Privacy Policy

1. Introduction and Scope
This Privacy Policy (“Policy”) describes how Totely India Pvt Ltd (“Totely”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects personal information in connection with the Retail Ordering platform operated through the Trelliso dashboard at www.retailordering.com, including the WhatsApp Ordering Channel.
Totely India Pvt Ltd is a company incorporated under the Companies Act 2013, with its registered office at Desk 115, Level 3, NSL Centrum, Kukatpally, Hyderabad – 500072, Telangana, India.
This Policy is governed by and complies with the following applicable Indian laws:
• Information Technology Act 2000 and the IT (Amendment) Act 2008;
• Digital Personal Data Protection Act 2023 (“DPDP Act”);
• Consumer Protection Act 2019; and
• Any sector-specific regulations applicable to the processing of personal data.

2. Information We Collect

2.1 Information Provided by Retailers
[For Retailers] When Retailers register and use the platform, we collect:
• Full name and designation of the account holder;
• Business name, registered business address, and business type;
• GSTIN and PAN of the business;
• Email address and mobile phone number;
• Bank account details (for COD remittance and subscription billing); and
• WhatsApp business phone number (for registration on the WhatsApp Ordering Channel, where subscribed).
Totely does NOT collect or store credit card numbers, card expiry dates, or CVV codes. All payment instrument data is handled exclusively by PCI-DSS compliant payment gateways (currently Razorpay).

2.2 Information Collected Automatically
[For Retailers] When Retailers access the Trelliso dashboard, we automatically collect:
• IP address and approximate geographic location;
• Browser type, version, and device information;
• Pages visited, features used, and session duration; and
• Error logs and performance data to maintain and improve the platform.

2.3 Information Collected Through WhatsApp Ordering
[For End Customers] See Section 3 below for a full disclosure of data collected through the WhatsApp Ordering Channel from the Retailers’ end customers.

3. Data Collected Through the WhatsApp Ordering Channel
[For End Customers] When an end customer places an order or communicates with a Retailer through the WhatsApp Ordering Channel powered by Totely, the following data is collected and processed by Totely as Data Processor on behalf of the Retailer:

3.1 What Data is Collected
Data Type Details How It Arises
WhatsApp Phone Number The customer’s registered WhatsApp mobile number Collected when the customer first messages the Retailer’s WhatsApp business number
Message Content Text messages in the ordering conversation, including product selections, quantities, and special instructions Transmitted via the WhatsApp Cloud API when the customer sends messages
Order Details Items ordered, quantities, total value, preferred payment method, and delivery address Generated from the conversation and structured into an order record on the backend
Delivery Address Full delivery address as provided by the customer Shared by the customer voluntarily as part of the ordering process
Message Metadata Timestamps, delivery status (sent/delivered/read), and message IDs Provided by the WhatsApp Business Platform as part of API response data
Customer Name Name as shared by the customer during the conversation Shared by customer or retrieved from WhatsApp profile information
Location Data Approximate location if shared by the customer via WhatsApp Only if voluntarily shared by the customer

3.2 What We Do NOT Collect via WhatsApp
• End-to-end encrypted content of messages not processed through the WhatsApp Business API;
• Payment instrument details (card numbers, UPI PINs) — all payments are processed through the integrated payment gateway; and
• Biometric data or government identification documents unless explicitly provided by the customer for a specific regulated transaction.

3.3 The Retailer’s Responsibility for This Data
The Retailer whose WhatsApp number was contacted is the Data Fiduciary for all end-customer data described above. Totely processes this data solely on the Retailer’s behalf and under the Retailer’s instruction. End customers should also review the privacy policy published by the Retailer whose WhatsApp channel they are using.

