Privacy Policy
Last updated: REPLACE_WITH_DATE
Intraeats ("we", "us", "the app") is operated by REPLACE_WITH_LEGAL_ENTITY_NAME, registered in India. This page explains what information we collect when you use the Intraeats Android app or our website at intraeats.com, and how we handle it.
1. Information we collect
- Account information: name, email, phone number, password (hashed by Firebase Authentication โ we never see your plaintext password).
- Location data: with your permission, we use your GPS coordinates to find restaurants near you and verify that you're inside the delivery radius. We do not track your location in the background.
- Order data: items ordered, addresses, order totals, and order history.
- Payment data: processed by Razorpay (a PCI-DSS compliant payment processor). We never store your card number, CVV, or UPI PIN on our servers.
- Device data: device model, Android version, app version, and (anonymously) crash reports via Firebase Crashlytics.
- Marketing analytics: if you arrive via a campaign link (e.g. from a Meta/Instagram/WhatsApp ad), we record the click, app open, and (if you place an order) the order so the restaurant can measure their advertising performance. This data is not sold to third parties.
2. How we use your data
- To deliver food orders to your selected address.
- To verify payment via Razorpay.
- To send order status notifications (push notifications via Firebase Cloud Messaging).
- To improve the app (crash reports, anonymized usage analytics).
- To send promotional offers โ only if you've opted in (you can opt out anytime in Settings).
3. Who we share data with
We share the minimum necessary data with:
- The restaurant you order from (your name, address, phone, order items).
- The delivery partner assigned to your order (name, address, phone for delivery).
- Razorpay (payment data โ see Razorpay's privacy policy).
- Google Firebase (authentication, database hosting, crash reports โ see Firebase Privacy).
We do not sell your personal data to advertisers or third parties.
4. Data retention
Account and order data is retained for the duration of your account plus 7 years for tax/legal compliance (GST records). You can request account deletion at REPLACE_WITH_SUPPORT_EMAIL โ we will delete personal data within 30 days, except where retention is legally required.
5. Your rights
You can at any time:
- View and edit your profile in the app (Profile โ Edit Profile).
- Delete saved addresses (Profile โ My Addresses).
- Request a complete data export by emailing REPLACE_WITH_SUPPORT_EMAIL.
- Request account deletion (same email).
- Opt out of promotional notifications (Settings โ Notifications).
6. Children's privacy
Intraeats is not directed at children under 13. We do not knowingly collect data from users under 13. If you believe we have, please contact us.
7. Security
We use HTTPS for all network traffic, Firebase Authentication for password handling, and Razorpay (PCI-DSS Level 1 certified) for payments. Our Firestore security rules enforce strict access control โ see our public rules file if you'd like to verify.
8. Changes to this policy
We may update this policy. Material changes will be announced in the app. Continued use after a change means you accept the updated policy.
9. Contact
Questions? Email us at REPLACE_WITH_SUPPORT_EMAIL
Postal address: REPLACE_WITH_BUSINESS_ADDRESS