MealMatrix
← Legal Center

Privacy Policy

How we collect, use, share, retain, and protect your personal data — and the rights you have under the DPDP Act, 2023.

Version 2.0.0 Effective 17 June 2026
Not legal advice. This policy is informational scaffolding grounded in how the software actually behaves.

This Privacy Policy describes how Agrotis Catering Service Private Limited (“we”, “our”, “the Platform”) collects, uses, shares, retains, and protects your personal data when you use the MealMatrix mess-management platform — comprising our web admin panel, our customer mobile app, our counter / point-of-sale app, and our staff mobile app. We are the data fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the data controller under the EU General Data Protection Regulation (“GDPR”) where applicable, for personal data we collect through the Platform.

The mess (canteen / food-service operator) you are registered with is a separate data fiduciary for the operational decisions it makes using the Platform. Where its operational terms differ from this Privacy Policy, this Privacy Policy governs the Platform itself; the operator's terms govern your meal-service relationship with them.

At a glance

A plain-language summary of the key points. It is not a substitute for the full policy below.

  • We collect only what running your meals needs — name, contact, orders, and wallet activity.
  • Your card / UPI details go straight to the payment gateway; we never see or store them.
  • Data is stored in India; payment data and backups are pinned to Indian regions.
  • Analytics and crash reporting are off by default — you opt in, and can opt out anytime.
  • You can delete your account in-app (More → Privacy → Delete account).
  • You have DPDP rights: access, correction, erasure, and consent withdrawal.
  • Financial records are kept 7 years where Indian tax law requires it.
  • We do not sell your data and do not show targeted ads.

1. Personal data we collect

Depending on the features your mess operator enables, we may collect:

2. Data we do not collect

3. How we use your data (purposes & lawful basis)

4. Encryption and security safeguards

We apply technical safeguards proportionate to the sensitivity of the data:

5. Who we share your data with (sub-processors)

We share the minimum personal data necessary with the processors below. We do not sell your personal data, and we do not share it with advertisers. Which processors apply depends on the features your operator has enabled.

Sub-processors and what each receives
ProcessorPurposeData it receivesRegion
Razorpay Software Pvt LtdPrimary payment processing & payouts (hosted checkout)Name, email, phone, transaction amount; card/UPI/net-banking handled on Razorpay's surfacesIndia
Google LLC — Firebase Cloud MessagingPush-notification delivery (mobile app)Device token, platform, device model, app versionUnited States
Google LLC — Firebase Analytics / CrashlyticsAggregate app analytics & crash diagnostics (opt-out)Pseudonymous installation ID, event/crash data; no direct member identifiersUnited States
Self-managed infrastructureData-centre hosting of the application servers, PostgreSQL database, and disaster-recovery backups (self-hosted, not a public-cloud tenancy)All hosted data; payment-classified stores and DR targets pinned to IndiaIndia
CloudPe (S3-compatible object storage)Storage of uploaded files (profile photos, documents) and off-site backup mirroringProfile photos and uploaded documents; encrypted backup archivesIndia
SMTP relay providerTransactional email (welcome, password reset, notices)Email address and message bodyOperator-configured

6. Payments and data residency

Payments are taken through the gateway's hosted checkout; card, UPI, and net-banking credentials are entered on the gateway and never reach our servers. We store only the gateway order/payment identifiers and amounts needed to reconcile your wallet and orders.

Our data residency is India. Payment-classified data stores and their backups are pinned to Indian regions regardless of other configuration, consistent with the Reserve Bank of India's “Storage of Payment System Data” directive and DPDP requirements. Disaster-recovery copies of payment data are not transferred outside India.

7. Cross-border transfers

The Google / Firebase processors listed in section 5 operate from servers outside India. By using push notifications, or by leaving app analytics / crash reporting enabled, you consent (DPDP §16) to the transfer of the limited data described in section 5 to those jurisdictions, on the basis that those processors are bound by their own published data-protection commitments. You may disable push notifications in your device settings or opt out of the optional diagnostics in your account settings at any time; the Platform will continue to function. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

8. Sensitive personal data (DPDP §9 / §17)

If you choose to record dietary preferences, allergens, or biometric identifiers (face or fingerprint template, or NFC/RFID card binding) — where your operator enables these — that constitutes sensitive personal data. We collect it only with your explicit, granular consent gathered at the moment you opt in — never bundled with general account consent. You may withdraw that specific consent at any time through your profile; the related records are purged on the schedule in section 9 and are excluded from any analytics or marketing surfaces. Biometric templates are stored as encrypted, reversible representations under envelope (KEK/DEK) encryption — not one-way hashes — and are decrypted only transiently at match time; any raw enrolment image is discarded once the template has been derived.

9. Retention

10. Account deletion

You can request deletion of your account and associated personal data directly in the member app, at More → Privacy → Delete account. The flow shows you the impact (wallet balance, loyalty points, and subscriptions are forfeited; order history is archived), asks you to re-authenticate, and then schedules the server-side erasure. You may cancel the request from the app during the cancellation window before it completes; you can also check its status in the app.

As a fallback, you may request deletion by emailing privacy@mealmatrix.app from your registered address. Where law (for example tax records) requires us to keep a row, we anonymise the personal-data fields on that row instead of deleting it, and retain cryptographic tombstones as required under the Information Technology Act, 2000.

11. Your rights

Subject to the DPDP Act and applicable law, you have the right to:

To exercise any of these rights, contact our Grievance Officer using the details in section 15 below. We acknowledge requests within 72 hours of receipt.

12. Children and the DPDP age gate

Under the DPDP Act, 2023 §9, the Platform does not process the personal data of a child — a person under 18 years — without verifiable parental or guardian consent. We require every new registrant to confirm their date of birth at registration; if it indicates the person is under 18, registration is rejected before any personal data is stored, and the person is directed to the mess operator for a parental-consent pathway. The app's Google Play target audience excludes Children categories. We do not serve targeted advertising, do not engage in behavioural monitoring, and do not process biometric data of children.

13. Cookies, SDK identifiers and analytics

On the web, we use only the cookies necessary to operate authentication and session management. We do not place tracking cookies, advertising pixels, or cross-site analytics.

In the member app, product analytics (Firebase Analytics) and crash/diagnostics reporting (Firebase Crashlytics) are off by default and run only if you enable the corresponding consent. You can change these at any time at More → Privacy, where you can independently opt in or out of analytics, crash reports, personalised recommendations, and marketing emails. A device-installation token is used for push delivery, and a Play Integrity verdict is used for anti-tampering; no Android Advertising ID is read.

14. Changes to this Policy

We post the new version on this page and update the version number and effective date. For material changes affecting your rights, we request your explicit acceptance the next time you log in. Continued use of the Platform after a non-material update constitutes notice of the new version.

15. How to contact us & Grievance Officer

Agrotis Catering Service Private Limited
921, Bharadi, Taluka Sillod, Dist. Chhatrapati Sambhajinagar
Email: support@mealmatrix.app
Web: https://mealmatrix.app

For privacy questions, data-rights requests, and complaints, contact our Grievance Officer, published under the DPDP Act, 2023 and the Information Technology Rules, 2021:

Grievance Officer: Yusuf Bohra
Email: yusufbohra786@gmail.com
Phone: 8793202531

We acknowledge grievances within 72 hours of receipt and aim to resolve them within 15 days. If your data-protection grievance is not resolved to your satisfaction, you may escalate to the Data Protection Board of India.

↑ Back to top