Customer Privacy Policy

LAST UPDATED: July 24, 2026

This Privacy Policy ("Policy") outlines how DIGITAL ENGINEERING AND TECHNOLOGIES PRIVATE LIMITED (hereinafter referred to as the "Company", "we", "us", or "our") collects, uses, processes, stores, shares, and protects your personal information when you register, access, or use the mobile application platform widely known by its brand name "Cravioo" (the "App" or "Platform"), which is owned, operated, and maintained by the Company, during our hyperlocal neighborhood trials.

This Policy is formulated and published in compliance with Section 43A of the Information Technology Act, 2000; Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011; and the Digital Personal Data Protection (DPDP) Act, 2023.

1. Consent and User Agreement

1.1 Express Consent: By clicking "I Agree" during account creation, or by continuing to access or use the Platform, you provide your explicit, unambiguous, and informed consent to the collection, storage, processing, and sharing of your personal data as detailed in this Policy.

1.2 Age Restriction: The Platform is not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If we discover a minor has created an account, we will purge their data immediately.

1.3 Withdrawal of Consent: You retain the right to withdraw your consent at any time by deleting your account through the app settings or by emailing our data team. Withdrawing consent will result in the immediate termination of your access to the Platform.

2. Information We Collect

To operate a functional, real-time food ordering and delivery ecosystem, we collect the following categories of information:

2.1 Information Provided Directly by You:

  • Identity and Contact Data: Full name, mobile phone number, secondary contact number, and email address provided during account registration.
  • Delivery Addresses: Specific geographic drop-off locations, house/flat numbers, apartment names, streets, land-markers, and structural access instructions.
  • Profile Data: Order histories, item preferences, customer feedback ratings, and communications sent to our customer support agents.

2.2 Information Collected Automatically via App Permissions:

  • Precise Real-Time Location Data (GPS Tracking): We collect your exact background and foreground location data through your mobile device's GPS, Bluetooth, and Wi-Fi signals. This tracking is mandatory to verify your delivery zone, calculate delivery fees, match orders to nearby restaurants, and track the live approach of your Delivery Partner.
  • Device Information: Device ID, unique mobile identifiers, operating system version, browser type, IP address, app crashes, and systemic analytics.

2.3 Information Handled via Secure Third Parties:

  • Payment Credentials: We do not collect or store your credit card numbers, debit card numbers, or UPI PINs on our servers. All transaction processing is managed directly by third-party payment gateways (e.g., Razorpay, Cashfree). Your payment data is protected under Payment Card Industry Data Security Standard (PCI-DSS) encryption.

3. How We Use Your Data

We process your personal information strictly for legitimate business and operational necessities, including:

3.1 Verifying your identity and setting up your customer profile.

3.2 Processing, routing, and completing your food orders.

3.3 Enabling live, turn-by-turn navigation for Delivery Partners to locate your doorstep.

3.4 Communicating critical order status updates, OTPs, and receipt confirmations via SMS, WhatsApp, or Push Notifications.

3.5 Optimizing app performance, identifying systemic software bugs, and debugging features during our neighborhood beta trial phase.

3.6 Preventing fraud, financial abuse, and unauthorized account access.

4. Strict Data Sharing Disclosures

We treat your personal information with absolute confidentiality. We do not sell, trade, or rent your data to external marketing companies. However, to execute your order fulfillment, we must share limited data with specific actors in our operational chain:

4.1 Sharing with Merchant Restaurants: We share your order contents, item customization instructions, first name, and generic neighborhood zone with the accepting kitchen so they can prepare your food accurately. Your private contact number is completely masked.

4.2 Sharing with Independent Delivery Partners: We share your full name, precise delivery address, drop-off instructions, and live GPS location coordinates with the delivery rider assigned to your route. This sharing automatically ceases the moment the order status is marked as "Delivered."

4.3 Sharing with Management Roles: Zonal Franchise Owners and Zonal Managers have restricted, dashboard-only access to view order logs and masked customer profiles within their specific territories to resolve localized transit issues or complaints.

4.4 Legal and Regulatory Mandates: We may disclose your data if legally required to do so by a court order, a law enforcement agency, or government entities acting under statutory authority.

5. Data Security and Storage Practices

5.1 Security Standards: We implement standard technical, physical, and administrative security protocols designed to safeguard your personal data against accidental loss, unauthorized access, alteration, or disclosure.

5.2 Data Isolation: Testing teams, helpers, and coordinators do not have access to our central production databases or unmasked user logs. They only interact with mock data or anonymized profiles on project boards.

5.3 Retention Limits: We store your personal information only for as long as your account remains active or as required to fulfill the operational and legal purposes outlined in this Policy. Once your account is deleted, your personal data will be completely erased or permanently anonymized within 30 days, except where retention is legally mandated for tax or accounting audits.

6. Your Legal Data Rights

Under applicable Indian data privacy regulations, you possess the following rights regarding your data:

6.1 Right to Access & Review: You can request a summary of the personal data we hold about you at any time.

6.2 Right to Correction: You can update or correct inaccurate profile details directly inside the App.

6.3 Right to Erasure ("Right to be Forgotten"): You can demand the permanent deletion of your account and associated personal information from our active databases.

7. Official Grievance Officer Details

In compliance with the Information Technology Act, 2000 and the Consumer Protection (E-Commerce) Rules, 2020, if you have any questions, concerns, or formal complaints regarding how your privacy is managed, please contact our designated Grievance Officer:

Attn: Grievance Redressal Officer

Corporate Entity: Digital Engineering and Technologies Private Limited

Postal Address: Hyderabad, India

Email Address: [email protected]

Response SLA: We will acknowledge receipt of your complaint within 48 hours and resolve it within one month from the date of receipt.