Privacy Policy
Comprehensive data governance, privacy disclosures, and DPDP Act 2023 compliance for BlazeEats customers, ordering services, and cloud kitchen operations.
1. Legal Entity & Regulatory Scope
This Privacy Policy ("Policy") sets forth the data processing practices of BlazeEats Private Limited ("Company", "BlazeEats", "we", "our", or "us"), a private limited company duly incorporated under the provisions of the Companies Act, 2013, with its registered office in New Delhi, India.
This document governs your access to and use of the BlazeEats platform (available via blazeeats.in, mobile web, and associated applications), our cloud kitchen food ordering services, live delivery tracking interfaces, customer support systems, and related digital properties (collectively, the "Platform").
This Policy is formulated in strict accordance with the applicable statutory requirements of India, including without limitation:
- The Digital Personal Data Protection (DPDP) Act, 2023 and rules notified thereunder;
- The Information Technology Act, 2000 (and amendments thereof);
- The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011;
- The Consumer Protection (E-Commerce) Rules, 2020; and
- The Food Safety and Standards Act, 2006 (FSSAI) and Food Safety and Standards (Licensing and Registration of Food Businesses) Regulations.
2. Data Roles under DPDP Act 2023
For the purposes of data protection legislation in India, the roles and responsibilities are defined as follows:
- Data Fiduciary: BlazeEats Private Limited is the Data Fiduciary responsible for determining the lawful purpose, scope, and technical means of processing customer personal data collected via the Platform.
- Data Processors: Vetted third-party infrastructure providers, payment gateways, messaging service aggregators, and contracted logistics partners act as Data Processors strictly on behalf of and under documented data-processing agreements with BlazeEats.
- Data Principal: You, the customer, recipient, or user of our Platform whose personal data is provided or processed in connection with ordering meals, creating accounts, or receiving deliveries.
3. Categories of Personal Data Collected
3.1 Account Identification & Authentication Data
To register, maintain, and authenticate your customer profile, we collect:
- Primary Mobile Number: Used to generate, transmit, and verify cryptographically secure One-Time Passwords (OTPs) for passwordless authentication.
- Full Name & Email Address: Used for account personalization, GST tax invoice generation, and essential transactional notices.
- OAuth Credentials (Optional): If you authenticate via third-party providers such as Google OAuth, we receive only basic public profile information (verified email, full name, profile image). We do not request, access, or store your external passwords, contacts, Google Drive contents, or calendar entries.
3.2 Delivery Address & Geographical Location
To ensure accurate meal dispatch and hyper-local routing:
- Saved Delivery Addresses: House/flat number, building name, street address, area/locality, landmark, city, state, and PIN code.
- Geographical Coordinates: Precise or approximate GPS coordinates collected with your device permission at the time of order placement to locate the nearest operating cloud kitchen and optimize rider navigation.
- Delivery Instructions: Notes provided by you for entry gates, contact preferences, or building security handoffs.
3.3 Order Details, Dietary Preferences & Transaction Data
To fulfill orders and tailor nutritional offerings:
- Order Histories: Items selected, ingredient customizations, portion sizes, preparation notes, allergen alerts, coupon codes applied, and total amounts paid.
- Voluntary Dietary Metadata: Customer-selected dietary flags (e.g., Vegetarian, High-Protein, Low-Carb, Vegan, Dairy-Free).
- Financial Transaction Metadata: Payment method selected (UPI, Credit/Debit Card, Net Banking), transaction reference IDs, and payment clearance status. (Note: We do not store raw card numbers, CVVs, or bank passwords.)
3.4 Customer Support & Communication Recordings
When you interact with our helpdesk, kitchen dispatch, or delivery riders:
- Support Inquiries: Transcripts of live chat sessions, email tickets, feedback ratings, and photographic evidence submitted for damaged/spilled items.
- Masked Rider Communications: For security and privacy, phone calls and text messages between customers and delivery riders are mediated through number masking where available, and call records/metadata may be logged for quality, safety, and dispute resolution.
