Policy
Privacy Policy
Last updated: August 2026
This Privacy Policy explains how The Tiffin ("we", "us") collects, uses and protects your personal information when you use our website and tiffin delivery service in Jaipur, Rajasthan.
1. Information we collect
- Account details: name, email address, mobile number and password (stored only as a secure hash).
- Delivery details: addresses, map coordinates you confirm, landmarks and delivery instructions.
- Order details: bookings, meal selections, pauses, payments and payment references you submit.
- Communication records: support messages, assistant chats you start, and notification history.
- Technical data: basic logs (IP address, browser type) kept for security and troubleshooting.
2. How we use it
- To prepare and deliver your meals, including sharing your name, address and phone number with the assigned delivery rider.
- To verify payments and maintain your booking, credit and invoice history.
- To send service notifications (order confirmations, delivery updates) on the channels you opt into — WhatsApp and/or SMS.
- To respond to support requests and improve the menu and service.
3. What we do not do
- We do not sell your personal information.
- We do not send marketing messages on channels you have not opted into.
- We do not store card or UPI credentials — payment happens in your own UPI app.
4. Sharing
Your details are shared only with: (a) the delivery rider assigned to your order (name, address, phone, instructions); (b) service providers we use to send notifications you opted into; and (c) authorities when the law requires it.
5. Retention
Order, payment and invoice records are retained as required for accounting and tax. You may request deletion of your account; records we must keep by law are retained and the rest is removed or anonymised.
6. Your choices
- Update your profile, addresses and notification preferences from your dashboard at any time.
- Withdraw notification consent whenever you like — essential service messages may still be sent.
- Contact us to access or correct your information.
7. Security
Passwords are hashed, access to admin systems is role-restricted and audited, and sensitive values are masked in logs. No internet service can promise absolute security, but we design for it.
8. Contact
Questions about this policy: use the Contact & Support page or email us. We aim to reply within two working days.