SnakTap · Legal
Privacy Policy
SnakTap, operated by SnakTap (Fenebris) (registered office: Bengaluru, Karnataka, India), is the Data Fiduciary for personal data we collect through the Platform.
This Privacy Policy describes what we collect, why, how we use it, who we share it with, and the rights you have as a Data Principal under the Digital Personal Data Protection Act, 2023 (the "DPDP Act"). If you have questions about anything below, write to our Data Protection Officer at info@snaktap.com.
01Notice - what we collect & why
| Category | Examples | Purpose | Lawful basis |
|---|---|---|---|
| Identity | Name, email, phone, password hash | Account creation, authentication, communication | Consent (§6) + contract performance (§7(a)) |
| Order / transaction | Items ordered, delivery address, totals, payment status | Order fulfilment, support, refunds | Contract performance (§7(a)) |
| Merchant KYC | PAN, GSTIN, cancelled cheque, bank account (last 4 + IFSC + holder name) | Statutory verification before live payments, GST §9(5) attribution, TDS §194-O reporting | Compliance with law (§7(b)) + contract (§7(a)) |
| Device + technical | IP address, user-agent, push tokens (FCM) | Security, fraud prevention, push notifications you opted into | Consent (push) + legitimate use (§7(c) security) |
| DPDP consent record | Privacy-policy version + timestamp accepted | Audit-trail proof of consent | Compliance with law (§7(b)) |
| Audit log | Admin action records (approvals, rejections, KYC re-verifications, password resets) | Forensic review, dispute resolution | Legitimate use (§7(d) compliance) |
Payment data
We do not store raw card numbers, UPI VPAs, or net-banking credentials. Our payment processor (PayU India) handles these under its own PCI-DSS scope. We retain only a tokenised reference plus the last four digits and card brand for display, never the full PAN of the card.
02How we use your data
- To create and maintain your account and process the orders you place
- To send transactional notifications (order status, refunds, password resets, monthly TDS reports) by email, SMS, push, or WhatsApp where you have opted in
- To verify Merchant KYC documents with statutorily-recognised verification providers (Surepass / Karza / IDfy or equivalents) before activating live-payment processing
- To compute and report 0.1% TDS under §194-O of the Income-Tax Act, 1961, and 5% GST under §9(5) of the CGST Act, 2017, where applicable
- To detect, prevent, and investigate fraud, abuse, or violation of our Terms
- To improve the Platform via aggregated, anonymised analytics
03Sharing & subprocessors
We share personal data only as needed to deliver the service. Our active subprocessors:
| Subprocessor | Purpose | Data shared |
|---|---|---|
| PayU India | Customer order payment processing + merchant subscription charges | Order amount, customer name/email/phone (for receipts), merchant subscription details |
| Surepass | KYC verification (NSDL PAN, GST portal, NPCI penny-less) | PAN number, GSTIN, bank account number + IFSC + holder name |
| SendGrid | Transactional email delivery | Email address + email body |
| Twilio | SMS + WhatsApp transactional messaging | Phone number + message body |
| MSG91 | OTP delivery | Phone number + OTP body |
| Cloudinary | Image storage (menu items, KYC docs, review photos) | Uploaded image bytes |
| Firebase Cloud Messaging | Mobile + web push notifications (when enabled) | FCM device token |
| Sentry | Error monitoring | Stack traces, request IDs (sensitive headers redacted) |
| Groq | AI menu-import OCR (merchant-side) | Menu image (transient) |
| Turso (libSQL) | Database | All persisted application data |
| Render | Application hosting | All inbound HTTP requests |
We disclose personal data to tax authorities as required by law. We may disclose data when compelled by a valid legal process. We do not sell personal data to advertisers or third-party marketers.
04Cross-border transfer
Some subprocessors host data outside India:
- Sentry - United States / European Union
- Firebase - United States (Google)
- Cloudinary - United States / European Union
By using the Platform you consent to such transfer. Our complete subprocessor list and the regions they host data in is available on request from info@snaktap.com.
05Retention
- Account data - kept while your account is active. After deletion (see §6), profile fields are anonymised within 30 days.
- Order, invoice, and tax records - retained for 8 years to comply with the GST Act and Income-Tax Act record-keeping rules. These records persist after account deletion in anonymised form.
- Audit log - retained for 3 years for forensic investigation and regulatory enquiries.
- Push tokens - deleted when you disable notifications or sign out.
- Idempotency keys - automatically expire 24 hours after creation.
- Cart sync data - retained while you have an active cart; replaced on every sync write; cleared when you check out or sign out.
06Your rights as a Data Principal (DPDP §11)
You can exercise the following rights at any time. The endpoints below are wired into the SnakTap dashboard's My Privacy page; you can also call them directly with your access token:
- Right to access - download every record we hold about you as a JSON file:
GET /api/me/data-export - Right to correction - edit profile fields directly; submit a correction request for records you cannot edit:
POST /api/me/data-correction. Admin reviews and applies within 7 working days. - Right to erasure - request anonymisation of your personal data:
DELETE /api/me/data-delete. Order, tax, and invoice records are retained as required by law but no longer identify you. - Right to grievance redressal - contact our Grievance Officer (see §10).
- Right to nominate - under DPDP §12, you may nominate another individual to exercise your rights in the event of incapacity.
07Children
We do not knowingly collect personal data of individuals under 18. If you believe we have inadvertently collected data of a minor, contact info@snaktap.com and we will delete it.
08Security
We protect your data with multiple safeguards:
- Transport encryption - every API call goes over HTTPS / TLS
- Password hashing - bcrypt with per-user salts; raw passwords are never stored or logged
- Multi-tenant isolation - every per-merchant row is scoped by merchantId and enforced by a central tenant guard service
- Role-based access control - staff permissions are catalogued and enforced server-side; kitchen staff cannot see revenue or billing data
- Idempotency - payment endpoints accept an Idempotency-Key header so a retried request never double-charges
- Audit log - every admin action (merchant approval, KYC re-verification, password reset) is recorded immutably
- Rate limiting - auth, payment, and general endpoints have separate per-route throttles to prevent abuse
- Error monitoring - exceptions are forwarded to Sentry with sensitive fields redacted
Despite these safeguards, no system is perfectly secure. Notify us immediately at info@snaktap.com if you suspect a breach affects you.
09Cookies
We use a small number of strictly-necessary cookies for authentication. We do not use marketing or third-party tracking cookies.
10Grievance redressal
- Grievance Officer: Grievance Officer
- Email: grievance@snaktap.com
- Data Protection Officer: Data Protection Officer · info@snaktap.com
- Address: Bengaluru, Karnataka, India
- Response time: 7 working days for acknowledgement, 30 days for resolution.
If you are dissatisfied with our response, you may file a complaint with the Data Protection Board of India under DPDP §27.
11Changes to this policy
We will increment the version above and prompt re-acceptance whenever this policy changes materially. The current version is reflected on every login. Your acceptance of any version is recorded in our audit log.
12Contact
For privacy questions, write to info@snaktap.com. For general support, support@snaktap.com.
