Privacy Policy

Last updated: 1 May 2025

TruClario is a B2B vendor review platform operated in India. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our platform. It also explains your rights under India's Digital Personal Data Protection Act 2023 (DPDP Act).

By using TruClario you agree to the collection and use of your data as described in this policy. If you do not agree, please do not use the platform.

1. What We Collect

1.1 Account Information

When you create an account or submit a review we collect your email address. We store a hashed version of your email for identity verification and deduplication. We store an encrypted version separately only for the purpose of sending you one-time passwords and important account notifications.

1.2 Review Content

We collect the content of reviews you submit including your overall rating, written experience, tags, vendor type, city, and engagement duration. This content is published publicly on the platform.

1.3 Verification Documents

If you choose to upload a verification document to achieve Verified Vendor status we collect and store the document temporarily. All verification documents are permanently deleted after 30 days regardless of the outcome of the verification review.

1.4 Technical Data

We collect a hashed version of your IP address at the time of review submission for fraud prevention purposes. We do not store raw IP addresses. We collect standard server logs including request timestamps, endpoints accessed, and response codes. These logs do not contain personal data beyond hashed identifiers.

2. How We Use Your Data

We use your data only for the following purposes:

To verify your identity via one-time password before publishing a review
To prevent duplicate reviews from the same vendor for the same company
To send you notifications about your reviews such as moderation decisions and appeal outcomes
To verify your vendor credentials if you choose to upload a document
To detect and prevent automated or fraudulent review submissions
To comply with legal obligations including court orders and government requests

We do not use your data for advertising, marketing, or any purpose not listed above. We do not sell your data to any third party.

3. How We Protect Your Data

All data is stored on servers located in India or in countries approved under the DPDP Act 2023. We use the following technical measures to protect your data:

All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher
Your email address is hashed using SHA-256 before storage and separately encrypted using AES-256 for delivery purposes
Your IP address is hashed before storage and cannot be reversed to identify you
All databases are encrypted at rest using AES-256
Access to systems that can link a review to its author is restricted to authorised personnel only and requires two factor authentication
Verification documents are stored in encrypted storage and permanently deleted after 30 days

4. How We Protect Your Anonymity

Anonymity is a core architectural feature of TruClario, not just a setting. Your review is stored separately from your identity at the database level. The connection between your email and your review is stored in a restricted table that is never exposed via any public API.

What is shown publicly on your review:

Your vendor type (e.g. Recruitment Agency, Freelance Developer)
Your city
Your engagement duration
The month and year of submission (never the exact date)
Whether you are a current or former vendor

Your name, email address, and company name are never shown publicly under any circumstances.

5. How Long We Keep Your Data

Account data (hashed email)
Until you delete your account or request deletion
Review content
Indefinitely in anonymous form. Not deleted when you delete your account.
Verification documents
30 days from upload then permanently deleted
Application logs
90 days then permanently deleted
Audit logs
3 years as required by the IT Rules 2021
Security logs
3 years for legal compliance

6. Your Rights Under the DPDP Act 2023

As a user of TruClario you have the following rights under India's Digital Personal Data Protection Act 2023:

Right to Access

You have the right to know what personal data we hold about you. Contact us at support@truclario.com to request a summary of your data.

Right to Correction

You have the right to correct inaccurate personal data we hold about you. Contact us at support@truclario.com with your correction request.

Right to Erasure

You have the right to delete your account and personal data. You can do this directly from your account settings page. Your account will be permanently deleted within 48 hours of your request. Reviews submitted under your account remain on the platform in anonymous form as they are no longer linked to your identity after deletion.

Right to Grievance Redressal

You have the right to raise a grievance about how we handle your data. Contact our Grievance Officer at grievance@truclario.com. We will respond within 72 hours and resolve your grievance within 15 days.

7. When We May Disclose Your Data

We do not share your personal data with any third party except in the following circumstances:

When required by a valid court order issued by an Indian court
When required by a government authority under applicable Indian law
When necessary to prevent fraud or protect the security of the platform

In all cases we will notify you of any disclosure request to the extent permitted by law before complying.

8. Cookies and Tracking

TruClario uses only essential cookies required for the platform to function. We do not use advertising cookies, tracking cookies, or any third party analytics that collect personal data. We do not display advertisements.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes by email before they take effect. Continued use of the platform after changes take effect constitutes acceptance of the updated policy.

10. Contact Us

For any questions about this Privacy Policy or to exercise your rights contact our Grievance Officer:

Grievance Officer: To be appointed

Email: grievance@truclario.com

Response time: Within 72 hours