Privacy Policy

Last updated: February 23, 2026

Effective date: February 23, 2026

This Privacy Policy ("Policy") describes how EatingMinds ("Company," "we," "us," or "our") collects, uses, stores, shares, and protects your personal data when you use the EatingMinds platform, website (eatingminds.com), mobile applications, and related services (collectively, the "Service").

This Policy is published in compliance with the Information Technology Act 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, and the Digital Personal Data Protection Act 2023 ("DPDPA") of India.

By using the Service, you consent to the collection and use of your data as described in this Policy. If you do not agree, please do not use the Service.

1. Information We Collect

1.1 Information You Provide Directly

CategoryData CollectedPurpose
AccountName, email address, Google/LinkedIn profile IDAuthentication, account creation
ProfileAge, gender, profession, bio, city, profile photosDisplaying profile to other users, matching
ContactPhone number (optional, only when you choose to share)Shared with confirmed meal partners only
Meal DataAvailability listings, preferences, meal type, time, location, payment preference, vibe tagsDiscovery, matching, displaying listings
CommunicationsMessages sent to meal partners, support requestsFacilitating meal coordination, customer support
ReviewsRatings and comments about meal partnersTrust and safety, quality improvement
Social HandlesInstagram, LinkedIn, Facebook usernames (optional)Displayed on profile for social verification

1.2 Information Collected Automatically

CategoryData CollectedPurpose
Device InfoDevice type, operating system, browser type, screen resolutionService optimization, debugging
Usage DataPages visited, features used, actions taken, timestampsAnalytics, improving user experience
LocationGPS coordinates (only when permission granted), IP-based approximate locationShowing nearby meals, distance calculations
Log DataIP address, access times, referring URLs, error logsSecurity, debugging, fraud prevention

1.3 Information from Third-Party Authentication

When you sign in via Google or LinkedIn, we receive your name, email address, and profile picture from those services. We do not receive or store your Google/LinkedIn passwords. We access only the minimum data required for authentication as authorized by you during the sign-in process.

2. Lawful Basis for Processing (DPDPA 2023)

Under India's Digital Personal Data Protection Act 2023, we process your data based on:

3. How We Use Your Information

4. How We Share Your Information

4.1 With Other Users

4.2 With Service Providers

We share data with trusted third-party service providers who assist in operating the Service:

ProviderPurposeData Shared
Microsoft AzureCloud hosting, database, file storageAll service data (encrypted at rest and in transit)
GoogleAuthentication (Sign-In)OAuth tokens (no passwords)
LinkedInAuthentication (Sign-In)OAuth tokens (no passwords)
Azure Communication ServicesTransactional emailsEmail address, notification content
OpenStreetMap / PhotonLocation search and geocodingSearch queries, coordinates (no user identifiers)

All service providers are contractually obligated to process data only as instructed by us and to maintain appropriate security measures.

4.3 For Legal Reasons

We may disclose your information if required to do so by law or in response to:

4.4 Business Transfers

In the event of a merger, acquisition, or sale of all or a portion of our assets, your data may be transferred as part of that transaction. We will notify you via email or prominent notice on the Service before your data is transferred and becomes subject to a different privacy policy.

4.5 What We Do NOT Share

5. Data Storage and Security

5.1 Storage Location

Your data is stored on Microsoft Azure servers. While our primary infrastructure is hosted in Azure regions, data may be processed in data centers outside India as part of Azure's global infrastructure. By using the Service, you consent to this transfer, provided that appropriate safeguards are in place.

5.2 Security Measures

We implement industry-standard security measures including:

While we strive to protect your data, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.

5.3 Breach Notification

In the event of a data breach that is likely to result in a risk to your rights, we will notify affected users and the relevant Data Protection Board of India as required under the DPDPA 2023, within 72 hours of becoming aware of the breach.

6. Data Retention

Data TypeRetention Period
Active account dataAs long as your account is active
Deactivated account data30 days after deactivation (then permanently deleted)
MessagesRetained while both users have active accounts. Deleted when either user deletes their account.
ReviewsRetained to maintain platform trust. Anonymized if the reviewer's account is deleted.
Log/analytics data90 days (aggregated/anonymized data may be retained indefinitely)
Legal compliance dataAs required by applicable law (typically 3-8 years for financial/legal records)

7. Your Rights

Under the DPDPA 2023 and applicable law, you have the following rights:

7.1 Right to Access

You may request a summary of your personal data that we process. Your profile information is always accessible through the app.

7.2 Right to Correction

You may update or correct your personal data at any time through the Edit Profile feature in the app, or by contacting us.

7.3 Right to Erasure (Right to be Forgotten)

You may delete your account through Settings > Delete My Account. This will:

Certain data may be retained beyond 30 days where required by law or for legitimate business purposes (e.g., preventing re-registration of banned users, legal compliance).

7.4 Right to Withdraw Consent

You may withdraw your consent to data processing at any time by deleting your account. Withdrawal of consent does not affect the lawfulness of processing based on consent before withdrawal.

7.5 Right to Grievance Redressal

If you believe your data has been processed in violation of your rights, you may raise a grievance with our Grievance Officer (see Section 12) or file a complaint with the Data Protection Board of India.

7.6 Right to Nominate

Under the DPDPA 2023, you have the right to nominate another individual to exercise your data rights on your behalf in the event of your death or incapacity. To register a nominee, contact us at privacy@eatingminds.com.

8. Location Data

We collect location data in two ways:

We do not track your location in the background. Location is only accessed when you actively use the Discover or Circles features.

9. Cookies and Local Storage

We use the following client-side storage:

TypeNamePurposeDuration
Local Storageeatingminds-authStores your authentication sessionUntil logout
Local Storageem-themeStores your dark/light mode preferencePersistent
Local Storageem-email-notif, em-push-notifNotification preferencesPersistent
Session Storagelinkedin_oauth_stateCSRF protection during LinkedIn loginSession only

We do not use third-party tracking cookies. We do not use cookies for advertising purposes. If we implement analytics in the future (e.g., Google Analytics), we will update this Policy and provide opt-out mechanisms.

10. Children's Privacy

The Service is strictly intended for users aged 18 and above. We do not knowingly collect personal data from anyone under the age of 18. If we become aware that we have collected data from a person under 18, we will promptly delete that data. If you believe a minor is using the Service, please report it to safety@eatingminds.com.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes:

Your continued use of the Service after the effective date of changes constitutes acceptance of the updated Policy.

12. Grievance Officer

In accordance with the Information Technology Act 2000 and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, the Grievance Officer for EatingMinds is:

Grievance Officer

EatingMinds

Email: eatingminds.care@gmail.com

Response time: Acknowledgment within 24 hours; resolution within 15 days of receipt

If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India as established under the DPDPA 2023.

13. Contact Us

For any questions, concerns, or requests related to your privacy, contact us at:

EatingMinds

Email: eatingminds.care@gmail.com

By using EatingMinds, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and use of your data as described herein. This Policy should be read together with our Terms of Service.