Skip to content
Legal

Privacy Policy

Effective Date: July 26, 2026

This policy describes how Hotelic Essentials handles the information you give us when you browse this website, use our ordering app, or buy from us. We have written it in plain language, and we mean every line of it.

Who We Are & Scope

Hotelic Essentials (“Hotelic Essentials”, “we”, “us” or “our”) supplies hospitality, housekeeping and commercial kitchen products to businesses across India. This Privacy Policy explains what information we collect, why we collect it, who we share it with, how long we keep it and what control you have over it.

This policy applies to: (a) this website; (b) our customer mobile application, through which approved customers browse the catalogue and place orders; (c) our internal sales application used by our field representatives; and (d) the enquiry, ordering, delivery and support services we provide through those channels (together, the “Services”).

Our Services are for trade buyers — hotels, restaurants, cafés, cloud kitchens, caterers, institutions and similar businesses — as well as for individual customers buying for personal use. Where this policy refers to “you”, it means the customer named on the account — a business or an individual — and, where relevant, the individual using the account.

By using the Services you agree to this policy. If you do not agree, please do not use the Services. Your use is also governed by our Terms & Conditions.

Registered / operating address: Survey No 27, Hissa No 2, 2A, Punyadham Ashram Rd, near DMart Kondhwa, Kondhwa Budruk, Pune, Maharashtra 411048

Contact for privacy matters: enquiry@hotelicessentials.com

Information We Collect

We collect only what we need to open your account, take your orders, deliver them and support you afterwards.

a. Account information

  • Business name, business type and (where applicable) GSTIN or other tax registration details you provide for invoicing.
  • When you give us a GSTIN we verify it, and we store what the verification returns: your registered legal name, trade name, and the registration’s status, along with the date we verified it.
  • The name, mobile number and email address (optional) of the contact person, and of any additional staff logins you choose to create under your account.
  • The mobile number, together with its country code, is the account’s login ID.
  • Your password, which is stored only in an irreversible hashed form — we cannot read it and will never ask you for it.
  • Account status information such as approval, activation, credit terms and assigned sales territory.
  • A security log of sign-ins to your account (date, time, and whether the attempt succeeded), and the date and time you accepted this policy and our terms.

b. Delivery addresses

  • Address lines, landmark, city, state and PIN code for each delivery location you save, along with the contact name, phone number and any alternate phone number for that location.
  • A GSTIN saved against a specific delivery address, where that location is billed under a different registration — for example a branch or sister concern.
  • Any delivery instructions you add for our team or our logistics partner.

c. Order information

  • The products and quantities you order, order value, taxes, invoice and reference numbers, and any notes attached to the order.
  • Order status and its timeline — placed, accepted, packed, dispatched, delivered, cancelled or returned — with timestamps.
  • Dispatch details for each order: the courier or transport partner used and the consignment or tracking number, so you and we can both follow the shipment.
  • Cash-collection records where an order was settled in cash, and the identity of the representative or driver who handled the order.

d. Payment information

  • Payments are handled by your sales representative and our accounts team, not through the app or website. You agree the terms with your representative — bank transfer, cheque, cash, or against your credit account — and our accounts team records and reconciles it.
  • Because settlement happens that way, we never receive, store or transmit your card number, CVV, card PIN, UPI PIN, net-banking password or any other payment credential — there is no screen in the app or on this site that asks for one.
  • What we do record against your order is the settlement method agreed, the amount received, any reference number you or your bank give us, and the date, so that we can reconcile the payment and issue an invoice and receipt.

e. Push notification token

  • If you allow notifications, our app registers a device token with Google Firebase Cloud Messaging (FCM). We store that token against your account so we can send you order confirmations, dispatch and delivery updates, and occasional announcements about stock or new arrivals.
  • The token identifies the app installation on your device, not you personally, and it is removed when you log out, uninstall the app or ask us to delete your account.

f. Search queries and catalogue activity

  • What you search for and which categories or products you open, so we can improve the catalogue, fix search results that return nothing useful, and stock the lines our customers actually ask for.

g. Technical and diagnostic information

  • App version, device model, operating system version, coarse network information, IP address, and crash or error logs. This is used for security, troubleshooting and stability — not for profiling you.

h. Communications

  • Enquiries submitted on this website or from the app (your name, business name, phone, email, city, your message, and the product you were asking about, if any), and your correspondence with us over email, phone or WhatsApp, including support tickets, quotes we send you and complaints.

i. If you are one of our field sales staff

  • Our internal sales app additionally records your code name, the customers and territory assigned to you, the orders you place on behalf of customers, tasks assigned to you and your activity in the app. This is employment-related processing and is governed by your terms of engagement with us.

j. What we do NOT collect

  • No card, UPI or banking credentials. Payments are arranged with your representative and our accounts team, so these are never entered in the app and never reach our servers.
  • No precise or background location. Our apps do not track your location in the background, and the customer app does not request location permission at all.
  • No contacts, call logs, SMS or microphone access. We never read your address book, messages or calls.
  • No biometric data and no health, financial-account, caste, religion or other sensitive personal information beyond what is listed above.
  • No advertising identifiers and no third-party ad networks. We do not run behavioural advertising, and we do not sell, rent or trade your information.

How We Use It

We use the information described above only for the purposes below.

  • To open and operate your account — verifying that you are a genuine buyer (for business accounts, that you are a genuine trade buyer), approving your account, setting up staff logins, and authenticating you when you sign in.
  • To process and fulfil orders — confirming, picking, invoicing, dispatching and delivering what you have ordered, and handling cancellations, returns and replacements.
  • To reconcile payment — recording which settlement method was agreed and what has been received, matching cash collections and bank transfers against orders, and issuing invoices and receipts.
  • To keep you informed — order confirmations, dispatch and delivery notifications, payment receipts, and service messages such as changes to these policies. These are transactional messages and are part of the service.
  • To provide support — answering your enquiries, resolving delivery or quality issues, and maintaining a record of what was discussed and agreed.
  • To improve the Services — understanding which products and categories are in demand, improving search, planning stock, and fixing bugs and crashes.
  • To protect the Services — detecting and preventing fraud, abuse, unauthorised access, and misuse of trade pricing.
  • To meet legal obligations — issuing tax invoices, maintaining books of account and GST records, and responding to lawful requests from authorities.
  • Marketing, only where permitted — occasional announcements about new arrivals, restocks or offers. You can opt out at any time by turning off notifications, using the unsubscribe link in an email, or writing to us. Opting out of marketing does not stop transactional order messages.

We process this information because it is necessary to perform our contract with you, because you have consented (for example to push notifications), because we have a legitimate business interest in running and securing our supply operation, or because the law requires it.

Who We Share With

We do not sell, rent or trade your personal information. We share it only with the parties below, and only to the extent needed.

  • No payment gateway. Payments are handled directly by our own sales and accounts teams, so no third-party payment processor receives anything about you or your order.
  • Google LLC / Google India (Firebase) — we use Firebase Cloud Messaging to deliver push notifications. Firebase receives the device token and the content of the notification we send you.
  • GST verification service — when you enter a GSTIN, we send it (and nothing else) to a GST lookup provider to confirm it is genuine and to fetch your registered legal name, which we store on your account. No other detail about you or your orders is shared with this service.
  • Logistics, courier and delivery partners — we share the recipient name, delivery address, contact phone, order contents where needed for handling, and the amount to be collected on Cash on Delivery orders.
  • Our own field sales representatives — the representative assigned to your territory can see your account details, addresses and order history so they can serve your account and place orders on your behalf when you ask them to.
  • Service providers — hosting, storage, communications, accounting and IT support vendors who process data on our instructions under confidentiality obligations, and only for the purpose we engaged them for.
  • Authorities and legal — courts, tax authorities, law-enforcement and regulators where we are required to disclose by law, or where disclosure is necessary to establish, exercise or defend a legal claim, prevent fraud, or protect the rights and safety of any person.
  • Business transfers — if our business is merged, acquired or reorganised, your information may transfer to the successor entity, which will remain bound by this policy or a policy at least as protective. We will tell you if this happens.

Some of these providers operate infrastructure outside India. Where information is transferred outside India, we take reasonable steps to ensure it continues to be protected to a standard comparable to that required under Indian law.

Data Security

We take security seriously and apply reasonable security practices and procedures, including:

  • Encryption in transit — all traffic between our apps, our website and our servers uses HTTPS/TLS.
  • Passwords stored only as salted, irreversible hashes; we never store or display them in readable form.
  • We keep a log of sign-in events (date, time and success or failure) on your account for security, and we record the date and time you accept this policy and our terms.
  • Token-based authentication with sessions that can be revoked, and immediate revocation when an account or staff login is removed.
  • Role-based access control inside our admin systems, so staff can only see the data their role requires, on a least-privilege basis.
  • Payment credentials kept entirely out of our environment by delegating payment capture to a PCI-DSS compliant gateway.
  • Regular patching, access reviews, logging of administrative actions, and backups of production data.

