Zesday — Privacy Policy
Version: 1.0 (DRAFT) Effective date: [[EFFECTIVE_DATE]]
⚠️ Draft for legal review against the Digital Personal Data Protection Act, 2023 (DPDP) and its Rules as notified, plus the IT Act SPDI Rules, 2011 (to the extent in force). Not effective until reviewed.
Qubrix Technode Private Limited ("Zesday", "we") operates the Zesday platform and is the Data Fiduciary for personal data processed through it. This policy explains what we collect, why, your rights, and how to reach us. It applies to Customers, Restaurant users and Delivery Partners ("you", "Data Principal").
1. Personal data we process
| Category | Examples | Why (purpose) |
|---|---|---|
| Identity & contact | name, phone, email | account, orders, communication |
| Address & location | delivery addresses; live GPS while a rider is on duty; approximate customer location for serviceability | fulfilment, dispatch, tracking, ETA |
| Order & transaction | items, amounts, invoices | processing, support, tax records |
| Payment | tokens/refs from Razorpay (not full card/CVV) | payments, refunds |
| KYC (partners/riders) | PAN, FSSAI/GST, bank, licence, vehicle docs | onboarding, payouts, statutory compliance |
| Device & usage | device, app logs, cookies/identifiers | security, fraud prevention, analytics |
| Communications | support chats, ratings, reviews (incl. review photos) | support, quality, safety |
We collect data directly from you, from your use of the app, and from partners involved in your order. We do not knowingly process data of persons under 18 as customers; children's data protections under DPDP apply and verifiable parental consent is required where relevant.
2. Purposes & legal basis
We process personal data to: create/operate your account; take, fulfil and deliver orders; process payments/refunds/settlements; run dispatch and live tracking; prevent fraud and ensure safety; provide support and grievance redressal; comply with tax, food-safety and other legal obligations; and, with your consent, send promotions. Our bases are your consent (DPDP s.6), performance of the service you request, and legal obligation/legitimate uses as permitted by DPDP.
3. Consent & notice
We present a clear consent notice at or before collection (DPDP requirement), in plain language. You may withdraw consent for consent-based processing at any time in-app; withdrawal does not affect prior lawful processing and may limit service where the data is essential to it.
4. Sharing — and who we do NOT sell to
4.1 We share personal data only as needed with: the restaurant and delivery partner for your order (minimum necessary); Razorpay and banks for payments; communication/mapping/ cloud processors under contract; and authorities where legally required. 4.2 Restaurants and riders may use order data only to fulfil the order and are contractually barred from reusing it. 4.3 We do not sell your personal data. 4.4 Any cross-border transfer occurs only to countries permitted under DPDP and with appropriate safeguards.
5. Your rights (DPDP)
You have the right to: access a summary of your data and processing; correct/complete/update; erase data no longer needed; nominate another person to exercise rights in case of death/ incapacity; and grievance redressal. Exercise these in-app or via our Grievance/Data-Protection contact (§9). We respond within the timeframe the DPDP Rules prescribe.
6. Retention
We keep personal data only as long as needed for the purpose or as required by law. Tax and financial records (invoices, TDS/TCS, settlement, tax_filing_evidence) are retained for the periods required under GST/income-tax law (generally several years). After that, data is deleted or anonymised.
7. Security
We use reasonable technical and organisational safeguards (encryption in transit, access controls, tokenised payments, audit logs). No system is perfectly secure; you help by protecting your OTP/ credentials. On a personal-data breach, we will notify the Data Protection Board and affected Data Principals as required by DPDP.
8. Cookies & analytics
We use cookies/identifiers for login, security, preferences and analytics. You can control non- essential cookies via your device/browser; essential ones are needed for the service.
9. Grievances & Data-Protection contact
- Grievance Officer:
[[GRIEVANCE_OFFICER_NAME]]—[[GRIEVANCE_EMAIL]]—[[GRIEVANCE_PHONE]] - Data-Protection/Nodal contact:
[[NODAL_OFFICER_NAME]]—[[GRIEVANCE_EMAIL]]
We acknowledge within 48 hours and resolve within the statutory timeline. Unresolved DPDP matters may be escalated to the Data Protection Board of India.
10. Changes
We may update this policy; material changes will be notified and, where required, fresh consent requested. The current version and effective date are shown in-app.
Prepared as a draft. Legal review is mandatory before use.