Last Updated: December 2025
Introduction and Scope
- Sapaad Software Pvt Ltd, a company incorporated under the Companies Act, 2013, and its relevant subsidiaries and affiliates (collectively, "Sapaad," "we," "us," or "our") respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard personal data in compliance with applicable laws.
-
Applicable Laws: This Privacy Policy complies with:
- India's Digital Personal Data Protection Act, 2023 (DPDPA) and rules notified thereunder;
- Information Technology Act, 2000 and rules thereunder; and
- Other applicable data protection laws in jurisdictions where we operate or serve customers.
-
Scope of Application: This Privacy Policy applies to personal data that we collect:
- Through our website at www.sapaad.com/in and related websites;
- When you register for, access, or use our Service (as defined in our Terms of Service);
- Through direct communications with you (email, phone, in-person meetings, etc.);
- At events, webinars, demonstrations, and trade shows;
- From third-party sources with your consent or as permitted by law; and
- Through cookies and similar tracking technologies.
Personal data collected by Sapaad will be transferred to Sapaad Pte. Ltd. (Singapore) and other Sapaad group entities located outside India for centralized processing, to provide you with the services and other legitimate business needs in accordance with applicable law. Further, your personal data may be shared with authorized data processors appointed by Sapaad strictly for service delivery purposes.
Definitions
-
"Personal Data" means information that identifies or can reasonably be used to identify an individual, including:
- Name, title, gender, date of birth;
- Contact details (email address, phone number, postal address);
- Identification numbers (passport, national ID, tax ID);
- Financial information (bank account, credit card details);
- IP address, device identifiers, geolocation data;
- Online identifiers (cookies, session IDs);
- Employment information (company name, job title);
- Transaction history and usage data; and
- Any other information defined as "personal data" under applicable laws.
-
"Sensitive Personal Data" (or "Special Category Data") means personal data revealing:
- Racial or ethnic origin, political opinions, religious or philosophical beliefs;
- Biometric or genetic data processed to uniquely identify an individual;
- Health data, including dietary restrictions or food allergies;
- Sexual orientation or gender identity; or
- Financial account credentials, passwords, PINs.
We do not intentionally collect Sensitive Personal Data except where strictly necessary for service delivery (e.g., dietary restrictions for meal planning) and only with your explicit consent or as required by law.
- "Processing" means any operation performed on personal data, including collection, recording, storage, use, disclosure, transfer, deletion, destruction and other activities as prescribed under applicable laws.
Personal Data We Collect
-
Data You Provide Directly: We collect personal data you voluntarily provide when you:
- Express Interest in Our Services: Name, title, company name, business address, phone number, email address, job function; Purpose of inquiry or information requested.
- Create an Account or Subscribe: Account credentials (username, password); Billing and payment information (credit/debit card details, bank account information, billing address, GSTIN); Company registration details, business licenses (including FSSAI license numbers); Authorized user information for your organization.
- Use Our Service: Customer Data uploaded to the Service (including menu items, inventory records, transaction data, customer contact information collected by you); Support requests and communications with our customer service team, preferences and settings within the Service.
- Attend Events or Webinars: Registration information (name, title, company, email, phone, country). Badge scan information at sponsored events; Dietary preferences or accessibility requirements.
- Participate in Marketing or Surveys: Responses to surveys, questionnaires, or feedback forms; Marketing preferences and communication opt ins.
- Register for Online Communities: Username, profile photo, biographical information (occupation, location, social media profiles, areas of expertise and interests).
- Visit Our Offices: Visitor registration details (name, email, phone, company, date and time of visit); Non-disclosure agreements (if required); Security footage from CCTV cameras in office premises.
-
When You Visit Our Website: We automatically collect:
- Device and browser information: IP address, device type, operating system, browser type and version, screen resolution, language preferences;
- Usage data: Pages viewed, links clicked, time spent on pages, referring URLs, search queries, date and time stamps;
- Location data: General geographic location derived from IP address.
- Service usage data: Features accessed, modules used, frequency of use, actions taken within the Service;
- Performance data: Page load times, error logs, system performance metrics;
- Device data: Mobile device identifiers, operating system, app version, push notification tokens;
- Location data: Geolocation (if you grant permission via mobile app);
- Transaction metadata: Transaction times, amounts, payment methods (but not full card numbers or CVV codes).
-
Cookies and Tracking Technologies: We use cookies, web beacons, pixels, JavaScript, and similar technologies to:
- Authenticate users and prevent fraud;
- Remember preferences and settings;
- Analyze website and Service usage;
- Deliver personalized content and advertisements;
- Measure marketing campaign effectiveness.
