arrow_back

Privacy Policy

KhauGully · Legal

home

Privacy Policy

How KhauGully handles personal data on the KhauGully platform. Written to comply with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and the SPDI Rules, 2011.

Effective 16 August 2026Last updated 16 August 2026Version 1.0
info

The short version

We collect the minimum we need to deliver your food: who you are, where you live, and what you ordered. We share your address and phone number with the restaurant and rider handling your order, because they cannot deliver it otherwise. We never sell your data. We do not store your card or UPI details — the payment gateway does.

1.Who is responsible for your data

KhauGully, operating the KhauGully platform from TODO: Full street address, Jogeshwari West, Mumbai, Maharashtra – 400102, is the Data Fiduciary for the personal data described in this policy — meaning we decide why and how it is processed, and we are accountable for it under the Digital Personal Data Protection Act, 2023.

This policy covers our website, progressive web application, and the customer, restaurant partner and delivery partner interfaces within them.

2.What we collect

2.1 From customers.

Identity & contactName, mobile number, email address, and a hashed password if you set one. We never store your password in readable form.
Delivery addressesThe address text you save, its label (Home, Office and so on), and — only if you permit it — the GPS latitude and longitude of your location, used to check you are inside our delivery radius and to guide the rider.
Order dataItems ordered, quantities, prices, the restaurant, cooking or delivery instructions you type, the delivery OTP, order status timestamps, and the address snapshot taken at checkout.
Payment dataPayment method, amount, and the transaction reference returned by Razorpay Software Private Limited. We do NOT receive or store your card number, CVV, UPI PIN, or bank credentials.
Device & usageA device identifier generated in your browser, the pages you visit, your cart contents, the browser user-agent string, and IP address. Used to keep guest carts working, to show you your own orders, to rate-limit abuse, and for internal analytics.
NotificationsA Firebase Cloud Messaging token for each browser or device on which you enable push notifications, so we can tell you when your order is on its way.
Support & reviewsYour name, the contact detail you give us, and the content of any support ticket or review you submit.

2.2 From Restaurant Partners. In addition to the above, we collect business information required to onboard and pay a kitchen: owner name and phone, business address, FSSAI licence number, expiry date and a copy of the certificate, GSTIN, PAN, photographs of the storefront and menu, and payout details (bank account name, account number, IFSC, and UPI ID).

2.3 From Delivery Partners. In addition to identity and contact details, we collect vehicle registration number, driving licence number and a copy of the licence, and a government-issued identity document, along with earnings, cash-collection and settlement records.

warning

Sensitive documents

Identity documents, licences and financial account details of partners are sensitive personal data under the SPDI Rules, 2011. We collect them solely to verify that a partner is who they claim to be, that they are legally permitted to trade or to ride, and to pay them. They are visible only to authorised administrative staff, are never published on the Platform, and are never shared with customers or other partners.

2.4 What we deliberately do not collect. We do not collect biometric data, health data, caste or religion, political opinions, or continuous background location. We do not run third-party advertising trackers or sell data to data brokers.

3.Why we use it, and on what legal basis

To fulfil your orderTransmitting the order to the restaurant, assigning a rider, navigating to your address, verifying handover by OTP. Basis: performance of the contract you entered into.
To take and reconcile paymentProcessing the transaction, matching it to your order, issuing refunds, settling amounts owed to partners. Basis: contract and legal obligation.
To keep you informedOrder status notifications by push and, where relevant, email. Basis: contract. These are transactional and cannot be switched off while an order is live, though you may disable push at the browser level.
To provide supportInvestigating complaints, resolving payment disputes, handling grievances. Basis: contract and legitimate use.
To prevent fraud and abuseRate-limiting, detecting fake orders and refund abuse, blocking accounts. Basis: legitimate use and protection of the platform.
To improve the serviceAggregate analytics on what is ordered, when, and where demand is unmet. Wherever possible this is done on aggregated or de-identified data. Basis: legitimate use.
Promotional messagesOffers and new-restaurant announcements. Basis: your consent, which you may withdraw at any time without affecting the service.
To meet legal dutiesTax records, responding to lawful requests from a court, police, food safety authority or regulator. Basis: legal obligation.

4.Who we share it with

We share only what is necessary, only with the following categories, and never for sale.

