The short version
We collect the minimum we need to deliver your food: who you are, where you live, and what you ordered. We share your address and phone number with the restaurant and rider handling your order, because they cannot deliver it otherwise. We never sell your data. We do not store your card or UPI details — the payment gateway does.
1.Who is responsible for your data
KhauGully, operating the KhauGully platform from TODO: Full street address, Jogeshwari West, Mumbai, Maharashtra – 400102, is the Data Fiduciary for the personal data described in this policy — meaning we decide why and how it is processed, and we are accountable for it under the Digital Personal Data Protection Act, 2023.
This policy covers our website, progressive web application, and the customer, restaurant partner and delivery partner interfaces within them.
2.What we collect
2.1 From customers.
2.2 From Restaurant Partners. In addition to the above, we collect business information required to onboard and pay a kitchen: owner name and phone, business address, FSSAI licence number, expiry date and a copy of the certificate, GSTIN, PAN, photographs of the storefront and menu, and payout details (bank account name, account number, IFSC, and UPI ID).
2.3 From Delivery Partners. In addition to identity and contact details, we collect vehicle registration number, driving licence number and a copy of the licence, and a government-issued identity document, along with earnings, cash-collection and settlement records.
Sensitive documents
Identity documents, licences and financial account details of partners are sensitive personal data under the SPDI Rules, 2011. We collect them solely to verify that a partner is who they claim to be, that they are legally permitted to trade or to ride, and to pay them. They are visible only to authorised administrative staff, are never published on the Platform, and are never shared with customers or other partners.
2.4 What we deliberately do not collect. We do not collect biometric data, health data, caste or religion, political opinions, or continuous background location. We do not run third-party advertising trackers or sell data to data brokers.
3.Why we use it, and on what legal basis
4.Who we share it with
We share only what is necessary, only with the following categories, and never for sale.
- The Restaurant Partner handling your order — your first name, the items ordered, your instructions, and your contact number if they need to reach you about the order. They do not receive your full order history or your saved addresses.
- The Delivery Partner assigned to your order — your name, delivery address, location coordinates and contact number, for the duration of that delivery only. Delivery Partners are contractually forbidden from retaining, reusing or contacting you outside the delivery, and we act on any report that they have.
- Razorpay Software Private Limited, our payment gateway, which processes your payment directly and under its own privacy policy.
- Infrastructure providers who host the application, database and file storage, and who send transactional email and push notifications on our behalf. They act as processors on our instructions and may not use your data for their own purposes.
- Google Firebase Cloud Messaging, which delivers push notifications to your device.
- Courts, regulators and law-enforcement agencies, where we are legally compelled to disclose, or where disclosure is necessary to investigate a food safety incident or a crime.
- A successor entity, if the business is reorganised, merged or sold — in which case your data remains subject to this policy or a materially equivalent one.
5.How long we keep it
- Order and payment records are retained for at least eight years, as required for tax and accounting purposes under Indian law.
- Account details are kept while your account is active, and for a reasonable period afterwards to resolve disputes and enforce our agreements.
- OTP codes expire within minutes and are deleted after use.
- Activity and analytics records, including cart snapshots and page views, are retained only for short-term operational monitoring and are pruned regularly.
- Partner verification documents are retained for as long as the partnership subsists, plus the period during which a regulatory authority may lawfully call for them.
- Support tickets and grievances are retained for three years from resolution, so a repeat complaint can be understood in context.
6.Your rights
Under the Digital Personal Data Protection Act, 2023 you have the following rights, which you may exercise free of charge by writing to grievance@khaugully.in:
- Access — a summary of the personal data we hold about you and of how it has been processed.
- Correction — to have inaccurate or incomplete data corrected or completed. Most details can be corrected yourself from your profile page.
- Erasure — to have your data deleted where it is no longer needed for the purpose it was collected for. We may retain the minimum required by law, such as transaction records for tax.
- Withdrawal of consent — for anything processed on the basis of your consent, such as marketing messages or location access. Withdrawal does not affect processing already carried out.
- Grievance redressal — to complain to our Grievance Officer, and, if still unsatisfied, to the Data Protection Board of India.
- Nomination — to nominate a person who may exercise these rights on your behalf in the event of your death or incapacity.
We will respond to a rights request within 30 days. We may ask you to verify your identity before acting, to make sure we are not disclosing your data to someone else.
7.How we protect your data
- All traffic to and from the Platform is encrypted in transit using HTTPS/TLS.
- Passwords are stored only as salted bcrypt hashes and are never recoverable in plain text.
- Access to the administrative console and to partner documents is restricted by role-based authentication, and administrative actions are recorded in an audit log.
- Payment credentials never touch our servers; they are handled entirely within the PCI-DSS compliant environment of our payment gateway.
- Order data is served only to the account, device or partner entitled to see it.
- Rate limiting is applied to sensitive endpoints to resist automated abuse.
No system is perfectly secure, and we cannot guarantee absolute security. If a personal data breach occurs, we will notify the Data Protection Board of India and every affected user, in the manner and within the timelines required by law.
8.Cookies, device identifiers and tracking
We use a small number of cookies and browser-storage identifiers, chiefly to keep you signed in and to hold your cart together. Full detail, and how to turn each one off, is in our Cookie & Tracking Policy.
9.Children
The Platform is not directed at children below 18. We do not knowingly collect personal data of a child, and in line with the Digital Personal Data Protection Act, 2023 we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has given us personal data, write to grievance@khaugully.in and we will delete it.
10.Data location and transfers
Your data is stored on cloud infrastructure which may be located outside India. Where data is transferred outside India, we do so only to countries not restricted by the Central Government and under contractual terms requiring a standard of protection equivalent to that described in this policy.
11.Contact and grievances
For any privacy question or to exercise a right, contact our Grievance Officer, who is also our point of contact for data protection:
If your grievance is not resolved to your satisfaction, you may escalate it to the Data Protection Board of India.
12.Changes to this policy
We may update this policy as the service or the law changes. The current version is always on this page with its effective date. Where a change materially affects how we use your data, we will notify you in the app or by email before it takes effect.