Legal
Privacy policy
What we hold, why we hold it, who touches it, and how to take it back.
Tiffino / privacy
We collect what delivery needs.
To get a hot paratha from our hands to your door, we need your name, phone, address and order. That's most of it. We don't sell your data, and we never see your card details.
- Account & identity
- Phone & notifications
- Address & location
- Orders & rewards
- Payment outcomes
- FCM device token
What we collect
We only collect what we need to get hot parathas to your door and keep your account working. Here is the full list.
- Account details: your name, email address, Google sign-in identity, and the profile photo you chose.
- Phone number: for order confirmation, delivery calls and OTPs. We mark whether it's verified.
- Delivery addresses: the labels, address lines and default flag you save, plus the pin and location label attached to each order.
- Location: the coordinates you share at checkout, so we can check you're in range and route the rider. We also keep a flag telling us whether the pin was accurate or a rough map position.
- Order history: what you ordered, quantities, extras, what you paid, discounts, delivery fee, promo codes, and any cooking or delivery instructions you wrote.
- Payments: only the outcome — paid, pending, refunded — plus Razorpay's order and payment references. We never see or store card numbers, CVV, or your UPI PIN.
- Device push token: so we can send order updates to this device. You can switch these off.
- Rewards and referrals: your streak progress, rewards earned, milestone claims, referral code, and referrals attributed to you.
- Support records: messages you send us, order issues you report, and photos you attach.
Why we collect it
Every piece of data above has a job. Here's what it's for.
- To cook and deliver: your address, pin, and order details tell our kitchen what to make and our rider where to go.
- To keep the app honest: phone verification and OTPs stop someone placing orders on your number.
- To take your money correctly: order and payment references let us reconcile what you owe and refund what we're returning.
- To run rewards: order history is what counts towards your weekly streak, milestones and referral credits.
- To send updates: your push token and contact details get you order status, OTPs and offers you asked for.
- To keep the service safe: logs, order records and issue reports help us investigate problems and prevent abuse.
Who processes it — Firebase and Razorpay
We don't run everything ourselves. These are the processors that hold your data on our behalf, and each is used only for the job described.
- Google Firebase Authentication handles sign-in. Google gives us your name, email and photo — we never see your Google password.
- Firebase Cloud Firestore stores your profile, addresses, orders, wallet and reward records.
- Firebase Cloud Functions run our server-side logic: payment verification, promo validation, referral codes, loyalty updates and account deletion.
- Firebase Cloud Messaging holds the device push token used for order updates.
- Firebase Cloud Storage holds menu and dish imagery. It doesn't hold your documents.
- Razorpay processes payments. Your card, UPI or netbanking details go straight to Razorpay on their secure screen and never touch our servers. We only receive the transaction result and reference IDs.
- Our delivery and support partners see only what a handover needs: your name, phone, address and order.
How long we keep it
We keep data for as long as there's a reason to, and no longer than the law allows.
- Account data stays while your account is active, so your order history and rewards remain available to you.
- Order and payment records are retained for the period required by Indian tax and accounting law, even after you delete your account.
- Support records are kept as long as needed to resolve the issue and establish a pattern if there is one.
- Marketing preferences and notification tokens are removed as soon as you opt out or close your account.
- When we delete your account, your profile, addresses, referral data and push tokens are removed from Firestore. The minimum we must keep for legal reasons — invoices, transaction records — is retained separately and no longer used to serve you.
Your rights
You can ask for any of this at any time, and we'll action it.
- Access — ask what we hold about you and get a copy.
- Correction — fix a wrong name, phone number or address in your profile, or ask us to correct a record.
- Deletion — close your account and have your data erased, as described below.
- Withdraw consent — turn off marketing messages, or disable location access in your device settings. Note that disabling location may stop you checking out.
- Complain — email us and we'll respond. You also have the right to complain to the relevant data protection authority.
- We don't sell your personal data, and we don't share it for other companies' advertising.
How to delete your account
Deleting your account is permanent and happens inside the app, where we can verify you first. It's not something you can do over email, because we need to be sure it's really you.
- Go to Profile, then the Delete account option, and confirm.
- We'll check for anything in flight — an order on its way, a pending refund, an open issue — and may ask you to settle that first.
- Signing in again after deletion creates a brand new account. Your old order history, wallet balance, streak and referrals won't come back.
- Records we're legally required to keep, such as tax invoices, are retained separately.
- Deleting the app from your phone does not delete your account. You have to do this deliberately, and we'll ask you to confirm.
How we protect it
Reasonable, proportionate safeguards — none of them magic.
- Data in transit is encrypted over TLS. Payment card details are captured by Razorpay in a PCI-compliant environment we never see.
- Access to customer records is limited to staff who need it, and authenticated wherever possible.
- We keep the data we hold to a minimum and avoid collecting anything we have no use for.
- No system is perfect. If a breach affects your data and the law requires it, we'll tell you and the relevant authority without undue delay.
Children
Tiffino isn't aimed at children. If you order for a child, you're the account holder and responsible for the data in it. We don't knowingly collect data directly from children, and if we learn that we have, we delete it.
Changes and contact
We may update this policy as the service changes. The date at the top always reflects the current version, and material changes will be called out in the app.
- This policy was last updated on 24 September 2026.
- Questions, access requests or complaints: email support@tiffino.app and we'll respond.
- Our full commercial terms, including cancellation and refund rules, are in the Terms & Conditions and Refund Policy.
Done with Tiffino?
You can delete your account and erase your personal data from inside the app, where we can verify it's really you. It's permanent — your history, wallet balance, streak and referrals don't come back.
Deleting the app from your phone does not delete your account — you have to do it deliberately from your profile.
© 2026 Tiffino. All rights reserved.
Last updated 24 September 2026. See also our Terms & Conditions and Refund Policy.