Customer Privacy Policy
Official privacy charter and personal data protection policy for Gram customers, detailing data collection, processing purposes, mobile app permissions, security standards, DPDP Act rights, account deletion, and grievance redressal.
Introduction, Corporate Identity & Scope
This Customer Privacy Policy (“Privacy Policy” or “Policy”) governs the collection, receipt, storage, processing, transfer, disclosure, and protection of personal information and sensitive personal data collected from customers and end-users (“Customer,” “User,” “you,” or “your”) by Kalp Intelligence Private Limited (“Company,” “Gram,” “we,” “us,” or “our”).
This Policy applies comprehensively to all interactions with Gram, including downloading, browsing, or using our Android and iOS mobile applications, visiting our official website at gramapp.co, subscribing to daily homestyle meal plans, communicating with our support representatives, and availing of our food delivery services.
Corporate & Regulatory Particulars
Gram
U62013KA2025PTC203953
10th June, 2025
Bangalore, Karnataka, India
Statutory Framework & Legal Grounds
We are committed to upholding the highest standards of digital privacy, transparency, and data integrity. This Policy has been formulated in strict compliance with all relevant legislation and rules governing electronic data protection in India, including:
- The Digital Personal Data Protection Act, 2023 (“DPDPA 2023”) and any operational rules notified thereunder, recognizing Gram as a Data Fiduciary and the customer as a Data Principal.
- The Information Technology Act, 2000 (“IT Act”), as amended from time to time.
- The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”).
- The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, concerning grievance officer appointment, user notices, and statutory compliance.
- The Consumer Protection (E-Commerce) Rules, 2020, enacted under the Consumer Protection Act, 2019.
- Reserve Bank of India (“RBI”) Directives regarding Card-on-File Tokenization (CoFT) and electronic payment transaction protocols.
Our lawful grounds for collecting and processing your personal data include: (i) your specific, informed, and unambiguous consent; (ii) necessary performance of our meal delivery contract with you; (iii) compliance with Indian statutory and taxation mandates; and (iv) legitimate business interests such as fraud prevention, platform security, and service reliability.
Categories of Personal Data We Collect
To facilitate food ordering, coordinate preparation with home kitchens, assign delivery partners, and ensure smooth delivery handoffs, we collect the following categories of data:
A. Information You Provide to Us Directly
- Identity & Profile Data: Full name, verified mobile telephone number (primary unique customer identifier for OTP authentication), email address, and optional profile avatar photograph.
- Demographic & Verification Details: Date of birth and anniversary date (used to verify that you are at least 18 years of age and to offer celebratory loyalty meal perks).
- Delivery Addresses & Instructions: Residential or workplace addresses, apartment/flat numbers, floor, landmarks, city, postal code, and geocoded delivery coordinates pinned on the map.
- Dietary Preferences & Culinary Notes: Vegetarian/non-vegetarian preferences, spice level requests, dietary notes, and allergen warnings entered in checkout fields.
- Customer Support & Dispute Records: Transcripts of text chats, ticket correspondence with support, and photographic evidence submitted during refund or meal quality claims (e.g. damaged seal or wrong meal item).
B. Information Collected Automatically Through App & Website Usage
- Geolocation Data: Precise GPS coordinates (latitude, longitude, accuracy radius) collected when you browse nearby home kitchens, set your delivery address, or track active meal deliveries in real time.
- Device & Hardware Telemetry: Device brand, model, operating system name and version, unique device identifier (IDFV on iOS, Android Device ID), mobile carrier name, IP address, and preferred system language.
- Platform Interaction Logs: Log files including access timestamps, screens viewed, search queries for culinary dishes, items added or removed from carts, and system error/crash logs.
- Cookies & Local Storage: Small data tokens stored on your mobile browser or app cache to maintain secure session state and preserve interface preferences.
C. Financial, Billing & Transaction Data
When you pay for your orders via UPI, credit/debit card, net banking, or authorized digital wallets:
- We retain itemized order receipts, total amounts paid, platform and delivery fee breakdowns, payment timestamp, payment mode, and gateway transaction reference numbers.
- Zero Card Data Storage: Gram never captures, views, or stores your 16-digit debit/credit card numbers, CVV security codes, card expiry dates, or banking PINs. All payment transactions are processed through RBI-authorized, PCI-DSS Level 1 compliant Payment Aggregators using RBI-mandated Card-on-File Tokenization (CoFT).
Mobile Device Permissions & Hardware Access
In accordance with Google Play Developer Policy and Apple App Store Review Guidelines, we transparently disclose every hardware and system permission requested by the Gram Mobile Application:
| Permission | Classification | Operational Purpose |
|---|---|---|
| ACCESS_FINE_LOCATION & ACCESS_COARSE_LOCATION | Location (Foreground / Background for Active Deliveries) | Enables auto-detecting your delivery address, calculating delivery distance from partner kitchens, and rendering real-time courier movement on the live tracking screen. |
| CAMERA | Camera (Optional) | Allows you to snap a profile avatar or take direct photographs of damaged food containers, spilled contents, or packaging issues to submit for customer support refund claims. |
| READ_MEDIA_IMAGES / PHOTO_LIBRARY | Storage / Media (Optional) | Allows you to select and upload existing photographs from your gallery for profile customization or attaching visual proof to a refund ticket. |
| POST_NOTIFICATIONS | Push Notifications | Sends critical transactional alerts: order accepted by kitchen, meal in preparation, rider assigned, rider arrived at gate, OTP verification, and subscription renewal alerts. |
| RECEIVE_SMS / SMS Retriever API | SMS Verification | Permits one-touch automatic reading of numerical OTP authentication codes sent via SMS during login without granting Gram access to read personal messages. |
* You can modify or revoke any optional permission at any time through your mobile device’s operating system settings (Android Settings > Apps > Gram > Permissions, or iOS Settings > Gram).
Purposes of Personal Data Processing
Gram processes personal data strictly for legitimate operational, commercial, and legal purposes:
- Account Setup & Authentication: Registering and authenticating your customer account using verified phone OTPs and email notifications.
- Fulfillment of Food Orders & Subscriptions: Transmitting order specifications and dietary instructions to our partner home kitchens, routing courier partners to your doorstep, and managing recurring meal plans.
- Customer Service & Dispute Resolution: Reviewing inquiries, handling delivery delays, replacing items, and processing approved refunds within our 48-hour SLA.
- Platform Safety, Fraud Prevention & Integrity: Preventing fraudulent order bookings, verifying payment authenticity, preventing abusive behavior toward delivery partners, and enforcing our Terms of Service.
- Personalization & Operational Analytics: Recommending regional cuisines based on dietary choices, evaluating kitchen preparation speeds, and optimizing courier dispatch routes.
- Statutory Compliance & Tax Audits: Generating GST invoices, maintaining financial accounts under the Companies Act, 2013, and complying with statutory inspection orders from Indian authorities.
- Direct Marketing & Promotional Offers: Sending updates regarding meal discounts, curated regional menus, and seasonal culinary festivals directly from Gram. You can opt out of non-essential promotional messages at any time.
Data Sharing, Disclosures & Third Parties
Our Strict Non-Sharing & Anti-Monetization Commitment
We do not sell, rent, monetize, or trade your personal data (including your phone number, email, address, date of birth, or order history) to any third-party data brokers, marketing agencies, or external advertising networks. Your data is processed solely to fulfill your meals and operate Gram.
We only share necessary subsets of your data with verified third parties under strict confidentiality agreements:
- Partner Home Kitchens: Provided only with your first name, order items, allergy warnings, and special cooking instructions. Kitchens never receive your private phone number, email address, or billing details.
- Delivery & Logistics Partners:Provided with your first name, delivery address, geocoded map pin, delivery instructions (e.g. “leave at reception”), and a masked telephone contact number via our cloud telephony bridge to facilitate handoff.
- RBI-Licensed Payment Gateways: Transmit order values and transaction identifiers to PCI-DSS compliant payment gateways (such as Razorpay / Cashfree) for secure online payment authorization.
- Cloud Infrastructure & Technical Sub-processors: Encrypted hosting on cloud servers located in India (e.g., AWS / GCP), transactional SMS providers for one-time passwords, and transactional email providers.
- Statutory & Law Enforcement Authorities: Disclosures made exclusively in compliance with valid court orders, written summons, or mandatory statutory requirements under Section 69, 79, or 91 of the Code of Criminal Procedure / Indian criminal law.
Data Storage & Localization in India
In alignment with Indian data sovereignty principles and the provisions of the Digital Personal Data Protection Act, 2023, all primary customer personal data, active databases, transaction logs, and billing archives are stored and hosted within secure cloud data centers located within the territory of India.
In the event that limited technical sub-processing (such as specialized security analytics or crash telemetry) involves cross-border transmission, such transfer is conducted strictly in compliance with central government regulations, utilizing high-grade cryptographic encryption and contractual safeguards.
Reasonable Security Practices & Safeguards
Gram complies with Rule 8 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and international ISO/IEC 27001 data security standards:
Cryptographic Protection
All electronic communications between your mobile device and our backend servers are encrypted in transit using industry-standard TLS 1.3 protocols. Data at rest is secured via AES-256 encryption.
Access Restrictions
Strict role-based access control (RBAC) ensures that only authorized engineers and customer support agents with verified multi-factor authentication can access data strictly needed for resolution.
Vulnerability Assessments
We conduct routine vulnerability scans, dependency audits, and penetration tests to detect and remediate potential security flaws in our application infrastructure.
Incident Response
In the unlikely event of a verified data security breach, we maintain incident protocols to notify affected Data Principals and regulatory authorities in accordance with applicable CERT-In directives.
Data Retention & Account Deletion (Play Store & App Store Compliant)
We retain your personal data only for as long as your Gram account remains active or as needed to provide you with meal subscriptions, enforce agreements, and comply with legal requirements:
- Active Account Data: Maintained for the entire duration of your registered profile.
- Tax & Invoicing Archives: Maintained for up to 8 financial years as mandated under the Goods and Services Tax (GST) Act and the Companies Act, 2013.
- Inactive Accounts: Where an account has had zero login or transaction activity for 24 continuous months, it is slated for automated anonymization.
How to Delete Your Gram Account & Personal Data
In compliance with Google Play Data Safety requirements and Apple App Store Guideline 5.1.1, you have the absolute right to delete your customer account and associated personal data at any time via self-service or direct request:
Option A: In-App Self-Service
- Open the Gram Mobile App on your device.
- Tap your Profile Avatar in the top corner.
- Go to Settings > Privacy & Security.
- Select “Delete My Account & Data”.
- Verify your request via the one-time OTP sent to your registered mobile number.
Option B: Written Email Request
Send an email from your registered email address to hey@gramapp.co with the subject line: “Account Deletion Request”. Specify your registered phone number. Our privacy team will process and confirm deletion within 30 business days.
Upon deletion, your profile details, avatars, saved delivery locations, and marketing identifiers will be permanently removed. Only anonymized order records required for statutory taxation audits will be archived.
Your Rights as a Data Principal (DPDP Act, 2023)
Under the Digital Personal Data Protection Act, 2023, you have clear statutory rights regarding the personal data we hold about you:
Right to Access Information
You can request a summary of the personal data being processed by us, along with the identities of all third parties with whom your data has been shared.
Right to Correction & Updation
You have the right to correct inaccurate or misleading personal data, complete incomplete details, and update obsolete delivery addresses or names.
Right to Erasure / Deletion
You have the right to request the permanent erasure of your personal data when it is no longer necessary for the purpose for which it was collected.
Right of Grievance Redressal
You have the right to readily available grievance redressal provided by our designated Grievance Officer, and can escalate complaints to the Data Protection Board of India.
Right to Nominate
You have the right to nominate another individual who shall, in the event of your death or incapacity, exercise your data principal rights.
Right to Withdraw Consent
You may withdraw consent for promotional emails, SMS notifications, and marketing communications at any time with immediate effect.
Protection of Children’s Privacy
Gram is designed and intended strictly for use by individuals who have attained the age of majority (18 years and above under the Indian Majority Act, 1875).
In strict adherence to Section 9 of the DPDP Act, 2023, we do not undertake tracking, behavioral monitoring, or targeted advertising directed at children, nor do we knowingly process personal data of individuals under 18 years without verifiable parental consent. If we become aware that personal information of a child has been gathered without parental consent, we take immediate steps to delete such data from our servers.
Delivery Verification & 48-Hour Refund SLA
Gram provides fresh homestyle meal deliveries directly from verified neighborhood culinary partners. To maintain accountability and food safety standards:
- Delivery Verification: Delivery partners may log a digital timestamp or capture a photo of the handed-over parcel at your doorstep as proof of completed delivery.
- Issue Reporting & Photographic Evidence: In case of packaging compromise, damaged containers, spoiled meals, or missing dishes, customers are invited to share a photograph via the in-app support chat within 2 hours of delivery.
- 48-Hour Refund Crediting SLA: Once a claim is verified and approved by our support desk, the refund amount is initiated immediately and credited back to your original source of payment (UPI ID, card, or original bank account) within a maximum SLA of 48 hours.
For full terms on meal replacement policies and subscription credits, please inspect our dedicated Refund & Cancellation Policy.
Cookies & Digital Tracking Technologies
Our website and web views utilize essential session cookies and local storage tokens to recognize authenticated users, retain shopping cart selections across navigation, and remember language preferences.
You can configure your browser settings to reject non-essential cookies. However, disabling all cookies may impair certain features of the web platform, such as persistent cart contents or automated address lookups.
Amendments to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our operational procedures, culinary features, or updated statutory rules under the DPDP Act or IT Act.
Whenever material updates are introduced, we will revise the “Last Updated” date at the top of this document, publish the amended policy across our website and mobile application, and notify you through an in-app banner or push notification where legally required.
Statutory Grievance Redressal & Contact Desk
In accordance with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the provisions of the Digital Personal Data Protection Act, 2023, the details of our designated Grievance Redressal & Data Protection Officer are provided below:
Designated Officer:Grievance Redressal & Data Protection Officer
Company Name: Kalp Intelligence Private Limited (Operating brand: Gram)
Corporate Identification Number (CIN): U62013KA2025PTC203953
Registered Office: Bangalore, Karnataka, India - 560001
Grievance & Privacy Email: hey@gramapp.co
Statutory Redressal Timelines:
- Acknowledgement: Within 24 to 48 hours of receiving your written grievance.
- Resolution: Comprehensive investigation and final resolution within 15 business days from the date of receipt, as mandated by Indian intermediary guidelines.
If you have any questions, clarifications, or feedback concerning this Privacy Policy, our data practices, or wish to exercise any Data Principal rights, please reach out directly to hey@gramapp.co.