Introduction
Fudybox Private Limited("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and safeguard your personal information when you use our website, mobile application, and smart vending services (collectively, the "Service").
By using our Service, you consent to the collection and use of information as described in this Policy. We encourage you to read this document in full so you understand your rights and our obligations.
This Policy complies with applicable data protection laws in India, including the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
Information We Collect
We collect information that you provide directly to us and information gathered automatically through your use of the Service.
Personal Information You Provide
- Account details: Name, email address, phone number, and workplace information when you register.
- Payment information: Transaction identifiers and payment method details processed through our secure payment partners. We do not store full card details.
- Order history: Records of meals ordered, machine locations used, and timestamps.
- Communications: Messages or enquiries you send to our support team.
Information Collected Automatically
- Device data: Device type, operating system, browser version, and unique device identifiers.
- Usage data: App interactions, features used, session duration, and navigation paths.
- Location data: Approximate location (when permission is granted) to help you find nearby Fudybox machines.
- Log data: IP address, access timestamps, and error logs for security and diagnostic purposes.
How We Use Information
We use the information we collect for the following purposes:
- Service delivery: Processing and fulfilling your food orders and ensuring accurate machine dispensing.
- Account management: Creating and managing your Fudybox account, authenticating you, and maintaining your preferences.
- Communications: Sending order confirmations, receipts, service updates, and responses to your enquiries.
- Service improvement: Analysing usage patterns to improve our app, machine performance, and restaurant partnerships.
- Personalisation: Recommending meals and restaurants based on your order history and preferences.
- Legal compliance: Meeting obligations under applicable law, resolving disputes, and enforcing our agreements.
- Security: Detecting, investigating, and preventing fraud, abuse, or unauthorised access.
We will not use your personal information for purposes other than those stated above without your explicit consent.
Data Protection
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction.
Our security measures include:
- Encryption of data in transit using TLS/SSL protocols.
- Encryption of sensitive data at rest in our databases.
- Role-based access controls limiting employee access to personal data on a need-to-know basis.
- Regular security audits and vulnerability assessments.
- Secure third-party payment processing with PCI-DSS compliant partners.
Despite these measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to applying industry best practices.
We retain your personal data only for as long as necessary to fulfil the purposes described in this Policy, or as required by law. When your data is no longer needed, we securely delete or anonymise it.
Third-Party Services
We work with trusted third-party service providers to operate and improve our Service. These include:
- Payment processors: For secure handling of financial transactions.
- Cloud infrastructure providers: For hosting, data storage, and application delivery.
- Analytics platforms: For understanding app and website usage (data shared is anonymised).
- Communication services: For sending order notifications, SMS, and email confirmations.
All third-party providers are contractually bound to handle your data confidentially and to use it only for the specific purposes we authorise. We carry out due diligence to ensure they meet appropriate data protection standards.
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We may share aggregated, anonymised data that cannot identify you.
Our Service may contain links to external websites. We are not responsible for the privacy practices of those sites and encourage you to review their policies separately.
Contact Information
You have the right to access, correct, or request deletion of the personal data we hold about you. To exercise these rights or for any privacy-related questions, concerns, or requests, please contact our data controller:
- Company: Fudybox Private Limited
- Email: info@fudybox.com
- Address: Tulips, KKRA 08, Thundathil Road, Kariyavattom, Thiruvananthapuram, Kerala, India – 695581
We will respond to all legitimate requests within 30 days. In certain circumstances, we may need to verify your identity before processing your request.
If you are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction.