PRIVACY NOTICE
Supermarket Grocery Supplies Private Limited (“SGSPL” or “we”) takes the privacy of your information seriously. This privacy notice (“Privacy Notice”) describes the types of personal information we collect from you, through our stores, other premises, website (including sub-domains and microsites) mobile applications, or other means. It describes the purposes for which we collect that personal information, the other parties with whom we may share it, and the measures we take to try and protect it. It also tells you about some of your rights and choices with respect to your personal information, and how you can contact us about our privacy practices.
You are advised to carefully read this Privacy Notice before using or availing any of our products and/or services. By doing so you are consenting to the collection and processing of your Data (including SPDI) in accordance with the practices and policies outlined in this Privacy Notice.
Our products and services are targeted at users in India, and this Privacy Notice is intended to comply with the laws of India. If you are accessing or using the website or mobile application from an overseas location, you are requested to independently validate the impact of any applicable local laws.
If you do not agree with this Privacy Notice at any time, in part or as a whole, write to our Grievance Office at the address specified below.
1. DEFINITIONS
In this Privacy Notice, the following definitions are used:
Cookies - a small file placed on your device by our website or mobile application when you either visit or use certain features of our website or mobile application. A cookie generally allows a website to remember your actions or preference for a certain period of time.
Data - means personal information and SPDI about you, which either directly or indirectly in combination with other information, could allow you to be identified when you visit our [stores, website and/or mobile application].
Data Protection Laws - any applicable law for the time being in force relating to the processing of Data, including the Information Technology Act, 2000 and Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Information) Rules, 2011, as amended or replaced from time to time.
Partners - select third parties (including Tata Group Entities) with whom we have contracts or arrangements through which they may offer products or services to You or our other users, and to whom we may disclose your Data for a relevant purpose.
Service Providers - includes entities to whom we, or other Tata Group Entities, will disclose your Data in order for them to process it for the purpose of providing services to us pursuant to written contract.
SPDI - the Data Protection Laws define sensitive personal data or information of a person as personal information about that person relating to (a) passwords; (b) financial information such as bank account credit and debit card details or other payment instrument details; (c) physical, physiological and mental health condition; (d) sexual orientation; (e) medical records and history; or (f) biometric information.
SGSPL - SGSPL is a company incorporated in India whose registered office is at Fairway Business Park, 2nd, 7th And 8th Floor, Challaghatta Village, Behind Dell, Domlur, Bangalore, 56007.
Tata Group Entity - Tata Sons Private Limited, and its subsidiaries, affiliates, associate companies and joint venture companies with whom we have a contractual arrangement to, inter alia, share data for the purposes described in this Privacy Notice.
User or you - the natural person who accesses our stores, website or mobile application.
2.WHAT DATA DO WE COLLECT ABOUT YOU
SGSPL collects Data for various purposes set out in this Privacy Notice. This Data includes, without limitation, the following categories 1 :
Contact information: first and last name, email address, postal address, country, employer, phone number and other similar contact data.
Financial information: payment instrument information, transactions, transaction history, preferences, method, mode and manner of payment, spending pattern or trends, and other similar data.
Technical information: website, device and mobile app usage, Internet Protocol (IP) address and similar information collected via automated means, such as cookies, pixels and similar technologies.
Transaction information: the date of the transaction, total amount, transaction history and preferences and related details.
Product and service information: Your account membership number, registration and payment information, and program-specific information, when you request products and/or services directly from us, or participate in marketing programs.
Personal information: Age, sex, date of birth, marital status, nationality, details of government identification documents provided, occupation, ethnicity, religion, travel history, or any other personal information provided in responses to surveys or questionnaires.
Your reviews, feedback and opinions about our products, programmes and services.
Loyalty programme information: your loyalty membership information, account details, profile or password details and any frequent flyer or travel partner programme affiliation.
Payment instrument information – through our application pages , you may choose a 3 rd payment service provider of your choice for making payment and may agree to store your payment instrument details with the chosen service provider/s. The payment instrument data is managed by service provider/s.
3.HOW WE COLLECT DATA
We collect Data in the following ways:
Information You Give Us: We receive and store any information you enter on our website or mobile application or give us in any other way (e.g., at outlets, stores, hotels, kiosks). Please see the section titled “Data Shared by You” for more information.
Automatic Information We Collect: We use “cookies”, pixels and similar technologies to receive and store certain types of information whenever you interact with us. Please see the section below, titled “Data that is Collected Automatically” for more information.
E-mail Communications: To help us make e-mails more relevant and interesting, we often receive a confirmation (if your device supports such capabilities) when you open e-mail from us or click on a link in the e-mail. You can choose not to receive marketing emails from us by clicking on the unsubscribe link in any marketing email.
