Privacy Policy
Last updated: May 2025
1. Introduction
WyldTrace Pvt. Ltd. ("WyldTrace", "we", "our", or "us") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, share, and safeguard your data when you use our platform, website, and services — including our supply chain traceability tools, harvester portal, and blockchain-based product verification system.
By accessing or using WyldTrace's services, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of our platform.
2. Information We Collect
We collect the following categories of information:
2.1 Account & Identity Information
- Full name, email address, and phone number
- Role on the platform (Harvester, FPO, Brand, or Admin)
- Organisation name and registration details
- Identity proof type (for harvester verification, e.g. Aadhaar, voter ID)
2.2 Harvester & Supply Chain Data
- Collection area and geographic zone information
- GPS coordinates of harvest locations captured via your device at the time of harvest logging
- Species harvested, quantities, dates, and harvesting methods
- Batch codes, QR codes, and custody transfer records
- Harvest site photographs — images of harvested material and the surrounding collection site, which may depict forest land, farmland, community-managed territories, or other private or semi-public property. These photos may also incidentally capture landscape features or structures on private land.
2.3 Payment Information
- Payment amounts, dates, and methods (bank transfer, UPI, cash)
- Payment reference numbers
- Sustainability premium details
2.4 Technical & Usage Data
- IP address, browser type, and device information
- Pages visited, features used, and session duration
- Cookies and similar tracking technologies (see Section 8)
3. Harvest Site Photographs — Special Notice
Because harvest site photographs may depict private land, community forests, tribal territories, or other sensitive locations, we treat photo data with additional care.
3.1 What photos may contain
Photographs uploaded by harvesters may include:
- Forest land, farm fields, and collection sites that may be privately or community owned
- Harvested plant material, roots, bark, or produce
- Landscape features, paths, or structures incidentally visible at the collection site
- In some cases, the harvester themselves or other community members (if included in the frame)
3.2 Who can view photos
Harvest photographs are not fully private. Depending on the supply chain stage, photos may be visible to:
- FPO managers — for batch verification and quality assessment during the review process
- Brand partners — to validate the origin and quality of products they receive
- The general public — via the consumer-facing product trace page, which is accessible to anyone who scans the product's QR code, with no login required
Important: If a photograph is attached to a batch that reaches the public trace page, that photograph becomes publicly accessible worldwide — including to search engines — via a non-guessable URL. Please only upload photos you are comfortable being publicly visible.
3.3 Photo storage
All photographs are stored on Amazon Web Services (AWS) Simple Storage Service (S3), hosted in the Asia Pacific (Mumbai / ap-south-1) region. Photos are stored in a dedicated bucket with access-controlled URLs. We apply reasonable security measures to prevent unauthorised access.
Photos are retained for the duration of your account and for a minimum of 7 years alongside other supply chain records. You may request removal of a specific photograph by emailing info@wyldtrace.com. Removal from our storage does not remove any blockchain hash that references the photograph.
3.4 Your responsibility when uploading photos
By uploading a photograph, you confirm that:
- You have the legal right to be on the land shown in the photograph
- You have not photographed any person without their knowledge and consent
- You have the right to submit the photograph and grant WyldTrace the licence to display it
- The photograph genuinely depicts the harvest batch being documented
4. How We Use Your Information
We use your data for the following purposes:
- Platform operation: Creating and managing accounts, processing harvest batches, and enabling supply chain traceability.
- Verification: Verifying harvester identities and collection areas in partnership with FPO managers.
- Blockchain recording: Recording immutable supply chain events (harvest, transfer, quality check, delivery) on-chain for product authenticity. GPS coordinates are included in the on-chain data hash.
- Public traceability: Displaying harvest batch information — including photographs, GPS location, species, and custody chain — on the public product trace page accessible via QR code.
- Payments: Processing and tracking payments to harvesters, including sustainability premiums.
- Communication: Sending platform notifications, updates, and support responses.
- Analytics: Improving our platform through aggregated, anonymised usage insights.
- Legal compliance: Meeting our obligations under applicable Indian law.
