform operations
    • • Promotional or marketing communications, if any, are sent only in accordance with applicable consent requirements.
    F. Fraud Prevention, Security & Legal Obligations
    Data is processed to:
    • • Detect and prevent fraud, misuse, or unauthorized activity
    • • Enforce Platform policies and contractual obligations
    • • Respond to lawful requests from government authorities, courts, or regulators
    G. Consent & Lawful Basis
    Processing of Vendor’s Data is carried out:
    • • With explicit consent obtained during onboarding and continued Platform usage; and/or
    • • As a legitimate use necessary for providing Platform services, complying with legal obligations, and fulfilling contractual responsibilities, as permitted under the DPDP Act, 2023.
    • • Withdrawal of consent may result in suspension or termination of Vendor access, subject to legal requirements.
    H. Purpose Limitation & Retention
    • • Data is collected only to the extent necessary for the purposes defined above
    • • Data is retained only for as long as required for operational, legal, taxation, or audit purposes
    • • Upon termination, data is erased or anonymized unless retention is mandated by law
    Important Clarification:
    • • Live location tracking, delivery routing, rider safety data, and pickup/drop navigation are NOT applicable to Vendors
    • • Vendors are not tracked in real time
  • CONSENT MANAGEMENT
    • • Consent is obtained digitally during onboarding and app usage
    • • Consent may be withdrawn at any time, subject to legal obligations
    • • Withdrawal may limit or terminate access to Platform services
    • • Consent withdrawal requests can be made via the App or email.
  • DISCLOSURE & DATA SHARING
    • • Data is shared strictly on a need-to-know basis, including:
    With Customers
    • • Business/service details
    • • Restaurant location
    With Data Processors
    • • Payment gateways
    • • Cloud hosting providers
    • • Communication service providers (SMS, Email, Push Notifications)
    With Government / Legal Authorities
    • • Where required by law, court order, or statutory obligation
    Data Sharing with Group Entities & Associated Organizations (Vendors)
    • Personal Data of Vendors may be shared strictly on a need-to-know basis with entities that are directly or indirectly associated with the Platform, only for lawful and legitimate purposes, in accordance with Section 6 of the Digital Personal Data Protection Act, 2023.
    Such entities may include:
    • • Group companies, sister concerns, and affiliates
    • • Non-Governmental Organizations (NGOs) and Co-operative Societies
    • • Private Limited Companies, Limited Liability Partnerships (LLPs)
    • • Partnership Firms and Sole Proprietorships
    • • Franchisees, authorized representatives, and channel partners
    • • Vendors, service partners, and subcontractors
    • • Branch offices, associates, and operational units
    Purpose Limitation
    Data sharing with the above entities is limited only to the extent necessary for:
    • • Vendor onboarding, verification, and regulatory compliance
    • • Restaurant listing, operational enablement, and order coordination
    • • Payment processing, settlements, accounting, and audits
    • • Statutory, tax, and legal compliance
    • • Customer support, grievance handling, and dispute resolution
    • Consent & Safeguards
    • • Such sharing is undertaken with explicit consent obtained during Vendor onboarding and continued Platform usage, or as a legitimate use permitted under the DPDP Act, 2023.
    • • All recipient entities are contractually obligated to:
      • • Process Personal Data only for authorized purposes
      • • Maintain confidentiality and reasonable security practices
      • • Comply with applicable data protection laws
    Personal Data is not sold, rented, or shared for independent marketing or unrelated commercial purposes without separate, explicit consent.
  • DATA RETENTION & ERASURE
    • • Data is retained while the Delivery Partner account is active
    • • Retained longer only if required by law (taxation, disputes, audits)
    • • Upon request, data is erased or anonymized unless legally required otherwise
  • DATA SECURITY (SECTION 8 – IT ACT & DPDP ACT)
    The Company implements reasonable security practices, including:
    • • Encryption at rest and in transit
    • • Secure servers and access controls
    • • Periodic security audits
    • • Role-based internal access
    • • Despite safeguards, no system can guarantee absolute security.
    Requests will be addressed within statutory timelines.
  • DATA RETENTION & ERASURE
    Data is retained:
    • • As long as the Vendor’s account is active
    • • As required under applicable laws (taxation, disputes, audits)
    • • Upon request, data will be erased or anonymized, unless retention is legally required.
  • RIGHTS OF DATA PRINCIPALS (DPDP ACT – CHAPTER III)
    Vendor’s have the right to:
    • • Access restaurant data
    • • Correct or update inaccurate data
    • • Withdraw consent
    • • Request data erasure
    • • Nominate another person to exercise rights in case of death/incapacity
    • • File grievance or complaint
    • • Requests will be addressed within reasonable timeframes as prescribed by law.
  • CONFIDENTIALITY OBLIGATIONS OF PARTNERS
    Vendors must:
    • • Protect customer data received through the Platform
    • • Use data only for service fulfillment
    • • Not store, misuse, sell, or disclose customer data
    • • Violation may lead to termination, penalties, and legal action.
  • PLATFORM VS VENDOR DATA ROLE DISCLAIMER
    • Vendors act as independent business entities and do not function as Data Fiduciaries for customer Personal Data collected by the Platform. Vendors shall process customer information strictly for order fulfilment and in accordance with applicable data protection laws.
  • AGE RESTRICTION
    • • Only individuals 18 years and above may register as Vendors.
    • • Any violation results in immediate account termination.
  • CROSS-BORDER DATA TRANSFER
    Data may be processed or stored outside India only in compliance with:
    • • DPDP Act, 2023
    • • Government-notified permitted jurisdictions
  • POLICY UPDATES
    This Policy may be updated periodically. Changes will be notified via the App or website. Continued usage constitutes acceptance.
  • GRIEVANCE REDRESSAL (SECTION 8 – DPDP ACT)
    • Grievance Officer: Praveen
    • Email: info@vcojob.com
    • Address: 903, 80 Feet Rd, 6th Block, Koramangala, Bengaluru – 560095
    • Grievances will be acknowledged within 48 hours and resolved within statutory timelines.