Privacy Policy
Last updated: 2026-07-21 · Compliant with the Digital Personal Data Protection Act, 2023 (India)
1. Who we are (Data Fiduciary)
Yoters (“we”, “us”) operates a cafeteria pre-ordering platform. Under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) we are the Data Fiduciary for the personal data described below, and you are the Data Principal.
2. What personal data we collect
- Account data: name, email address, phone number, and password (stored hashed by our auth provider).
- Order data: items ordered, amounts, order/queue status, and (for delivery) the address you provide.
- Payment data: processed by Razorpay; we store only a payment/order reference, never your card or bank details.
- Approximate/precise location: only when you explicitly allow your browser to share it, to show the restaurant on a map and estimate distance. You can decline; the app still works.
- Technical data: IP address and request metadata, used for security and rate limiting.
- Cookies: essential cookies to keep you signed in and remember your preferences (see our cookie notice below).
3. Why we use it (purposes) & legal basis
We process your data on the basis of your consent (DPDP s.6) and for the following purposes only: creating and managing your account; placing, tracking, and fulfilling orders; processing payments and refunds; sending order-status notifications; security, fraud-prevention and rate-limiting; and complying with law. We practise purpose limitation and data minimisation — we do not use your data for unrelated purposes.
4. Who we share it with (Data Processors)
We share the minimum necessary data with processors that act on our instructions:
- Supabase — database, authentication, and storage.
- Razorpay — payment and refund processing.
- Twilio / Resend — SMS and email notifications.
5. How long we keep it (retention)
We retain account and order data only as long as needed for the purposes above and to meet legal obligations — by default up to 365 days after an order is completed or cancelled, after which records are eligible for deletion or anonymisation. You may request earlier erasure at any time (see your rights below).
6. Your rights as a Data Principal
Under the DPDP Act you have the right to:
- Access a summary of the personal data we hold and how it is processed.
- Correction & updating of inaccurate or incomplete data.
- Erasure — ask us to delete your data and account.
- Withdraw consent at any time, as easily as you gave it.
- Grievance redressal — raise a complaint with our Grievance Officer (below), and escalate to the Data Protection Board of India.
- Nominate another individual to exercise your rights in the event of death or incapacity.
7. Children's data
The service is intended for users aged 18 and over. We do not knowingly process the personal data of a child (under 18) without verifiable consent of a parent/guardian, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children (DPDP s.9). If you believe a minor has provided data without appropriate consent, contact us and we will delete it.
8. How we protect your data
We apply reasonable security safeguards: encrypted transport (HTTPS/HSTS), a strict Content-Security-Policy, server-side authentication and authorisation on privileged operations, server-side payment-signature verification, rate limiting, PII-scrubbed logging, and least-privilege database access. No system is perfectly secure; in the event of a personal-data breach we will notify the Data Protection Board of India and affected Data Principals as required by the DPDP Act.
10. Grievance Officer
For any privacy question, request, or complaint, contact:
Grievance Officer
Email: privacy@yoters.example
We aim to respond within the timelines prescribed by the DPDP Act and its rules.
We may update this policy; material changes will require your renewed consent. See also our Terms of Service.