5. Blockchain & Immutable Records
WyldTrace uses blockchain technology to record supply chain events. Once data is written to the blockchain, it cannot be deleted or altered — this is a core feature of our traceability system.
Data written to the blockchain includes batch codes, data hashes (which incorporate GPS coordinates and batch details), custody transfer records, and verification events. Personal identifiers (such as names or phone numbers) are not written directly to the blockchain — only anonymised batch and transaction references are recorded on-chain.
GPS coordinates captured at the time of harvest are included in the data hash that is permanently recorded on the blockchain. While the raw coordinates are not stored on-chain in plain text, the hash references them. This means GPS data is effectively part of the permanent record.
By submitting a harvest batch for blockchain recording, you acknowledge and consent to the permanent and public nature of on-chain records.
6. Sharing Your Information
We do not sell your personal data. We may share your information with:
- FPO organisations: Your harvester profile, batch data, GPS location, and harvest photographs are visible to the FPO you are registered under, for verification and management purposes.
- Brand partners: Brands accessing traceability data see supply chain records linked to product batches, including harvest photographs and GPS origin data. Personal harvester information such as full name and contact details is not shared with brands.
- The public: The product trace page, accessible via QR code scan with no login required, displays batch information including the harvest photograph, GPS location, species, and custody chain. This page is publicly accessible and may be indexed by search engines.
- Service providers: Trusted third-party vendors who help us operate the platform (AWS for cloud storage, Auth0 for authentication, Polygon blockchain network) under strict confidentiality agreements or their own published privacy policies.
- Legal authorities: Where required by Indian law, court order, or regulatory authority.
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. Supply chain records (including batch data, GPS history, photographs, and payment history) are retained for a minimum of 7 years to comply with financial and regulatory requirements.
Photographs stored on AWS S3 are retained for the same minimum period. Deletion of a photograph from our cloud storage does not remove any blockchain hash that references it.
You may request deletion of your account and personal data by contacting us at info@wyldtrace.com. Note that records on the blockchain cannot be deleted due to their immutable nature.
8. Cookies
We use cookies and similar technologies to:
- Maintain your login session (via Auth0 authentication cookies)
- Store offline batch data locally in your browser (localStorage and IndexedDB) when you are in a low-connectivity area — this data is synced to our servers when connectivity is restored
- Remember your preferences
- Understand how visitors use our website (analytics)
You can disable cookies in your browser settings, but this may affect platform functionality, including the ability to stay logged in or use offline features.
9. Data Security
We implement industry-standard security measures including encrypted data transmission (HTTPS), JWT-based authentication via Auth0, role-based access controls, and cloud storage access policies. Photographs are stored in AWS S3 with access-controlled URL paths. Access to personal data is restricted to authorised personnel only.
While we take all reasonable steps to protect your data, no system is completely secure. In the event of a data breach affecting your rights, we will notify you as required by applicable law.
10. Your Rights
Under applicable Indian privacy law, you have the right to:
- Access: Request a copy of the personal data we hold about you, including a list of harvest photographs associated with your account.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data and photographs (subject to legal retention obligations and the irreversible nature of blockchain records).
- Objection: Object to processing of your data for certain purposes.
- Portability: Request your data in a portable format.
To exercise any of these rights, contact us at info@wyldtrace.com. We will respond within 30 days.
11. Children's Privacy
WyldTrace's platform is not intended for use by individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal information, or appears in a photograph submitted to the platform without appropriate consent, please contact us and we will address it promptly.
12. Third-Party Services
WyldTrace uses the following third-party services that have their own privacy practices:
- Auth0 (Okta) — Identity and authentication management. Governs login, session management, and user roles. Auth0 Privacy Policy
- Amazon Web Services (AWS S3) — Cloud storage for harvest photographs. Hosted in the Asia Pacific (Mumbai) region. AWS Privacy Policy
- Polygon (blockchain network) — Public blockchain on which supply chain events are permanently recorded. Transactions on the Polygon network are publicly visible. Polygon Privacy Policy
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and notify registered users via email for material changes. Your continued use of the platform after changes constitutes acceptance of the updated policy.
14. Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us: