Cookzy — Privacy Policy
How we collect, use, and protect your information. Last updated: 12-Jan-2024
Thank you for choosing to be part of our community at Upsway Services Private Limited, doing business as Cookzy ("Cookzy," "we," "us," or "our"). We are the data fiduciary / data controller in respect of personal data processed through the Cookzy mobile application and our website (together, the "App"). We are committed to protecting your personal data and your right to privacy.
If you have any questions or concerns about this privacy policy or our practices with regard to your personal information, please contact our Grievance Officer at contact@cookzy.in (see Section 15). This Privacy Policy should be read together with our Terms of Use.
Table of Contents
- What Information Do We Collect?
- How Do We Use Your Information?
- Legal Basis for Processing
- Will Your Information Be Shared?
- Who Will Your Information Be Shared With?
- How Do We Handle Social Logins?
- Cookies and Tracking Technologies
- How Long Do We Keep Your Information?
- How Do We Keep Your Information Safe?
- Children's Privacy
- Your Privacy Rights
- GDPR Rights (EU Users)
- CCPA/CPRA Rights (California Residents)
- DPDPA Rights (Indian Residents)
- Grievance Officer
- Data Breach Notification
- International Data Transfers
- Automated Decision-Making
- Do-Not-Track Features
- Third-Party Websites
- Cooks' Information
- Policy Updates
- Contact Us
- Review, Update, or Delete Your Data
1. What Information Do We Collect?
Personal Information You Provide
We collect personal data that you voluntarily provide to us when you register, purchase a plan, contact a cook, or contact our support team.
- Name, email, phone number
- Gender, date of birth
- Cook preferences and cooking requirements
- Address, city, and locality
- Allergies and dietary restrictions you choose to share
- Login credentials (passwords are stored as one-way salted hashes)
- Messages, ratings, reviews, and feedback
- Plan purchases, trial bookings, and call history
- Communication preferences
Sensitive Personal Data (SPDI Rules, 2011)
Certain categories — including financial information, identity-document numbers, and any health-related information you choose to share — receive additional protection.
Information Automatically Collected
- Device Data: Device type, model, operating system, app version, and unique installation identifiers.
- Log Data: IP address, network carrier, timestamps, screens viewed, taps, crashes, and diagnostic events.
- Usage Data: Features used, plan and trial activity, daily call counts, and interaction patterns.
- Location Data: Approximate location (derived from IP, city selection, or coarse device location).
2. How Do We Use Your Information?
We process your personal data only for specific, lawful, and proportionate purposes.
- Account creation and authentication
- Listing cooks, matching, and enabling contact
- Processing plan purchases and trial bookings
- Customer support and grievance handling
- Service-related notices, OTPs, and security alerts
- Marketing and promotional messages (only with your consent)
- Personalising your experience and recommendations
- Analytics, debugging, and Service improvement
3. Legal Basis for Processing
For most processing, we rely on the consent you give when you sign up or accept this policy. You can withdraw consent at any time as described in Section 11.
Processing necessary to provide the Services you have requested.
Fraud prevention, security, debugging, defending legal claims.
Processing required to comply with applicable laws (e.g., tax, accounting, anti-money-laundering).
4. Will Your Information Be Shared?
We may share your data in the following situations: with cooks (when you choose to hire), with service providers (vetted vendors), for legal reasons, or in a corporate transaction.
5. Who Will Your Information Be Shared With?
- Payments: Razorpay Payments Pvt. Ltd.
- Cloud & hosting: Google Cloud / Firebase
- Analytics & crash reporting: Google Analytics, Firebase Analytics, Crashlytics, Sentry
- Communications: SMS gateway providers, email service providers
- Support tooling: Helpdesk and ticketing platforms
- Cooks: Independent cooks listed on the Mobile Application
6. How Do We Handle Social Logins?
If you register or log in using a third-party identity provider (such as Google or Apple), we may receive your name, email address, profile picture, and other publicly available information that you have authorised the provider to share.
7. Cookies and Tracking Technologies
We use cookies, mobile advertising identifiers, and SDKs to operate, secure, and improve the Service. Categories include strictly necessary, analytics, functional, and advertising (only with consent).
8. How Long Do We Keep Your Information?
- Account data: Until you close your account, plus up to 90 days for backup rotation
- Transaction & tax records: 8 years (Income Tax Act, GST law)
- Marketing preferences: Until you opt out
- Support communications: 2 years after the last interaction
9. How Do We Keep Your Information Safe?
- Encryption in transit (TLS) and encryption at rest
- Salted, one-way password hashing
- Role-based access controls and audit logging
- Confidentiality obligations on all staff and processors
- Access on a need-to-know basis
- Security training and incident-response procedures
10. Children's Privacy
11. Your Privacy Rights
Obtain a summary of the personal data we hold about you.
Request correction of inaccurate or incomplete personal data.
Request deletion of your personal data, subject to retention exceptions in Section 8.
Email contact@cookzy.in with the subject line "Withdraw consent".
12. GDPR Privacy Rights (EU Users)
For Users in the European Union / EEA
In addition to the rights in Section 11, GDPR gives EU/EEA users the right to data portability, the right to object to automated decision-making, and the right to lodge a complaint with a supervisory authority. Email contact@cookzy.in with subject "GDPR Request".
13. CCPA / CPRA Privacy Rights (California Residents)
For California Residents
Email contact@cookzy.in with subject "CCPA Request". We will respond within 45 days.
14. DPDPA Rights (Indian Residents)
For Users in India
For users in India, this Privacy Policy serves as the "Notice" under Section 5 of the Digital Personal Data Protection Act, 2023. The Data Fiduciary is Upsway Services Private Limited.
DPDPA enquiries: Email contact@cookzy.in with subject "DPDPA Request"
Response time: Within 30 days
15. Grievance Officer
Designation: Grievance Officer, Upsway Services Private Limited (Cookzy)
Email: contact@cookzy.in (subject line: "Grievance")
Postal address: Cookzy, Rajasthan, India
We will acknowledge receipt of a grievance within 24 hours and dispose of it within 15 days.
16. Data Breach Notification
In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as prescribed under the DPDPA. For GDPR users, we notify the relevant supervisory authority within 72 hours of becoming aware.
17. International Data Transfers
We primarily store and process personal data in India. Some service providers may process your data in other jurisdictions (e.g., the United States). All processors are bound by written agreements with equivalent confidentiality and security obligations.
18. Automated Decision-Making
We do not use your personal data for automated decision-making that produces legal effects concerning you or similarly significantly affects you.
19. Do-Not-Track Features
Our App does not currently respond to DNT browser signals because no uniform technical standard has been adopted.
20. Third-Party Websites
21. Cooks' Information
Cooks who register on the Mobile Application also fall within the scope of this Privacy Policy. They have the same rights of access, correction, erasure, and grievance redressal as any other Data Principal.
22. Do We Make Updates to This Policy?
Yes, we may update this policy from time to time. For material changes, we will notify you via in-app notice or email. The updated version will indicate the "Last updated" date at the top of this page.
23. How Can You Contact Us?
Company name: Upsway Services Private Limited
Business name: Cookzy
General enquiries:
contact@cookzy.in
24. How Can You Review, Update, or Delete Your Data?
In-app access
Open the App and go to Settings → Account to view and update your personal information.
Account deletion
- In the App: Settings → Account → Delete Account
- By email: Write to contact@cookzy.in with subject "Delete account". We'll complete deletion within 30 days.