Legal
Privacy Policy
Version 2026-09-13 · Aligned with the Digital Personal Data Protection Act, 2023 (DPDP Act) and related rules, as applicable to our restaurant and online ordering operations in India.
1. Scope
This Policy explains how Biryani & Beyond (“we”, “us”) processes personal data when you order online or at the counter, create an account, earn loyalty points, use the Digital Passport, contact us, or visit our website.
2. Data we collect
- Identity & contact: name, mobile number, email, account password (stored as a one-way hash).
- Order data: items, amounts, GST-related bill details, payment status, pickup/delivery notes, order history.
- Loyalty & Passport: points balance, stamp counts, rewards progress, staff-awarded achievements.
- Technical: device/browser type, approximate logs (IP, timestamps) for security, fraud prevention, and consent records.
- Optional: feedback, allergy notes you choose to share, Google profile basics if you sign in with Google.
Counter orders may create a temporary walk-in profile keyed to your mobile number so points and Passport stamps can later merge into your registered account.
3. Purposes & legal bases
We use personal data to:
- Take and fulfil orders, process payments, and provide customer support (contract / legitimate use).
- Operate loyalty and Passport programmes you choose to join (consent / contract).
- Send transactional messages (order status, OTP, password reset).
- Improve menu operations, prevent fraud, and secure our systems.
- Meet tax, accounting, and other legal obligations.
Where the DPDP Act requires consent for a purpose, we will ask for it (for example, at account signup for Terms and this Policy). You may withdraw consent for optional processing where the law allows; this may limit certain features.
4. Sharing
We may share data with:
- Payment gateways and banks to complete transactions.
- Cloud hosting, SMS/email, and analytics providers acting on our instructions.
- Delivery partners when delivery is part of your order.
- Aggregator platforms when you order through them (their policies also apply).
- Professional advisers and authorities when required by law or to protect rights and safety.
We do not sell your personal data.
5. Retention
We keep account and order records for as long as needed to provide the Services and meet tax / legal retention periods, then delete or anonymise where practicable. Consent records (including version and time of acceptance) are retained to demonstrate compliance.
6. Security
We use reasonable technical and organisational measures (including encrypted transport, hashed passwords, and access controls). No method of transmission or storage is perfectly secure; please use a strong unique password.
7. Your rights
Subject to the DPDP Act and other applicable law, you may request access, correction, or erasure of your personal data, and withdraw consent for consent-based processing. Contact us using the restaurant channels on our site. We may need to verify your identity (e.g. registered mobile / email).
8. Children
Our Services are not directed at children under 18 without guardian involvement. We do not knowingly create marketing profiles for children.
9. Cross-border processing
Our primary operations and customer records are intended for India. If a processor stores data outside India, we will do so only as permitted under applicable law and contractual safeguards.
10. Updates
We may update this Policy and will change the version date above. Significant changes affecting consent will be surfaced in the product where required.
11. Contact
For privacy requests, email or call the restaurant using the contact details on the ordering site or your bill, and mark the message “Privacy request”.
Also see our Terms & Conditions.