1. Scope and responsible entity
Yash Taza Dudh Dairy (“we”, “our”, or “us”) provides dairy ordering, subscriptions, delivery, wallet and fulfilment services through its customer app, delivery partner app, website and supporting systems. This policy explains the information handled when you use those services.
2. Information we may collect
- Account and identity: name, mobile number, email address, customer or employee identifier, password hash and account status.
- Address and location: delivery address, area, PIN code, map coordinates and route information supplied for delivery fulfilment. Precise or background location is collected only if enabled in the relevant app for a clearly disclosed delivery feature.
- Orders and subscriptions: products, quantities, schedules, delivery slots, preferences, skips, holds, notes and fulfilment history.
- Payments: payment method, amount, transaction reference, wallet balance, recharge request and uploaded payment evidence. Full card or bank credentials are not stored by us unless expressly disclosed.
- Delivery operations: assigned route, attendance, delivery status, collected payments, proof of delivery, returns and waste records.
- Device and technical information: app version, device identifiers, IP address, diagnostics, security logs and notification token, where used.
- Media: profile, address, delivery or payment images that you intentionally upload or capture.
3. How we use information
- Create and secure accounts and authenticate users.
- Accept, schedule, prepare, route, deliver and support orders and subscriptions.
- Process payments, wallet entries, refunds, approvals and accounting records.
- Send transactional notifications and service communications.
- Prevent misuse, investigate incidents and maintain audit trails.
- Improve service reliability, catalogue planning and customer support.
- Meet tax, accounting, legal and regulatory obligations.
4. How information may be shared
Information is shared only as needed with assigned delivery partners, authorised dairy staff, payment or messaging service providers, hosting and technology providers, professional advisers, and government or law-enforcement authorities when legally required. We do not sell personal information. Service providers are expected to use information only for the contracted purpose and protect it appropriately.
5. Security
We use access controls, password hashing, role-based administration, encrypted network transport where configured, audit records and reasonable operational safeguards. No internet or storage system is completely secure, so absolute security cannot be guaranteed. Users must protect their password and device and promptly report suspected misuse.
6. Data retention
Account and operational data is kept while the account is active and as reasonably needed to provide services. Transaction, invoice, tax, fraud-prevention and audit information may be retained after account deletion when required by law or legitimate business obligations. Data no longer required is deleted or anonymised according to applicable requirements and operational schedules.
7. Access, correction and deletion
You may review or update available profile information in the app or contact support. If the app permits account creation, you may initiate deletion from the in-app account settings and through our public Account Deletion page. We may verify identity before acting. Deletion will remove or anonymise associated personal data except information that must be retained for legal, security, fraud-prevention, tax or accounting reasons.
8. Permissions and consent
The app should request device permissions only when required for a feature—for example camera or media access for uploading evidence, notifications for service updates, or location for delivery operations. Permission may be refused or withdrawn through device settings, although the related feature may stop working. Where sensitive collection is not reasonably expected, an in-app prominent disclosure and consent will be presented before collection.
9. Children’s privacy
The services are intended for adults capable of placing orders and making payments. They are not directed to children under 13. If we learn that a child supplied personal information without appropriate consent, we will take reasonable steps to delete it.
10. Policy changes
We may update this policy when services, legal requirements or data practices change. The revised effective date will be displayed here. Material changes may also be communicated in the app.
11. Contact
For privacy, correction, security or deletion requests, email support@groyaatechnology.in or submit an account-deletion request using the dedicated page. Include your registered mobile number but never send your password, OTP or payment PIN.
