EFFECTIVE 1 SEPTEMBER 2026

Privacy Policy

This Policy explains what personal data Orderly.Food collects, the purposes for which it is processed, with whom it is shared, how long it is retained, and the rights available to you. It applies to the website, the web application and every service offered through them.

1. Who we are and how to reach us

The Orderly.Food platform (the “Platform”) is operated by Taksham Enterprise, an MSME incorporated in India (“Orderly.Food”, “we”, “us”). For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) we are the Data Fiduciary in respect of the personal data described in this Policy.

Questions, requests and complaints concerning personal data should be addressed to our Grievance Officer at support@orderly.food. Contact details and escalation routes are set out in Section 13 and on the Contact and grievance page.

2. Scope and definitions

This Policy applies to every person who visits the Platform, creates an account, places an order (a “Buyer”), or applies to and operates a home kitchen through the Platform (a “Cook”). “Personal data” means any data about an individual who is identifiable by or in relation to such data. “Processing” carries the meaning given in the DPDP Act and includes collection, storage, use, disclosure and erasure.

The Platform is intended for persons aged eighteen years and above. We do not knowingly process the personal data of a child, and an account found to belong to a child will be closed and its data erased in accordance with Section 9.

3. Personal data we collect

We collect only the personal data that the operation of a prepaid, pickup-only food marketplace requires. Data is collected in three ways: you provide it directly, it is generated by your use of the Platform, or it is received from a third party you have authorised.

3.1 All account holders

Identity and contact: full name, email address and, where provided, mobile number, together with the verification status of each. If you sign in with Google, we receive from Google your name, email address, whether Google has verified that address, and a stable account identifier. We do not receive your Google password or contacts.

Credentials: a password, if you set one, stored only as a salted cryptographic hash from which the password cannot be recovered. One-time codes sent by email for passwordless sign-in and for verifying your address, stored as hashes and expiring within minutes.

Session and security data: the browser user-agent string and IP address associated with each sign-in and each active session, the time of your last sign-in, and an audit log of security-relevant actions taken on your account.

Communications: messages you send to support, complaints you raise about an order together with any evidence you attach, and our records of notifications sent to you.

3.2 Buyers

Location: a PIN code you type, or an approximate latitude and longitude if you allow your browser to share your position, used to show kitchens within walking distance. We store the most recent position and a display name of your choosing. We do not track your location in the background.

Orders: the meals you reserve, the amounts paid, the pickup window, the time of collection, and the status history of each order. A one-time pickup code, stored as a hash, confirms handover.

Reviews and preferences: ratings and written reviews you leave, and a dietary preference if you set one. Reviews are attributed to your display name and are visible to other users.

3.3 Cooks

Legal and public identity: your legal name, the public name of your kitchen, a short biography, a portrait photograph and photographs of your kitchen. The public name, biography and photographs are displayed to Buyers.

Address: the address from which food is collected, including any landmark you add. The exact address is encrypted at rest and is disclosed only as described in Section 5. Separately, we derive and store an approximate position and a public area label (for example the neighbourhood name) for search results.

Food-safety registration: your FSSAI registration number, its issue and expiry dates, and a photograph or PDF of the certificate. The number is displayed to Buyers on your kitchen page; the certificate itself is not.

Settlement details:the account holder name, and either a bank account number with IFSC or a UPI ID. Full account numbers are transmitted directly to our payment provider for the purpose of paying you. We retain only the account holder name, a masked bank name, the last four digits of the account, a masked IFSC or UPI ID, and the provider’s reference for the account, so that you and our support staff can recognise it.

Declarations and performance: the hygiene declaration you sign, the date you accept the Seller Terms, and operational statistics derived from your orders such as on-time rate, average rating and order count.

We do not collect Aadhaar numbers, PAN numbers, or copies of government identity documents from Cooks. Applications submitted before 1 September 2026 may include an identity document uploaded under the previous process; such documents remain in private storage subject to Section 6 and may be erased on request.

3.4 Waitlist and visitors

If you join the waitlist for an area we do not yet serve, we collect the email address or mobile number you give, the PIN code or area, and whether you are interested as a Buyer or a Cook. Each waitlist message carries a link to remove yourself from it.

4. Purposes and lawful basis

We process personal data for the following purposes. Where the DPDP Act requires consent, it is obtained when you create an account or supply the data in question, and may be withdrawn as described in Section 9. Where processing is necessary to perform a transaction you have requested, or to comply with law, we rely on those grounds.

  1. Operating the marketplace: creating and securing your account, showing you kitchens near you, taking and fulfilling orders, confirming handover, and settling payments to Cooks.
  2. Verifying Cooks: reviewing an application, confirming an FSSAI registration, and inspecting kitchen photographs before a kitchen is permitted to sell.
  3. Communicating with you: transactional notifications about your orders, your application, your settlements and your account, delivered in the app and by email.
  4. Safety and integrity: investigating complaints and food-safety reports, preventing fraud and abuse, enforcing our Terms, and keeping an audit trail of sensitive actions.
  5. Legal obligations: maintaining records required by tax law, the Food Safety and Standards Act, 2006, the Consumer Protection (E-Commerce) Rules, 2020 and the Information Technology Act, 2000 and rules made under it.
  6. Improving the service: analysing aggregated, de-identified usage to understand which areas, times and dishes are in demand. This analysis does not identify individuals.

We do not process personal data for targeted advertising, we do not build profiles for sale, and we do not sell or rent personal data to anyone.

5. How a Cook's address is protected

The exact address of a home kitchen is the most sensitive item on the Platform, and its handling is deliberately narrow.