5. Purpose & Lawful Grounds for Processing
BlazeEats processes personal data exclusively under legitimate, lawful grounds recognized by the DPDP Act 2023 and Indian jurisprudence:
Processing food orders, allocating tickets to our cloud kitchens, packaging fresh meals, dispatching delivery riders, and processing payments.
Issuing GST-compliant tax invoices, maintaining financial audit ledgers under Section 36 of the CGST Act, and adhering to FSSAI food safety regulations.
Investigating delivery disputes, preventing payment fraud, securing customer accounts, and improving cloud kitchen fulfillment speed.
Sending promotional chef specials, loyalty discounts, and nutritional wellness updates where you have opted in.
6. Direct Communications & Opt-Out
We respect your communication preferences:
- Transactional Notifications: Essential order confirmations, live kitchen progress, OTP verifications, and delivery rider alerts sent via SMS, WhatsApp, or push notifications cannot be opted out of, as they are mandatory for order fulfillment.
- Promotional Messages: Marketing communications regarding seasonal discounts, new menu launches, or subscription plans are sent only where permitted. You may opt out of promotional messages at any time by clicking the unsubscribe link in emails or replying "STOP" to marketing SMS.
7. Payment Security & Zero Raw Card Storage
Financial security and customer payment isolation are paramount:
All financial transactions are conducted directly through RBI-authorized, PCI-DSS Level 1 compliant payment gateways (Razorpay). Card details are tokenized in compliance with Reserve Bank of India (RBI) tokenization guidelines. BlazeEats receives only an encrypted transaction token, payment method identifier, and clearance status code to verify payment.
8. Authorized Service Providers & Data Sharing
We strictly maintain a zero-monetization policy: We do not sell, rent, trade, or lease personal customer data to data brokers or third-party advertisers.
We share necessary data solely with authorized, contractually bound service providers essential for platform operations:
9. Technical Safeguards & Data Protection
BlazeEats implements defense-in-depth security standards across all layers of its digital and kitchen infrastructure:
All network communication is secured using TLS 1.3 encryption. All customer records, database clusters, and backups are encrypted at rest using AES-256 standards.
Internal access to customer data is strictly governed by the principle of least privilege, requiring multi-factor authentication (MFA) and immutable audit logging.
10. Statutory Retention & Account Deletion
We retain personal data only for the period necessary to fulfill operational purposes and statutory mandates:
- Active Customer Profile: Stored while your account remains active and in good standing.
- Tax & Accounting Records: In compliance with Section 36 of the Central Goods and Services Tax (CGST) Act, 2017, and applicable corporate laws, financial transaction ledgers, digital tax invoices, and payment tokens are retained for a statutory period of 8 years.
- Account Deletion: You may request deletion of your account at any time via your account settings. Upon verified request, personal identifiers, saved addresses, and profile metadata are permanently deleted or anonymized within 30 days, except for statutory records required to be retained by law.
11. Data Principal Rights & Self-Service Tools
In accordance with the DPDP Act 2023, you are entitled to exercise the following rights:
- Right to Access & Information: Request a summary of the personal data held about you and the processing activities undertaken.
- Right to Correction & Updating: Correct inaccurate, incomplete, or outdated profile and delivery information directly within your account settings.
- Right to Erasure: Request the deletion of your personal data where its retention is no longer necessary for service delivery or statutory compliance.
- Right to Nominate: Nominate an authorized individual to exercise your data rights in the event of death or incapacity.
- Right to Grievance Redressal: Submit inquiries or grievances to our designated Grievance Officer for prompt investigation.
12. Protection of Children & Minors
The Platform is intended exclusively for individuals aged 18 years and older. We do not knowingly solicit, collect, or process personal data from children under the age of 18 without verified parental consent. If we discover that personal data of a minor has been collected without appropriate consent, we will promptly delete such records from our systems.
13. Data Localization & Storage
In compliance with Indian data sovereignty and localization guidelines, customer data, payment transaction logs, and order records are stored and processed primarily in secure data centers located within the territory of India.
14. Grievance Redressal Officer & Contact
In accordance with the Information Technology Act, 2000, and the Digital Personal Data Protection Act, 2023, the details of the designated Grievance Redressal Officer for BlazeEats are published below: