1. Overview & Applicability
This Privacy Policy describes the policies and procedures of Tiffino ("we", "our", or "us"),
operated under Bits and Bytes and holding Food Safety and Standards Authority of India (FSSAI)
License No. 22426077001432, regarding the collection, use, disclosure, and protection of your
information when you use our mobile application (Package Name: com.bitsandbytes.tiffino) and our
online services at tiffino.in.
Tiffino operates exclusively as a delivery-first cloud kitchen specializing in 100% whole-wheat chakki atta parathas with zero maida. By downloading, accessing, or using the Tiffino Android application or visiting our website, you consent to the practices described in this Privacy Policy.
2. Information We Collect
We only collect information necessary to fulfill your freshly baked paratha orders, confirm deliveries, and provide a delightful customer experience.
A. Information You Provide Directly
- Authentication Credentials: Your phone number and email address for secure One-Time Password (OTP) login via Firebase Authentication.
- Profile Details: Your full name and optional dietary preferences.
- Delivery Addresses: Street address, apartment/flat number, landmarks, and postal code for routing hot food dispatch.
- Customer Reviews & Feedback: Product reviews, ratings, and culinary feedback submitted inside the app.
B. Information Collected Automatically
- Device Information: Device hardware model, operating system version, unique device identifiers, and network connection type.
- Log & Performance Data: Application crash reports, latency metrics, and interaction analytics to ensure fast load times and crash-free ordering.
3. Device & Location Usage
Our application requests access to your device's Precise and Coarse Location permissions (GPS and network-based location).
Why Tiffino Needs Location Permission:
Because Tiffino is a perishable hot-food cloud kitchen, our dispatch system uses your location strictly to: (1) verify that your delivery address is within our kitchen service radius, (2) provide real-time distance and ETA calculations, and (3) guide our delivery riders accurately to your address.
Location data is only accessed when the application is active in the foreground or while an active order is under delivery. We never track your background location when the app is closed or outside active delivery fulfillment.
4. Live Kitchen Cam Clarification
100% One-Way Broadcast — Zero Customer Recording
The Tiffino Live Kitchen Cam is a strictly one-way broadcast FROM our kitchen TO your screen. Tiffino does NOT request or access your device's camera, does NOT access your microphone, and does NOT capture video, audio, or photographs of our customers under any circumstance.
The live stream is an amenity dedicated entirely to radical culinary transparency — demonstrating that our dough is 100% chakki atta, no maida is ever used, and our tawas and workstations adhere to hospital-grade hygiene standards.
5. How We Use Information
We utilize the collected information strictly for legitimate business and operational purposes:
- Order Processing & Fulfillment: Receiving, baking, packaging, and dispatching your orders.
- Streak Mechanics & Mystery Rewards: Calculating your weekly order count (3x orders/week) to unlock complimentary mystery dishes and rewards.
- Order Notifications: Sending essential SMS, WhatsApp, or Push notifications regarding order receipt, kitchen baking progress, and delivery rider arrival.
- Customer Support: Assisting you via email at
tiffino098@gmail.comwith order queries, refunds, or dietary guidance. - Platform Security: Detecting and preventing fraud, unauthorized logins, and malicious usage.
6. Third-Party Integrations & Sub-Processors
We do not sell your personal data. We share only the minimum required information with vetted third-party technology service providers who adhere to strict data security contracts:
- Google Cloud Platform & Firebase: Provides secure phone authentication, cloud databases (Firestore), and crash diagnostics under SOC 2 and ISO 27001 certified data centers.
- Digital Payment Gateways (e.g. Razorpay / UPI): When you pay for your order, financial transactions are processed directly by RBI-licensed payment aggregators. Tiffino does not collect or store your credit/debit card numbers, CVV, or UPI PINs.
- Delivery Logistics Fleet: Only the recipient name, delivery address, contact phone number, and delivery coordinates are shared with assigned delivery riders to complete drop-off.
7. Account Deletion & User Rights (Google Play Compliant)
In full accordance with Google Play Developer Policy and user privacy standards, Tiffino provides users with full control over their personal data, including the right to delete their account and associated records at any time.
How to Delete Your Account:
In-App Deletion (Instant)
Open the Tiffino Android App > Tap on your Profile / Account tab > Navigate to Settings > Tap Delete My Account and confirm with your OTP.
Email Request Deletion
Send an email from your registered email address to tiffino098@gmail.com with the subject line "Request Account Deletion". Our data compliance team will process your request within 48 to 72 hours.
What Data is Deleted or Anonymized:
- Deleted Immediately: Your user profile, phone number, saved delivery addresses, push notification tokens, and customer reviews written by your account.
- Retained for Legal Compliance: Historical billing invoices and financial ledger entries are anonymized and retained only for the minimum period legally required under Indian taxation (GST) and accounting regulations, without being tied to your identity.
8. Data Retention & Security Safeguards
We employ state-of-the-art technological and physical safeguards to protect your personal information against loss, theft, unauthorized access, disclosure, copying, or alteration.
All communications between the Tiffino application, website, and our cloud databases are encrypted in transit using Transport Layer Security (TLS 1.3). Database access is governed by strict principle-of-least-privilege IAM roles and automated vulnerability audits.
9. Children's Privacy
Our application and services are not directed to children under 13 years of age. We do not knowingly collect
personal identifiable information from children under 13. If you become aware that a child has provided us
with personal information without parental consent, please contact us immediately at
tiffino098@gmail.com so that we may delete such data without delay.
10. Grievance Officer & Contact Information
In accordance with the Information Technology Act 2000 and the Digital Personal Data Protection Act (DPDPA), if you have questions, comments, or grievances regarding this Privacy Policy or our data practices, please contact:
Tiffino Privacy & Grievance Desk
Entity: Tiffino (Bits and Bytes)
FSSAI License: 22426077001432
Support & Privacy Email: tiffino098@gmail.com
Official Website: https://tiffino.in
Package Identifier: com.bitsandbytes.tiffino