This Privacy Policy describes how Agrotis Catering Service Private Limited (“we”, “our”, “the Platform”) collects, uses, shares, retains, and protects your personal data when you use the MealMatrix mess-management platform — comprising our web admin panel, our customer mobile app, our counter / point-of-sale app, and our staff mobile app. We are the data fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the data controller under the EU General Data Protection Regulation (“GDPR”) where applicable, for personal data we collect through the Platform.
The mess (canteen / food-service operator) you are registered with is a separate data fiduciary for the operational decisions it makes using the Platform. Where its operational terms differ from this Privacy Policy, this Privacy Policy governs the Platform itself; the operator's terms govern your meal-service relationship with them.
At a glance
A plain-language summary of the key points. It is not a substitute for the full policy below.
- We collect only what running your meals needs — name, contact, orders, and wallet activity.
- Your card / UPI details go straight to the payment gateway; we never see or store them.
- Data is stored in India; payment data and backups are pinned to Indian regions.
- Analytics and crash reporting are off by default — you opt in, and can opt out anytime.
- You can delete your account in-app (More → Privacy → Delete account).
- You have DPDP rights: access, correction, erasure, and consent withdrawal.
- Financial records are kept 7 years where Indian tax law requires it.
- We do not sell your data and do not show targeted ads.
1. Personal data we collect
Depending on the features your mess operator enables, we may collect:
- Identity & contact: name, email address, phone number, postal address, profile photo, roll/ID (member) number, and branch / department.
- Authentication: a one-way hashed password, login session cookies, and one-time passcodes (OTPs, transient).
- Order, wallet & transaction data: what you ordered and when, your wallet balance and top-ups, refunds, rebates, loyalty-point and gift-card balances, and the location at which a wallet transaction took place.
- Payment metadata: the payment gateway's order and payment identifiers and the amounts. See section 2 for what we deliberately never receive.
- Device & technical data: device model, app version, push-notification token (Firebase Cloud Messaging), IP address, and user-agent string.
- Diagnostics (optional): aggregate app-interaction analytics and crash reports, only where you have left the corresponding consent enabled (see section 13).
- Approximate location (optional): coarse location, used at the moment you opt into facility auto-detect to suggest the nearest facility, and/or to record where a wallet transaction took place. Precise (GPS) location is never collected.
- Health-related preferences (optional): dietary restrictions, allergen flags, a diabetic indicator, and free-form dietary notes — only if you choose to provide them. See section 8.
- Biometric / access-card data (operator-dependent): a face or fingerprint template, or an RFID card UID, where your mess uses biometric- or card-based meal pickup and you have given explicit biometric consent. The biometric template is an encrypted, reversible mathematical representation of your enrolment capture — it is not a one-way hash. It is stored under envelope (key-encryption-key / data-encryption-key) encryption and decrypted only transiently, in memory, at the moment a match is computed. See section 8.
- Camera (in-app use only): the member app uses the camera to scan QR codes for pickup; images are processed on-device and are not stored or transmitted.
- Audit data: timestamps and IP / user-agent values associated with significant account events (registration, policy acceptance, login, profile changes).
2. Data we do not collect
- Card / UPI / banking credentials. Your card number, UPI handle, CVV, and net-banking credentials are entered into the payment gateway's own hosted checkout. MealMatrix never sees or stores them; we receive only the gateway's order/payment IDs and the amount.
- Your mailbox, SMS inbox, contacts, photos, files, or calendar. The app does not read these. Bill-splitting uses an in-app roster search, not your device contacts.
- The Android Advertising ID. We do not read it and we do not serve targeted advertising.
3. How we use your data (purposes & lawful basis)
- To provide the meal service — recording orders, charging your wallet, dispatching kitchen tickets, marking attendance, processing rebates and refunds. Lawful basis: performance of the contract you have with the mess.
- To authenticate and secure your account — hashed-password login, sessions, OTPs, fraud-throttling, and anti-money-laundering velocity checks. Lawful basis: a legitimate use necessary to operate the Platform safely under DPDP §7, and to meet our legal obligations.
- To send transactional notifications — wallet credits, order confirmations, password resets, and security alerts. Lawful basis: necessary for the contract.
- To meet legal obligations — tax, accounting, and financial-record retention under the Income Tax Act §44AA and the GST Act §36 of India, and payment-data localisation under the Reserve Bank of India's directions. Lawful basis: legal obligation.
