Privacy Policy
INCOSS Technologies Private Limited ("INCOSS", "INCOSS Technologies", "we", "us", or "our"), operating under the flagship brand Cravme ("Cravme"), respects your privacy and is committed to protecting the personal and business information entrusted to us.
This Privacy Policy explains how INCOSS Technologies collects, uses, stores, shares, and protects information when you access or use our websites, mobile applications, restaurant technology, ordering systems, point-of-sale systems, delivery services, and other products and services operated under the Cravme brand (collectively, the "Services").
Our Services may include, without limitation:
- cravme.com
- cravme.in
- biz.cravme.com
- Cravme Customer App
- Cravme Partner POS
- Cravme Delivery Partner App
- Cravme-powered restaurant websites, digital menus, ordering interfaces, QR ordering systems, and related restaurant technology.
By using the Services, you acknowledge that you have read and understood this Privacy Policy.
1. Who This Policy Applies To
This Privacy Policy applies to individuals and organizations interacting with Cravme, including:
Customers and Diners
Individuals who browse restaurant menus, scan QR codes, place food or beverage orders, make payments, request delivery, or otherwise use Cravme-powered customer experiences.
Restaurant and Merchant Partners
Restaurant owners, operators, managers, administrators, kitchen personnel, cashiers, POS operators, and other authorized personnel using Cravme's merchant and restaurant-management services.
Delivery Partners
Independent delivery personnel, drivers, riders, or logistics partners using the Cravme Delivery Partner application to accept and fulfill delivery assignments.
Website and Platform Visitors
Individuals who visit Cravme websites, landing pages, documentation, marketing pages, or other publicly accessible portions of the Services.
2. Information We Collect
Depending on how you interact with Cravme, we may collect different categories of information.
2.1 Account and Identity Information
We may collect:
- Name
- Mobile phone number
- Email address
- Profile photograph
- Preferred language
- Account identifiers
- Login and authentication information
- Account preferences
- Information submitted during account registration or verification
Where authentication is provided through a third-party provider, such as Google, we may receive information permitted by that provider and your authorization.
2.2 Customer and Ordering Information
When you use Cravme to browse or place an order, we may collect:
- Restaurant or outlet selected
- Items ordered
- Quantity and pricing information
- Order history
- Delivery address
- Table or seating information where applicable
- Special instructions and delivery notes
- Contact information required for fulfillment
- Order status
- Cancellation and refund information
- Customer support communications
2.3 Merchant and Restaurant Information
For restaurant and business accounts, we may collect:
- Restaurant and business name
- Legal entity information
- Outlet information and addresses
- Business contact details
- FSSAI registration and license information
- GSTIN and applicable tax information
- Bank account and settlement information
- UPI-related information
- Restaurant operating hours
- Menus and catalogues
- Food item names, descriptions, prices, taxes, and availability
- Food and restaurant photographs
- Employee and staff information submitted by authorized merchant administrators
- POS and device information
- Settlement and transaction records
Merchant administrators are responsible for ensuring that information submitted about their employees and business is accurate and that they have the appropriate authority to provide such information to Cravme.
2.4 Payment and Financial Information
Payments made through Cravme may be processed by third-party payment processors, payment gateways, banks, or other regulated payment service providers.
Depending on the payment method, we may receive information such as:
- Payment status
- Transaction ID
- Payment reference number
- Payment method
- UPI transaction identifiers
- Payment gateway response information
- Refund information
- Settlement information
Cravme does not intentionally store complete raw credit or debit card numbers when payments are processed through third-party payment providers.
Payment information may be processed by payment service providers such as Juspay, Razorpay, banks, UPI ecosystem participants, or other providers integrated with the Services.
2.5 Delivery Partner Information
If you use the Cravme Delivery Partner application, we may collect information necessary to operate delivery services, including:
- Name
- Mobile number
- Account information
- Vehicle-related information
- Delivery activity
- Order assignments
- Delivery status
- Earnings and incentive information
- Device information
- GPS/location information
- Information required for identity or operational verification
3. Location Information
Location information is an important part of certain Cravme Services.
