This Privacy Policy explains how Spoon (the "Service"), an online food-ordering platform for the TCET canteen, collects, uses, and protects your personal data. It is written in line with India's Digital Personal Data Protection Act, 2023 (DPDP Act). By using Spoon, you consent to the practices described here.

1. Data We Collect

  • Account data: your email address and the name (nickname) you provide.
  • Contact data: a phone number, if you choose to provide it for order notifications.
  • Order & wallet data: your order history, order status, and Spoon Wallet balance.
  • Payment data: processed by our payment partner. We receive a payment reference/confirmation but do not store your card, UPI, or banking details.
  • Technical data: a login session token and basic request information needed to keep you signed in and to protect the Service from abuse.

2. Why We Collect It (Purpose)

  • To create and secure your account and sign you in via email one-time passcode (OTP).
  • To process, prepare, and fulfil your orders and issue Spoon Wallet refunds.
  • To send you order-status notifications (e.g. "Ready for Pickup").
  • To operate, secure, and improve the Service and prevent misuse.

We use your data only for these purposes and do not sell it.

3. Third-Party Processors

Spoon relies on the following trusted service providers to operate. Your data is shared with them only as needed to run the Service:

  • Supabase — hosts our database, which stores your account, order, and wallet data.
  • Razorpay — processes your payments securely.
  • Upstash — temporarily stores login OTPs and rate-limiting data.
  • Email delivery (SMTP) — sends your OTP and order-notification emails.
  • Google Cloud Run — hosts the application that runs the Service.
  • Web Push — delivers browser notifications, if you enable them.

These providers may store data on cloud infrastructure. We do not use advertising or analytics trackers that profile you.

4. Data Retention

We keep your account, order, and wallet data for as long as your account is active or as needed to provide the Service and meet legal/operational requirements. Login OTPs are short-lived and expire within minutes. You may request deletion of your account and data (see "Your Rights").

5. How We Protect Your Data

  • Data is transmitted over encrypted (HTTPS/TLS) connections.
  • Access to production data is restricted, and payments are handled by a PCI-compliant partner (Razorpay).
  • Database access is governed by row-level security so users can only access their own records.

No method of transmission or storage is 100% secure, but we take reasonable measures to protect your data.

6. Local Storage on Your Device

Spoon stores your login/session information and cart in your browser's local storage so you stay signed in and your cart is remembered. This data stays on your device and can be cleared any time via your browser settings or by logging out.

7. Your Rights (DPDP Act)

You have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate or incomplete data.
  • Request deletion of your account and personal data.
  • Withdraw consent (note: this may prevent you from using the Service).
  • Raise a grievance with our Grievance Officer.

To exercise any of these rights, contact our Privacy Contact below.

8. Children

Spoon is intended for TCET students. If you are under 18, you should use Spoon only with the consent of a parent or guardian, in line with the DPDP Act. We do not knowingly collect data from children without such consent.

9. Changes to This Policy

We may update this policy from time to time. Changes will be posted on this page with an updated "Last Updated" date.

10. Privacy Contact & Grievance Officer

Arjun Yadav — Privacy Contact & Grievance Officer

imarjunyadav@hotmail.com

9152116021