  1. The address lines and landmark are encrypted before they are written to the database. The precise coordinates used to plan a pickup are held apart from the public listing and are never returned by any public endpoint.
  2. Public search results, kitchen pages and listings carry only an approximate position and an area label, never the encrypted address or true coordinates.
  3. The address is disclosed to a Buyer only after that Buyer’s payment for an order at that kitchen has been verified, and only for the day of the pickup. Each such disclosure is bound to the specific order.
  4. The decision to disclose is made by a single, auditable rule in our systems.

Attempting to obtain a Cook’s address other than through a paid order is a breach of our Terms of Use and may be reported to the authorities.

6. Compliance documents and photographs

FSSAI certificates, kitchen photographs and any legacy identity documents are held in private object storage that is not publicly addressable. Access is limited to members of our verification team, is granted through short-lived links, and every access is recorded in an audit log against the individual who opened the document. Portrait and kitchen photographs that you have chosen to make public are served from public storage. All images are automatically reduced in size on upload; metadata such as camera location is not retained.

7. Who we share personal data with

We engage the following categories of Data Processors to operate the Platform. Each processes personal data only on our instructions, under contract, and for no purpose of its own.

  1. Payment provider:a payment aggregator licensed by the Reserve Bank of India, which receives the amounts and references needed to collect payment from Buyers and to settle funds to Cooks, including a Cook’s full settlement account details. We never receive or store card numbers, UPI PINs or net-banking credentials.
  2. Database and infrastructure hosting: providers that host our database, application servers, caching layer and object storage.
  3. Email delivery: a transactional email service that sends notifications on our behalf and reports delivery status back to us.
  4. Google:if you choose “Continue with Google”, Google processes your sign-in under its own privacy policy and shares with us the data described in Section 3.1.

Beyond Data Processors, personal data is shared in three situations only: with the other party to your order, to the extent needed to complete it (a Buyer sees the Cook’s public kitchen details and, after payment, the pickup address; a Cook sees the Buyer’s display name and order details, never the Buyer’s address or contact details); with a regulator, court or law-enforcement agency where we are legally required to do so; and with a successor entity in the event of a merger, acquisition or reorganisation, in which case this Policy will continue to apply.

8. Cross-border transfer

Some of our Data Processors operate infrastructure outside India. Where personal data is transferred outside India, we do so only to countries not restricted by the Central Government under the DPDP Act, and under contractual terms that require protection no less stringent than this Policy. Cooks’ encrypted addresses remain encrypted wherever they are stored.

9. Your rights

Subject to the DPDP Act, you have the right to:

  1. Access a summary of the personal data we hold about you and the purposes for which it is processed.
  2. Correct personal data that is inaccurate or incomplete. Most profile fields can be edited in the app; others may be corrected by writing to us.
  3. Erase your personal data and close your account, subject to the retention obligations in Section 10.
  4. Withdraw consent for any processing that rests on consent. Withdrawal does not affect processing that took place beforehand, and may mean that parts of the Platform can no longer be provided to you.
  5. Nominate another person to exercise these rights on your behalf in the event of your death or incapacity.
  6. Raise a grievance with our Grievance Officer, and, if unsatisfied with the response, with the Data Protection Board of India.

To exercise a right, write to support@orderly.food from the email address registered to your account. We may ask you to verify your identity before acting. We respond within the period the DPDP Act and rules prescribe, and in any event within thirty days.

10. Retention

We keep personal data for as long as your account is active and for as long afterwards as the purpose for which it was collected requires. On closure of an account we erase or de-identify personal data within ninety days, except that:

  1. Order records, invoices, settlement records and refund records are retained for the period required by applicable tax and company law, currently up to eight years from the end of the relevant financial year.
  2. Records relating to a food-safety complaint or investigation are retained for the period required under the Food Safety and Standards Act, 2006 and, where a dispute is ongoing, until it is resolved.
  3. Audit logs of security-relevant actions are retained for one year.
  4. Where a record must be retained but no longer needs to identify you, we remove or replace the identifying fields.

Sign-in sessions expire automatically. One-time codes expire within minutes and are then deleted. Waitlist entries are deleted when you unsubscribe or when the area is launched and you have been notified.

11. Security

We apply technical and organisational measures appropriate to the sensitivity of the data, including encryption in transit, encryption at rest for addresses, hashed storage of passwords, codes and tokens, role-based access to administrative functions, time-limited access to private documents, and audit logging of sensitive actions. In the event of a personal data breach that is likely to affect you, we will notify you and the Data Protection Board of India in the manner and within the time the DPDP Act requires.

12. Cookies and local storage

We use strictly necessary cookies to keep you signed in. They are set with the HttpOnly and Secureattributes and cannot be read by script. Your browser’s local storage holds your cart, your chosen locality and links to track orders you have placed. We do not use advertising cookies, third-party analytics trackers or cross-site tracking of any kind. The embedded video on our registration guide is served from YouTube’s privacy-enhanced domain, which sets no cookies until you press play.

13. Grievance Officer

In accordance with the Information Technology Act, 2000, the rules made under it and the DPDP Act, our Grievance Officer may be contacted at:

Grievance Officer, Orderly.Food
support@orderly.food

Grievances are acknowledged within twenty-four hours and resolved within fifteen days of receipt, or such shorter period as the law prescribes for the matter concerned.

14. Changes to this Policy

We may revise this Policy from time to time. The effective date at the top reflects the current version. Where a change materially affects how personal data already collected is processed, we will notify you by email or in the app before the change takes effect, and where the law requires it, seek your consent afresh.

Governing law: the laws of India. Courts at Chittaurgarh, India have exclusive jurisdiction over disputes arising from this Policy, subject to the grievance mechanisms described above.