4. How We Use Your Information
4.1 Retailer Data
[For Retailers] We use information collected from Retailers for the following purposes:
• Account creation, authentication, and management;
• Providing and improving the platform’s features and performance;
• Processing subscription payments and billing;
• KYC verification and fraud detection;
• Sending platform updates, service notifications, and support communications;
• Legal compliance, tax reporting, and maintenance of audit trails; and
• Registering the Retailer’s phone number on the WhatsApp Business Platform (where subscribed).

4.2 End-Customer Data (Collected via WhatsApp)
[For End Customers] We use end-customer data collected through the WhatsApp Ordering Channel for the following purposes only:
• Processing and fulfilling the order placed by the customer;
• Sending order confirmation, payment status, dispatch notifications, and delivery updates;
• Facilitating customer service responses by the Retailer;
• Sharing delivery-relevant data with the logistics provider to fulfil the delivery; and
• Maintaining order records for the Retailer’s business records and for dispute resolution.
Totely does not use end-customer WhatsApp data for its own marketing, advertising, cross-platform tracking, or profiling purposes.

5. Data Sharing with Retailers and Third Parties
5.1 Sharing with Retailers
End-customer order data (including name, phone number, order details, and delivery address) is made available to the Retailer associated with the WhatsApp number through which the order was placed. This is the primary intended purpose of the WhatsApp Ordering Channel.

5.2 Sharing with Delivery Partners
Where the Retailer has enabled delivery integration, the following end-customer data is shared with the selected third-party logistics provider (such as Shadowfax, Shiprocket, Porter, Delhivery, Pidge, or such other providers as made available):
• Customer’s full name;
• Delivery address (including PIN code);
• Customer’s contact phone number; and
• Order details necessary for the shipment (product description, weight category, COD amount if applicable).
Totely shares only the minimum data necessary for delivery. The logistics provider’s own privacy policy governs their use, retention, and security of this data.

5.3 Meta / WhatsApp as Platform Provider
The WhatsApp Ordering Channel operates via Meta’s WhatsApp Business Cloud API. When a customer messages the Retailer’s WhatsApp business number, the message is transmitted through Meta’s infrastructure. Meta independently processes message metadata as part of operating the WhatsApp Business Platform. Meta’s processing is governed by Meta’s Privacy Policy and their Data Processing Terms, which are separate from this Policy.

5.4 Other Third-Party Processors
Totely may use trusted sub-processors to assist in operating the platform (such as cloud hosting providers, data analytics tools, and customer support systems). All sub-processors are bound by data processing agreements requiring them to maintain appropriate security and confidentiality. A current list of sub-processors is available upon written request to legal@retailordering.com.

5.5 Legal Disclosures
Totely may disclose personal data without prior consent where required by:
• A lawful order, summons, or direction from a court of competent jurisdiction;
• A direction from a law enforcement or regulatory authority under applicable Indian law;
• The Data Protection Board of India under the DPDP Act 2023; or
• A requirement to protect the legal rights or safety of Totely, its Retailers, or any third party.
Totely will endeavour to notify the affected Retailer of any such disclosure request, where legally permissible, before complying.

5.6 No Sale of Data
Totely does not sell, rent, trade, or share personal data of Retailers or end customers with any third party for advertising, marketing, or commercial purposes not described in this Policy.

6. Data Storage and Backend Processing

6.1 Where Data is Stored
Personal data collected and processed by Totely is stored on cloud infrastructure hosted within India. All data at rest is encrypted using AES-256 encryption. All data in transit is protected using TLS 1.2 or higher.

6.2 How WhatsApp Data is Processed
When an end customer sends a message to a Retailer’s WhatsApp business number, the following process occurs:
1. The message is transmitted from the customer’s WhatsApp app to Meta’s WhatsApp Business Cloud API servers;
2. Meta’s API delivers the message content and metadata to Totely’s secure backend via an encrypted HTTPS webhook;
3. Totely’s backend parses the message content, identifies it as an ordering interaction, and structures it into an order record;
4. The structured order data is stored in Totely’s encrypted database and made available to the relevant Retailer on their Trelliso dashboard; and
5. Order confirmation and update messages are sent back to the customer via Meta’s WhatsApp Cloud API using pre-approved message templates.