  • The Restaurant Partner handling your order — your first name, the items ordered, your instructions, and your contact number if they need to reach you about the order. They do not receive your full order history or your saved addresses.
  • The Delivery Partner assigned to your order — your name, delivery address, location coordinates and contact number, for the duration of that delivery only. Delivery Partners are contractually forbidden from retaining, reusing or contacting you outside the delivery, and we act on any report that they have.
  • Razorpay Software Private Limited, our payment gateway, which processes your payment directly and under its own privacy policy.
  • Infrastructure providers who host the application, database and file storage, and who send transactional email and push notifications on our behalf. They act as processors on our instructions and may not use your data for their own purposes.
  • Google Firebase Cloud Messaging, which delivers push notifications to your device.
  • Courts, regulators and law-enforcement agencies, where we are legally compelled to disclose, or where disclosure is necessary to investigate a food safety incident or a crime.
  • A successor entity, if the business is reorganised, merged or sold — in which case your data remains subject to this policy or a materially equivalent one.

5.How long we keep it

  • Order and payment records are retained for at least eight years, as required for tax and accounting purposes under Indian law.
  • Account details are kept while your account is active, and for a reasonable period afterwards to resolve disputes and enforce our agreements.
  • OTP codes expire within minutes and are deleted after use.
  • Activity and analytics records, including cart snapshots and page views, are retained only for short-term operational monitoring and are pruned regularly.
  • Partner verification documents are retained for as long as the partnership subsists, plus the period during which a regulatory authority may lawfully call for them.
  • Support tickets and grievances are retained for three years from resolution, so a repeat complaint can be understood in context.

6.Your rights

Under the Digital Personal Data Protection Act, 2023 you have the following rights, which you may exercise free of charge by writing to grievance@khaugully.in:

  • Access — a summary of the personal data we hold about you and of how it has been processed.
  • Correction — to have inaccurate or incomplete data corrected or completed. Most details can be corrected yourself from your profile page.
  • Erasure — to have your data deleted where it is no longer needed for the purpose it was collected for. We may retain the minimum required by law, such as transaction records for tax.
  • Withdrawal of consent — for anything processed on the basis of your consent, such as marketing messages or location access. Withdrawal does not affect processing already carried out.
  • Grievance redressal — to complain to our Grievance Officer, and, if still unsatisfied, to the Data Protection Board of India.
  • Nomination — to nominate a person who may exercise these rights on your behalf in the event of your death or incapacity.

We will respond to a rights request within 30 days. We may ask you to verify your identity before acting, to make sure we are not disclosing your data to someone else.

7.How we protect your data

  • All traffic to and from the Platform is encrypted in transit using HTTPS/TLS.
  • Passwords are stored only as salted bcrypt hashes and are never recoverable in plain text.
  • Access to the administrative console and to partner documents is restricted by role-based authentication, and administrative actions are recorded in an audit log.
  • Payment credentials never touch our servers; they are handled entirely within the PCI-DSS compliant environment of our payment gateway.
  • Order data is served only to the account, device or partner entitled to see it.
  • Rate limiting is applied to sensitive endpoints to resist automated abuse.

No system is perfectly secure, and we cannot guarantee absolute security. If a personal data breach occurs, we will notify the Data Protection Board of India and every affected user, in the manner and within the timelines required by law.

8.Cookies, device identifiers and tracking

We use a small number of cookies and browser-storage identifiers, chiefly to keep you signed in and to hold your cart together. Full detail, and how to turn each one off, is in our Cookie & Tracking Policy.

9.Children

The Platform is not directed at children below 18. We do not knowingly collect personal data of a child, and in line with the Digital Personal Data Protection Act, 2023 we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has given us personal data, write to grievance@khaugully.in and we will delete it.

10.Data location and transfers

Your data is stored on cloud infrastructure which may be located outside India. Where data is transferred outside India, we do so only to countries not restricted by the Central Government and under contractual terms requiring a standard of protection equivalent to that described in this policy.

11.Contact and grievances

For any privacy question or to exercise a right, contact our Grievance Officer, who is also our point of contact for data protection:

NameShoaib Qureshi
DesignationGrievance Officer & Proprietor
Emailgrievance@khaugully.in
Phone+91 TODO
AddressTODO: Full street address, Jogeshwari West, Mumbai, Maharashtra – 400102
Supportsupport@khaugully.in · 10:00 AM – 11:00 PM IST, all days

If your grievance is not resolved to your satisfaction, you may escalate it to the Data Protection Board of India.

12.Changes to this policy

We may update this policy as the service or the law changes. The current version is always on this page with its effective date. Where a change materially affects how we use your data, we will notify you in the app or by email before it takes effect.

Questions about this document? Write to our Grievance Officer or raise a ticket from Help & Support.

listAll legal documents