Menu

PRIVACY POLICY – VENDORS / RESTAURANT OWNERS

Home / Privacy Policy- VENDORS / RESTAURANT OWNERS

PRIVACY POLICY – VENDORS / RESTAURANT OWNERS

VCO Ventures App | VCO Job

Entity: VDurga Industries Private Limited

Jurisdiction: Bangalore, Karnataka, India

Last Updated: 17th August 2026

This Privacy Policy describes how VDurga Industries Private Limited, operating VCO Job, collects, processes, stores, uses, shares, and protects Personal Data of individuals registering or operating on the VCO Ventures App as Vendors / Restaurant Owners.

Vendors are referred to as Data Principals under applicable data-protection law.

By registering, accessing, or using the Platform, you acknowledge this Privacy Policy and the processing of Personal Data described in it. Where applicable law requires consent, the relevant consent or permission will be obtained.

1. LEGAL BASIS & APPLICABILITY

  • Information Technology Act, 2000 and applicable rules, including the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, where applicable.
  • Digital Personal Data Protection Act, 2023.
  • Digital Personal Data Protection Rules, 2025, to the extent the relevant provisions are in force.
  • This Policy applies to Vendors / Restaurant Owners using the VCO Ventures App. Other VCO Job participant categories are governed by their applicable privacy policies.

2. DEFINITIONS

  • Personal Data: data about an individual who is identifiable by or in relation to that data.
  • Data Principal: the individual to whom Personal Data relates.
  • Data Fiduciary: VDurga Industries Private Limited, operating VCO Job, in relation to Personal Data processed for the purposes described in this Policy.
  • Data Processor: a third party that processes Personal Data on behalf of the Data Fiduciary.
  • Sensitive or regulated information: information subject to enhanced protection under applicable law or contractual requirements, where applicable.

3. CATEGORIES OF PERSONAL DATA COLLECTED

3.1 IDENTITY & CONTACT DATA

  • Full name
  • Mobile number
  • Email address
  • Photograph
  • Date of birth / age verification
  • Residential or business address

3.2 BUSINESS / PROFESSIONAL DATA

  • Restaurant/business name
  • Business address
  • FSSAI, GST, trade licence or other applicable registration details
  • Menu, pricing, operating hours and business/service information

3.3 FINANCIAL & TAX DATA

  • Bank account details for payouts
  • PAN/GST where applicable
  • Transaction, payout, commission, reconciliation, and settlement records

3.4 LOCATION DATA

The Platform may collect and process the registered business location, service area or delivery-radius information, order-fulfilment location information, and location information used for address verification, compliance, fraud prevention, audits, and operational analytics where applicable. The current Vendor policy does not contemplate continuous real-time movement tracking of Vendors or restaurant staff.

3.5 TECHNICAL & USAGE DATA

  • IP address
  • Device identifiers or similar technical identifiers where required
  • App usage logs
  • Crash diagnostics
  • App version, operating system, and related technical information

3.6 APP PERMISSIONS & DEVICE ACCESS

  • Notifications: for order updates, settlement information, operational alerts, security notices, and other Platform communications.
  • Camera / Photos / Files: where the App provides document, profile, menu, business, or verification-image upload functionality and the participant grants the relevant permission.
  • Location: where required for registered business-location, serviceability, verification, or other enabled location features; continuous real-time movement tracking of Vendors is not intended under this policy.
  • Microphone: only if an in-App voice communication feature is enabled and used.
  • Storage / Files: where applicable for uploading or accessing documents, invoices, images, or other business records.

The App should request only permissions actually required by its implemented features. The permission disclosures in this Policy, Google Play Data Safety information, Apple App Privacy information, and the App's actual technical behaviour must remain consistent.

4. PURPOSE OF PROCESSING OF PERSONAL DATA

Personal Data is processed only for specific, lawful, necessary, and clearly defined purposes, including the following:

A. Onboarding & Regulatory Compliance

  • Verify business ownership or authorized signatories
  • Validate FSSAI, GST, trade licences and other applicable statutory approvals
  • Verify identity documents and eligibility
  • Support food-safety, taxation and local regulatory compliance

B. Restaurant Listing & Platform Enablement

  • Create and manage restaurant/business profiles
  • Display business name, cuisine/service type, menu/items, pricing, availability, and operating hours
  • Enable order acceptance, preparation workflows, serviceability configuration, and customer discovery

C. Order Management & Fulfilment

  • Share limited order-related information necessary for order preparation and fulfilment
  • Coordinate order preparation and logistics
  • Minimize customer Personal Data shared with Vendors to what is reasonably necessary for fulfilment

D. Financial Settlements & Tax Compliance

  • Calculate commissions and platform fees
  • Process payouts
  • Maintain transaction and reconciliation records
  • Comply with GST, TDS, tax, invoicing and financial requirements

E. Business Communication & Support

  • Send order updates, settlement statements, operational alerts and policy communications
  • Provide support and dispute resolution
  • Send promotional communications where permitted

F. Fraud Prevention & Legal Compliance

  • Detect and prevent fraud, misuse or unauthorized activity
  • Enforce Platform policies
  • Respond to lawful requests from authorities

5. CONSENT & LAWFUL BASIS

  • Where consent is required, consent may be obtained during onboarding, through in-app controls, or through device permissions.
  • Where permitted by applicable law, processing may also be undertaken for service delivery, contractual or operational requirements, legal obligations, security, fraud prevention, or other lawful uses.
  • Withdrawal of consent may limit or terminate access to features that require the relevant data or permission.