Automatic Information We Collect from Other Websites: We receive and store certain types of information when you interact with third-party websites that use our technology or with whom we have a specific agreement. Because we process this information on behalf of the applicable website operators, collection, processing, and use of such information is subject to the applicable website operators’ privacy policies and is not covered by our Privacy Notice.
Information from Other Sources: We may obtain information from other sources. An example of this is when you authorize a third-party website (such as the website of another Tata Group Entity), to interact directly with our website or mobile application to provide or receive Data about you. In that case, we might receive such Data used by that third-party website to identify your account with that website.
Information Previously Provided to Tata Group Entities: Where you have shared any information previously with any of the Tata Group Entities and have consented to the further sharing of such information, such information will be shared with us by the Tata Group Entities.
You can make choices about our collection and use of your Data. For example, you may want to access, edit or remove your Data on our website or mobile application. When you are asked to provide Data, you may decline, however, in such a case, you may not be able to avail benefit of some of our products, programmes or services or access our stores or physical premises.
4.DATA SHARED BY YOU
- SGSPL may collect your Data in several ways from your use of our stores, website or mobile application. For instance:
- when you register with us to receive our products and/or services;
- when you conduct a transaction with us or attempt a transaction at our stores, on our website or mobile application;
- when you complete surveys conducted by or for us;
- when you elect to receive any communications (including promotional offers) from us;
- from the information gathered by your visit to our stores, website or mobile application; or
- by way of correlation or inferences from information sourced from sources, which have collected or processed this data based on your consent.
5.DATA THAT IS COLLECTED AUTOMATICALLY
- We automatically collect some information when you visit our website or use our mobile application. This information helps us to make improvements to our content and navigation. The information collected automatically includes your IP address.
- Our web servers or affiliates who provide analytics and performance enhancement services collect IP addresses, operating system details, browsing details, device details and language settings. This information is aggregated to measure the number of visits, average time spent on the site, pages viewed and similar information. Tata X uses this information to measure the site usage, improve content and to ensure safety and security, as well enhance performance of our website or mobile application.
- We may collect your Data automatically via Cookies, pixels and similar technologies in line with settings on your browser. For more information about Cookies, please see the section below, titled “Cookies”.
6.OUR USE OF DATA
- Any or all the above Data may be required by us from time to time to provide information relating to SGSPL and to work on the experience when using our website or mobile application. Specifically, Data may be used by us for the following reasons:
- carry out our obligations arising from any contract entered into between you and us;
- provide (including customizing and improving) products and/or services and communicate with you about products and/or services offered by us;
- enable payment, billing and invoicing related purposes;
- enable Tata Group Entities, Service Providers and Partners to offer their products and/or services and communicate with you about such products and/or services;
- processing, disclosing, transmitting, and/or sharing the Data with Tata Group Entities, and other third parties which have business or contractual dealings with us for any legitimate purpose/use and in terms of this Privacy Notice;
- provide you with offers (including for financial products and/or services), personalized services and recommendations and improve your experience on our website and mobile application;
- operate, evaluate and improve our business (including for administration and management related purposes), website and mobile application;
- generate aggregated data to prepare insights to enable us to understand customer behaviour, patterns and trends with a view to learning more about your preferences or other characteristics;
- provide privileges and benefits to you, marketing and promotional campaigns based on your profile;
- in connection with loyalty programs owned and operated by us or by other Tata Group Entities;
- communicate with you (including to respond to your requests, questions, feedback, claims or disputes) and to customize and improve our services;
- enforce the terms of use of our website and mobile application;
- protect against and prevent fraud, illegal activity, harm, financial loss and other legal or information security risks; and
- serve other purposes for which we provide specific notice at the time of collection, and as otherwise authorized or required by applicable law.
We treat these inferences as personal information (or SPDI, as the case may be), where required under applicable law. Some of the above grounds for processing will overlap and there may be several grounds which justify our use of your personal information.
Where required under applicable law, we will only use your personal information with your consent; as necessary to provide you with products and/or services; or for such other purpose as is permissible under applicable law We may make broader use of anonymized personal information from which individuals cannot be identified.
7.MINORS
Our website and mobile application do not offer products or services for use by minors. If you are under 18, you may use our website or mobile application only with the consent of a parent or your guardian. In the event that we learn that we have collected personal information from a minor without verification of parental consent, we will delete that information at the earliest. If you believe that we might have any such information, please contact the Grievance Officer.
