1. Introduction
Truffle Systems India Private Limited (“Truffle”, “Company”, “we”, “our” or “us”) respects the privacy of individuals and the confidentiality of business information entrusted to us.
This Privacy Policy explains how we collect, receive, use, disclose, store, retain, secure and otherwise process information when you visit our websites, register for or use our software, SaaS products, mobile applications, APIs, cloud services, portals, POS and business-management solutions, or communicate with us (collectively, the “Services”).
This Policy is intended to be read together with our Terms & Conditions, applicable product/order agreements and other notices provided at the point of collection.
2. Regulatory & Compliance Framework
Truffle seeks to maintain privacy and security practices consistent with applicable Indian law and, where applicable, contractual or jurisdiction-specific requirements. Our privacy programme is designed with reference to the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025 as and when their respective provisions become applicable, applicable provisions of the Information Technology Act, 2000 and related rules, and applicable CERT-In directions.
The DPDP Act provides the statutory framework for processing digital personal data in India. The notified DPDP Rules, 2025 provide implementation requirements and a phased commencement schedule.
Where a particular legal requirement is not yet in force, this Policy should not be interpreted as a representation that Truffle has already assumed every future statutory obligation. Truffle may implement controls in advance where commercially and technically appropriate.
3. Scope
This Policy applies to information processed through or in connection with:
- Truffle Systems websites and web properties;
- Truffle POS, ERP and business-management platforms;
- Merchant Portal and Owner Dashboard;
- Kitchen Display System (KDS), Mobile POS and Customer Display;
- QR Ordering, Waiter/Captain and Driver applications;
- CRM and Lead Management platforms;
- HRMS and operational platforms;
- Mobile applications, APIs and integrations;
- Trial, subscription, support, training and onboarding services; and
- Business communications, enquiries and transactions with Truffle.
This Policy does not govern third-party websites, applications, payment services or platforms that operate independently of Truffle. Their own privacy notices apply.
4. Roles: Data Fiduciary, Data Processor and Business Data
Depending on the service and processing activity, Truffle may act as a data fiduciary/data controller for personal data it determines the purposes and means of processing, or as a service provider/data processor processing information on behalf of a customer.
For merchant or enterprise customers using Truffle to process their customers’, employees’ or vendors’ information, the customer may determine the purposes for which such information is processed. In those circumstances, Truffle will process such data primarily to provide the contracted Services and in accordance with the customer’s documented instructions, applicable agreements and law.
Customers remain responsible for ensuring that they have an appropriate lawful basis, notices, consents and permissions for personal data they upload or otherwise make available to Truffle, where required.
5. Categories of Information We May Collect
A. Identity and Contact Information
Name, business name, designation, mobile number, email address, company details and contact information.
B. Business and Merchant Information
Restaurant/outlet details, branches, menus, products, inventory, tax information, employee information, customer records and vendor information.
C. Billing and Transaction Information
Invoices, subscription details, transaction references, payment status and related billing information.
We do not intentionally store complete debit-card numbers, credit-card numbers, UPI PINs or banking passwords on our application servers. Payment credentials may be handled directly by authorised payment service providers.
D. Technical and Device Information
IP address, browser type, device model, device identifiers, operating system, language, time zone, application version, crash/error logs and security telemetry.
E. Usage and Operational Information
Login/logout events, session information, pages and features used, reports generated, system events, CRM activity, attendance information and other operational activity necessary to provide and secure the Services.
F. Location Information
GPS/location information only where a relevant feature is enabled, required for the stated service purpose, and appropriately disclosed.
G. Communications
Support tickets, emails, calls or meeting records, feedback, complaints, requests and information voluntarily provided to us.
6. Purposes of Processing
We process information only for identified and legitimate purposes, which may include:
- Creating and administering accounts;
- Providing, maintaining and improving the Services;
- Processing subscriptions, invoices, payments and renewals;
- Providing onboarding, implementation, training and customer support;
- Authenticating users and protecting accounts;
- Monitoring performance, reliability and service quality;
- Detecting, preventing and investigating fraud, abuse, unauthorised access and security incidents;
- Generating operational and aggregated analytics;
- Communicating service notices, product updates and, where permitted, marketing communications;
- Complying with tax, accounting, legal, regulatory and governmental requirements;
- Enforcing agreements and protecting the rights, property and safety of Truffle, customers and users; and
- Other purposes specifically disclosed at the time information is collected or otherwise permitted by applicable law.