3.1 Customers
With appropriate permission, Cravme may use location information to:
- Identify nearby restaurants
- Display relevant restaurant options
- Estimate delivery availability
- Improve delivery estimates
- Support order fulfillment
You can control location permissions through your device settings. Disabling location access may affect certain features.
3.2 Delivery Partners
For delivery partners, Cravme may collect location information while the Delivery Partner application is being used for active delivery operations.
Depending on the application's permissions and operating-system capabilities, location information may be collected while a delivery partner is actively performing or completing a delivery assignment.
This information may be used to:
- Provide navigation and routing
- Monitor delivery progress
- Display delivery status to customers
- Calculate delivery distances
- Calculate applicable delivery earnings or incentives
- Detect operational anomalies or fraudulent activity
- Resolve customer or merchant disputes
- Improve delivery operations and safety
Location collection is intended for legitimate operational purposes and is not intended to provide continuous tracking unrelated to delivery operations.
4. Device and Technical Information
When you use the Services, we may automatically collect certain technical information, including:
- IP address
- Device type
- Operating system
- Browser type
- Application version
- Device identifiers
- Installation identifiers
- Push notification tokens
- Network information
- Approximate location derived from IP address
- Crash reports
- Diagnostic information
- Log information
- Authentication and security events
We use this information to operate, secure, troubleshoot, and improve the Services.
5. How We Use Information
Cravme uses information for legitimate business, operational, contractual, security, and legal purposes, including:
Service Delivery
- Providing restaurant menus
- Processing orders
- Sending orders to restaurant systems
- Managing kitchen order tickets
- Processing dine-in, takeaway, and delivery orders
- Coordinating delivery operations
- Providing order status and notifications
Payments and Settlements
- Processing payments
- Confirming transactions
- Processing refunds
- Calculating merchant settlements
- Calculating commissions and applicable charges
- Maintaining financial records
- Generating invoices and transaction documents
Delivery Operations
- Assigning delivery orders
- Providing navigation and routing
- Tracking active delivery progress
- Calculating distance-based delivery information
- Communicating delivery status to customers and merchants
Account and Platform Management
- Creating and managing accounts
- Authenticating users
- Managing merchant access
- Managing POS devices
- Maintaining user preferences
- Providing customer and merchant support
Security and Fraud Prevention
We may process information to:
- Detect suspicious activity
- Prevent fraudulent orders
- Protect accounts
- Prevent unauthorized access
- Detect misuse of the Services
- Protect merchants, customers, delivery partners, and Cravme
- Investigate security incidents
Analytics and Product Improvement
We may use aggregated, statistical, or appropriately de-identified information to:
- Understand product usage
- Improve platform performance
- Develop new features
- Diagnose technical problems
- Improve restaurant and delivery operations
- Measure service reliability
Legal and Regulatory Compliance
We may process and retain information when necessary to comply with applicable laws, regulations, legal processes, governmental requests, tax requirements, accounting requirements, or lawful orders.
6. How We Share Information
Cravme does not sell personal information for monetary consideration.
We may disclose information when reasonably necessary to provide the Services, operate our business, protect users, or comply with legal obligations.
6.1 Restaurant and Merchant Partners
Depending on the order and service being provided, merchants may receive information necessary to prepare and fulfill an order, such as:
- Customer name or identifier
- Ordered items
- Order instructions
- Delivery information
- Contact information where required for fulfillment
- Order status and transaction information
Merchants may only use customer information for legitimate purposes connected with the relevant transaction and their relationship with Cravme.
6.2 Delivery Partners
For delivery fulfillment, delivery partners may receive information necessary to complete the delivery, including:
- Customer name or identifier
- Delivery address
- Delivery instructions
- Contact information where necessary
- Relevant order details
- Information necessary for navigation and delivery status
Delivery partners are expected to use this information only for legitimate delivery-related purposes.
6.3 Service Providers
Cravme may use third-party service providers to operate portions of the platform, including providers for:
- Cloud hosting and infrastructure
- Database and authentication services
- Image and media storage
- SMS and OTP delivery
- Payment processing
- Analytics
- Crash reporting
- Push notifications
- Customer support
- Security and fraud prevention
- Communication services
Examples of technology or service providers may include Google/Firebase, Cloudinary, MSG91, Juspay, Razorpay, and other providers used by Cravme from time to time.
Third-party providers may process information on Cravme's behalf and are expected to handle information in accordance with applicable contractual and legal requirements.
6.4 Legal and Regulatory Authorities
We may disclose information where reasonably necessary to:
- Comply with applicable law
- Respond to lawful governmental requests
- Comply with court orders
- Comply with tax or regulatory requirements
- Protect the rights, safety, and property of Cravme or others
- Investigate fraud or security incidents
6.5 Business Transfers
If Cravme is involved in a merger, acquisition, restructuring, financing, sale of assets, or similar corporate transaction, information may be transferred as part of that transaction, subject to applicable law and appropriate protections.
7. Cookies and Similar Technologies
Cravme may use cookies, local storage, session identifiers, device identifiers, and similar technologies.
These technologies may be used to:
- Keep users signed in
- Maintain sessions
- Remember preferences
- Maintain shopping carts
- Secure accounts and POS terminals
- Prevent unauthorized access
- Detect abuse and fraudulent activity
- Understand platform usage
- Improve website and application performance
Where applicable, analytics technologies may collect aggregated or pseudonymous usage information.
You can manage cookies through your browser settings. Disabling certain cookies may affect the functionality of the Services.
8. Data Security
Cravme implements reasonable technical and organizational safeguards designed to protect information against unauthorized access, alteration, disclosure, loss, or destruction.
Depending on the system and service involved, safeguards may include:
- Encryption in transit
- Encryption at rest where supported
- Access controls
- Role-based permissions
- Authentication controls
- Tenant isolation
- Logging and monitoring
- Secure infrastructure configuration
- Backup and recovery mechanisms
- Security reviews and vulnerability management
No internet-based service can guarantee absolute security. You should also take reasonable steps to protect your account credentials, devices, and authentication information.
9. Data Retention
Cravme retains information only for as long as reasonably necessary for the purposes described in this Policy, including:
- Providing the Services
- Maintaining business and transaction records
- Resolving disputes
- Preventing fraud and abuse
- Maintaining security
- Complying with contractual obligations
- Complying with applicable legal, tax, accounting, and regulatory requirements
Certain transaction, accounting, tax, and business records may need to be retained for longer periods where required by applicable law.
When information is no longer required, Cravme may delete, anonymize, aggregate, or otherwise securely dispose of it, subject to applicable legal requirements.
10. Account Deletion and Grace Period Policy
Customers, delivery partners, and restaurant merchant owners may submit a formal request to delete their account and associated personal data directly within their respective mobile applications (Cravme Customer App, Cravme Partner or POS, Cravme Delivery Partner App) or through our web portals at cravme.com/delete-account and biz.cravme.com, or by emailing [privacy@cravme.com](mailto:privacy@cravme.com).
10.1 Account Deletion Grace Period & Auto-Cancellation Upon Login
- 30-Day Scheduled Deletion Window: Once an account deletion request is submitted and verified, the account is placed in a pending deletion state and scheduled for permanent automated purging after 30 consecutive days.
- Cancellation via Account Login: During this 30-day grace period, users must refrain from logging into their account. If a user logs into their account at any time during the 30-day grace period, the pending account deletion request will be automatically cancelled, and normal account access will be restored.
10.2 Merchant and Restaurant Partner Audit Window
- 2 to 6 Month Settlement & Audit Period: For restaurant and merchant accounts, permanent deletion is processed only after a 2 to 6 month audit window to verify that all financial payout settlements, customer refunds, commission charges, tax GST filings, and merchant contracts are fully settled, and to confirm there are no pending legal, tax, or operational disputes.
10.3 Statutory Retention Exceptions
Certain transaction, tax, accounting, or security records may be preserved beyond account deletion where required by Indian statutory law (including GST tax compliance records retained for a minimum of 7 years).
10.4 Data Excluded From Deletion & Anonymized Record Retention
When an account deletion request is completed, your personal profile identifiers (such as name, personal email, phone number, and authentication credentials) are permanently purged or anonymized. However, specific operational, financial, and public platform records are retained in anonymized or non-personally identifiable form for legitimate business and legal purposes:
- Invoices, Billing & Tax Records: Itemized order invoices, payment reference logs, GST tax receipts, and merchant settlement statements are legally retained for a minimum of 7 years in accordance with Indian tax laws (Goods & Services Tax Act 2017 and Income Tax Act 1961).
- Order Records & Restaurant CMS Logs: Historical order tickets (KOT), transaction logs, and kitchen sales records stored in the Restaurant CMS are preserved in anonymized form for outlet accounting, inventory auditing, and financial reconciliation.
- Ratings, Reviews & Customer Feedback: Star ratings, dish reviews, food photographs, and feedback submitted for restaurants remain on the platform to maintain authentic outlet ratings and community reviews. Upon account deletion, the reviewer's personal profile name and photo are permanently unlinked and displayed as an anonymized reviewer (e.g., "Cravme Diner").
- Dispute & Fraud Prevention Records: Information relevant to active legal disputes, pending credit card chargebacks, unresolved customer refund claims, or verified fraud investigations is retained until the matter is fully settled.
11. Your Privacy Rights and Choices
Subject to applicable law, you may have rights relating to your personal information, including the ability to:
- Request access to certain personal information
- Request correction of inaccurate information
- Request deletion of information where legally permitted
- Withdraw consent where processing is based on consent
- Manage application permissions
- Manage location permissions through your device
- Opt out of certain marketing communications
- Raise a privacy-related complaint or grievance
Requests may be subject to identity verification and applicable legal limitations.
To exercise applicable privacy rights, contact:
[privacy@cravme.com](mailto:privacy@cravme.com)
12. Children's Privacy
The Services are not intentionally designed to collect personal information from children who are below the age at which they can lawfully provide such information under applicable law.
If you believe that a child has provided personal information to Cravme without appropriate authorization, please contact us at [privacy@cravme.com](mailto:privacy@cravme.com).
Where legally required, we will take reasonable steps to address such information.
13. Third-Party Services and Links
The Services may contain links to or integrations with third-party websites, applications, payment providers, social platforms, or other services.
Third-party services operate under their own privacy policies and terms. Cravme is not responsible for the privacy practices of third parties that it does not control.
We encourage you to review the privacy policies of relevant third-party services before providing information to them.
14. Merchant and Business Responsibilities
Merchant partners using Cravme are responsible for ensuring that they have an appropriate legal basis and authority to provide information about their employees, staff, customers, or other individuals to Cravme where required.
Merchants must use information received through Cravme only for legitimate business and service-related purposes and must comply with applicable privacy and data protection requirements.
Where Cravme provides tools that allow merchants to independently collect or manage customer information, the merchant may also act as an independent data controller/data fiduciary or equivalent entity under applicable law.
15. International and Cross-Border Processing
Cravme and its service providers may process or store information using infrastructure located in India or other countries, depending on the Services and technology providers being used.
Where information is transferred or processed outside India, Cravme will take reasonable steps to comply with applicable data protection and transfer requirements.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in:
- Our Services
- Technology
- Business operations
- Applicable laws and regulations
- Privacy practices
When we make material changes, we may provide an appropriate notice through the Services or other reasonable means.
The "Last Updated" date at the beginning of this Policy indicates when this Policy was most recently revised.
17. Grievance Officer and Privacy Contact
INCOSS Technologies Private Limited
Brand & Service: Cravme
Attn: Privacy & Compliance Desk
Address:
Indiranagar, 100 Feet Road,
Bengaluru, Karnataka 560038, India
Privacy: privacy@cravme.com
Support: support@cravme.com
Website: cravme.com
For privacy requests, account deletion requests, or data-related complaints, please use [privacy@cravme.com](mailto:privacy@cravme.com).
18. Governing Law
This Privacy Policy shall be interpreted in accordance with applicable laws and regulations of India.
Any dispute arising in connection with this Privacy Policy or the Services shall be subject to the applicable jurisdiction and laws of India, subject to any mandatory rights or remedies available to users under applicable law.
19. Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or the way INCOSS Technologies handles information for Cravme Services, please contact:
INCOSS Technologies Private Limited
Brand: Cravme
Email: privacy@cravme.com
Support: support@cravme.com
Website: cravme.com
We will make reasonable efforts to review and respond to privacy-related requests within the period required by applicable law.