8.SHARING OF DATA
We may share your Data with/ for:
- Partners: We may make available to you services, products, or applications provided by Partners for use on or through our website or mobile application. If you choose to use such service, customer information related to those transactions may be shared with such Partner. Such Partners will be required to respect the security of your Data and to treat it in accordance with this privacy policy and applicable law
- Tata Group Entities: We may make available to you products, services and /or applications of Tata Group Entities, to assist them to reach out to you in relation to their programs or campaigns and to process your queries and requests. Accordingly, we may share your Data with Tata Group Entities. We may also share your Data with the Tata Group Entities as is relevant for the purposes set out in Clause 7 above, and to facilitate the operation of our business.
- Tata Consumer Platform: Your Data may be shared with Tata Group Entities and other participating entities on the Tata Consumer Platform operated by Tata Digital Limited (“TCP”) for purposes of enrolment, offering you products, services and benefits on the TCP. Accordingly, we may share your Data with other Tata Group Entities, Partners and Service Providers.
- Service Providers: We or other Tata Group Entities may share your Data with Service Providers. Examples include storing and analyzing Data, protecting and securing our systems, providing search results and links, providing customer service, credit analysis, processing your information for profiling, user analysis and payment processing.
These Service Providers will be required to only process Data in accordance with express instructions and as necessary to perform services for purposes set forth in this Privacy Notice. The Service Providers will also be required to safeguard the security and confidentiality of the Data they process by implementing appropriate technical and organizational security measures and confidentiality obligations binding employees accessing Data.
- When SGSPL acts as a Service Provider: We may process and share your Data with Tata Group Entities and Partners when we act as a service provider to such Tata Group Entities and Partners.
- Protecting SGSPL: We may release Data when we believe release is appropriate to comply with applicable law or legal process, enforce or apply the Terms of Use of our website or mobile application and other agreements, protect SGSPL against harm or financial loss, when we believe disclosure is necessary to protect individuals’ vital interests, or in connection with an investigation of suspected or actual fraudulent or illegal activity. This may include exchanging information with other companies and organizations for fraud protection, risk management and dispute resolution. This does not include selling or otherwise disclosing personally identifiable information from users for commercial purposes in violation of this Privacy Notice.
- Business Transfers: As we continue to develop our business, we might sell or buy subsidiaries or business units. Your Data (including in relation to loyalty programs) may be transferred as part of such transaction or in the course of exploratory activities related thereto, including due diligence and audit exercises. The relevant transferee may thereafter make use of Data in accordance with then applicable Law.
- Third Parties: We may also share your Data with other third parties where:
- You request or authorize us to do so;
- We need to comply with applicable law or respond to valid legal process; or We need to operate and maintain the security of our website or mobile application, including to prevent or stop an attack on our computer systems or networks.
- We require these third parties by contract to only process sensitive personal data in accordance with our instructions and as necessary to perform services on our behalf or in compliance with applicable law. We also require them to safeguard the security and confidentiality of the sensitive personal data they process on our behalf by implementing appropriate confidentiality, technical and organizational security measures.
- Please note that Tata Group Entities and Partners may have privacy practices that differ from those of SGSPL. The use of your Data will be governed by their privacy statements when you provide Data on their websites.
9.KEEPING DATA SECURE
We will use technical and organisational measures to safeguard your Data and we store your Data on secure servers. Technical and organisational measures include measures to deal with any suspected data breach. If you suspect any misuse or loss or unauthorised access to your Data, please let us know immediately by contacting us by e-mail.
10.RETENTION OF DATA
- SGSPL retains Data for as long as necessary for the use of our products and/or services or to provide access to and use of our website or mobile application, or for reasonable purposes such as complying with our legal obligations, resolving disputes, enforcing our agreements or as otherwise stated in this Privacy Notice, and for such periods or purposes as are permitted under applicable law,. Because these needs can vary for different data types and purposes, actual retention periods can vary significantly.
Even if we delete your Data, including on account of exercise of your right under Clause 12 below, it may, subject to applicable law, persist on backup or archival media for audit, legal, tax or regulatory purposes.
11.YOUR RIGHTS AND CHOICES
When we process Data about you, we do so with your consent and/or as necessary to operate our business, meet our contractual and legal obligations, protect the security of our systems and our customers, or fulfil other legitimate interests of SGSPL as described in this Privacy Notice. We may transfer Data we collect about you to recipients in India, where we are headquartered. India may not have the same Data Protection Laws as the country in which you initially provided the information. When we transfer your Data to India, we will protect that information as described in this Privacy Notice, as disclosed to you at the time of data collection or as described in our program-specific privacy notice.
Depending on which Data Protection Laws are applicable to you, you may have the right or choice to:
- opt out of some collection or uses of your Data, including the use of cookies, pixels and similar technologies and the use of your Data for marketing purposes.
- access your Data, rectify it, restrict or object to its processing, or request its deletion or anonymization.
- change or edit information submitted to us.
- receive the Data you provided to us to transmit it to another company.
- withdraw any consent provided or alter your preferences.
