Privacy Policy
NutriAtta (“we”, “our”, “us”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use nutriatta.com. It is drafted in accordance with the Information Technology Act, 2000, the SPDI Rules, 2011, and the Digital Personal Data Protection Act, 2023 (DPDPA).
By using our services you consent to the practices described here.
1. What we collect
- Account data: full name, email, password (hashed with bcrypt), and phone number.
- Delivery data: address, city, state, pincode, and optional landmarks.
- Health-adjacent data (only if you use the AI Advisor and voluntarily provide it): age, gender, weight, height, activity level, dietary conditions (e.g., diabetic, gluten-free). This is treated as sensitive personal data.
- Order data: your grain mix, order history, delivery status, notes, and cancellation reasons.
- Payment metadata: Razorpay order/payment IDs and payment status. We do not store your card number, CVV, UPI PIN, or bank credentials — Razorpay processes these under PCI-DSS Level 1 compliance.
- Technical data: IP address, browser user-agent, timestamps, referring URL, and standard server logs, used for security and analytics.
- Cookies & local storage: authentication token, session preferences, and dark-mode toggle.
2. Why we collect it (Purposes)
- To create and manage your account.
- To fulfil your orders — grinding, packing, dispatch, and delivery.
- To provide personalized recommendations via the AI Nutrition Advisor.
- To process payments and issue refunds.
- To respond to customer support queries and dispute resolution.
- To detect and prevent fraud, abuse, or security incidents.
- To comply with legal, tax, and regulatory obligations (e.g., GST invoicing).
- With your explicit opt-in, to send promotional emails/SMS about offers and new grains. You can opt out at any time.
3. Legal basis
Under the DPDPA 2023, we process your data based on: (a) your consent given at signup and checkout; (b) the necessity of performing a contract with you (delivering your order); (c) legitimate use such as fraud prevention; and (d) legal obligation where applicable.
4. Who we share it with
- Vendor mills (to grind and pack your atta): receive your name, phone, order contents, delivery address, and pincode.
- Delivery partners (to deliver the parcel): receive your name, phone, and full delivery address.
- Razorpay (payment processor): receives billing name, email, phone, and amount to process the transaction.
- Cloud infrastructure providers (MongoDB Atlas, Emergent, AWS/GCP data centres in India): host data on our behalf under strict data-processing agreements.
- Government / law enforcement: only when compelled by valid legal process.
We never sell your personal data to advertisers or third parties.
5. Where your data is stored
All personal data is stored on secure servers primarily located in India. Backups may be replicated to data centres within the Asia-Pacific region. We use TLS 1.2+ in transit and industry-standard encryption at rest.
6. Retention
- Account data: retained while your account is active, plus up to 3 years after last activity for audit/legal purposes.
- Order & invoice data: 8 years, as required under Indian tax laws.
- Marketing consent: retained until you opt out.
- Anonymised analytics: retained indefinitely for business intelligence.
7. Your Rights (DPDPA 2023)
- Right to access a summary of the personal data we hold about you.
- Right to correction of inaccurate data — you can update most fields from your dashboard.
- Right to erasure (“Right to be forgotten”) of your account and personal data, subject to legal retention obligations.
- Right to withdraw consent at any time (may affect ability to use certain features).
- Right to grievance redressal — contact our Grievance Officer below.
To exercise any right, email privacy@nutriatta.com from the address on your account. We respond within 30 days.
8. Cookies
We use only strictly-necessary cookies and browser localStorage to keep you signed in and remember your preferences. We do not use third-party advertising cookies. You can disable cookies in your browser, but some features (like login) will not work.
9. Children
Our services are not intended for children under 18. We do not knowingly collect data from minors. If you believe a child has provided us data, please contact us so we can delete it.
10. Security
We implement industry-standard controls: bcrypt password hashing, JWT-based session tokens, HTTPS everywhere, role-based access control for staff, and regular security audits. However, no online service is 100% secure. Please use a strong, unique password.
11. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will reflect the latest version.