Privacy Policy
Welcome to CityOffersHub. Your privacy is paramount to us. This Privacy Policy outlines our practices regarding the collection, use, processing, and disclosure of personal data for consumers and merchants in India. This policy is aligned with the Digital Personal Data Protection (DPDP) Act, 2023 and the DPDP Rules, 2025 notified by the Ministry of Electronics and Information Technology (MeitY), Government of India.
Contents
- Personal Data We Collect
- Lawful Basis of Processing
- Purpose of Processing
- Data Principal Rights
- Right to Nominate DPDP 2025
- Children's Data & Parental Consent DPDP 2025
- Third-Party Data Sharing
- Security Safeguards
- Data Breach Notification DPDP 2025
- Data Retention and Deletion
- Grievance Redressal Officer
1. Personal Data We Collect
We only collect the minimum amount of personal data necessary to provide our hyper-local deal aggregation and merchant services. This includes:
- Consumers: Mobile phone number, display name, geolocation coordinates (to calculate distance to merchants), pre-order items, stamp card activity, loyalty points ledger, and transactional/payment details.
- Merchants: Business owner name, email address, password hashes (bcrypt), business contact number, storefront address, city, area/neighbourhood boundary coordinates, and subscription payment history.
- Automatically collected: Device type (mobile/desktop), browser type, and anonymised session logs for fraud prevention only. We do not use tracking cookies or cross-site behavioural analytics.
2. Lawful Basis of Processing
In accordance with Section 4 of the DPDP Act 2023, we process personal data under the following lawful bases:
- Consent: When you register as a consumer via OTP verification, or register as a merchant via the onboarding wizard and accept these terms, you grant us explicit permission to process your data for deal exploration, pre-orders, and loyalty programs.
- Legitimate Uses: For completing pre-orders, verifying billing transactions with Razorpay, executing transactional WhatsApp notifications, and preventing fraudulent redemptions — as permitted under Section 7 of the Act.
3. Purpose of Processing
Your personal data is used exclusively for:
- Creating and managing secure user accounts.
- Providing hyperlocal sorting of offers based on your GPS distance.
- Processing prepaid restaurant pre-orders and facilitating appointments.
- Calculating loyalty points and generating double-entry ledger listings.
- Preventing fraudulent check-ins and duplicate offer redemptions.
- Sending transactional WhatsApp messages via the Merchant C2B Messenger (opt-in only).
- Processing subscription payments for merchant plans via Razorpay.
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
4. Data Principal Rights
Under the DPDP Act 2023, you are the Data Principal and possess the following rights:
- Right to Access: You may request a summary of the personal data we hold about you and the processing activities performed, within 30 days of request.
- Right to Correction & Erasure: You can edit your profile at any time from the app, or request complete erasure of your account and all associated personal data.
- Right to Grievance Redressal: You may report data protection concerns to our Grievance Officer (see Section 11). We will acknowledge within 48 hours and resolve within 30 days.
- Right to Withdraw Consent: You may withdraw consent at any time by deleting your account via the Profile section. All processing of your personal data will cease upon confirmed deletion.
5. Right to Nominate DPDP Rules 2025
In accordance with Section 14 of the DPDP Act 2023 and the DPDP Rules 2025, every Data Principal has the right to nominate another individual to exercise their data rights on their behalf in the event of death or incapacity.
The nominated individual will be able to exercise rights such as access, correction, and erasure of your data upon providing verifiable proof of the Data Principal's death or incapacity.
6. Children's Data & Parental Consent DPDP Rules 2025
CityOffersHub does not knowingly collect, process, or store personal data of children under the age of 18 without verifiable parental or guardian consent, as mandated by Section 9 of the DPDP Act 2023.
- Our consumer registration is restricted to individuals with a valid Indian mobile number. By registering, you confirm you are 18 years of age or older.
- We do not conduct behavioural monitoring or serve targeted advertising to any user, including children.
- If we become aware that personal data of a child has been inadvertently collected without parental consent, we will delete such data immediately upon notice.
7. Third-Party Data Sharing
We share your personal data with third parties only where strictly necessary for delivering our services, and only to the extent required:
- Razorpay Financial Solutions Pvt. Ltd.: For processing prepaid pre-orders and merchant subscription payments. Razorpay is PCI-DSS compliant and operates under their own Privacy Policy. We share only the payment amount and a unique order reference — we do not share your full card or bank details with Razorpay; those go directly to them via their secure checkout.