6.3 Access Controls
Access to personal data within Totely’s systems is restricted on a need-to-know basis:
• Retailer data is accessible only to the Retailer’s own authorised dashboard users and to Totely’s authorised operations and support staff;
• End-customer order data is accessible to the associated Retailer and to Totely’s authorised staff for support and dispute resolution purposes only;
• No Totely staff member accesses personal data for purposes outside those described in this Policy; and
• All internal access to personal data is logged and subject to periodic audit.

6.4 Automated Processing
Totely uses automated systems to parse WhatsApp messages and identify order intents, product mentions, and delivery details. This automated processing is used solely to structure the ordering conversation into an order record. No automated profiling or decision-making with legal or significant effect on end customers is conducted by Totely using WhatsApp data.

7. Data Security and Protection
Totely implements the following technical and organisational security measures to protect personal data:
• Encryption: AES-256 encryption for all data at rest; TLS 1.2+ for all data in transit;
• Access Authentication: Two-factor authentication (2FA) and OTP-based verification for platform access;
• Access Control: Role-based access permissions limiting data access to authorised personnel only;
• Payment Security: Payment processing exclusively through PCI-DSS compliant third-party gateways; Totely does not store any payment card data;
• Security Audits: Regular internal security reviews and periodic third-party penetration testing; and
• Incident Response: A documented data breach response procedure.

7.1 Breach Notification
In the event of a confirmed personal data breach that is likely to result in harm to individuals, Totely will:
• Notify affected Retailers within 72 hours of becoming aware of the breach;
• Provide details of the nature of the breach, categories of data affected, and steps being taken to address it; and
• Report the breach to the Data Protection Board of India and other applicable authorities as required under the DPDP Act 2023.
Retailers must notify Totely immediately at legal@retailordering.com upon becoming aware of any suspected breach involving their account or their end customers’ data.

8. Data Retention
Totely retains personal data for the periods specified below, after which data is deleted or anonymised:

Data Category Retention Period Reason
Retailer account information Duration of active account + 3 years after closure Legal compliance, dispute resolution
Transaction and order records 7 years from the date of transaction GST compliance, Income Tax Act, audit
Support and grievance records 3 years from the date of the interaction Dispute resolution and legal protection
WhatsApp conversation message content 12 months from the date of conversation, then deleted Operational support and dispute resolution
End-customer order data (from WhatsApp) 7 years (as part of transaction records) GST, legal, and audit requirements
End-customer phone numbers Active Retailer account duration + 90 days after closure Order fulfilment; deleted upon account closure
Delivery partner data shared Subject to logistics provider’s own retention policy Totely does not control data after transmission
Platform usage logs (IP, browser, session) 12 months Security, fraud prevention, platform improvement

Where a legal proceeding, regulatory investigation, or dispute resolution process is active, relevant data may be retained beyond the standard periods specified above until the matter is resolved.

9. Cross-Border Data Processing

9.1 Meta / WhatsApp Infrastructure
The WhatsApp Business Cloud API is operated by Meta Platforms Inc., a company incorporated in the United States. When end customers exchange messages with a Retailer’s WhatsApp business number, those messages are transmitted through and temporarily processed on Meta’s global infrastructure, which includes servers located outside India.
This cross-border transmission is an inherent feature of the WhatsApp Business Platform. Totely has accepted Meta’s Data Processing Terms, which include appropriate safeguards (including Standard Contractual Clauses where applicable) for the transfer of personal data outside India. The end-customer’s WhatsApp message content is transmitted to Totely’s India-based backend as soon as it is delivered via the API webhook.

9.2 Totely’s Own Infrastructure
Totely’s primary data storage and processing infrastructure is located in India. Totely does not independently transfer personal data of Retailers or end customers outside India except as described above (Meta’s WhatsApp infrastructure) or where required by a specific service feature enabled by the Retailer and disclosed at the time of enabling.

