Privacy Policy
Sauceit Private Limited ("Sauceit", "we"), a company registered in India (GSTIN 29ABRCS4358J1ZH), principal place of business: 3rd Floor, Property No.224 & 80/3, Vijnapura Village, Old Madras Road, WorkFlo Ranka Junction, K R Puram Hobli, Bengaluru, Bengaluru Urban, Karnataka 560016, is committed to handling personal data responsibly under India's Digital Personal Data Protection Act, 2023 (DPDP) and other applicable law. This policy explains what we collect and why.
1. What we process
- Account data — name, work email, password hash (or Google sign-in identifier), organisation and kitchen details you provide.
- Camera video — frames from CCTV cameras that our customer (your employer or facility operator) connects. Frames are analysed to detect people, PPE items and meal-related events.
- Derived analytics — detections, counts, compliance scores and incident records produced from that video.
- Technical data — logs necessary to run and secure the service.
- Website usage — on our public website only (sauceit.ai), we count page views and which buttons are used, so we can see where people get stuck. This uses no cookies. We store a random identifier in your browser so repeat pages in one visit are not counted as separate people; it means nothing outside our own site. We do not record your IP address, your browser details, or the full address of the page you arrived from — only which website it was. If your browser sends a "Do Not Track" or Global Privacy Control signal, we count nothing at all.
2. Why we process it
Solely to provide the service our customer signed up for: food-safety compliance monitoring, meal counting and billing reports. We do not sell personal data. We do not use identifiable footage for advertising or unrelated purposes. Aggregated, anonymised statistics may be used to improve detection quality.
3. Retention
Different kinds of data are kept for different periods. The periods below are the ones our systems actually enforce — each is an automatic, scheduled deletion. Imagery is always the shortest-lived thing we hold: the numbers and the audit record outlive the pictures they came from.
| What | How long we keep it |
|---|---|
| Camera frames saved for video rewind / playback | 3 days on our servers, then deleted. |
| Analysed frames where nothing was flagged — a detection record only, with no image attached | 7 days, then deleted. |
| Evidence image attached to a hygiene / PPE incident | The image is deleted after 14 days. The incident record itself — time, camera, what was detected, with no picture — is kept for the audit trail for as long as the account exists. |
| Reference photo held against an anonymous person ID (used to show "who" in reports; never linked to a name, and no face template is created) | 14 days after that ID was last seen, then deleted. |
| Evidence image attached to a cafeteria meal-counting event | We do not currently capture one. Meal counting records the event only — time, camera, area and an anonymous person ID — with no picture at all. The system is built to attach an image and delete it after 90 days; if we ever switch that on, this page will say so before it starts. |
| Cafeteria zone event records (no imagery) | 12 months, then deleted. |
| Meal counts and billing numbers (no imagery) | Kept for the life of the account — this is the billing record and is needed for reconciliation. |
| Account data — name, work email, organisation and kitchen details | Life of the account, plus any statutory record-keeping period. |
| Data belonging to a trial that ended without a subscription | The account is put on hold with its configuration and data intact. We email the account owner around 30 days after the trial ends, and recorded detections may be deleted from around 90 days after it ends. |
These periods apply platform-wide and are not configurable per customer today. If a deployment of yours needs a different period, agree it with us in writing before you sign up.
4. Where it lives & how it's protected
Data is hosted in India (Mumbai region). Transport is encrypted (TLS); access requires authenticated, role-scoped accounts; camera credentials are stored encrypted; organisations are strictly isolated from each other.
5. Sharing
Only with infrastructure processors needed to run the service (cloud hosting, email/SMS delivery, payment processing) under contract, and with authorities where the law requires it.
6. Your rights
Under the DPDP Act you may request access to, correction of, or erasure of your personal data, and may raise grievances. Workers whose images appear in a customer's footage should contact their facility operator (the data fiduciary for their premises) or us directly.
7. Grievance officer
[GRIEVANCE OFFICER NAME] — info@sauceit.ai, [PHONE]. We acknowledge complaints within 3–5 business days and resolve within statutory timelines.
8. Changes
We will notify account owners of material changes to this policy by email and keep prior versions available on request.