- WhatsApp / Meta Platforms Ireland Ltd.: When merchants use the C2B Messenger to send transactional notifications to opted-in consumers, messages are routed through the WhatsApp Business API. Only the consumer's phone number and message content are shared. This is opt-in only.
- ipapi.co: An anonymised IP-to-city lookup is used to suggest your nearest city on first load. No personal data (name, phone, account) is transmitted — only your IP address, which is a standard internet protocol parameter.
- Google Maps / Leaflet / OpenStreetMap: Used for rendering store location maps. Only approximate coordinates of merchant storefronts (not consumer GPS) are displayed publicly.
We do not share personal data with advertisers, data brokers, analytics companies, or government entities unless legally compelled to do so by a valid court order or statutory authority under Indian law.
8. Security Safeguards
In compliance with Section 8(5) of the DPDP Act 2023, we implement the following reasonable security safeguards to protect your personal data against unauthorised access, disclosure, alteration, or destruction:
- Encryption in Transit: All data between your device and our servers is encrypted using TLS 1.2/1.3 (HTTPS). HTTP connections are automatically redirected to HTTPS via Nginx.
- Password Security: Merchant passwords are hashed using bcrypt with a salt factor of 10. Plaintext passwords are never stored.
- Consumer OTP Authentication: Consumers authenticate via a time-limited one-time password (OTP) sent to their registered mobile number. No passwords are stored for consumers.
- JWT Token Authentication: All authenticated API requests use short-lived JSON Web Tokens (JWT) with automatic expiry. Expired tokens are rejected server-side.
- Access Controls: Merchant data is isolated by business account. Merchants can only access their own business data. Admin access requires elevated credentials and is logged.
- Infrastructure Security: Our servers are hosted on DigitalOcean (Bangalore, India) behind firewall rules. Only ports 80 (HTTP→HTTPS redirect) and 443 (HTTPS) are publicly accessible. SSH access is key-authenticated only.
- Regular Backups: Automated encrypted backups of the database are performed daily to prevent data loss.
9. Data Breach Notification DPDP Rules 2025
In the event of a personal data breach that is likely to result in harm to any Data Principal, CityOffersHub will act in accordance with Section 8(6) of the DPDP Act 2023 and the DPDP Rules 2025:
- Affected users will be notified individually via SMS or email within 72 hours of us becoming aware of the breach.
- The notification will include: the nature of the breach, the categories of data affected, the likely consequences, and the steps we are taking to mitigate harm.
- The breach will be reported to the Data Protection Board of India as required by applicable rules.
- We will document all breaches internally (even if not reportable) and maintain a breach register.
10. Data Retention and Deletion
We retain your data only for as long as your account remains active or as required by applicable Indian law (including the Information Technology Act and GST regulations for transaction records).
- Account deletion: Upon receiving an erasure request, all associated personal details (phone, name, location history, loyalty ledger entries) will be permanently purged from our databases within 30 business days.
- Transaction records: Payment and transaction records may be retained for up to 7 years as required by Indian financial regulations (GST/Income Tax Act), in anonymised or pseudonymised form wherever possible.
- Logs: Server access logs are retained for a maximum of 90 days for security and fraud investigation purposes, then automatically deleted.
11. Grievance Redressal Officer
In compliance with the DPDP Act 2023 and DPDP Rules 2025, CityOffersHub has appointed a Grievance Redressal Officer (GRO) / Data Protection Officer (DPO). If you have any questions, feedback, or complaints regarding how your personal data is handled, please contact:
Name: Mr. K. B. Chandra, Data Protection Officer (DPO)
Email: support@cityoffershub.com
Address: CityOffersHub Private Limited, Phase-2, Uniquegrow Layout, Doddabanahalli, Bangalore – 560067, Karnataka, India
Phone: +91 9550249900
Support Hours: Monday to Friday, 10:00 AM – 6:00 PM IST (excluding public holidays)
This policy was last reviewed and updated on August 15, 2026 to incorporate requirements under the Digital Personal Data Protection Rules, 2025 (DPDP Rules 2025), notified by MeitY. CityOffersHub reserves the right to update this policy as regulations evolve. Material changes will be communicated to registered users via SMS or email before taking effect.