Privacy Policy
Effective: {{DD MONTH YYYY}} · Last updated: {{DD MONTH YYYY}}
1. Who we are
OrdNow is operated by {{OrdNow Technologies Pvt. Ltd.}} ("OrdNow", "we", "us", "our"), a company incorporated under the Companies Act, 2013 with registered office at {{registered office address}}, CIN {{U-CIN-XXXXX}}. For questions about this policy, contact our Data Protection Officer at {{dpo@ordnow.in}}.
This policy explains what personal data we collect through the OrdNow mobile app and the website at app.ordnow.in(together, the "App"), how we use it, and the rights you have over your data under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and, where applicable, the EU General Data Protection Regulation ("GDPR").
2. What we collect
We collect only the data we need to run the App and deliver your orders.
2.1 Data you give us
- Account details: your name, phone number, email address, and an optional profile photo.
- Delivery addresses: the physical address, area, PIN code, and (if you allow) precise latitude and longitude for each saved address.
- Order information: items you order, quantities, cart notes, and delivery instructions.
- Recipient details when you order for someone else: their name and phone number.
- Support messages and any feedback or complaints you send us.
2.2 Data we collect automatically
- Precise location at the moment you tap "Use my location" — used to show nearby restaurants and to match your delivery address to a service zone. We do not track your location in the background.
- Device push token from Firebase Cloud Messaging so we can send order-status notifications to your device.
- Session cookie containing an authentication JWT bound to your account. Marked HttpOnly, Secure, SameSite=Lax; expires after 30 days of inactivity.
- Local browser storage for your theme, language, recent searches, and last-used address — stored on your device only, not on our servers.
- Basic technical metadata associated with every request (IP address, user agent, timestamp) which our hosting provider logs for security and abuse prevention.
2.3 Data we do not collect
- We do not use third-party advertising, tracking, or analytics SDKs.
- We do not collect microphone, camera, contacts, calendar, or health data.
- We do not sell or rent your personal data to anyone.
3. Why we collect it — purposes and legal basis
| Purpose | DPDP / GDPR basis |
|---|---|
| Create your account and authenticate you (phone OTP or email + password) | Contract with you |
| Show restaurants near you and route orders to the nearest branch | Contract with you |
| Process payments through Razorpay and issue refunds | Contract with you |
| Send order-status push notifications and delivery updates | Contract with you |
| Fraud prevention (order-frequency and coupon-reuse checks) | Legitimate interest |
| Meet tax, accounting, and consumer-protection record-keeping obligations | Legal obligation |
| Improve the App (aggregate, non-identifying metrics only) | Legitimate interest |
4. Who we share your data with
We share the minimum data necessary with the following processors, each bound by a data-processing agreement:
- Firebase (Google LLC / Google India Pvt. Ltd.) — phone-number authentication, push notifications, and Crashlytics (anonymised crash + performance diagnostics on our Android and iOS apps only). Google's Data Processing Terms apply.
- Razorpay (Razorpay Software Pvt. Ltd.) — payment processing. PCI-DSS Level 1 certified. Card details are captured directly by Razorpay and never touch our servers.
- MSG91 (Walkover Web Solutions Pvt. Ltd.) — SMS OTP delivery, used as a fallback when Firebase Phone Auth is unavailable.
- Neon (Neon Inc.) — managed PostgreSQL hosting for our operational database.
- Vercel (Vercel Inc.) — hosting for the App's web layer and API endpoints.
- OpenStreetMap Foundation — reverse-geocoding your delivery coordinates into a human-readable address.
- Restaurant partners — your name, delivery address, and order contents so they can prepare your order. They may not use this data for any other purpose.
- Delivery partners — your name, phone number, and delivery address so the rider can reach you. Rider access ends when the order is delivered.
- Government authorities — where we are legally required to disclose data (tax audit, court order, statutory notice).
We never share your personal data with third parties for their own marketing.
5. How long we keep it
- Active account data — kept for as long as your account is active plus 12 months after your last login, then anonymised.
- Order records — retained for {{8 years}} in anonymised form to satisfy tax and consumer-protection record-keeping. Your name, contact details, and address are removed from the anonymised copy.
- Support and complaint records — {{3 years}} after resolution.
- Fraud logs — {{2 years}} to detect repeat abuse.
- Session cookies and push tokens — cleared when you log out or delete your account.
6. Your rights
Under the DPDP Act 2023 and, where applicable, the GDPR, you have the right to:
- Access a copy of the personal data we hold about you — available inside the App via Profile → Settings, or by emailing our DPO.
- Correct inaccurate data — you can edit your name, email, and addresses in Profile → Edit at any time.
- Delete your account and personal data — Profile → Settings → Delete account. Your name, phone, email, addresses, and favourites are removed immediately; order records are anonymised as described in Section 5.
- Withdraw consent for optional processing (e.g. push notifications) — Profile → Notifications. Withdrawal does not affect processing already carried out.
- Portability — request a machine-readable copy of your data at {{dpo@ordnow.in}}.
- Complain to the Data Protection Board of India (or, in the EU/UK, your local Data Protection Authority) if you believe your rights have been violated.
Our Grievance Officer under Rule 3(11) of the IT Rules 2011 is {{Grievance Officer Name}}, reachable at {{grievance@ordnow.in}}. We respond to written grievances within 15 days.
7. Security
- All traffic between your device and our servers is encrypted with TLS 1.2+.
- Passwords are hashed with bcrypt; we never store them in plain text.
- Payment card details are handled exclusively by Razorpay and never enter our systems.
- Access to production data is restricted to a small number of engineers on a need-to-know basis.
- We keep audit logs of database access and review them for anomalies.
No system is perfectly secure. In the unlikely event of a breach that risks harm to your rights, we will notify you and the Data Protection Board within the timelines the DPDP Act requires (currently 72 hours).
8. Children
OrdNow is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us and we will delete it.
9. International transfers
Your data is stored on servers operated by our hosting providers. Some of these providers may process data outside India (for example, database backups in {{region}}, or Firebase-issued authentication tokens routed via Google infrastructure). Where transfers happen, we rely on the provider's Standard Contractual Clauses and other safeguards recognised under Section 16 of the DPDP Act.
10. Changes to this policy
We may update this policy from time to time. If the change is material we will notify you in-app or by email at least 14 days before it takes effect. Continued use of the App after the effective date constitutes acceptance of the updated policy.
11. Contact
Questions, requests, or complaints: {{support@ordnow.in}} · Data Protection Officer: {{dpo@ordnow.in}} · Postal: {{registered office address}}.