Bharat Grocery Store

Indische Spezialitäten · Privacy Policy

Privacy Policy — Bharat Grocery Store Mobile App

Last updated: 24 May 2026 · Effective from: 24 May 2026

This policy applies to the mobile app only. If we collect data via a website or in-store, separate notices apply at those points of collection.

1. Who we are (Data Controller)

The data controller responsible for processing your personal data through the Bharat Grocery Store mobile application ("the App") is:

Tadastithi GmbH
Münchbergerstr. 31
81549 München
Germany

Telephone: +49 89 23885888
Email: tadastithi@bharatonline.de
Authorized representative (Geschäftsführer): Ankur Gupta
Trade register: HRB 254117, Amtsgericht München
VAT ID (USt-IdNr.): DE328162511

Data Protection Officer (DPO)

We are not required to appoint a Data Protection Officer under § 38 BDSG. For all data-protection questions, contact us at tadastithi@bharatonline.de.

2. What data we collect and why

We process the following categories of personal data through the App:

2.1 Data we receive when you log in

DataSourcePurposeLegal basis
Mobile phone numberYou enter it; we verify it against our existing customer databaseAuthenticate you as an existing customerArt. 6(1)(b) GDPR — performance of contract
First and last nameAlready in our customer database from when you registered in-storePersonalize the App (greeting, profile screen)Art. 6(1)(b) GDPR — performance of contract
Customer barcodeAlready in our customer databaseDisplay in the App so you can show it at the counterArt. 6(1)(b) GDPR — performance of contract
Your chosen 4-digit PIN (stored as a one-way hash; never as plain text)You set it on first loginAuthenticate you on subsequent app launchesArt. 6(1)(b) GDPR — performance of contract
One-Time Password (OTP) you receive by SMS (stored as a one-way hash, deleted after 5 minutes)We generate it; Twilio delivers itVerify your phone numberArt. 6(1)(b) GDPR — performance of contract
Refresh tokens and device identifiersGenerated by the App on your deviceKeep you logged in across sessions; limit the number of simultaneous devicesArt. 6(1)(b) GDPR — performance of contract
Failed login attempts, account-lock timestampsApp / server records them automaticallyProtect your account from brute-force attacksArt. 6(1)(f) GDPR — legitimate interest in account security

2.2 Data we collect when you use the App

DataPurposeLegal basis
Technical error reports (crash logs, error messages — without personal content)Diagnose and fix App problemsArt. 6(1)(f) GDPR — legitimate interest
Last login timestampDisplay "last login" information; identify dormant accountsArt. 6(1)(f) GDPR — legitimate interest

2.3 Push notification data (future feature — not active in current version)

If and when we activate push notifications, we will additionally process a device push token (Apple Push Notification Service / Firebase Cloud Messaging) only with your explicit consent at the time you enable notifications. You can revoke consent at any time in your device settings or in the App's Profile screen.

2.4 Data we do NOT collect through the App

3. Who we share data with (Recipients / Processors)

We use the following service providers ("processors" under Art. 28 GDPR). A Data Processing Agreement (Auftragsverarbeitungsvertrag / DPA) is in force with each — either signed directly or automatically incorporated through the provider's standard Terms of Service.

ProcessorServiceData sharedLocation
Twilio Inc.SMS delivery (OTP)Your phone number, OTP message textAccount region: United States. Message metadata stored in the US. Covered by Standard Contractual Clauses + EU-US Data Privacy Framework.
Server hosting provider (to be selected before public launch)Server hostingAll app data (encrypted at rest)EU (Germany)
Cloudflare Germany GmbHImage storage (banners, product images) and static web hosting (this page)No personal dataEU
Apple Inc.App distribution via App StoreYour Apple ID — only Apple sees this; we do not receive itUS (with EU-US Data Privacy Framework certification)
Google Ireland LimitedApp distribution via Play Store; push notifications (future)Your Google Play account — only Google sees this; we do not receive itEU + US (with EU-US Data Privacy Framework certification)

We do not share your data with any other third party, with advertisers, or with analytics providers.

4. International data transfers

Most processing occurs within the European Union. Some incidental transfers may occur to the United States (e.g. Apple, Google, Twilio). These transfers are covered by:

You can request a copy of the relevant safeguards by contacting us at tadastithi@bharatonline.de.

5. How long we keep your data (Retention)

DataRetention
Phone number, name, barcodeAs long as you remain a customer of Tadastithi GmbH (these are part of our shop customer database, not specific to the App)
PIN hash, refresh tokens, device IDsWhile your app account is active; deleted when you log out, delete your account, or 12 months after last login
OTP hashes5 minutes
Failed login records30 days
Crash logs / error logs90 days
Audit logs of administrative access to your data12 months (Art. 32 GDPR — security)

When you delete your app account (see Section 7), we immediately remove your app login, PIN, and any active sessions. There is no grace period — deletion is final. Your underlying customer record at the shop is retained for tax, accounting, and legitimate-business-interest reasons (typically 10 years under § 257 HGB / § 147 AO if you have purchase history).

6. Your rights under GDPR

You have the following rights regarding your personal data. To exercise any of them, contact us at tadastithi@bharatonline.de. We will respond within one month (Art. 12(3) GDPR).

RightWhat it meansHow to exercise
Access (Art. 15)Receive a copy of all your data we holdUse the "Export My Data" button in Profile, or email us
Rectification (Art. 16)Correct inaccurate dataEmail us or ask in-store
Erasure (Art. 17)Have your app account deletedUse "Delete Account" in Profile, or email us to request deletion
Restriction (Art. 18)Restrict processing in certain casesEmail us
Portability (Art. 20)Receive your data in a machine-readable formatUse the "Export My Data" button (returns JSON)
Object (Art. 21)Object to processing based on legitimate interestEmail us
Withdraw consent (Art. 7(3))Where processing relies on consent (e.g. push notifications)Disable in the App's Profile screen

You may also lodge a complaint with the supervisory authority:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
https://www.lda.bayern.de/

7. Account deletion

You can delete your app account at any time:

  1. In the App: Profile → Delete Account → confirm.
  2. Outside the App: Email us at tadastithi@bharatonline.de from the address tied to your account, with the subject line "Delete my app account" and your registered mobile number. We will confirm and complete the deletion within 30 days.

What happens when you delete your account:

8. Security

We protect your data using:

In the unlikely event of a data breach affecting your data, we will notify you and the supervisory authority as required by Art. 33-34 GDPR.

9. Children

The App is not intended for children under 16. We do not knowingly collect data from anyone under 16. If you believe we have, contact us at tadastithi@bharatonline.de and we will delete the data.

10. Automated decision-making

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.

11. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top reflects the latest revision. Material changes will be notified in the App and via a notice on https://www.bharatonline.de at least 30 days before they take effect.

12. Contact

Questions about this policy or your data:

Tadastithi GmbH
Email: tadastithi@bharatonline.de
Postal: Münchbergerstr. 31, 81549 München, Germany