7. Lawful Basis and Consent
Depending on the applicable law and context, processing may be based on consent, performance of a contract, compliance with a legal obligation, or another lawful basis recognised by applicable law.
Where consent is required, Truffle will seek consent in an appropriate manner and will provide a practical mechanism for withdrawal. Withdrawal of consent does not invalidate processing already lawfully carried out before withdrawal and may affect our ability to provide features that depend on the relevant data.
8. Data Minimisation and Purpose Limitation
Truffle seeks to collect information relevant to the stated purpose and to avoid unnecessary collection. We do not use personal data for materially incompatible purposes without an appropriate legal basis, notice, consent or other permission required by law.
9. Data Sharing and Disclosure
We do not sell personal data.
We may disclose or provide access to information to the following categories of recipients where necessary for the purposes described in this Policy:
- Cloud hosting and infrastructure providers;
- Payment gateways and financial service providers;
- SMS, email, WhatsApp and communication providers;
- Analytics, monitoring, security and technical service providers;
- Implementation, support and professional-service partners;
- Third-party platforms and integrations selected or authorised by the customer;
- Auditors, insurers, legal advisers and professional advisers subject to appropriate confidentiality obligations; and
- Government, law-enforcement, tax, regulatory or judicial authorities where disclosure is required or legally permitted.
Where third parties process personal data on our behalf, Truffle seeks to use appropriate contractual, technical and organisational safeguards consistent with the nature of the processing.
10. Third-Party Integrations
Truffle may integrate with payment gateways, accounting software, delivery platforms, restaurant marketplaces, SMS/WhatsApp providers, ERP systems, cloud storage services, authentication services and other third-party platforms.
Information shared with an integration may be governed by the third party’s terms and privacy policy. Customers should review the relevant third-party terms before enabling an integration and should configure integrations to disclose only the information necessary for the intended purpose.
11. Security Measures
Truffle maintains a risk-based information-security programme designed to protect personal data against unauthorised access, alteration, disclosure, loss, destruction and other reasonably foreseeable risks.
Depending on the product, environment and risk, safeguards may include:
- Encryption in transit using industry-standard secure transport protocols;
- Encryption or other protective controls for sensitive data at rest where appropriate;
- Role-based and least-privilege access controls;
- Strong authentication and credential protections;
- Administrative access restrictions and privileged-access controls;
- Firewall, network and infrastructure security controls;
- Security monitoring, audit trails and activity logging;
- Backups and recovery procedures;
- Vulnerability management, patching and security testing appropriate to the environment;
- Malware and endpoint protections where applicable;
- Employee confidentiality obligations and security awareness measures;
- Incident response and escalation procedures; and
- Supplier/third-party risk management appropriate to the services involved.
Truffle continually evaluates its safeguards against evolving risks. No internet transmission, cloud environment or electronic storage system can be guaranteed to be completely secure.
12. Cybersecurity Incident Management
Truffle maintains procedures for identifying, containing, investigating, mitigating and documenting suspected security incidents. Where applicable law requires notification to a regulator, authority, customer or affected individual, Truffle will follow the applicable legal and contractual requirements.
Truffle also maintains security logs and records in accordance with applicable requirements. CERT-In directions require specified entities to enable ICT-system logs and maintain them securely for a rolling period of 180 days within Indian jurisdiction, subject to the scope and applicability of those directions.
13. Data Retention and Deletion
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, to provide Services, satisfy contractual requirements, maintain financial/accounting records, comply with legal obligations, resolve disputes, enforce agreements, prevent fraud, maintain security, or meet other lawful requirements.
When personal data is no longer required, Truffle may securely delete, anonymise or otherwise dispose of it in accordance with applicable law and contractual requirements.
Customer-specific retention periods may also be governed by the applicable service agreement, order form or documented customer instruction.
