Skip to content

Legal

Privacy policy

What we collect, why we need it, who else sees it, and how to get it back or have it deleted. We sell food, not data — this page is short because there is not much to say.

Effective 10 September 2026. Applies to every order placed on Ready Rasoi.

The short version

  • We never sell your data, and we run no advertising trackers.
  • We never see your card details. They are entered on the payment gateway's systems and never reach ours.
  • We collect what an order needs — an email to verify you, a name and phone so the rider can find you, an address to deliver to.
  • You can ask for your data, or ask us to delete it, at readyrasoifoods@gmail.com.

Who is responsible for your data

Ready Rasoi is the data fiduciary for the personal data described here — meaning we decide what is collected and why, and we are accountable for it under the Digital Personal Data Protection Act, 2023.

Registered office: 243 Santhi Nagar Society SH 167 Surat. Data queries go to readyrasoifoods@gmail.com.

What we collect

  • Your email address — the identity your account is keyed on, verified with a six-digit code.
  • Your name and phone number, as typed at checkout. The phone is the delivery contact and is not verified.
  • Delivery addresses you save or enter, including pincode.
  • Your orders: what you bought, what it cost, the tax charged, the batch each pack came from, and the delivery outcome.
  • Payment metadata — the gateway reference, amount, status and method. Never card numbers, UPI credentials or bank logins.
  • Anything you write to us: support emails, the contact form, notes on an order.
  • Ordinary technical records — IP address, browser, and timestamps in our server logs.

That is the whole list. We do not ask for a date of birth, a gender, an income band or anything else a food order does not need, and we do not buy data about you from anybody.

Why we collect it

  • Taking, packing and delivering your order, and calling you to arrange the delivery.
  • Verifying that the email address on an order belongs to whoever placed it.
  • Taking payment and issuing a refund when one is due.
  • Issuing the GST invoice the law requires for every order.
  • Keeping batch-level traceability, so that if a batch is ever recalled we can reach everyone who received it.
  • Answering your questions and investigating anything that went wrong.
  • Keeping the service secure — rate limits, fraud checks, and finding out what broke.

Most of this is consent: you give us an address because you want the food brought there. Some of it we have no choice about — a GST invoice and batch traceability records are legal obligations, and they are kept even if you ask us to delete everything else.

Marketing

Order emails — your confirmation, the invoice, a delivery update — are part of the service and are sent to everybody who orders. They are not marketing and cannot be turned off while an order is live.

Anything else, such as a newsletter or a note about new dishes, is opt-in only. If you subscribed, every one of those emails carries an unsubscribe link, and unsubscribing takes effect immediately. We do not add customers to a mailing list because they ordered.

Who else sees it

Only these, and each of them only gets what its job requires:

  • Our payment gateway — the order amount and reference, so it can take the payment and process a refund. It handles your card or UPI credentials directly; we never receive them.
  • Our transactional email provider — your email address and the contents of the message being sent, such as a sign-in code or an order confirmation.
  • Our delivery team — your name, address, phone number and what is in the order. Inside Gujarat that is our own staff. Everywhere else in India the order is handed to a courier, who receives the same details because they are what a parcel cannot be delivered without.
  • Our hosting and database providers, who store the data on our behalf under contract.
  • A government authority, court or regulator, where the law actually requires disclosure. We do not volunteer data, and we tell you where we are permitted to.

We do not sell, rent or trade personal data, and we do not share it with advertisers or data brokers. There is no arrangement under which anybody pays us for access to our customers.

How long we keep it

  • Order and invoice records: kept for as long as tax law requires — under the GST rules that is six years from the due date of the annual return for the year the order falls in.
  • Batch traceability records linking an order to the batches it was packed from: kept for at least a year past that batch’s expiry date, so a recall can reach every recipient.
  • Your account, saved addresses and order history: kept while the account exists, and deleted on request except for the records above.
  • Sign-in codes: valid for minutes, and deleted by a scheduled sweep once used or expired.
  • Server logs: kept only as long as they are useful for security and debugging, then rotated away.

Your rights

Under the DPDP Act you have the right to each of the following:

  • Access — ask what personal data we hold about you, and what we have done with it.
  • Correction — have anything inaccurate or incomplete fixed, or anything outdated updated.
  • Erasure — ask us to delete your data, except records we are legally obliged to keep, such as invoices and batch traceability.
  • Grievance — complain to us first, and escalate to the Data Protection Board of India if we do not resolve it.
  • Nomination — name somebody who may exercise these rights on your behalf if you die or become incapacitated.

To use any of them, write to readyrasoifoods@gmail.com from the address on your account — that is how we know it is you. We respond within 30 days, and sooner where we can.

If you are not satisfied with the answer, our grievance officer is Shital Gabani, reachable at the same address. Beyond that, you can complain to the Data Protection Board of India.

Cookies and what is stored in your browser

We use no advertising or cross-site tracking cookies. There is nothing on this site that follows you to another one. What we do set:

WhatWhyHow long
rr_cartIdentifies your basket so it survives a page reload, and so a guest basket can be merged into your account when you sign in.Up to 30 days
Session tokensKeep you signed in after you enter the code from your email. Set httpOnly, so no script on the page — ours or anybody else’s — can read them.Short-lived, renewed while you are active
rr-checkout-keyHeld in your browser’s session storage, not a cookie. Stops a double-click or a refresh at checkout from placing the same order twice.Until the browser tab is closed
rr-visitorAlso session storage, not a cookie. A random number your browser makes up so we can count how many people are on the site at once. It is sent only to our own server, is never linked to an account or an order, and carries no page, device or location.Until the browser tab is closed

The first three are necessary for the site to work — blocking them in your browser will break the basket and sign-in. The fourth only feeds a “people viewing now” number on our own admin screen; block it and the site works exactly the same. Nothing here is used to profile you.

Analytics

We currently run no third-party analytics on this site — no Google Analytics, no advertising pixels, no session recording. If that ever changes we will name the provider on this page and say what it receives, before it is switched on.

The one thing we do count ourselves is how many people are on the site right now. Your browser sends our server an anonymous, made-up id every half-minute while a tab is open; we keep only the last minute of those and show the total to our own team. No page, product, account or location travels with it, and it is discarded within a minute of the tab closing.

How we protect it

  • Traffic is encrypted in transit, and sign-in tokens are httpOnly cookies that no script on the page can read.
  • Card and banking credentials never touch our systems — the gateway handles them, and we store only its reference.
  • Sign-in is by a short-lived code to a verified email, so there is no password of yours for us to lose.
  • Access to customer data inside the business is limited to the people who need it to run orders.

No system is perfect. If a breach ever affects your data we will tell you and the Data Protection Board, promptly and in plain words, rather than quietly.

Children

This service is for adults. We do not knowingly collect data from anybody under 18, and we do not profile or target children. If you believe a child has given us personal data, tell us and we will delete it.

Changes to this policy

When this page changes, the effective date at the top moves with it. If a change materially affects what we do with data we already hold, we will tell you by email rather than relying on you to re-read the page.

Questions about anything here — or a request to see, correct or delete your data — go to readyrasoifoods@gmail.com. For anything about an order instead, the contact page is faster.

Ready Rasoi · FSSAI licence 10726997000216 · GSTIN 24ELVPG2821K1ZT