Privacy Policy
Last updated: 10 August 2026
OliveTree — Global Logistics & Advisory ("OliveTree", "we", "us") operates a managed marketplace connecting Indian exporters and importers with vetted service providers (CHAs, freight forwarders, insurers, NBFCs and consultants). This policy explains what we collect, why, and how you can control it.
1. What we collect
- Account details — name, email, phone number, and a securely hashed password.
- Company & compliance details — company name, address, GSTIN, IEC code, AD code, and PAN, submitted when you set up an organization profile.
- KYC documents — scans/photos of the above (PAN card, GSTIN certificate, IEC certificate, AD code letter, certifications) uploaded for identity/business verification. These are stored with access restricted to your organization's members and platform administrators — never public.
- Marketplace activity — RFQs you post, bids you submit or receive, awarded shipments and their tracked milestones, and messages/notes exchanged through the platform.
- Payment records — subscription and transaction records processed through our payment partner, PayU. We do not store your card, UPI, or bank credentials — PayU handles that directly.
- Session data — a single, HTTP-only authentication cookie used to keep you signed in. We don't use third-party advertising or tracking cookies.
2. How we use it
- To operate the core marketplace — matching seekers with providers, processing RFQs and bids.
- To verify organizations before granting a "Verified" badge visible to other users.
- To process subscription payments via PayU and reconcile transaction records.
- To follow up on new registrations and inquiries — new signups may be recorded as leads in our CRM (Zoho) so our team can assist with onboarding and, where relevant, advisory/consulting services.
- To detect and prevent fraud, abuse, and unauthorized access (e.g. failed-login tracking).
- To comply with applicable Indian law, including tax and foreign-trade recordkeeping obligations.
3. Who we share it with
We do not sell personal data. We share the minimum necessary information with:
- PayU — to process payments (name, email, phone, and transaction amount).
- Zoho CRM — to manage leads and follow-ups (name, email, phone).
- Supabase — our database and infrastructure provider, which stores the data above on our behalf under its own security controls.
- Other marketplace users — your organization's public profile (name, service categories, verification badge, tenure, completed-order count) is visible in the provider directory. Bid and RFQ details are visible only to the seeker and providers directly involved.
- Law enforcement or regulators, only when legally required.
4. Your rights
Under India's Digital Personal Data Protection Act, 2023, you can request access to, correction of, or deletion of your personal data, and withdraw consent for optional processing (such as CRM follow-ups). Contact us using the details below to exercise these rights. Some data (e.g. records needed for tax or trade compliance) may need to be retained even after a deletion request, as required by law.
5. Data retention
We retain account and transaction data for as long as your account is active and as needed to meet legal and regulatory recordkeeping requirements. KYC documents are retained for verification purposes and can be deleted on request once no longer legally required.
6. Security
Passwords are hashed, sessions are signed and HTTP-only, and KYC documents are served only to authenticated, authorized users — never from a public URL. No system is 100% secure; if you believe your account has been compromised, contact us immediately.
7. Contact us
For privacy questions or to exercise your data rights, contact us through the details on our homepage.
This policy is provided as a general description of our practices and is not a substitute for legal advice specific to your business.
