Kitchen, hospitality & home essentials
Enter your pincode to see products available near you from verified neighborhood sellers.
No products in the cart.
Policy: Privacy Policy
Supersedes: the previous Privacy Notice
Version: 2.0 | Effective: 7 August 2026
This Privacy Policy explains what personal data Horekaa Technocon Private Limited (“Horeka”, “we”, “us”) collects when you use horeka.co, why we collect it, who we share it with, and the rights you have over it.
It is written to comply with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000 and the SPDI Rules, 2011, and the Consumer Protection (E-Commerce) Rules, 2020.
Horeka is the Data Fiduciary for the personal data described here — we decide why and how it is processed.
| Entity | Horekaa Technocon Private Limited |
| CIN | U22202DL2025PTC446187 |
| Registered office | D-2/11, Model Town 3, Opposite D Park Main Gate, New Delhi — 110009, India |
| Data protection contact | [email protected] |
| Grievance Officer | Mr. Chirag Arora — [email protected] |
| Category | Includes | When |
|---|---|---|
| Account | Name, mobile number, email, password | Registration |
| Delivery | Delivery address, pin code, landmark, alternate contact, delivery instructions | Checkout, saved addresses |
| Order | Items ordered, value, date, seller, delivery status | Each purchase |
| Payment | Payment method chosen, transaction reference, last four digits of a card, UPI handle | Checkout |
| Tax | GSTIN, where you buy as a business | B2B checkout, Horeka Bulk |
| Communications | Messages, emails, WhatsApp messages, call recordings, photographs you send us | When you contact support |
| Content | Reviews, ratings, questions, photographs you post | When you post |
| Seller data | KYC documents — see Verification Policy | Seller onboarding |
This corrects our previous notice, which stated we collect no data from third parties. We do, as follows:
We do not seek sensitive personal data. However, note that financial information and passwords are classified as sensitive personal data under the SPDI Rules, 2011. We handle these with corresponding safeguards: passwords are stored only as salted hashes, and full payment credentials are never stored by us at all.
Our services are not directed at children under 18, and we do not knowingly collect their data. As required by Section 9 of the DPDP Act, we do not carry out behavioural tracking or targeted advertising directed at children. If you believe a child has given us data, contact [email protected] and we will delete it.
Under the DPDP Act we process personal data either with your consent or for certain legitimate uses permitted by Section 7.
| Purpose | Data used | Basis |
|---|---|---|
| Create and manage your account | Account | Consent — you voluntarily provide it for this purpose |
| Process and deliver orders | Account, delivery, order, payment | Consent / performance of the service you requested |
| Share with the seller for fulfilment | Name, address, phone, order | Consent — necessary for the purpose you gave it |
| Payment processing and refunds | Payment, order | Consent; legal obligation |
| Customer support and grievance redressal | Communications, order | Consent; legal obligation under CP Rules |
| Tax invoicing and statutory records | Order, tax, payment | Legal obligation — CGST Act, Income-tax Act, Companies Act |
| Fraud prevention and platform security | Device, usage, order, payment | Legitimate use — Section 7(g), DPDP Act |
| Improving the service and fixing faults | Usage, device | Consent, withdrawable via cookie settings |
| Personalised recommendations | Usage, order history | Consent, withdrawable |
| Marketing communications | Account, order history | Consent, withdrawable at any time |
| Responding to legal process | As required | Legal obligation — Section 7(c) |
Withdrawing consent is as easy as giving it. Use the settings in your account, the unsubscribe link in any marketing message, or email [email protected]. Withdrawal does not affect processing already carried out, and we may still need to process data to complete an order in progress or to meet a legal obligation.
