1. Introduction & Scope
This Privacy Policy (“Policy”) is published by Hindu Swad Private Limited
(“Hindu Swad”, “we”, “us”, or “our”), a company incorporated under the
Companies Act, 2013 (CIN: U63120KA2025PTC206410), with its registered office
at Hindu Swad Pvt. Ltd., Karnataka Regional Office, Bangalore, Karnataka —
560001, India.
This Policy applies to all personal data processed in connection with:
- The Hindu Swad mobile application (iOS and Android)
- The website at hinduswad.com and all subdomains
- The Hindu Swad Restaurant Partner Portal
- The Hindu Swad Delivery Partner Application
- Any APIs, web services, or third-party integrations operated by Hindu Swad
- Interactions with our customer support, partner support, or grievance teams
This Policy is governed by the
Information Technology Act, 2000, the
Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal
Data or Information) Rules, 2011
(“SPDI Rules”), the
Consumer Protection Act, 2019, the
Consumer Protection (E-Commerce) Rules, 2020,
and all other applicable Indian laws and regulations.
By accessing or using any part of our Platform, you acknowledge that you have
read, understood, and freely and expressly consent to the collection, use,
processing, storage, and disclosure of your personal information as described
in this Policy. If you do not agree with any part of this Policy, you must
immediately cease using our Platform and request deletion of your account and data.
2. Data Controller Information
For the purposes of applicable Indian data protection law, the data
controller and data fiduciary is:
-
Entity:
Hindu Swad Private Limited
-
CIN:
U63120KA2025PTC206410
-
GSTIN:
29AAICH1082Q1ZY
-
Registered Address:
Hindu Swad Pvt. Ltd., Karnataka Regional Office, Bangalore,
Karnataka — 560001
-
Privacy Email:
support@hinduswad.com
-
Grievance Officer Email:
support@hinduswad.com
3. Data We Collect
We collect the following categories of personal data, including
“Sensitive Personal Data or Information” (SPDI)
as defined under the SPDI Rules:
3.1 Account & Identity Data
- Full name, display name, and profile photograph
- Mobile phone number (used as primary identifier and for OTP authentication)
- Email address
- Date of birth (for age verification)
- Gender (optional)
- Profile preferences and dietary requirements (optional)
3.2 Location Data (Sensitive)
- Precise GPS location when the app is open and actively used — for restaurant discovery, delivery
address auto-fill, and ETA calculations
- Background location data while an order is active — for real-time delivery tracking visible to
both the customer and the assigned delivery partner
- Delivery partner location: continuous, precise GPS tracking while a delivery partner is logged
in and active on the app — for route optimisation, order assignment, and ETA accuracy
- Saved addresses (home, work, and other custom labels), including GPS coordinates and
street-level address data
- Location history associated with past orders (retained as per Section 9)
3.3 Order & Transaction Data
- Complete order history including items ordered, quantities, customisations, restaurant name,
order timestamps, and order values
- Cancellation history and reasons for cancellation
- Refund history and dispute records
- Delivery addresses associated with each order
- Ratings and reviews submitted for restaurants and delivery partners
3.4 Financial & Payment Data (Sensitive)
- Payment method type (credit card, debit card, UPI, net banking, digital wallet)
- Last 4 digits of payment card numbers (we do not store full card numbers)
- UPI Virtual Payment Address (VPA / UPI ID)
- Transaction reference numbers and payment gateway tokens
- Hindu Swad Wallet balance and transaction history
- Refund processing records
Important: Full payment card details are processed
exclusively by our PCI-DSS certified payment gateway partners.
Hindu Swad does not store, transmit, or process complete card numbers
or CVV/CVC codes.
3.5 Device & Technical Data
- Device type, manufacturer, and model (e.g., Samsung Galaxy S24)
- Operating system name and version (iOS, Android)
- Unique device identifiers (IMEI, advertising ID, Android ID, IDFA)
- Mobile network operator, carrier information, and connectivity type (Wi-Fi, 4G, 5G)
- App version number and session data
- IP address and approximate IP-based location
- Crash logs, error reports, and diagnostic data
- Browser type and version (for web users)
- Push notification token
3.6 Behavioural & Usage Data
- Restaurants viewed, clicked, or bookmarked
- Search queries entered in the app or website
- Features used, buttons tapped, and navigation patterns
- Session duration and frequency of app usage
- A/B test group assignments and feature flag states
- Response to push notifications and in-app messages
3.7 Communications Data
- Chat transcripts from in-app customer support conversations
- Email communications with our support, partner, or grievance teams
- Ratings, reviews, and comments submitted on the platform
- Voice call recordings (with consent) between customer and delivery partner or support agent
3.8 Partner-Specific Data (Restaurant Partners)
- Restaurant owner/proprietor full name and contact details
- FSSAI licence number and expiry date
- GST registration number
- Bank account details (account number, IFSC code) for payment settlement
- Business registration and KYC documents
- Menu data, pricing, and restaurant operating hours
3.9 Partner-Specific Data (Delivery Partners)
- Full name, date of birth, and photograph
- Aadhaar Card number (masked) and copy
- PAN Card number and copy
- Driving licence number and copy
- Vehicle registration number (RC Book) and insurance
- Bank account details for weekly earnings payouts
- Continuous GPS location while on active duty (see Section 7)
- Delivery performance metrics, ratings, and incident history
4. Legal Basis for Processing
We process your personal data under the following legal bases:
-
Your consent:
For sensitive personal data (location, financial data),
biometric data processing, and marketing communications.
You may withdraw consent at any time (see Section 11).
-
Contractual necessity:
To fulfil our obligations under the User Agreement,
Restaurant Partner Agreement, or Delivery Partner Agreement
you have entered into with us.
-
Legal obligation:
To comply with applicable Indian laws including the
IT Act, GST Act, Consumer Protection Act, and orders of
competent courts and regulatory authorities.
-
Legitimate interests:
For fraud prevention, platform security, improving our
services, and analytics — provided such interests are
not overridden by your fundamental rights.
5. How We Use Your Data
We use the data we collect for the following specific purposes:
-
Account creation and authentication:
Creating and verifying your account, authenticating logins,
and managing sessions.
-
Order fulfilment:
Processing food orders, assigning delivery partners,
facilitating communication between parties, and tracking
delivery status.
-
Delivery route optimisation:
Using GPS data to assign the nearest available delivery
partner, calculate real-time ETAs, and optimise delivery routes.
-
Personalised restaurant recommendations:
Analysing your order history, search queries, and browsing
behaviour to surface relevant restaurants and cuisines you
are likely to enjoy.
-
Payment processing:
Facilitating secure payment collection, refund processing,
and settlement payments to restaurant and delivery partners.
-
Fraud detection and prevention:
Monitoring account activity, payment patterns, and device
fingerprints to detect and prevent fraudulent transactions,
fake orders, and coupon abuse.
-
Customer support:
Investigating and resolving order complaints, refund requests,
account issues, and grievances.
-
Platform improvement:
Conducting internal analytics, A/B testing, and user research
to improve product features and user experience.
-
Legal compliance:
Maintaining transaction records for statutory periods,
responding to law enforcement requests, and complying with
court orders.
-
Marketing communications:
Sending promotional offers, personalised discounts, and
platform updates via push notifications, SMS, and email
(with your consent; opt-out available at any time).
-
Delivery partner performance management:
Monitoring delivery performance, ratings, and compliance
with our Partner Code of Conduct.
6. Third-Party Data Sharing
We do not sell your personal data to third parties for their independent
commercial use. However, we share specific data with the following
third-party categories as necessary for the functioning of our platform.
We have entered into data processing agreements with all third-party
processors requiring them to maintain equivalent data protection standards.
6.1 Restaurant Partners
When you place an order, we share with the relevant restaurant partner:
- Your first name (for order identification)
-
A masked version of your mobile number (for order clarifications only —
full number is never shared)
-
Complete order details including items, quantities,
customisations, and special instructions
-
Order time and requested delivery time (if scheduled)
We do NOT share your delivery address, last name,
email address, or payment details with restaurant partners.
6.2 Delivery Partners
When a delivery partner is assigned to your order, we share:
- Your first name
- Your precise delivery address (required for delivery)
-
A masked/proxied mobile number for in-app calling
(actual number is never directly exposed)
-
Delivery instructions (e.g., gate code, flat number, landmark)
-
Your real-time location (only if you enable live tracking sharing
for the order)
6.3 Payment Gateway Partners
We share payment initiation data with PCI-DSS certified payment gateway
providers (including but not limited to Razorpay, Cashfree, or equivalent)
for secure transaction processing. These partners do not receive your
order history, location data, or app usage data.
6.4 Cloud Infrastructure & Technology Providers
We use leading cloud service providers (including AWS and/or Google Cloud)
to host our application and databases. These providers have access to
infrastructure level data under strict contractual obligations and are
prohibited from using data for their own purposes.
6.5 Analytics Providers
We use analytics platforms (such as Firebase, Mixpanel, or equivalent)
to understand app usage. These tools receive anonymised or pseudonymised
usage data. They do not receive your name, contact details, or
financial data.
6.6 SMS & Push Notification Providers
We share your mobile number with SMS gateway providers
(e.g., Exotel, Twilio) for OTP delivery and order notifications.
We share your device push token with push notification services
(e.g., Firebase Cloud Messaging) for in-app alerts.
6.7 Legal & Regulatory Authorities
We may disclose your personal data to government authorities,
law enforcement agencies, courts, or regulatory bodies where legally
required, including in response to lawful subpoenas, court orders,
or legal process. We will notify you of such disclosures where
permitted by law.
6.8 Business Transfers
In the event of a merger, acquisition, restructuring, sale of assets,
or insolvency proceedings, your personal data may be transferred to the
relevant successor entity, subject to equivalent privacy protections.
We will notify you of any such transfer within 30 days.
7. Location Data — Detailed Disclosure
Given the sensitivity of location data, we provide this dedicated
section to explain exactly how location is collected and used.
7.1 When You Open the App
We collect your precise GPS location (latitude and longitude,
accurate to approximately 5 metres) to show nearby restaurants
and auto-populate delivery addresses.
7.2 While an Order is Active
We collect your device location in the background to allow you
to see the delivery partner approaching your location on the
live tracking map.
This background location collection stops automatically when
your order is marked delivered or cancelled.
7.3 Delivery Partner Tracking
While a delivery partner is logged in and set to
“Available” or on an active delivery,
their device transmits GPS location to our servers every
5 seconds.
This data is used exclusively for:
- Order assignment
- Route optimisation
- ETA calculation
It is not shared with other users or third parties except as
described in Section 6.2.
7.4 Location History
We retain location data associated with completed orders for
24 months for fraud prevention, dispute resolution, and legal
compliance purposes.
7.5 How to Control Location Permissions
You may revoke location permissions at any time through your
device settings:
-
iOS:
Settings → Privacy → Location Services
-
Android:
Settings → Apps → Hindu Swad → Permissions
Revoking location access will prevent restaurant discovery
and real-time delivery tracking but will not affect your
ability to manually enter a delivery address.
8. Financial & Payment Data — Detailed Disclosure
All payment transactions are processed by PCI-DSS Level 1 certified
payment gateway partners. Hindu Swad operates as a payment aggregator
under RBI guidelines and does not independently store, transmit, or
process cardholder data.
Your payment instrument data (card tokens, UPI mandates) may be stored
in tokenised form by our payment partners to enable faster future
checkouts. This is subject to RBI Tokenisation Guidelines (2022).
Financial transaction records (order values, payment methods, refund
records) are retained for 7 years from the date of transaction in
compliance with the Companies Act, 2013, the Income Tax Act, 1961,
and GST rules.
Restaurant and delivery partner bank account details are stored in
encrypted form and used exclusively for settlement payments.
9. Data Retention
We retain your personal data for the following periods:
-
Account data:
For the duration of your active account, plus 3 years after
account closure or deletion request.
-
Order and transaction history:
7 years from the date of the transaction (statutory requirement).
-
Location data:
24 months from the date of the associated transaction.
-
Customer support records:
3 years from the date of resolution.
-
KYC documents (restaurant and delivery partners):
5 years from the termination of the partnership agreement.
-
Marketing preference records:
Updated immediately upon opt-out; retained for 2 years thereafter
for compliance.
-
Fraud investigation records:
7 years from the date of the incident.
-
Device and log data:
90 days on a rolling basis.
Upon expiry of the applicable retention period, your data will be
securely deleted or anonymised in a manner that prevents
re-identification.
10. Data Security
We implement a comprehensive set of technical, physical, and
organisational security measures, including:
-
Encryption in transit:
All data transmitted between your device and our servers is
encrypted using TLS 1.2 or higher (256-bit SSL certificates).
-
Encryption at rest:
Sensitive data stored in our databases is encrypted using
AES-256 encryption.
-
Access controls:
Access to personal data is restricted on a strict need-to-know
basis using role-based access control (RBAC). All internal
access is logged and audited.
-
Multi-factor authentication:
Required for all internal system access and for high-risk user
account operations.
-
Penetration testing:
We conduct regular third-party penetration testing and
vulnerability assessments.
-
Incident response:
We maintain a documented data breach response plan. In the event
of a breach affecting your personal data, we will notify affected
users and relevant authorities within the timelines required by
applicable law.
-
Vendor security:
All third-party data processors are subject to security due
diligence and contractual security obligations.
-
PCI-DSS compliance:
Our payment systems and payment gateway partners are
PCI-DSS compliant.
11. Your Rights
Under applicable Indian law, you have the following rights with respect
to your personal data. To exercise any right, contact us at
support@hinduswad.com.
We will respond within 30 days.
-
Right of Access:
You may request a copy of all personal data we hold about you.
We will provide this in a structured, machine-readable format.
-
Right to Correction:
You may request correction of any inaccurate or incomplete
personal data.
-
Right to Deletion:
You may request deletion of your account and associated personal
data. Deletion will be completed within 30 days, subject to our
legal retention obligations under Section 9. Data that must be
retained for statutory periods will be quarantined and used only
for compliance purposes.
-
Right to Withdraw Consent:
You may withdraw consent for processing at any time by:
(a) revoking app permissions through device settings;
(b) opting out of marketing through account settings or email
unsubscribe links;
(c) submitting a data processing objection to
support@hinduswad.com.
Withdrawal of consent will not affect the lawfulness of processing
carried out prior to withdrawal.
-
Right to Portability:
You may request a portable copy of your personal data in a
machine-readable format (JSON/CSV) for transfer to another
service provider.
-
Right to Object:
You may object to processing of your data for direct marketing
at any time. You may also object to other forms of processing
based on legitimate interests by demonstrating that your
fundamental rights override our legitimate interests.
-
Right to Manage Location Permissions:
Revoke or modify location permissions at any time through device
settings as described in Section 7.
-
Right to Lodge a Complaint:
If you are unsatisfied with our response, you may file a complaint
with the Consumer Disputes Redressal Commission under the Consumer
Protection Act, 2019, or the Ministry of Electronics and Information
Technology (MeitY) under the IT Act, 2000.
12. Children's Privacy
Our Platform is strictly intended for users who are 18 years of age
or older. We do not knowingly collect, store, or process personal
data of individuals under 18 years of age. Account registration
requires explicit confirmation that the user is 18 or older.
If we become aware that we have inadvertently collected personal
data from a minor, we will:
-
Immediately suspend the account pending investigation.
-
Delete all associated personal data within 72 hours.
-
Notify the parent or guardian if contact information is available.
Parents or guardians who believe their child has created a Hindu Swad
account should contact us immediately at
support@hinduswad.com.
13. Cookies & Tracking Technologies
We use the following tracking technologies on our website and app:
-
Session cookies:
Maintain your authenticated session. Expire when you close
the browser. Cannot be disabled without breaking platform
functionality.
-
Persistent cookies:
Remember your preferences (language, saved addresses,
recent searches). Expire after 12 months.
-
Analytics trackers:
Used by analytics partners to measure app and website usage.
Collect anonymised or pseudonymised data.
-
Advertising identifiers:
Used for measuring the effectiveness of our paid marketing
campaigns. You may opt out by resetting your advertising ID
in device settings.
-
Third-party pixels:
Social media platforms (Meta, Google) may set tracking pixels
on our website for ad measurement. These are subject to the
respective platform's privacy policies.
You may manage cookie preferences through your browser settings.
Disabling cookies other than strictly necessary cookies may affect
website functionality.
14. Cross-Border Data Transfers
Some of our third-party service providers (cloud hosting,
analytics, communication tools) may store or process your data
on servers located outside India.
Where such transfers occur, we ensure that equivalent data
protection standards are maintained through contractual safeguards,
including Standard Contractual Clauses (SCCs) and data processing
agreements.
We comply with all applicable RBI and SEBI data localisation
requirements regarding financial data. Payment transaction data
is stored on servers located in India.
15. Changes to This Privacy Policy
We reserve the right to modify this Privacy Policy at any time.
We will provide notice of material changes through one or more
of the following:
-
A prominent in-app notification at least 30 days before
the change takes effect.
-
An email notification to your registered email address.
-
A notice on the hinduswad.com website.
Material changes that expand our data collection or sharing
practices will require renewed consent where legally required.
Your continued use of the Platform after the effective date of a
revised Policy constitutes your acceptance of the revised Policy.
16. Grievance Officer
In accordance with Rule 5(9) of the SPDI Rules, 2011, and the
Consumer Protection (E-Commerce) Rules, 2020, we have designated
the following Grievance Officer for privacy-related complaints:
17. Contact
For any questions, concerns, or requests regarding this Privacy
Policy or the processing of your personal data:
This Privacy Policy is governed by the laws of the Republic of India.
Hindu Swad Private Limited (CIN: U63120KA2025PTC206410) is registered at
Hindu Swad Pvt. Ltd., Karnataka Regional Office, Bangalore, Karnataka —
560001, India. Any disputes arising out of this Policy are subject to the
exclusive jurisdiction of the courts at Bangalore, Karnataka.