6. DISCLOSURE & DATA SHARING

6.1 WITH CUSTOMERS

  • Business/service details
  • Restaurant/business location
  • Other information reasonably necessary for customer discovery or ordering

6.2 WITH DATA PROCESSORS

  • Payment gateways
  • Cloud hosting providers
  • Communication providers such as SMS, email and push-notification services
  • Analytics, security, support and other technology providers where applicable

6.3 WITH GROUP ENTITIES & ASSOCIATED ORGANIZATIONS

  • Group companies, sister concerns and affiliates
  • NGOs and co-operative societies where legitimately involved
  • Private limited companies, LLPs, partnership firms and proprietorships
  • Franchisees, authorized representatives and channel partners
  • Vendors, service partners, subcontractors, branches and operational units, where necessary for lawful Platform operations

6.4 WITH GOVERNMENT / LEGAL AUTHORITIES

  • Where required by law, court order, regulatory requirement, or lawful government request

Personal Data is not sold or rented for independent marketing purposes. Where a recipient is a Data Processor or other authorized recipient, appropriate contractual, confidentiality, and security safeguards should apply.

7. DATA SECURITY

  • Encryption at rest and in transit where appropriate.
  • Secure infrastructure and access controls.
  • Role-based internal access restrictions.
  • Security reviews and reasonable organizational safeguards.
  • No electronic system can guarantee absolute security.

8. DATA RETENTION & ERASURE

Personal Data is retained for as long as reasonably necessary for the purposes described in this Policy, including active account operations, payments, taxation, accounting, dispute resolution, fraud prevention, security, audits, and legal or regulatory requirements.

When retention is no longer necessary, data will be deleted or anonymized in accordance with applicable law and the Company's retention practices, subject to information that must or may lawfully be retained.

9. ACCOUNT DELETION

Users of the VCO Ventures App may initiate deletion of their account through an accessible account-deletion option within the App. The process should allow the participant to request deletion of the account and associated Personal Data, subject to lawful retention requirements.

Certain records may be retained where necessary or legally required for taxation, accounting, fraud prevention, security, dispute resolution, legal claims, regulatory compliance, or other lawful purposes. Such retained data will be limited to the applicable purpose and retention period.

Account Deletion URL: Create delete account request

10. RIGHTS OF DATA PRINCIPALS

  • Request access to Personal Data, subject to applicable law.
  • Correct or update inaccurate information.
  • Withdraw consent where processing is based on consent.
  • Request deletion or erasure, subject to lawful retention requirements.
  • Nominate another person where such nomination is available under applicable law.
  • Raise a privacy grievance or complaint.

11. CONFIDENTIALITY OBLIGATIONS

  • Vendors / Restaurant Owners must protect customer and Platform information received through VCO Ventures App.
  • Such information must be used only for authorized service or Platform purposes.
  • Personal Data must not be copied, sold, disclosed, or misused except as permitted by the Platform, the customer relationship, or applicable law.
  • Violations may result in account restriction, termination, contractual action, or legal action as permitted by law.

12. PLATFORM VS PARTICIPANT DATA ROLE DISCLAIMER

Vendors / Restaurant Owners operates as an independent participant/service provider and is not the Data Fiduciary for Personal Data processed by VDurga Industries Private Limited through VCO Job. Any participant handling customer information must use it only for authorized purposes and comply with applicable data-protection and confidentiality obligations.

13. AGE RESTRICTION

Only individuals 18 years or older may register as Vendors / Restaurant Owners, unless a different legal requirement applies to a particular category or service.

14. CROSS-BORDER DATA TRANSFER

Personal Data may be processed or stored outside India where permitted by applicable law and subject to applicable safeguards, contractual requirements, and government-notified restrictions, where relevant.

15. POLICY UPDATES

This Policy may be updated periodically to reflect changes in services, technology, law, or business practices. Updates will be made available through the Platform and/or public website. The latest version should be reviewed periodically.

Privacy Policy URL: Privacy Policy

16. GRIEVANCE REDRESSAL

Grievance Officer: Praveen

Email: info@vcojob.com

Address: 903, 80 Feet Road, 6th Block, Koramangala, Bengaluru – 560095

Grievances will be acknowledged and addressed within applicable statutory or reasonable timelines, depending on the nature and complexity of the complaint.