Back to Home
Privacy Policy

Privacy Policy

Last updated: February 2026

Cravitoo Foods Private Limited ("Cravitoo", "we", "us", or "our") operates the Cravitoo platform — a corporate food-ordering and cafeteria-management ecosystem comprising the cravitoo.com web application, the Cravitoo customer mobile app, and the Cravitoo Partner mobile app (collectively, the "Service"). This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, and the rights you have under India's Digital Personal Data Protection Act, 2023 (DPDP Act), the EU General Data Protection Regulation (GDPR) (where applicable), and other applicable laws.

1. Information We Collect

1.1 Account Information

When you register, we collect your name, email address, phone number, employer/corporate affiliation, work site, role, and a password (which is stored as a one-way bcrypt hash — we cannot retrieve it).

1.2 Order & Payment Information

For each order, we collect items ordered, prices, quantity, vendor, delivery type, pickup time, ratings/reviews, and payment status. Card and UPI details are processed by our PCI-DSS-compliant payment partner (Razorpay) and are never stored on Cravitoo servers — we only retain the last 4 digits and a payment reference ID for reconciliation.

1.3 Vendor Onboarding Documents

For vendor partners only: GST certificate, PAN card, FSSAI license, Shop & Establishment certificate, bank details (cancelled cheque), and optional MSME/Insurance documents. These are stored encrypted and used solely for compliance verification.

1.4 Device & Usage Data

Device identifier, OS version, app version, IP address (for security/fraud prevention), Expo push notification token, and crash logs. Usage analytics include screens viewed, features used, and session duration.

1.5 Camera & Photos (Mobile Only)

The Cravitoo Partner app requests camera access to scan customer pickup QR codes. Cravitoo customer app requests camera/photo access only when you choose to upload a profile picture. Camera frames are processed locally on your device and never uploaded.

2. How We Use Your Data

  • To provide, operate, and improve the Service — process your orders, generate pickup QR codes, deliver real-time order updates.
  • To enable authentication and prevent unauthorised access — brute-force lockout, JWT tokens, secure sessions.
  • To process payments via Razorpay and issue refunds.
  • To send transactional notifications (order confirmed, ready for pickup, refund processed) via push notifications and in-app alerts.
  • To generate AI-powered food recommendations, demand forecasts, and wastage analyses for vendors. These features use a managed GPT-5.2 LLM service; only aggregated, non-identifying signals are sent — never your name, email, or phone.
  • To comply with legal obligations, including India's DPDP Act, GST returns, and FSSAI record-keeping requirements.

3. Where We Store Your Data

Personal data of Indian residents is stored on MongoDB Atlas servers located in Mumbai (ap-south-1, India). Encrypted backups are retained for 30 days. Push notification tokens are stored alongside your account record. Uploaded documents (KYC) are stored in encrypted object storage and access-restricted to authenticated Cravitoo administrators on a least-privilege basis.

4. Who We Share Your Data With

Vendor partners: Your name, order items, and pickup QR are shared with the vendor fulfilling your order. They do not see your email, phone, or payment details.

Corporate / Site Admins: Your aggregated order activity (count, spend, sponsorship eligibility) is visible to your employer's admins for reporting. Individual order items are not exposed in admin dashboards.

Payment processor (Razorpay): Required transaction metadata only.

Cloud / infrastructure providers: MongoDB Atlas (India region), Expo (push delivery), Resend (transactional email), and a managed AI LLM service. All providers are bound by data-processing agreements.

We never sell your personal data to third parties for advertising or any other purpose.

5. Data Retention

  • Active accounts: Retained until you request deletion.
  • Inactive accounts: Anonymised after 24 months of inactivity (orders kept for tax/audit but stripped of personal identifiers).
  • Order records: 7 years (Indian GST & Companies Act requirements).
  • Vendor KYC documents: Duration of partnership + 7 years post-termination.
  • Payment records: 7 years (RBI/PCI-DSS requirements).
  • Server access logs: 90 days.

6. Your Rights (DPDP Act 2023 & GDPR)

You have the following rights at any time:

  • Right to access: Download a copy of all personal data we hold about you.
  • Right to correction: Update inaccurate or incomplete data via your Profile screen.
  • Right to erasure ("right to be forgotten"): Request deletion of your account and personal data. Tax-mandated order records will be anonymised, not deleted.
  • Right to grievance redressal: Contact our Data Protection Officer (below).
  • Right to nominate: Under the DPDP Act, you may nominate a person to exercise your rights in case of death or incapacity. Email us to set this up.
  • Right to withdraw consent: You may withdraw consent for non-essential processing (marketing, recommendations) without affecting account access.

To exercise these rights in-app, visit Settings → Data & Privacy after logging in. Requests are processed within 30 days as required by the DPDP Act.

7. Security

We employ industry-standard security measures: TLS 1.3 encryption in transit, encryption at rest, bcrypt password hashing (cost 12), JWT-based session management, brute-force lockout after 5 failed logins, role-based access control, and server-side validation on every endpoint. Despite these measures, no system is 100% secure. In the event of a data breach affecting your personal data, we will notify the Data Protection Board of India and affected users within 72 hours, as required by the DPDP Act.

8. Children

Cravitoo is a B2B service intended for users 18 years and older. We do not knowingly collect data from individuals under 18. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will delete it.

9. Cookies

The web app uses two essential, first-party HttpOnly cookies (access_token, refresh_token) for authentication. These are strictly necessary for the Service to function and do not require consent. We do not use third-party advertising or tracking cookies.

10. Changes to This Policy

We may update this Privacy Policy occasionally. Material changes will be notified by email and via an in-app banner at least 14 days before they take effect. The "Last updated" date at the top of this page always reflects the current version.

Contact / Grievance Redressal

Data Protection Officer

Cravitoo Foods Private Limited

Email: privacy@cravitoo.com

Grievance Officer (DPDP Act): grievance@cravitoo.com

Response time: Within 30 days as required by the DPDP Act 2023.