Privacy Policy

Last updated: May 2026. Operated by Nitesh Garg, trading as SupCarta, Delhi, India.

Note on legal review

This policy is a standard B2B services template. Clauses marked {{TODO: legal review before any paying customer}} require review by a qualified lawyer before SupCarta enters into any paid engagement. Do not rely on this policy as final legal documentation.

1. Who we are

SupCarta is a supply chain compliance operations service operated by Nitesh Garg, Delhi, India ("SupCarta", "we", "us"). We are not a registered legal entity at the date of this policy. Entity formation is in progress.

Contact: hello@supcarta.com

2. What data we collect

Visitors to this website: We collect information you voluntarily submit via the contact form (name, email address, phone number if provided, message). We also collect standard server logs (IP address, browser type, pages visited) for security and analytics purposes. We do not use third-party tracking pixels or behavioral advertising.

Clients and their representatives: We collect contact details, business information, and any documentation provided to us to deliver the service (e.g., supplier certificates, shipping documents, ESG questionnaire data). {{TODO: legal review before any paying customer}}

3. How we use data

Website inquiries: We use contact form data solely to respond to your inquiry. We do not add you to marketing lists without your explicit consent.

Service delivery: Client data is used exclusively to perform the work described in the engagement scope. We do not use client or supplier data for any secondary purpose, including training AI models, benchmarking, or resale. {{TODO: legal review before any paying customer}}

4. Data processing on behalf of clients (DPA)

Where SupCarta processes personal data on behalf of a client (for example, supplier contact information or employee data included in ESG questionnaires), SupCarta acts as a data processor and the client acts as the data controller. {{TODO: legal review before any paying customer}}

We process such data only in accordance with the client's documented instructions and for the purpose of delivering the engagement. We do not transfer personal data to third parties except where necessary to deliver the service (e.g., secure cloud storage providers) and where such transfers are lawful. {{TODO: legal review before any paying customer}}

We implement reasonable technical and organizational security measures appropriate to the risk level of the data processed. {{TODO: confirm specific security measures with technical review}}

5. Data retention

Website contact form submissions are retained for up to 12 months, after which they are deleted unless an active engagement exists.

Client and supplier documentation is retained for the duration of the engagement and for a reasonable period thereafter (typically 12 months) to support audit or dispute resolution needs. On written request from a client, we will delete their data within 30 days of termination of the engagement, except where retention is required by applicable law. {{TODO: legal review before any paying customer}}

6. Data sharing

We do not sell, rent, or share client or supplier data with third parties for commercial purposes. We may share data with:

7. Your rights

You have the right to request access to, correction of, or deletion of personal data we hold about you. You also have the right to object to processing in certain circumstances. To exercise any of these rights, email hello@supcarta.com.

{{TODO: legal review before any paying customer — add jurisdiction-specific rights (GDPR, PDPA, etc.) as applicable}}

8. Cookies

This website does not use tracking cookies. We use standard server-side logging for security purposes only.

9. Changes to this policy

We may update this policy as the service evolves and as the legal entity is established. Material changes will be communicated to active clients directly. The current version is always available at supcarta.com/privacy.

10. Contact

Questions about this policy: hello@supcarta.com — Nitesh Garg, SupCarta, Delhi, India.