9.3 DPDP Act Cross-Border Compliance
Any cross-border transfer of personal data by Totely is conducted in compliance with the provisions of the Digital Personal Data Protection Act 2023 and any rules or frameworks notified thereunder by the Government of India. Totely will update this Policy if the regulatory position on cross-border transfers changes materially.

10. Your Rights and Choices – Retailers
[For Retailers] As a Retailer (Data Principal under the DPDP Act with respect to your own personal data held by Totely), you have the following rights:
• Right to Access: Request a summary of personal data Totely holds about you. Requests are processed within 30 days. Submit requests to legal@retailordering.com.
• Right to Correction: Request correction of inaccurate or incomplete personal data. Corrections are made within 15 business days of verification.
• Right to Erasure: Request deletion of your personal data, subject to legal retention requirements. Certain data (e.g., transaction records) must be retained by law and cannot be deleted on request.
• Right to Withdraw Consent: Where processing is based on your consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
• Right to Grievance: Lodge a complaint with Totely’s Grievance Officer (see Section 16). You also have the right to escalate unresolved complaints to the Data Protection Board of India.
• Right to Nominate: Nominate an individual to exercise your rights on your behalf in the event of your death or incapacity, as provided under the DPDP Act.
To exercise any of these rights, write to legal@retailordering.com with your registered email address and a description of your request. Totely will verify your identity before processing any data request.

11. End Customer Rights

11.1 How End Customers Can Exercise Their Rights
[For End Customers] End customers have the following rights under the DPDP Act 2023 with respect to their personal data processed through the WhatsApp Ordering Channel:
• Right to Information: Know what personal data is being collected, how it is used, and with whom it is shared;
• Right to Correction: Request correction of inaccurate data;
• Right to Erasure: Request deletion of personal data, subject to the Retailer’s and Totely’s legal retention obligations;
• Right to Withdraw Consent: Withdraw consent for marketing messages at any time; and
• Right to Grievance: Lodge a complaint about how your data has been handled.

11.2 How to Contact Us
End customers may:
• Contact the Retailer whose WhatsApp number they interacted with, as the Retailer is the Data Fiduciary;
• Contact Totely at legal@retailordering.com for requests relating to data that Totely holds as Processor; Totely will acknowledge within 3 business days and coordinate with the relevant Retailer; or
• Escalate unresolved complaints to the Data Protection Board of India at meity.gov.in.

11.3 Opt-Out from WhatsApp Marketing
End customers can opt out of receiving marketing messages from a Retailer on WhatsApp by:
• Replying “STOP”, “UNSUBSCRIBE”, or a similar opt-out signal to any marketing message received on WhatsApp;
• Blocking the Retailer’s WhatsApp business number; or
• Contacting the Retailer directly to request removal from their messaging list.
Retailers are contractually obligated under their agreement with Totely to honour opt-out requests within 24 hours. If you continue to receive messages after opting out, please report this to grievances@retailordering.com.

12. Consent Management and Opt-Out

12.1 Retailer’s Consent Obligations
Totely relies on Retailers, as Data Fiduciaries, to have obtained valid and appropriate consent from their end customers before those customers are contacted via the WhatsApp Ordering Channel. Totely does not independently verify the existence or validity of end-customer consent obtained by the Retailer.

12.2 Platform-Level Consent Signals
The Retail Ordering platform records the following consent-related signals at the platform level:
• Customer opt-in events (where the ordering flow includes an opt-in mechanism);
• Customer opt-out events (replies such as “STOP” received on the Retailer’s WhatsApp number);
• Message delivery, read, and block status as reported by the WhatsApp Business API; and
• Complaints or blocks received from WhatsApp users (which affect the Retailer’s quality rating).
These signals are made available to the Retailer on their Trelliso dashboard and may be shared with Totely’s compliance team for quality monitoring purposes.