- where applicable, lodge a complaint with your supervisory authority.
You may submit a request as described in the “How to Contact Us” section below. We will not charge you for any request. Where we are legally permitted to do so, we may refuse your request. If we refuse your request, we will tell you the reasons why.
Below, you will find additional privacy information that you may find important. Data Protection Laws, depending on your country, may include the following rights in relation to your Data:
- Right to Confirmation and Access - the right to confirm our methods of processing and request copies of the information we hold about you at any time, or that we modify, update or delete such information.
- Right to Correction - the right to have your Data rectified if it is inaccurate or incomplete.
- Right to be Forgotten - the right to request that we delete or remove your Data from our systems.
- Right to Restrict / Object to Our Use of your Data - the right to limit the way in which we can use it.
- Right to Data Portability - the right to request that we move, copy or transfer your Data.
- Right to Withdraw Consent – the right to withdraw your consent provided earlier.
- Right to File Complaints – the right to raise complaints to a regulatory authority.
- For information about managing your Data and promotional communications, please e-mail us at customerservice@bigbasket.com.
- It is important that the Data we hold about you is accurate and current. Please keep us informed if your personal information changes during the period for which we hold it.
12.WHERE WE STORE DATA
Data collected under this Privacy Notice is hosted on servers located in India. Subject to applicable law, we may at our sole discretion, transfer Data, including SPDI to any other third party that agrees to ensure the same level of data protection as is provided by us under the terms hereof, located outside India. You hereby consent to the storage and processing of Data, including SPDI in locations outside India.
13.PROCESSING YOUR DATA
We take steps to ensure that the Data we collect under this Privacy Notice is processed according to the provisions of this Privacy Notice and the requirements of applicable law.
To ensure that your Data receives an adequate level of protection, we have put in place appropriate written contracts with Tata Group Entities, Partners and Service Providers that we share your Data with. This ensures your Data is treated by such parties in a way that is consistent with applicable law.
- SGSPL implements standard measures to protect against unauthorized access to and unlawful interception of Data. However, no internet site can fully eliminate security risks. SGSPL endeavors to take all measures to protect the security, integrity and confidentiality of the Data against unauthorized breach and hacking. For the purpose of checking possible vulnerabilities and attacks, SGSPL may conduct periodical internal review of data and security measures. However, the internet is not absolutely a secure environment, and we cannot ensure or warrant 100% security.
- If you are provided with any identification code, password or any other piece of information as part of the security procedure adopted by us, you should treat such information as confidential and not disclose it to any third party including to other users. You are solely responsible for the activities that occur under your account including the confidentiality of your password and SGSPL is not responsible for the same.
- Notwithstanding anything contained in this Policy or elsewhere, SGSPL shall not be held responsible for any loss, damage or misuse of the Data, if such loss, damage or misuse is attributable to a Force Majeure Event. A "Force Majeure Event" means any event that is beyond the reasonable control of SGSPL and includes, without limitation, fire, flood, explosion, acts of God, civil commotion, strikes, lock outs or industrial action of any kind, riots, insurrection, war, acts of government, power failure, sabotage, computer hacking, unauthorised access to computer data and storage device, system failure, virus, attacks, bugs, computer crashes, breach of security and encryption.
15.SEVERABILITY
If any court or competent authority finds that any provision of this Privacy Notice (or part of any provision) is invalid, illegal or unenforceable, that provision or part-provision will, to the extent required, be deemed to be deleted, and the validity and enforceability of the other provisions of this Privacy Notice will not be affected.
16.CHANGES TO THIS PRIVACY NOTICE
Our business changes constantly and our Privacy Notice will change also. We may e-mail periodic reminders of our notices and conditions, unless you have instructed us not to, but you should check our website and mobile application frequently to see recent changes The updated version will be effective as soon as it is accessible. Any changes will be immediately posted on our website and mobile application and you are deemed to have accepted the terms of the updated Privacy Notice on your first use of our website or mobile application or first purchase of the products and/or services following the alterations. We encourage you to review this Privacy Notice frequently to be informed of how we are protecting your information.
Your continued access to our stores, physical premises, website or mobile application, following any such amendments to the Privacy Notice, will be deemed as an implicit acceptance of the Privacy Notice in its amended form.
17.HOW TO CONTACT US
To request to review, update, or delete your personal information or to otherwise reach us, please submit a request by e-mailing us at customerservice@bigbasket.com. You may contact us for information on Service Providers, Partners and Tata Group Entities with whom we may share your Data in compliance with this Privacy Notice and applicable law. We will respond to your request within 30 days.
18. GRIEVANCE REDRESSAL
For information about management of your Data please reach out to us at
Email: grievanceofficer@bigbasket.com
Address: