🌿WasteZeroFood

Legal

Privacy Policy

Effective date: 14 April 2026

1. Who We Are

WasteZeroFood ("we", "our", "us") is a meal management platform for Paying Guest (PG) accommodations in India. We help PG owners, caretakers, cooks, and tenants coordinate daily meals and reduce food waste.

Registered contact: support@wastezerofood.com · +91 9508287279

2. Information We Collect

We collect only what is necessary to operate the platform:

  • Phone number — used for account identification and login. This is the primary identifier on the platform.
  • Email address — collected from tenants at onboarding. Used only to send a PIN reset code if you forget your Quick PIN. Not used for marketing.
  • Name — used to personalise the app and display you to your PG caretaker or owner.
  • Room number — optional, provided by your caretaker during onboarding.
  • Meal bookings and cancellations — records of which meals you booked, cancelled, or were served, for the current month.
  • Meal feedback — ratings and optional comments you submit about meals (taste, quantity).
  • Diet preference — vegetarian or non-vegetarian, provided when you join a PG.
  • Device push token — a browser-generated token used to send you meal notifications (e.g., when food is ready). We do not use this for advertising.
  • Device trust token — a token stored on your device to let you skip OTP on trusted devices. It has no connection to your browsing activity.
  • Payment information — if you are a PG owner paying for a subscription, payment details are processed by Razorpay. We do not store card numbers or UPI credentials on our servers.

3. How We Use Your Information

  • To verify your identity via OTP when you log in
  • To display your name and role within your PG
  • To record and display your meal bookings to your PG's caretaker and cook
  • To send you push notifications — meal ready alerts, booking deadline reminders, menu updates
  • To generate aggregated waste and booking statistics for your PG owner (your individual data is visible only to your PG's owner and caretaker)
  • To process subscription payments for PG owners (via Razorpay)
  • To improve platform features based on anonymised usage patterns

We do not use your data for advertising, profiling, or any purpose not listed above.

4. Who Can See Your Data

Your data is shared within your PG context as follows:

  • Your name and booking status are visible to your PG's owner and caretaker.
  • Your meal feedback (rating and quantity) is visible to the owner and caretaker. Comments are visible to the caretaker only.
  • Your phone number is visible to the PG owner and caretaker for operational purposes.
  • Other tenants cannot see your bookings, feedback, or any personal data.
  • Platform admins (WasteZeroFood staff) may access account data for support and debugging, always with an audit trail.

We do not sell, rent, or trade your personal data to any third party.

5. Third-Party Services We Use

  • AWS SES (Amazon Simple Email Service) — sends PIN reset codes to tenants' email addresses. Your email is transmitted to AWS solely to deliver the code.
  • Fast2SMS — sends OTP SMS to phone numbers for PG owners and caretakers during login. Your number is transmitted to Fast2SMS solely to deliver the OTP.
  • Razorpay — processes subscription payments for PG owners. Razorpay's privacy policy applies to payment data.
  • Railway — cloud hosting provider for our backend and database. Data is stored on Railway's infrastructure in India.
  • Vercel — hosts the web application. No personal data is stored on Vercel's servers.
  • Redis — stores OTPs (expire in 10 minutes) and trusted device tokens. No permanent personal data is stored in Redis.

6. Push Notifications

If you allow push notifications in your browser, we will send you:
  • Meal ready alerts when the cook marks a meal as done
  • Booking deadline reminders (~1 hour before cutoff) if you haven't booked yet
  • Menu confirmations when the caretaker sets tomorrow's menu

You can turn off push notifications at any time in your browser settings. Doing so will not affect your ability to use the app, but you will not receive meal alerts.

7. Data Retention

We retain your data only as long as necessary for the purposes described in this policy:

  • Meal bookings and feedback — retained for 12 months from the date of the booking, then permanently deleted or anonymised.
  • OTPs — deleted automatically after 10 minutes (stored only in Redis, not in the database).
  • Trusted device tokens — expire after 30 days or when you manually remove them from Settings.
  • Account data (name, phone number, role) — retained for as long as you are an active member of a PG on the platform.
  • After leaving a PG — when a tenant is removed (soft-deleted), their personal details are retained for 90 days for audit and dispute purposes, then permanently deleted.
  • After account deletion — all personal data is permanently deleted within 30 days of a confirmed deletion request. Anonymised aggregate statistics (e.g., total meals booked at a PG) may be retained indefinitely as they cannot be traced back to you.
  • Financial records — payment records (amounts, dates, plan type) are retained for 7 years as required by Indian accounting and tax law. These do not include card numbers or UPI details.

To request early deletion of your data, email us at support@wastezerofood.com. We will respond within 7 business days.

8. Your Rights

You have the right to:

  • Access — request a copy of the personal data we hold about you
  • Correction — request that inaccurate data (e.g., wrong name) be corrected
  • Deletion — request that your account and personal data be deleted. You can also do this yourself via Settings → Delete Account.
  • Portability — request your booking history in a readable format
  • Objection — object to any processing of your data that you believe is not justified

To exercise any of these rights, email us at support@wastezerofood.com or call +91 9508287279. We will respond within 7 business days.

9. Data Security

  • All data is transmitted over HTTPS — never over plain HTTP
  • Passwords are hashed using bcrypt and are never stored in plain text
  • OTPs are stored only temporarily in Redis and expire in 10 minutes
  • Admin access to user data is logged and audited
  • Database access is restricted to our application servers — no public access

Despite our measures, no internet service can guarantee 100% security. If you suspect your account has been compromised, contact us immediately.

10. Children's Privacy

WasteZeroFood is not intended for users under 18 years of age. We do not knowingly collect data from minors. If you believe a minor has created an account, please contact us and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will update the effective date at the top of this page. PG owners will be notified via the platform. Continued use of WasteZeroFood after any changes constitutes your acceptance of the updated policy.

12. Governing Law

This Privacy Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Any disputes shall be subject to the jurisdiction of the courts in Bengaluru, Karnataka, India.

13. Grievance Officer

In accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, WasteZeroFood has designated a Grievance Officer to address privacy-related complaints and requests:

Grievance Officer

👤 Manish Kumar

📧 support@wastezerofood.com

📞 +91 9508287279

Complaints will be acknowledged within 24 hours and resolved within 15 days of receipt, in accordance with applicable law.

14. Contact Us

For any privacy-related questions, requests, or complaints:

WasteZeroFood

📧 support@wastezerofood.com

📞 +91 9508287279

Terms of ServiceRefund PolicyFAQ