We do not sell your personal data. Ever.
| Recipient | What they receive | Why |
|---|---|---|
| Sellers | Name, delivery address, phone, order contents | To fulfil your order. Strictly bound by our Seller Data Protection Addendum — they may not market to you |
| Logistics partners | Name, address, phone, package details | Delivery |
| Payment aggregators | Order value, contact details, payment instrument data collected directly by them | Payment processing |
| Communication providers | Mobile number, email, message content | SMS, email and WhatsApp notifications |
| Analytics and advertising | Pseudonymous usage and device data | Measurement and advertising, subject to your cookie consent |
| Cloud and infrastructure | Hosted data | Hosting, backup, search and caching |
| Professional advisers | As necessary | Legal, audit and accounting |
| Authorities | As lawfully required | Court orders, regulatory and law-enforcement demands |
| Acquirer | As relevant | Merger, acquisition or restructuring — you will be notified |
Every processor is bound by contract to process data only on our instructions, apply reasonable security safeguards, and delete or return it when no longer needed.
Your data is stored primarily in India. Some of our processors — analytics, communications and cloud infrastructure — may process data outside India. Where they do, we transfer only to countries not restricted by the Central Government under Section 16 of the DPDP Act, and we impose contractual safeguards. Payment data is processed in India in accordance with RBI’s data localisation directions.
| Data | Retention |
|---|---|
| Account data | While your account is active, plus 1 year after your last activity |
| Order and invoice records | 8 years — CGST Act and Companies Act, 2013 |
| Payment transaction records | 8 years |
| Delivery address history | 3 years from last use |
| Support and grievance records | 3 years from resolution |
| Reviews and posted content | Until you delete them or close your account |
| Website analytics | 26 months |
| Session recordings | 12 months |
| Marketing consent records | 3 years after withdrawal, as evidence of consent |
| Seller KYC documents | Relationship duration plus 8 years |
As required by Section 8(7) of the DPDP Act, we erase personal data once the purpose is served and retention is no longer required by law. Where erasure is not possible, we anonymise it irreversibly.
Under the DPDP Act you have the right to:
Email [email protected] with the subject line PRIVACY — [your request], or use the privacy controls in your account. We will verify your identity — this protects you — and respond within 30 days. There is no charge. If we cannot fulfil a request, we will explain why and how to challenge that decision.
Under Section 15 of the DPDP Act you are required to provide authentic information and not to raise false or frivolous requests.
We apply reasonable security safeguards as required by Section 8(5) of the DPDP Act, including: TLS encryption in transit; encryption at rest for sensitive fields; salted password hashing; role-based access control and least-privilege access; multi-factor authentication for administrative accounts; network and application firewalls with malware scanning; logging and monitoring of access to personal data; regular backups; and vendor due diligence.
No system is perfectly secure. In the event of a personal data breach we will notify the Data Protection Board of India and every affected individual, in the form and within the time the Act requires.
If you discover a security vulnerability, please report it responsibly to [email protected]. We will not pursue action against good-faith researchers who report privately and do not access or exfiltrate other users’ data.
We send promotional messages by email, SMS and WhatsApp only where you have consented. Every message carries an opt-out, and you can change your preferences in your account at any time. Opting out of marketing does not stop transactional messages about your orders, which are necessary to deliver the service.
Our numbers are registered under the TRAI TCCCP Regulations, 2018, and commercial communications are sent through registered headers and consent-linked templates.
We use automated systems for fraud scoring, search ranking, recommendations and review moderation. These do not produce legal effects concerning you. Where an automated decision materially affects you — such as an order being declined for suspected fraud — you may request human review by contacting [email protected].
Our site links to seller storefronts, brand sites and payment pages operated by others. We are not responsible for their privacy practices. Please read their policies before providing data to them.
We update this policy as our practices or the law change. Material changes are notified by email or an in-app notice at least 7 days before they take effect. The version number and effective date at the top always reflect the current version, and previous versions are available on request.
Contact [email protected] first — we will acknowledge within 48 hours and respond within 30 days. If unresolved, escalate to our Grievance Officer via Grievance Redressal.
As required by Section 13(3) of the DPDP Act, you must exhaust our internal process before approaching the Data Protection Board of India. You retain the right to do so thereafter.