Legal
Privacy Policy
Effective date: 21 April 2026 · Truffaire Private Limited
Truffaire Private Limited ("Truffaire", "we", "our", or "us") operates the ARCORAagricultural intelligence platform ("Service"), accessible at arcora.truffaire.in. This Privacy Policy explains what personal data we collect, how we use and protect it, and your rights under applicable Indian law — including the Information Technology Act, 2000, the IT (Reasonable Security Practices) Rules, 2011, and the Digital Personal Data Protection Act, 2023 ("DPDP Act"). By using the Service, you consent to the practices described below.
1. Who We Are
Truffaire Private Limited is an Indian private limited company incorporated under the Companies Act, 2013, with its principal place of business in Bengaluru, Karnataka, India. Truffaire Private Limited is the Data Fiduciary as defined under the DPDP Act, 2023 for all personal data processed through the ARCORAplatform.
For all privacy-related enquiries or to exercise your rights, contact us at: one@truffaire.in
2. Data We Collect
2.1 Account and Identity Data
When you register, we collect your name, email address, and authentication credentials via our identity provider (Clerk, Inc.). We do not store passwords directly — Clerk manages credential security on our behalf.
2.2 Agricultural and Diagnostic Data
- Crop images you upload for diagnosis (stored in Convex cloud file storage)
- Plant part selections, crop type, growth stage, and symptom description
- Farm location (district/state level — you provide this voluntarily)
- Soil type, irrigation method, and recent farm activity inputs
- AI-generated diagnosis reports and treatment recommendations
2.3 Payment Data
Payments are processed by Razorpay Software Private Limited. We do not store your card number, UPI handle, or bank credentials. We retain payment metadata including order ID, plan purchased, amount, billing cycle, and transaction status for billing and support purposes.
2.4 Usage and Technical Data
- Pages visited, features used, and time spent on the platform
- Browser type, operating system, device type, and IP address
- Error logs and diagnostic data to maintain service quality
- Session tokens issued by Clerk for authentication
2.5 Communications
If you contact us by email, we retain the content of your message and your contact details to respond and for record-keeping.
3. How We Use Your Data
We process your personal data for the following purposes:
- Providing the ARCORA diagnostic service — running AI-assisted crop analysis on your uploaded images
- Account creation, authentication, and session management
- Processing payments, allocating credits, and managing your subscription plan
- Generating, storing, and displaying diagnosis reports in your dashboard and history
- Improving the accuracy and reliability of our diagnostic engine using anonymised and aggregated data
- Sending transactional communications (payment confirmation, service alerts) — not marketing without consent
- Complying with applicable laws, resolving disputes, and enforcing our Terms of Service
- Preventing fraud, unauthorised access, and abuse of the platform
We do not use your crop images or personal data to train third-party AI models without your explicit consent. Diagnostic queries are processed by OpenAI via their API under a data processing agreement that prohibits use of API inputs for model training.
4. Legal Basis for Processing
Under the DPDP Act, 2023, we process your personal data on the following grounds:
- Consent — you provide consent at account registration and by submitting data for diagnosis
- Contractual necessity — processing required to deliver the Service you have purchased
- Legitimate interests — fraud prevention, service security, and platform analytics (balanced against your rights)
- Legal obligation — compliance with applicable Indian statutes and regulatory requirements
5. Third-Party Service Providers
We share data with third-party processors only to the extent necessary to operate the Service. All processors are bound by data processing agreements:
| Provider | Purpose | Data Shared |
|---|---|---|
| Clerk, Inc. | Authentication and identity | Name, email, session tokens |
| Convex, Inc. | Database and file storage | All platform data including images and reports |
| OpenAI, L.L.C. | AI-powered crop diagnosis | Crop images and agronomic context inputs |
| Razorpay Software Pvt. Ltd. | Payment processing | Order details, transaction identifiers |
| Vercel, Inc. | Web hosting and deployment | IP address, request logs |
We do not sell, rent, or trade your personal data to any third party for commercial or marketing purposes. We may disclose data to law enforcement or regulatory authorities when required by valid legal process under Indian law.
6. Data Retention
- Account data — retained for the duration of your account and for 3 years after deletion for legal compliance
- Diagnosis reports and crop images — retained for the duration of your plan's history window (30 days for Scout; full history for Cooperative and Alliance) and deleted upon account deletion
- Payment records — retained for 8 years as required under Indian accounting and tax laws
- Usage logs — retained for 90 days for security and debugging, then deleted
- Communications — retained for 2 years from last contact
You may request deletion of your account and associated personal data at any time by emailing one@truffaire.in. Certain data may be retained longer where required by law or for legitimate dispute resolution purposes.
7. Data Security
We implement industry-standard technical and organisational measures to protect your personal data, including:
- TLS/HTTPS encryption for all data in transit
- Encryption at rest for database records and stored files via Convex's infrastructure
- Role-based access controls limiting internal access to personal data
- JWT-based authentication with short-lived tokens issued by Clerk
- Payment data handled exclusively by PCI-DSS compliant Razorpay — we never touch card data
No method of transmission or storage is 100% secure. While we take all reasonable precautions, we cannot guarantee absolute security. In the event of a data breach that poses risk to your rights, we will notify affected users and the relevant authority in accordance with applicable law.
8. Your Rights
Under the DPDP Act, 2023 and applicable Indian law, you have the following rights with respect to your personal data:
- Right to access — request a copy of the personal data we hold about you
- Right to correction — request correction of inaccurate or incomplete data
- Right to erasure — request deletion of your personal data, subject to legal retention obligations
- Right to withdraw consent — withdraw consent at any time without affecting prior processing
- Right to grievance redressal — lodge a complaint with our grievance officer or the Data Protection Board of India
To exercise any of these rights, email us at one@truffaire.in with the subject line "Data Rights Request". We will respond within 30 days. If you are not satisfied with our response, you may escalate to the Data Protection Board of India once it is operationally constituted.
9. Children's Privacy
The Service is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us immediately and we will delete such data promptly.
11. International Data Transfers
Our service providers (Clerk, Convex, OpenAI, Vercel) may process data in jurisdictions outside India, including the United States. We rely on contractual protections (data processing agreements incorporating standard contractual clauses) to ensure your data receives a level of protection consistent with Indian data protection standards. By using the Service, you acknowledge and consent to these transfers.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify registered users by email. Your continued use of the Service after changes are posted constitutes acceptance of the revised policy.
13. Grievance Officer and Contact
In accordance with the Information Technology Act, 2000 and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the following person is designated as the Grievance Officer for the Service:
Grievance Officer — Truffaire Private Limited
Email: one@truffaire.in
Address: Bengaluru, Karnataka, India
Response time: Within 30 days of receipt
Also read our Terms of Service. For any questions, email one@truffaire.in.