- To improve the Platform — anonymised, aggregated analytics about feature usage, only with your consent. We do not track you across other websites or apps, and we do not serve advertising. Lawful basis: consent.
- For optional biometric meal pickup — only where you have given explicit, granular biometric consent. Withdrawing biometric consent stops any further enrolment or matching of your template. Lawful basis: consent (DPDP §6).
4. Encryption and security safeguards
We apply technical safeguards proportionate to the sensitivity of the data:
- Email, phone number, and (where configured) other identity fields are encrypted at rest using AES-256-GCM with fresh per-row nonces; equality lookups use a separately-keyed HMAC-SHA256 blind index, so the encryption key is never loaded merely to run a search.
- Passwords are stored only as one-way hashes; we cannot recover them and will never ask for them.
- Web traffic is served only over TLS 1.2 or 1.3 with HSTS in production; the member mobile app refuses cleartext HTTP at the operating-system network-security layer (it trusts only system certificate authorities on release builds).
- On your device, the member app stores authentication cookies and session tokens in Android EncryptedSharedPreferences (AES-256-GCM, backed by the Android Keystore / StrongBox where available), and excludes credential data from OS backups.
- Payment-gateway webhooks are verified by HMAC signature, with a freshness window and a database unique constraint, before any balance change — preventing replay and duplicate credits.
- Authentication cookies are HttpOnly, Secure, and SameSite-restricted; sessions expire on a sliding 8-hour window.
- Biometric templates are stored under envelope encryption (a per-tenant key-encryption-key wrapping per-record data-encryption-keys) and are decrypted only transiently, in memory, when a match is computed. They are not irreversible one-way hashes; we protect them with key management commensurate with sensitive personal data, and decrypt only the templates of members who have an active biometric consent.
5. Who we share your data with (sub-processors)
We share the minimum personal data necessary with the processors below. We do not sell your personal data, and we do not share it with advertisers. Which processors apply depends on the features your operator has enabled.
| Processor | Purpose | Data it receives | Region |
|---|---|---|---|
| Razorpay Software Pvt Ltd | Primary payment processing & payouts (hosted checkout) | Name, email, phone, transaction amount; card/UPI/net-banking handled on Razorpay's surfaces | India |
| Google LLC — Firebase Cloud Messaging | Push-notification delivery (mobile app) | Device token, platform, device model, app version | United States |
| Google LLC — Firebase Analytics / Crashlytics | Aggregate app analytics & crash diagnostics (opt-out) | Pseudonymous installation ID, event/crash data; no direct member identifiers | United States |
| Self-managed infrastructure | Data-centre hosting of the application servers, PostgreSQL database, and disaster-recovery backups (self-hosted, not a public-cloud tenancy) | All hosted data; payment-classified stores and DR targets pinned to India | India |
| CloudPe (S3-compatible object storage) | Storage of uploaded files (profile photos, documents) and off-site backup mirroring | Profile photos and uploaded documents; encrypted backup archives | India |
| SMTP relay provider | Transactional email (welcome, password reset, notices) | Email address and message body | Operator-configured |
6. Payments and data residency
Payments are taken through the gateway's hosted checkout; card, UPI, and net-banking credentials are entered on the gateway and never reach our servers. We store only the gateway order/payment identifiers and amounts needed to reconcile your wallet and orders.
Our data residency is India. Payment-classified data stores and their backups are pinned to Indian regions regardless of other configuration, consistent with the Reserve Bank of India's “Storage of Payment System Data” directive and DPDP requirements. Disaster-recovery copies of payment data are not transferred outside India.
7. Cross-border transfers
The Google / Firebase processors listed in section 5 operate from servers outside India. By using push notifications, or by leaving app analytics / crash reporting enabled, you consent (DPDP §16) to the transfer of the limited data described in section 5 to those jurisdictions, on the basis that those processors are bound by their own published data-protection commitments. You may disable push notifications in your device settings or opt out of the optional diagnostics in your account settings at any time; the Platform will continue to function. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
8. Sensitive personal data (DPDP §9 / §17)
If you choose to record dietary preferences, allergens, or biometric identifiers (face or fingerprint template, or NFC/RFID card binding) — where your operator enables these — that constitutes sensitive personal data. We collect it only with your explicit, granular consent gathered at the moment you opt in — never bundled with general account consent. You may withdraw that specific consent at any time through your profile; the related records are purged on the schedule in section 9 and are excluded from any analytics or marketing surfaces. Biometric templates are stored as encrypted, reversible representations under envelope (KEK/DEK) encryption — not one-way hashes — and are decrypted only transiently at match time; any raw enrolment image is discarded once the template has been derived.
9. Retention
- Account profile: for as long as your account is active, plus a short reconciliation window after deactivation.
- Wallet, payment, order, refund & rebate records: retained for at least seven (7) years from the financial year of the transaction, per the Income Tax Act §44AA and the GST Act §36 of India.
- Authentication logs & audit trail: retained for security-investigation purposes, then progressively reduced.
- Push-notification tokens: deleted when you uninstall the app or disable notifications.
- Dietary & allergen preferences: retained while your account is active; purged on erasure within our published erasure SLA.
- Biometric identifiers (face / fingerprint templates): deleted when you exercise your right to erasure or revoke biometric consent. Templates are encrypted, reversible representations (not one-way hashes); superseded templates and erased-account tombstones are purged on a bounded schedule.
- Photo-ID images uploaded for KYC (where applicable): retained for the minimum period required by the operator's KYC obligation (typically 90 days post-verification), then purged.
10. Account deletion
You can request deletion of your account and associated personal data directly in the member app, at More → Privacy → Delete account. The flow shows you the impact (wallet balance, loyalty points, and subscriptions are forfeited; order history is archived), asks you to re-authenticate, and then schedules the server-side erasure. You may cancel the request from the app during the cancellation window before it completes; you can also check its status in the app.
As a fallback, you may request deletion by emailing privacy@mealmatrix.app from your registered address. Where law (for example tax records) requires us to keep a row, we anonymise the personal-data fields on that row instead of deleting it, and retain cryptographic tombstones as required under the Information Technology Act, 2000.
11. Your rights
Subject to the DPDP Act and applicable law, you have the right to:
- Access a copy of the personal data we hold about you.
- Correct personal data that is inaccurate or out of date.
- Erase personal data we no longer need to retain (subject to legal retention above).
- Withdraw consent at any time, without affecting processing already carried out.
- Lodge a grievance with our Grievance Officer (see section 15 below) and, if unresolved, escalate to the Data Protection Board of India.
- Nominate another individual to exercise these rights on your behalf in the event of death or incapacity (DPDP §14).
To exercise any of these rights, contact our Grievance Officer using the details in section 15 below. We acknowledge requests within 72 hours of receipt.
12. Children and the DPDP age gate
Under the DPDP Act, 2023 §9, the Platform does not process the personal data of a child — a person under 18 years — without verifiable parental or guardian consent. We require every new registrant to confirm their date of birth at registration; if it indicates the person is under 18, registration is rejected before any personal data is stored, and the person is directed to the mess operator for a parental-consent pathway. The app's Google Play target audience excludes Children categories. We do not serve targeted advertising, do not engage in behavioural monitoring, and do not process biometric data of children.
13. Cookies, SDK identifiers and analytics
On the web, we use only the cookies necessary to operate authentication and session management. We do not place tracking cookies, advertising pixels, or cross-site analytics.
In the member app, product analytics (Firebase Analytics) and crash/diagnostics reporting (Firebase Crashlytics) are off by default and run only if you enable the corresponding consent. You can change these at any time at More → Privacy, where you can independently opt in or out of analytics, crash reports, personalised recommendations, and marketing emails. A device-installation token is used for push delivery, and a Play Integrity verdict is used for anti-tampering; no Android Advertising ID is read.
14. Changes to this Policy
We post the new version on this page and update the version number and effective date. For material changes affecting your rights, we request your explicit acceptance the next time you log in. Continued use of the Platform after a non-material update constitutes notice of the new version.
15. How to contact us & Grievance Officer
Agrotis Catering Service Private Limited
921, Bharadi, Taluka Sillod, Dist. Chhatrapati Sambhajinagar
Email: support@mealmatrix.app
Web: https://mealmatrix.app
For privacy questions, data-rights requests, and complaints, contact our Grievance Officer, published under the DPDP Act, 2023 and the Information Technology Rules, 2021:
Grievance Officer: Yusuf Bohra
Email: yusufbohra786@gmail.com
Phone: 8793202531
We acknowledge grievances within 72 hours of receipt and aim to resolve them within 15 days. If your data-protection grievance is not resolved to your satisfaction, you may escalate to the Data Protection Board of India.