Privacy Policy
This Privacy Policy explains what information the VKS Palate app and related services (collectively, the “Service”) collect about you, how we use it, and the choices you have. The Service is operated by Vinfraa Lab Private Limited on behalf of the corporate cafeteria your employer has enrolled with us.
By using the Service you agree to the practices described below. If you do not agree, please do not use the app.
1. Information we collect
1.1 Information you provide
- Account details — name, work email, mobile number, and (optionally) profile photo. We use these to identify you and authenticate you in the app.
- Workplace information — the cafeteria, campus, or site your employer has linked you to.
- Order details — items you order, pre-bookings you make, payment status, and notes you add to your order.
- Customer support content — messages, photos, or screenshots you share when you raise an issue.
1.2 Information collected automatically
- Device + push notifications — a Firebase Cloud Messaging (FCM) token so we can send you order-status updates. We do not use this for advertising.
- Location — your approximate or precise location when you are placing an order, used only to confirm you are within your campus boundary. We do not track your location in the background.
- Camera — only when you actively scan a QR code to join a cafeteria or open an order. We do not retain camera frames on our servers.
- Microphone — only when you tap the voice-search button to speak your order. Audio is processed on-device and is not uploaded to our servers.
- Diagnostics — basic crash logs and performance metrics needed to keep the app stable. These do not include the content of your orders or messages.
2. How we use your information
- To authenticate you and keep your account secure.
- To process orders, payments, and refunds.
- To send transactional notifications about your orders.
- To support pre-bookings and corporate meal subsidies.
- To honour cancellations and resolve customer-support requests.
- To comply with applicable laws and prevent fraud or abuse.
We do not sell your personal information, and we do not use the data we collect for advertising or cross-app tracking.
3. Payments
Payments inside the app are processed by third-party gateways — PayU and Razorpay. When you pay, card details and bank credentials are entered directly into the gateway’s interface (PCI-DSS compliant). We never receive or store your full card number, CVV, or banking password. We retain only the payment reference, amount, and outcome so we can settle your order and process refunds.
Wallet balances are stored in your account in our database and are only debited when you place an order, top-up, or your employer auto-loads a subsidy.
4. Sharing your information
We share information only as needed to operate the Service:
- Your employer / cafeteria operator — order summaries, subsidy usage, and aggregate counts required for attendance, billing, or chargeback. We do not share message content or personal device data unless required by law.
- Restaurants / kitchen staff — your name and the specific items in your order, so they can prepare and hand over the food correctly.
- Service providers — Firebase (Google) for push notifications, PayU and Razorpay for payments, and our cloud hosting provider (AWS Mumbai region) for the back-end servers. These providers act on our instructions under written contracts.
- Legal — to comply with court orders, lawful requests, or to protect the rights, property, or safety of our users, our staff, or the public.
5. Data retention
| Category | Retention period |
|---|---|
| Account profile | Until you delete the account, your employer ends your enrolment, or your account is inactive for more than 90 consecutive days — whichever comes first. After that we automatically delete your personal profile and related identifiers (see §5.1). |
| Order & payment history | 7 years (financial record requirement under Indian law). |
| FCM push tokens | Until you log out, change devices, or revoke push permission. |
| Support tickets & messages | 3 years from resolution. |
| Crash logs & diagnostics | 90 days, then aggregated. |
5.1 Automatic deletion of inactive accounts
If you do not sign in, place an order, or take any other action inside the app for 90 consecutive days, your account is treated as inactive and is deleted automatically. We do this to minimise the personal data we hold about people who no longer use the Service.
What we mean by “activity” is any of: signing in, opening the app while signed in, placing an order, making a pre-booking, topping up your wallet, raising a support ticket, or tapping a push notification.
What gets deleted. Your profile (name, email, mobile number, photo, FCM push tokens, saved addresses, dietary preferences, wallet balance, authentication credentials and sessions, and any support content tied to your account).
What we keep, and why. Order and payment records are retained for the 7-year financial-record period required under Indian tax and accounting law, but they are de-identified — the personal identifiers above are stripped and only an anonymous customer reference remains so the records can be reconciled to invoices and tax filings without pointing back to you.
Heads-up before we delete. Before the 90-day mark, we send a reminder email to your registered work email address. If you sign in at any point after that reminder, the inactivity counter resets to zero and your account stays.
Re-joining later. If your employer re-enrols you after an auto-deletion, you will start with a fresh account. We cannot restore the previous profile.
6. Security
Traffic between the app and our servers is encrypted using TLS 1.2+. Passwords are stored as one-way bcrypt hashes. Auth tokens live in your device’s secure storage (Keychain on iOS, Keystore on Android). Database backups are encrypted at rest. We restrict access to production data to a small number of authorised engineers, on a need-to-know basis.
No system is perfectly secure. If we ever discover a breach affecting your data, we will notify you and the appropriate authorities as required by law.
7. Your rights
You can, at any time:
- Access the data we hold about you, by writing to the contact email below.
- Correct your account profile inside the app or by writing to us.
- Delete your account and the personal data tied to it. We retain financial records and aggregated, non-identifying analytics as required by law.
- Withdraw consent for optional permissions (location, microphone, camera, push notifications) from your device’s system settings.
- Export a copy of your order history in machine- readable form.
8. Children
The Service is intended for adults using a corporate cafeteria benefit. It is not directed at children under 18, and we do not knowingly collect personal information from anyone under 18. If you believe we have collected information from a child, please contact us and we will delete it.
9. International transfers
Our servers are hosted in India (AWS Mumbai). Some sub-processors (e.g. Firebase) may process limited operational data outside India. Where that happens, we rely on standard contractual safeguards.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page and, for material changes, surface a notice inside the app. Continued use of the Service after a change indicates your acceptance of the updated policy.
11. Contact us
Vinfraa Lab Private Limited · VKS Palate Privacy Team
Email:
privacy@vinfraa.com
Web: app.vinfraa.com