No system can be guaranteed completely secure. Please keep your password confidential, do not share staff logins, and tell us immediately at enquiry@hotelicessentials.com if you believe your account has been accessed without authorisation. If a breach occurs that is likely to affect you, we will notify you and the relevant authorities as required by law.

Retention & Deletion

We keep information only as long as we have a reason to.

  • Account and profile data — for as long as your account is active, and for a short period afterwards to handle disputes or reactivation requests.
  • Orders, invoices and payment records — retained for the period required by Indian tax, GST and company law (generally up to eight financial years from the end of the relevant year). These records cannot be deleted on request, because we are legally obliged to keep them.
  • Push notification tokens — deleted when you log out, uninstall the app, disable notifications or delete your account.
  • Support correspondence and enquiries — retained for up to three years to maintain a service history, then deleted.
  • Diagnostic and crash logs — retained for a short rolling period, typically no more than 90 days.
  • Backups — deleted data may persist in encrypted backups for a limited rolling window before those backups are overwritten.

You can ask us to delete your account at any time, from inside the app or by writing to us. We action verified deletion requests within 7 business days. See Delete your account for exactly what is erased and what we are required to retain.

Your Rights

Subject to applicable Indian law, you have the right to:

  • Access the personal information we hold about you and ask how it is being used.
  • Correct information that is inaccurate or out of date — most account and address details can be edited directly in the app, and we will correct the rest on request.
  • Withdraw consent you previously gave, for example by turning off push notifications. Withdrawing consent does not affect processing already carried out, and may mean we can no longer provide part of the Services.
  • Delete your account and the personal data we are not legally required to keep.
  • Opt out of marketing messages while continuing to receive transactional order updates.
  • Complain to us about how your information has been handled, and to escalate to the relevant authority if you are not satisfied with our response.

To exercise any of these rights, write to enquiry@hotelicessentials.com from the email address or using the mobile number registered on your account. We may ask for information to verify your identity before we act, so that we do not disclose or delete data on the instruction of the wrong person. We aim to respond within 7 business days, and within 30 days at the outside for complex requests.

Grievance Officer. Complaints about the handling of personal information can be addressed to our Grievance Officer at enquiry@hotelicessentials.com, or by post to Survey No 27, Hissa No 2, 2A, Punyadham Ashram Rd, near DMart Kondhwa, Kondhwa Budruk, Pune, Maharashtra 411048. Please write “Privacy Grievance” in the subject line so it reaches the right desk quickly.

Device Permissions

Our app asks for as few permissions as possible. Each one is optional unless marked otherwise, and each can be withdrawn at any time in your device settings.

  • Notifications (optional) — used to send order confirmations, dispatch and delivery updates and occasional stock announcements. Declining means you will still see order status inside the app, but you will not be alerted.
  • Camera and photos (optional) — requested only at the moment you choose to attach a photograph or video, for example when reporting a damaged item or uploading a business registration document. We do not browse your gallery.
  • Storage / files (optional) — used only to save an invoice or order summary to your device when you tap download.
  • Internet and network state (required) — needed for the app to communicate with our servers and to tell you when you are offline.

We do not request location, contacts, SMS, call logs, microphone or background-activity permissions in the customer app.

Children's Privacy

The Services are intended for adults — trade buyers and individual customers — and are not directed at children. You must be at least 18 years old and legally capable of entering into a contract to hold an account with us.

We do not knowingly collect personal information from anyone under 18. If we learn that we have collected such information, we will delete it promptly. If you believe a minor has provided us with personal information, please contact us at enquiry@hotelicessentials.com and we will remove it.

Changes & Contact

We may update this Privacy Policy from time to time to reflect changes in our Services, our providers or the law. The “Effective Date” at the top of this page always shows the current version.

If a change materially affects how we handle your information, we will give you notice in the app, by email or by a prominent notice on this website before it takes effect. Continuing to use the Services after a change takes effect means you accept the updated policy. If you do not accept it, you should stop using the Services and may ask us to delete your account.

Questions, requests or complaints about this policy:

  • Email: enquiry@hotelicessentials.com
  • Post: Survey No 27, Hissa No 2, 2A, Punyadham Ashram Rd, near DMart Kondhwa, Kondhwa Budruk, Pune, Maharashtra 411048
  • Business hours: Mon–Sat, 10:00 AM – 6:30 PM
Still unsure about something? Email enquiry@hotelicessentials.com or send us a message and a real person will answer.