This Privacy Policy ("Policy") describes how Zlice ("Zlice," "we," "us," or "our"), the operator of the Zlice mobile application and website (collectively, the "Platform"), collects, uses, stores, shares, and protects personal data of users ("you," "your," or "User") in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000, and other applicable laws of India.
Zlice operates as a technology platform facilitating food ordering, delivery, and related services within the IIT Kharagpur campus. By accessing or using the Platform, you consent to the practices described in this Policy.
For users under 18 years of age: Please read Section 6 carefully regarding verifiable parental consent requirements.
As the Data Fiduciary under the DPDP Act, 2023:
| Detail | Information |
|---|---|
| Platform Name | Zlice |
| Operating Address | IIT Kharagpur, Paschim Medinipur, West Bengal 721302 |
| Contact Email | privacy@zlice.in |
| Response Time | Within 72 hours of receipt |
*Note: Upon formal incorporation, this section will be updated with registered company details.*
We collect personal data based on lawful purposes and the principle of data minimization. Below is a comprehensive breakdown:
| Data Point | Purpose | Legal Basis |
|---|---|---|
| Full Name | User identification, delivery coordination | Contractual necessity |
| Mobile Number | OTP verification, order updates, delivery coordination | Contractual necessity |
| Email Address | Account recovery, transactional communications | Contractual necessity |
| Institute Email (@iitkgp.ac.in) | Campus affiliation verification | Legitimate interest |
| Roll Number | Campus residency verification, subsidized access | Legitimate interest |
| Hall of Residence | Delivery logistics within campus | Contractual necessity |
| Room Number | Last-mile delivery coordination | Contractual necessity |
| Profile Photo (Optional) | Account personalization | Consent |
| Data Point | Purpose | Retention Period |
|---|---|---|
| Order History | Order fulfillment, customer support, dispute resolution | 8 years (GST compliance) |
| Payment Method (masked) | Transaction processing | Duration of relationship |
| Delivery Addresses | Efficient delivery routing | Duration of account |
| Order Preferences | Personalized recommendations | Until withdrawal of consent |
| Invoices and Receipts | Legal and tax compliance | 8 years |
| Data Point | Purpose |
|---|---|
| Device ID/IMEI (hashed) | Fraud prevention, multi-accounting detection |
| Operating System & Version | App compatibility, troubleshooting |
| IP Address | Security, fraud detection |
| App Version | Technical support |
| Push Notification Token | Delivery updates, promotional messages (with consent) |
We collect location data only when you actively use the Platform for ordering or delivery tracking:
| Type | When Collected | Purpose |
|---|---|---|
| Precise Location | During active order | Show nearby eateries, delivery tracking, ETA calculation |
| Coarse Location | App foreground only | Campus zone identification |
| Data Point | Handling |
|---|---|
| Vegetarian/Non-Vegetarian/Eggetarian filters | Used solely to curate menu options |
| Jain/Halal/Other dietary markers | Stored locally on device when possible |
Commitment: We do NOT use dietary preferences for behavioral profiling, targeted advertising based on religious or cultural inferences, or discriminatory service provision.
| Data Point | Purpose |
|---|---|
| Points Balance | Reward tracking |
| Earning History | Program transparency |
| Redemption History | Fraud prevention, accounting |
| Tier Status | Benefit eligibility |
Your personal data is processed for the following purposes:
We share your personal data only as necessary for service delivery and legal compliance:
| Partner Type | Data Shared | Purpose |
|---|---|---|
| Restaurant Partners | Name, Phone (during active order only) | Order preparation and handover |
| Delivery Partners | Name, Phone, Delivery Address | Order delivery |
| Payment Gateway | Transaction details (encrypted) | Payment processing |
Masking Protocol: Your phone number is masked or replaced with a temporary proxy number during communications with Delivery Partners where technically feasible.
We may disclose your information if required by:
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the successor entity, subject to the same privacy protections.
In accordance with Section 9 of the Digital Personal Data Protection Act, 2023, individuals under 18 years of age are classified as "children." Processing their personal data requires verifiable parental or guardian consent.
Upon signup, you are required to provide your Date of Birth. If you are under 18:
For users identified as under 18, we:
In compliance with Draft Rule 10 of the DPDP Rules:
We retain your personal data as follows:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account Information | Duration of account + 1 year post-deletion | Account recovery, legal disputes |
| Order and Transaction Records | 8 years from transaction date | GST Act, Consumer Protection Act compliance |
| Payment Data | Not stored (processed by payment gateway) | PCI-DSS compliance |
| Location Data | Deleted within 24 hours of order completion | Data minimization |
| Aura Points History | Duration of account + 1 year | Audit trail |
| Support Tickets | 3 years from resolution | Quality assurance, legal disputes |
As a Data Principal, you have the following rights:
You may request a summary of your personal data processed by us and the processing activities undertaken.
You may request correction of inaccurate or misleading personal data. Update your profile directly in-app or contact us.
You may request deletion of your personal data by:
Timeline: Profile data will be erased from active servers within 30 days of request. Data required for legal compliance (e.g., transaction records) will be retained as mandated by law.
You may file a complaint with our support team. If unresolved within 30 days, you may escalate to the Data Protection Board of India.
You may withdraw consent for specific processing activities (e.g., marketing communications) at any time via app settings. Withdrawal does not affect the lawfulness of processing conducted prior to withdrawal.
We implement appropriate technical and organizational measures to protect your personal data:
| Measure | Implementation |
|---|---|
| Encryption | TLS 1.3 for data in transit; AES-256 for data at rest |
| Access Control | Role-based access; principle of least privilege |
| Authentication | OTP-based login; device binding |
| Monitoring | Automated anomaly detection for fraudulent access |
| Incident Response | Breach notification within 72 hours as per DPDP Act |
Your data may be stored on cloud infrastructure (e.g., AWS, Google Cloud) which may have servers located outside India. We ensure that such transfers comply with applicable data protection laws and that adequate safeguards are in place.
The Zlice app uses:
We do NOT use third-party advertising trackers or sell data to ad networks.
If you access Zlice via web browser, we use:
You may control cookie preferences via your browser settings.
The Platform may contain links to third-party websites (e.g., restaurant websites, payment gateways). We are not responsible for the privacy practices of such third parties. We encourage you to read their privacy policies before providing any personal data.
We may update this Privacy Policy from time to time. Changes will be notified via:
Continued use of the Platform after such updates constitutes acceptance of the revised Policy.
For any privacy-related queries, concerns, or requests:
| Channel | Details |
|---|---|
| privacy@zlice.in | |
| Operating Address | IIT Kharagpur, Paschim Medinipur, West Bengal 721302 |
| Response Time | Within 72 hours |
This Privacy Policy shall be governed by and construed in accordance with the laws of India. Any disputes arising under this Policy shall be subject to the exclusive jurisdiction of the courts in Paschim Medinipur, West Bengal.
By using the Zlice Platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.