12.3 Complaint Handling
If Totely receives a complaint from an end customer or a regulatory body that a customer received WhatsApp messages without valid consent, Totely reserves the right to temporarily restrict the Retailer’s WhatsApp messaging capability pending investigation, and to take action as described in the Terms and Conditions, including account suspension for confirmed breaches.

13. Data Deletion on Account Closure

13.1 Retailer Data on Account Closure
[For Retailers] When a Retailer’s account is closed, the following data deletion process applies:
• Active account data (dashboard credentials, phone registrations, active configurations): Deleted within 30 days of account closure confirmation;
• End-customer personal data (phone numbers, addresses, WhatsApp conversation content): Deleted or anonymised within 90 days of account closure; and
• Transaction records and order data: Retained for 7 years from the date of each transaction as required by applicable Indian tax and financial laws, then deleted.

13.2 Data Export Before Closure
Retailers may request an export of their business data (order history, customer contact list, product catalogue) before account closure. Such requests must be submitted to legal@retailordering.com at least 15 days before the requested account closure date. Totely will provide the export in a commonly used machine-readable format (CSV or JSON) within 15 business days of the request.

13.3 WhatsApp Number After Account Closure
If the Retailer’s WhatsApp number was registered under Totely’s WABA, the number is deregistered from Totely’s WABA within 15 days of account closure. The Retailer may request number migration to another provider or their own WABA in accordance with Section 13 of the Terms and Conditions.

14. Cookies and Tracking Technologies
[For Retailers] The Trelliso dashboard (retailordering.com) uses cookies and similar tracking technologies to:
• Maintain your login session and authentication state;
• Remember your preferences and dashboard settings;
• Analyse usage patterns to improve the platform; and
• Detect and prevent fraudulent or unauthorised access.
You can manage cookie preferences through your browser settings. Disabling essential cookies may impair the functionality of the dashboard. Totely does not use third-party advertising cookies or tracking pixels for behavioural advertising purposes on the platform.

15. Governing Law and Dispute Resolution
This Privacy Policy is governed by the laws of India. Any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts in Hyderabad, Telangana.
The three-step dispute resolution process outlined in the Terms and Conditions applies equally to disputes concerning this Privacy Policy. Data-related complaints may additionally be escalated to the Data Protection Board of India under the DPDP Act 2023.

16. Grievance Officer and Contact Information
In accordance with the Information Technology Act 2000, the IT (Intermediary Guidelines) Rules 2021, and the Digital Personal Data Protection Act 2023, Totely has appointed a Grievance Officer for privacy-related complaints:
Grievance Officer: Amit Pande
Organisation: Totely India Pvt Ltd
Address: Desk 115, Level 3, NSL Centrum, Kukatpally, Hyderabad – 500072, Telangana, India
Email: grievances@retailordering.com
Legal & Data Queries: legal@retailordering.com/ap@totely.net
Response Time: Acknowledgment within 3 business days; full investigation within 30 business days (60 for complex matters).
Escalation: Data Protection Board of India — meity.gov.in

17. Policy Modifications
Totely reserves the right to update this Privacy Policy at any time to reflect changes in our practices, services, legal requirements, or regulatory guidance. Material changes will be communicated to Retailers via:
• Email notification to the registered email address on the Retailer’s account; and
• A prominent notice on the Trelliso dashboard for a minimum of 30 days.
The “Last Updated” date at the top of this Policy indicates when the most recent revision was made. We encourage Retailers and end customers to review this Policy periodically. Continued use of the platform after the effective date of a revised Policy constitutes acceptance of the updated terms.
For changes mandated by Meta’s WhatsApp Business Platform policies, Totely may need to update this Policy on a shorter timeline. In such cases, Totely will provide as much advance notice as is reasonably practicable.

USA | INDIA | UAE