Privacy Policy
Written to the Digital Personal Data Protection Act, 2023. Plain-English on purpose.
1. Who we are
Orderzy is a dine-in ordering platform for restaurants, cafes, bars, and hotel restaurants in India. This policy explains what personal data Orderzy collects when you use the platform as a diner or as a restaurant, how we use that data, and how you exercise your rights over it. Personal data means information that identifies you or can identify you when combined with other information, as defined by the Digital Personal Data Protection Act, 2023 (DPDP Act).
The Data Fiduciary for this platform is Orderzy, operated by Aditya Asati, founder-led from India. Contact details for the Grievance Officer and the Data Protection Officer are in Section 12 below.
2. What data we collect
2.1 Data you give us directly
- When you sign up as a diner: your name, phone number, email address, and (optionally) delivery-time preferences.
- When you place an order without a signup: your first name and phone number, so we can send you the bill and any order updates.
- When a restaurant signs up: the owner's name, phone number, email, GST number where applicable, bank account details for payouts, and one or more addresses of the outlets being onboarded.
- When you contact us: whatever you write in the message plus any attachments.
2.2 Data we collect automatically
- Device and browser details (user agent, screen size, language).
- Approximate location, if you grant the browser permission and only for showing you nearby restaurants on the home page. Location is not stored; it is discarded once the page is closed.
- Pages you view, buttons you tap, and the time you spend on the platform, via first-party analytics (Google Analytics 4 with IP anonymisation, Microsoft Clarity).
- Order history, dining session history, and payment records associated with your account or your phone number.
2.3 Data we do not collect
- We do not collect your card number, UPI ID, or CVV. Payment details are entered on Cashfree's screens and never touch Orderzy servers.
- We do not collect precise GPS coordinates unless you explicitly grant browser location permission.
- We do not knowingly collect data about children under 18. See Section 7.
3. How we use your data
- To fulfil the order you place, including sending the bill to your phone number.
- To let the restaurant prepare the order and reconcile the bill.
- To send transactional notifications (order accepted, ready to serve, bill delivered) via SMS, email, or WhatsApp Business.
- To respond when you contact support or raise a grievance.
- To improve the product, understand how people use it, and fix bugs.
- To comply with tax and legal obligations under Indian law.
- We do not sell your personal data. We do not send promotional messages to your phone or email unless you have explicitly opted in.
4. Named sub-processors
Orderzy uses the following third parties to run parts of the platform. Each sees only the specific data it needs, under a contract that requires them to protect it.
- Cashfree Payments (payment processing). Processes card, UPI, and net-banking transactions. Sees payment amount, order ID, and the diner's name plus phone number to route the receipt.
- DigitalOcean (hosting). Runs the servers Orderzy is hosted on. Data stored in the Bangalore region (India).
- Meta (WhatsApp Business) (transactional messaging). Sends the itemised bill, order-ready pings, and reservation reminders to the phone number you provide.
- Google (Maps + Analytics 4). Maps performs reverse-geocode of your approximate location on the home page. Analytics 4 aggregates page views with IP anonymisation.
- Microsoft (Clarity). Session-level heatmap and playback analytics with PII masking.
- Twilio and MSG91 (SMS delivery). Sends OTPs and transactional SMS.
5. Where your data lives
Orderzy stores personal data on servers hosted by DigitalOcean in the Bangalore region of India. Where a sub-processor requires cross-border transfer (for example, Meta's WhatsApp servers or Google's Analytics servers), transfers are governed by the sub-processor's data-protection commitments, which include Standard Contractual Clauses where applicable.
6. How long we keep your data
- Diner order records: retained for 7 years to comply with Indian financial-record retention rules under the Income Tax Act.
- Diner account data: retained until you close the account or 3 years after your last order, whichever is later.
- Restaurant onboarding data: retained for the life of the restaurant's Orderzy account plus 7 years after closure for tax reasons.
- Support tickets and contact-form messages: retained for 2 years.
- Location data (when granted): not retained; discarded when the page closes.
7. Children under 18
Orderzy is not intended for anyone under 18. Under Section 9 of the DPDP Act, 2023, we do not knowingly process the personal data of a child (defined as an individual under 18 years of age) without verifiable parental consent, and we do not target advertising at children. If a parent or guardian believes we hold data about their child, contact the Grievance Officer and we will delete it.
8. Your rights under the DPDP Act
- Right to information. A summary of the personal data we hold about you, on request.
- Right to correction and erasure. Correct inaccurate data or delete data we no longer need.
- Right to grievance redressal. Contact the Grievance Officer (Section 12) with a specific concern.
- Right of nomination. Nominate a person to exercise your rights in the event of death or incapacity.
- Right to consent withdrawal. Withdraw consent for processing that relies on consent. Some processing that is required by law (financial-record retention) may continue after withdrawal.
Requests are answered within the timeline set by the DPDP Act and its rules.
9. Cookies and tracking
Orderzy uses cookies and local storage for these purposes.
- Session state (whether you are signed in, which restaurant table you scanned).
- Cart persistence for up to 24 hours so you do not lose items on page reload.
- First-party analytics (Google Analytics 4, Microsoft Clarity) with IP anonymisation.
You can clear cookies from your browser settings at any time. Doing so may sign you out of the platform.
10. How we protect your data
- Transport encryption (HTTPS with TLS 1.2 or higher) on every request.
- Passwords hashed with a modern one-way algorithm (Django's PBKDF2). Orderzy staff cannot read your password.
- Content Security Policy on every page to reduce the risk of injected scripts.
- Payment data never lands on Orderzy infrastructure. Cashfree's PCI-DSS-compliant flow handles it.
- Access to production data is limited to the founder and named engineers under NDA.
No system is perfectly secure. In the event of a personal-data breach that is likely to cause significant harm, Orderzy will notify affected individuals and the Data Protection Board of India as required by the DPDP Act.
11. Changes to this policy
We update this policy as the product evolves. Material changes will be reflected in the "last updated" date at the top of this page. Continued use of Orderzy after a change means acceptance of the updated policy.
12. Grievance Officer and Data Protection Officer
Under Rule 5 of the IT (Intermediary Guidelines) Rules, 2011, and the DPDP Act, 2023, Orderzy names the following officers.
- Name: Aditya Asati
- Role: Grievance Officer and Data Protection Officer
- Email: aditya@orderzy.in
- WhatsApp: +91 92380 08672
- Response time: within 15 working days as required by Rule 3 of the IT Rules 2011
If a grievance is not resolved to your satisfaction, you may escalate to the Data Protection Board of India at the addresses published by the Ministry of Electronics and Information Technology.
13. Governing law
This policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and the Consumer Protection Act, 2019.