-
Data From Third-Party Sources: We may collect personal data from:
- Business contact databases and lead generation services (name, title, company, email, phone);
- Social media platforms (LinkedIn, Facebook, Twitter) if you interact with our pages or authorize connections;
- Third party service providers integrated with our Service (payment processors, logistics partners, loyalty program providers);
- Publicly available sources (company websites, public registries, published directories);
- Event sponsors or co-marketing partners with your consent;
- Credit reporting agencies (for creditworthiness assessments where permitted).
How We Use Personal Data
- We process personal data only where we have a lawful basis under applicable law:
- Consent: You have given free, clear, specific, informed, unconditional consent;
- Contract Performance: Processing is necessary to fulfill our contractual obligations to you;
- Legal Obligation: Processing is required to comply with applicable laws or regulations;
- Legitimate Interests: Processing is necessary for our legitimate business interests, provided these do not override your fundamental rights and freedoms or any applicable law; or
- Vital Interests: Processing is necessary to protect your vital interests or those of another person.
- We process personal data for the following purposes:
Service Delivery and Performance (Contract Performance / Legitimate Interests):
- Provide access to and functionality of the Service;
- Authenticate users and manage accounts;
- Process transactions and maintain billing records;
- Deliver customer support and respond to inquiries;
- Fulfil orders and service requests;
- Enable integrations with Third-Party Services you authorize.
Legal and Regulatory Compliance (Legal Obligation):
- Comply with Indian tax laws (GST invoicing, TDS reporting, FSSAI licensing verification);
- Respond to lawful requests from government authorities, courts, or regulators;
- Maintain records required by law (including CERT-In log retention for customers);
- Report cybersecurity incidents as required by CERT-In;
- Comply with anti-money laundering and counter-terrorism financing obligations;
- Verify TRAI DLT registration for SMS users in India.
Security and Fraud Prevention (Legitimate Interests):
- Monitor for suspicious activity, unauthorized access, or security threats;
- Investigate and respond to security incidents;
- Enforce our Terms of Service and other policies;
- Protect the rights, property, and safety of Sapaad, our customers, and the public;
- Implement access controls and authentication measures.
Service Improvement and Development (Legitimate Interests):
- Analyze usage trends and user behavior;
- Identify bugs, errors, and performance issues;
- Develop new features, products, and services;
- Conduct research and analytics;
- Generate anonymized, aggregated statistics (which do not identify individuals).
Marketing and Communications (Consent / Legitimate Interests):
- Send marketing emails, newsletters, and promotional offers (with your consent);
- Conduct market research and customer satisfaction surveys;
- Display personalized advertisements on our websites and third-party platforms;
- Invite you to events, webinars, and product demonstrations;
- Share information about product updates and new features.
For marketing communications, we rely on consent where required by law. You may withdraw consent or opt out at any time (see Section 7).
Event Management (Contract Performance / Legitimate Interests):
- Process registrations and send event-related communications;
- Facilitate networking and attendee engagement;
- Share attendee information with event sponsors (with your consent via registration or badge scan).
Business Operations (Legitimate Interests):
- Manage vendor and partner relationships;
- Assess customer opportunities and business development;
- Facilitate corporate transactions (mergers, acquisitions, asset sales);
- Maintain internal records and documentation;
- Manage office security and visitor access.
Internal Training and Quality Assurance (Legitimate Interests):
- Train staff on product functionality and customer service;
- Monitor and improve the quality of customer support;
- Conduct internal audits and risk assessments.
Disclosure and Sharing of Personal Data
- Within Sapaad Group: We may share personal data among Sapaad Pte. Ltd., Sapaad Software Private Limited, and our affiliates for the purposes described in Section 4, including customer support, technical operations, marketing, and account management.
-
Service Providers and Processors: We share personal data with trusted third-party service providers who assist us in operating our business, including:
- IT and cloud infrastructure providers (hosting, storage, backup, disaster recovery);
- Payment processors and gateways (Stripe, Razorpay, PayPal, etc.);
- Customer support platforms (help desk software, live chat tools);
- Marketing and analytics providers (Google Analytics, email marketing platforms, CRM systems);
- Security and fraud prevention services;
- Professional advisors (lawyers, accountants, auditors, insurers).
- Integration Partners (With Your Authorization): When you activate third-party integrations (payment gateways, logistics providers, loyalty platforms, hardware providers), we share relevant personal data and Customer Data with those partners as necessary to deliver the integration functionality. You authorize such sharing by activating the integration.
- Event Sponsors and Co-Marketing Partners: If you attend an event or webinar we organize, or download sponsored content, we may share your registration information (name, title, company, email, phone) with event sponsors or content providers. Where required by law, you will be asked to consent via the registration form or by allowing your badge to be scanned. Sponsors' use of your information is governed by their own privacy policies.
- Business Transfers: If Sapaad is involved in a merger, acquisition, reorganization, asset sale, or bankruptcy, personal data may be transferred to the successor entity. We will use reasonable efforts to notify you (via email or prominent notice on our website) before your personal data is transferred and becomes subject to a different privacy policy.