14. Data Principal / Individual Privacy Rights
Subject to applicable law, individuals may have rights relating to their personal data, including rights to access information about processing, request correction or updating, request erasure where legally available, withdraw consent where processing is based on consent, and raise grievances.
Requests may be subject to identity verification and lawful limitations, including requirements to retain information for legal, regulatory, security or dispute-resolution purposes.
Where Truffle processes information solely on behalf of a customer, requests concerning that customer-controlled data may need to be directed to the relevant customer, with Truffle providing reasonable assistance as required by the applicable agreement and law.
15. Grievance Redressal
Privacy complaints, requests and concerns may be submitted using the contact details in Section 22. Truffle will review and address complaints through its internal grievance process and within the timelines required by applicable law.
Where a matter must be escalated to a competent regulatory authority or Data Protection Board under applicable law, the individual may exercise the applicable statutory mechanism.
16. Children’s Privacy
Our Services are primarily intended for businesses and professional users. We do not knowingly solicit personal data from children for independent use of our Services. If we become aware that personal data has been collected contrary to applicable requirements, we will take reasonable steps appropriate to the circumstances.
17. International Data Transfers
Truffle may use service providers or infrastructure located outside India where necessary for the Services. Where personal data is transferred, accessed or processed across jurisdictions, Truffle will apply safeguards and comply with applicable Indian law, contractual commitments and any applicable restrictions on transfer.
Customers using Truffle services internationally are responsible for considering the legal requirements applicable to their own processing activities and users.
18. Cookies and Similar Technologies
Our websites and applications may use cookies, SDKs, pixels, local storage or similar technologies to maintain sessions, remember preferences, improve performance, understand usage, secure accounts and analyse traffic.
Where required, consent or other appropriate controls will be provided. Disabling certain technologies may affect functionality.
19. Marketing and Communications
We may send transactional and service-related communications necessary to operate the Services, such as account alerts, invoices, security notifications, support messages and important product notices.
Promotional communications may be sent where permitted by law and, where required, with appropriate consent. Users may opt out of promotional communications through the available unsubscribe mechanism or by contacting us. Opting out of marketing does not stop essential service or security communications.
20. Automated Processing and AI
Where Truffle uses analytics, automation, machine learning or AI-enabled features, such processing will be governed by the applicable product functionality, contractual terms and law.
Truffle will not intentionally use customer personal data to train a publicly available general-purpose AI model without an appropriate legal basis, customer permission or contractual authorisation where such permission is required. Product-specific AI features may process information to provide the requested functionality, improve reliability, detect abuse or generate insights as disclosed for that product.
21. Business Transfers and Corporate Transactions
If Truffle undergoes a merger, acquisition, restructuring, financing, sale of assets or similar transaction, information may be transferred as part of that transaction subject to applicable confidentiality, security and legal requirements. Any successor handling personal data will remain subject to applicable privacy obligations.
22. Contact and Privacy Requests
For privacy questions, data-related requests, complaints or security concerns, please contact:
Truffle Systems India Private Limited
Email: info@trufflesystems.in
Support: support@trufflesystems.in
Registered Office: Sheth Corporate Tower, 302-C, Purshottam Mavlankar Marg, Near Nagri Hospital, Ellisbridge, Ahmedabad, Gujarat - 380009
Website: www.trufflesystems.in
When submitting a privacy request, please provide enough information to help us identify the relevant account or transaction. We may request reasonable identity verification before disclosing or changing personal information.
23. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in our Services, security practices, legal requirements or business operations. The revised version will be published on this page with an updated “Last Updated” date.
Where required by applicable law, we will provide additional notice or obtain consent for material changes.
24. Governing Law and Jurisdiction
This Privacy Policy is governed by the laws of India, subject to any mandatory rights or requirements applicable to an individual under the law of the relevant jurisdiction. Subject to applicable law and contractual arrangements, disputes relating to this Policy shall be subject to the jurisdiction of competent courts in Ahmedabad, Gujarat, India.
25. Relationship with Other Terms
This Privacy Policy should be read together with Truffle’s Terms & Conditions, applicable subscription/order terms, security commitments and product-specific notices. In the event of a conflict, the applicable written agreement and mandatory law will govern to the extent of the conflict.