1. Overview

Florvanta Commerce Pvt Ltd (“Florvanta“, “we“, “us“) values your privacy. This Privacy Policy is published in accordance with:

  • Section 43A of the Information Technology Act, 2000 read with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules“);
  • Rule 3 and Rule 4 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021;
  • The Digital Personal Data Protection Act, 2023 (“DPDPA“) as and when notified in force;
  • Applicable Reserve Bank of India (“RBI“) guidelines, including Card-on-File Tokenisation, Storage of Payment System Data, and Payment Aggregator norms;
  • The Consumer Protection (E-Commerce) Rules, 2020.

2. Scope & Applicability

This Policy applies to all users of the Florvanta website, mobile applications, APIs, and any related services (collectively, the “Platform“), including Buyers, Vendors, and visitors.

3. Key Definitions

  • Personal Data means any information relating to an identified or identifiable natural person.
  • Sensitive Personal Data or Information (SPDI) as defined under Rule 3 of the SPDI Rules includes passwords, financial information such as bank account or card details, physical, physiological and mental health condition, biometric information, etc.
  • Data Fiduciary and Data Principal shall have the meanings ascribed to them in the DPDPA.

4. Information We Collect

We collect the following categories of information:

  • Identity data: name, gender, date of birth (optional).
  • Contact data: email address, mobile number, shipping / billing address.
  • Account credentials: hashed password (never stored in plain text; hashed using bcrypt).
  • Vendor KYC data: PAN, GSTIN, business incorporation documents, bank account & IFSC, address proof.
  • Transaction data: orders, order status, payment method (COD / online), invoices.
  • Payment data: handled and stored solely by our RBI-authorised Payment Aggregator. Florvanta does not store card numbers, CVV, UPI PIN, or bank passwords on its servers.
  • Device & usage data: IP address, browser type, device identifiers, session logs, pages visited (for analytics and fraud prevention).
  • Location data: pincode / city for serviceability checks (grocery, shipping).

5. Purpose of Collection

We use your Personal Data for the following purposes:

  • To create and manage your account and provide the Platform’s features.
  • To process orders, payments, invoices, shipping, returns, and refunds.
  • To perform Vendor KYC and comply with Prevention of Money Laundering Act, 2002 (PMLA) and RBI KYC Master Directions where applicable.
  • To detect, prevent, and investigate fraud, security incidents, and prohibited activities.
  • To respond to customer support and grievance requests.
  • To send transactional and, with consent, promotional communications.
  • To comply with legal, tax (GST/TCS), and regulatory obligations.

7. Cookies & Tracking Technologies

We use strictly necessary cookies for authentication (HttpOnly, Secure) and analytics cookies to improve the Platform. You can control cookies through your browser settings. Disabling essential cookies may impair functionality such as login and checkout.

8. Data Sharing & Disclosure

We share Personal Data only with:

  • Vendors: Buyer’s name, shipping address, and phone number are shared with the fulfilling Vendor solely for order processing.
  • Payment Aggregators & Banks: for processing payments and refunds in accordance with RBI norms.
  • Logistics & Courier partners: shipping address, phone number, and order details for delivery.
  • Regulatory / Government authorities: where required under applicable law, court order, or lawful request.
  • Technology sub-processors: cloud hosting, email, SMS, WhatsApp providers, bound by strict confidentiality obligations.

We do not sell your Personal Data to any third party.

9. Payment Data — RBI & PCI-DSS

Florvanta uses RBI-authorised Payment Aggregators. In compliance with the RBI Circular on Storage of Payment System Data dated 6 April 2018, all payment data pertaining to Indian users is stored on servers located within India.

In compliance with the RBI Guidelines on Restrictions on Storage of Actual Card Data and the Card-on-File (CoF) Tokenisation Framework, we do not store actual card numbers or CVV on our systems. Where you choose to save a card, only a tokenised representation issued by the card network is retained, encrypted, and processed by the Payment Aggregator.

Our Payment Aggregator is PCI-DSS Level 1 certified. Payment data in transit is protected by TLS 1.2 or higher.

10. Data Retention

We retain Personal Data only for as long as necessary for the purposes set out above or as required under applicable law, including:

  • Invoices & tax records: 8 years (Section 36 CGST Act, 2017).
  • Vendor KYC: for the duration of the relationship plus 5 years thereafter (PMLA).
  • Transaction logs: minimum 180 days (Rule 3(1)(g) IT Rules 2021).
  • Marketing preferences: until withdrawal of consent.

11. Security Practices

We implement “reasonable security practices and procedures” as required under Section 43A of the IT Act and Rule 8 of the SPDI Rules, including:

  • Passwords stored only as bcrypt salted hashes.
  • TLS 1.2+ encryption in transit.
  • Role-based access control and audit logging.
  • Regular vulnerability assessments and penetration testing.
  • ISO/IEC 27001-aligned information security controls (best-effort during MVP; formal certification post-launch).

Despite these measures, no method of transmission over the Internet is 100% secure. In the event of a data breach affecting your Personal Data, we will notify the Indian Computer Emergency Response Team (CERT-In) within six (6) hours of becoming aware, in line with CERT-In Directions dated 28 April 2022, and notify affected users promptly.

12. Your Rights

Subject to applicable law, you have the following rights:

  • Right to access your Personal Data.
  • Right to correction and erasure of inaccurate or unnecessary data.
  • Right to grievance redressal via our Grievance Officer.
  • Right to nominate another individual to exercise rights in the event of your death or incapacity (DPDPA).
  • Right to withdraw consent at any time; withdrawal will not affect the lawfulness of processing based on prior consent.

To exercise your rights, write to privacy@florvanta.co.in.

13. Children’s Privacy

The Platform is not intended for individuals under the age of eighteen (18). We do not knowingly collect Personal Data from minors. If we become aware of such collection, we will promptly delete the data.

14. Cross-Border Transfers

Payment data is stored within India per RBI guidelines. Certain non-payment data may be processed by sub-processors located outside India; in such cases, transfers occur only to jurisdictions notified by the Central Government under Section 16 of the DPDPA or under contractual safeguards.

15. Third-Party Links

The Platform may contain links to third-party websites. We are not responsible for their privacy practices. Please review their policies separately.

16. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be notified through email or on-Platform notice. Continued use of the Platform after the effective date constitutes acceptance.

17. Grievance Officer

Under Rule 5(9) of the SPDI Rules and Rule 3(2) of the IT Rules 2021:

Name: Mr. Debasis Saibo
Company: Florvanta Commerce Private Limited
Email: info@florvanta.co.in
Phone: +91 91474 25375
Address: 63, Sri Arabinda Road, Salkia, Howrah, West Bengal – 711106
Acknowledgement: within 48 hours · Resolution: within 15 days

18. Contact Us

For any privacy-related queries: info@florvanta.co.in · General support: info@florvanta.co.in · +91 91474 25375