-
Legal Requirements and Protection of Rights: We may disclose personal data to government authorities, law enforcement, courts, or other third parties when we believe disclosure is:
- Required by law, regulation, legal process, or government request;
- Necessary to enforce our Terms of Service or other agreements;
- Necessary to detect, prevent, or address fraud, security, or technical issues;
- Necessary to protect the rights, property, or safety of Sapaad, our customers, or the public, as required or permitted by law.
- Aggregated and Anonymized Data: We may share aggregated, anonymized, or de-identified data that does not identify individuals (or permit re-identification) with third parties for analytics, research, marketing, and business intelligence purposes. Such data is not considered personal data.
- With Your Consent: We may share personal data with other third parties when you provide specific consent for such sharing.
International Data Transfers
- Cross-Border Transfers: Sapaad operates globally and may transfer personal data across international borders, including to countries that may not provide the same level of data protection as your home jurisdiction.
-
Safeguards for Transfers: When transferring personal data internationally, we implement appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the relevant authorities;
- Adequacy decisions recognizing certain jurisdictions as providing adequate protection;
- Binding Corporate Rules within the Sapaad group entities;
- Consent where required by law;
- Compliance with DPDPA requirements for transfers from India, including obtaining your explicit consent and implementing such transfer mechanisms or safeguards as may be prescribed under applicable law.
-
Primary Data Locations: Personal data is primarily stored and processed in:
- Singapore;
- India;
- Cloud infrastructure is provided by third-party service providers (AWS, Google Cloud, Microsoft Azure) with data centres in various locations.
- You may contact us at support@sapaad.com to obtain more information about international transfers and the safeguards in place.
Your Rights and Choices
-
Rights Under DPDPA: You have the following rights under the DPDPA:
- Right to Access: You may request confirmation of whether we process your personal data and obtain a copy of such data in a clear and concise manner, including the identities of all data fiduciaries and data processors with whom we have shared your personal data, together with a description of the personal data so shared subject to applicable laws.
- Right to Correction: You may request correction of inaccurate, misleading, incomplete, or outdated personal data.
-
Right to Erasure: You may request deletion of your personal data where:
- It is no longer necessary for the purposes for which it was collected;
- You withdraw consent (where processing is based on consent);
- Processing is unlawful; or
- Erasure is required by law.
- Right to Grievance Redressal: You may lodge a complaint with our Data Protection Officer (DPO) or the Data Protection Board of India if you believe your rights have been violated in accordance with applicable laws.
- Right to Nominate: You may nominate another individual to exercise your rights in the event of your death or incapacity.
-
Exercising Your Rights
- To exercise any of the above rights, please contact us at:
Email: support@sapaad.com
Phone: 1800 571 7272 - We will respond to your request within thirty (30) business days. We may request additional information to verify your identity before processing your request.
- To exercise any of the above rights, please contact us at:
-
Marketing Opt-Out: You may opt out of marketing communications at any time by:
- Clicking the "unsubscribe" link in any marketing email;
- Emailing support@sapaad.com with "OPT OUT" in the subject line;
- Updating your communication preferences in your account settings; or
- Contacting us using the contact details in Section 7.
- Opting out of marketing does not affect transactional or service-related communications (e.g., account notifications, billing statements, security alerts).
- Cookie Management: See Section 9 for information on managing cookies and tracking technologies.
Data Retention
- Retention Principles: We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.
-
General Retention Periods:
- Account and transaction data: Retained for the duration of the customer relationship plus 7 years (or longer if required by applicable tax, accounting, or legal requirements);
- Marketing data: Retained until you opt out or withdraw consent, plus up to 2 years for suppression purposes;
- Support and communication records: Retained for 5 years, unless a shorter retention period is required by applicable law;
- Website analytics and logs: Retained for up to 26 months;
- CCTV footage: Retained for 90 days unless required for security investigation or legal proceedings.
We retain:
- System logs, IP addresses, and usage records: Minimum 180 days from the date of generation;
- Financial and tax records: 7 years from the end of the relevant financial year (as required under Indian tax laws).
-
Deletion and Anonymization: After the retention period expires, we will:
- Securely delete or destroy personal data; or
- Anonymize personal data such that it can no longer identify individuals.
- Legal Holds: We may retain personal data beyond standard retention periods if required for legal proceedings, government investigations, or to defend legal claims.
Data Security
- We implement robust administrative, technical, and physical safeguards to protect personal data against unauthorized access, disclosure, alteration, and destruction, including, as may be appropriate, the following measures:
Administrative Safeguards:
- Data protection policies and procedures;
- Privacy and security training for employees;
- Designated Data Protection Officer (DPO) and security personnel;
- Background checks for employees with access to personal data;
- Regular security audits and risk assessments.
Technical Safeguards:
- Encryption of data in transit (TLS/SSL) and at rest (AES-256);
- Multi-factor authentication (MFA) for account access;
- Access controls and role-based permissions (principle of least privilege);
- Intrusion detection and prevention systems (IDS/IPS);
- Regular security patching and vulnerability scanning;
- Secure software development lifecycle (SDLC) practices;
- Data loss prevention (DLP) tools;
- Backup and disaster recovery procedures.
Physical Safeguards:
- Secure data center facilities with restricted access;
- 24/7 surveillance and monitoring of physical infrastructure;
- Environmental controls (fire suppression, temperature regulation).
- Payment Card Security (PCI DSS Compliance): We comply with the Payment Card Industry Data Security Standard (PCI DSS) for payment processing. We do not store complete credit card numbers, CVV codes, or magnetic stripe data. Payment processing is handled by PCI DSS-compliant third-party processors using encryption and tokenization.
-
CERT-In Compliance (India): We comply with CERT-In directives, including:
- Reporting cybersecurity incidents to CERT-In within six hours of noticing such incidents;
- Maintaining system logs for at least 180 days;
- Implementing security best practices and coordinating with CERT-In on incident response.
- Limitations of Security: While we employ industry-standard security measures, no system is completely secure. Data transmission over the internet and electronic storage carry inherent risks. We cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for any activity under your account. For your own protection, do not include sensitive personal data (e.g., passwords, credit card numbers, health information) in emails to us or our staff unless encrypted or transmitted through secure channels.
-
Security Incident Response: In the event of a data breach affecting personal data:
- We will investigate promptly and take steps to contain and mitigate the breach;
- We will notify affected individuals and relevant authorities including the Data Protection Board of India as required by law;
- Notice to affected individuals and the Data Protection Board without undue delay. We will cooperate with regulatory investigations and take corrective actions to prevent recurrence.
Children and Disabled Persons Privacy
- Our Service is not directed to children under the age of 18 (or the applicable age of majority in your jurisdiction) or to persons with disabilities who are legally unable to provide valid consent. We do not knowingly collect personal data from children under 18 or from persons with disabilities who are legally unable to provide valid consent without verifiable parental or guardian consent.
- If you are a parent or lawful guardian and believe your child or a person with a disability under your care has provided personal data to us without your consent, please contact us at support@sapaad.com. Upon verification, we will promptly delete such information from our systems.
- For residents under the age of 18, we require verifiable parental or guardian consent before processing personal data, in accordance with DPDPA requirements.
Third-Party Links and Services
- Our website and Service may contain links to third-party websites, applications, and services that are not owned or controlled by Sapaad. This Privacy Policy does not apply to such third-party sites. We are not responsible for the privacy practices or content of third parties.
- We encourage you to review the privacy policies of any third-party websites or services you visit or use. Third parties may have different data collection, use, and sharing practices than Sapaad.
Updates to This Privacy Policy
- We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or business operations. The "Last Updated" date at the top of this policy indicates when it was last revised.
- If we make material changes that significantly affect how we collect, use, or share personal data, we will:
- Post a prominent notice on our website;
- Send an email notification to registered users (where we have your email address); and/or
- Provide notice through the Service.
- Continued Use as Acceptance: Your continued use of our website or Service after the effective date of changes constitutes acceptance of the updated Privacy Policy. If you do not agree with the changes, you must stop using our Service and may request deletion of your personal data (subject to legal retention requirements).
Contact Us and Data Protection Officer
- For questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: support@sapaad.com
- Phone: 1800 571 7272
- Address: Sapaad Software Pvt Ltd, SCK01, 207, Second Floor, Smart City, Kakkanad, Ernakulam, Kerala 682030 and B4, 65/1389, Express Garden, Elamkulam Road, KALOOR, Ernakulam, Kerala, 682017
-
Grievance Officer: We have appointed a Grievance Officer in accordance with DPDPA requirements to address complaints and grievances related to personal data processing.
- Grievance Officer Name: Sikandar Kotwal
- Email: legal@sapaad.com
- Address: Sapaad Software Pvt Ltd, SCK01, 207, Second Floor, Smart City, Kakkanad, Ernakulam, Kerala 682030 and B4, 65/1389, Express Garden, Elamkulam Road, KALOOR, Ernakulam, Kerala, 682017
- The Grievance Officer will acknowledge your complaint within 24 hours and resolve it within 15 days (or such other timeframe as specified under DPDPA rules).
- Regulatory Authorities: You have the right to lodge a complaint with the relevant data protection authority in your jurisdiction: India: Data Protection Board of India.
By using our Service, you acknowledge that you have read, understood, and agree to this Privacy Policy.








