Last updated: February 23, 2026
Effective date: February 23, 2026
This Privacy Policy ("Policy") describes how EatingMinds ("Company," "we," "us," or "our") collects, uses, stores, shares, and protects your personal data when you use the EatingMinds platform, website (eatingminds.com), mobile applications, and related services (collectively, the "Service").
This Policy is published in compliance with the Information Technology Act 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, and the Digital Personal Data Protection Act 2023 ("DPDPA") of India.
By using the Service, you consent to the collection and use of your data as described in this Policy. If you do not agree, please do not use the Service.
1. Information We Collect
1.1 Information You Provide Directly
| Category | Data Collected | Purpose |
|---|---|---|
| Account | Name, email address, Google/LinkedIn profile ID | Authentication, account creation |
| Profile | Age, gender, profession, bio, city, profile photos | Displaying profile to other users, matching |
| Contact | Phone number (optional, only when you choose to share) | Shared with confirmed meal partners only |
| Meal Data | Availability listings, preferences, meal type, time, location, payment preference, vibe tags | Discovery, matching, displaying listings |
| Communications | Messages sent to meal partners, support requests | Facilitating meal coordination, customer support |
| Reviews | Ratings and comments about meal partners | Trust and safety, quality improvement |
| Social Handles | Instagram, LinkedIn, Facebook usernames (optional) | Displayed on profile for social verification |
1.2 Information Collected Automatically
| Category | Data Collected | Purpose |
|---|---|---|
| Device Info | Device type, operating system, browser type, screen resolution | Service optimization, debugging |
| Usage Data | Pages visited, features used, actions taken, timestamps | Analytics, improving user experience |
| Location | GPS coordinates (only when permission granted), IP-based approximate location | Showing nearby meals, distance calculations |
| Log Data | IP address, access times, referring URLs, error logs | Security, debugging, fraud prevention |
1.3 Information from Third-Party Authentication
When you sign in via Google or LinkedIn, we receive your name, email address, and profile picture from those services. We do not receive or store your Google/LinkedIn passwords. We access only the minimum data required for authentication as authorized by you during the sign-in process.
2. Lawful Basis for Processing (DPDPA 2023)
Under India's Digital Personal Data Protection Act 2023, we process your data based on:
- Consent: You provide explicit consent when creating an account and accepting this Policy. You may withdraw consent at any time by deleting your account.
- Legitimate Use: Processing necessary to provide the Service you have requested (e.g., showing your profile to potential meal partners, facilitating meal matching).
- Legal Obligation: Processing required to comply with applicable laws (e.g., responding to lawful requests from authorities, maintaining records as required by law).
3. How We Use Your Information
- Provide the Service: Create and display your profile, facilitate meal discovery and matching, enable messaging between confirmed partners.
- Safety and Trust: Detect and prevent fraud, abuse, and violations of our Terms. Implement blocking and reporting features. Monitor for suspicious activity.
- Communications: Send transactional notifications (meal requests, confirmations, cancellations, reminders). Send optional promotional emails (which you can opt out of).
- Improvement: Analyze usage patterns to improve features, fix bugs, and optimize performance. Conduct research and analytics in aggregated, de-identified form.
- Legal Compliance: Respond to legal requests, enforce our Terms, and protect the rights, property, and safety of EatingMinds and its users.
4. How We Share Your Information
4.1 With Other Users
- Profile Information: Your name, age, gender, profession, bio, photos, and city are visible to other users when browsing meal listings.
- Meal Listings: Your availability details (meal type, date, time, location, payment preference) are publicly visible on the Discover and Circles pages.
- Contact Information: Your phone number is shared only with confirmed meal partners and only when you explicitly choose to share it using the "Share Contact" feature. You can revoke this at any time.
- Reviews: Aggregate review ratings may be visible to other users.
4.2 With Service Providers
We share data with trusted third-party service providers who assist in operating the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Microsoft Azure | Cloud hosting, database, file storage | All service data (encrypted at rest and in transit) |
| Authentication (Sign-In) | OAuth tokens (no passwords) | |
| Authentication (Sign-In) | OAuth tokens (no passwords) | |
| Azure Communication Services | Transactional emails | Email address, notification content |
| OpenStreetMap / Photon | Location search and geocoding | Search queries, coordinates (no user identifiers) |
All service providers are contractually obligated to process data only as instructed by us and to maintain appropriate security measures.
4.3 For Legal Reasons
We may disclose your information if required to do so by law or in response to:
- Valid legal process (court orders, subpoenas, government requests).
- Protect the rights, property, or safety of EatingMinds, our users, or the public.
- Detect, prevent, or address fraud, security, or technical issues.
- Enforce our Terms of Service.
4.4 Business Transfers
In the event of a merger, acquisition, or sale of all or a portion of our assets, your data may be transferred as part of that transaction. We will notify you via email or prominent notice on the Service before your data is transferred and becomes subject to a different privacy policy.
4.5 What We Do NOT Share
- We do not sell your personal data to third parties.
- We do not share your data with advertisers for targeted advertising.
- We do not share your private messages with anyone other than the intended recipient.
5. Data Storage and Security
5.1 Storage Location
Your data is stored on Microsoft Azure servers. While our primary infrastructure is hosted in Azure regions, data may be processed in data centers outside India as part of Azure's global infrastructure. By using the Service, you consent to this transfer, provided that appropriate safeguards are in place.
5.2 Security Measures
We implement industry-standard security measures including:
- Encryption of data in transit (TLS/HTTPS) and at rest (AES-256).
- Secure authentication via Google and LinkedIn OAuth 2.0.
- Input validation and sanitization to prevent injection attacks.
- Rate limiting to prevent abuse and DDoS attacks.
- Regular security audits and code reviews.
- Access controls limiting employee access to personal data on a need-to-know basis.
- Secure password hashing for any stored credentials.
While we strive to protect your data, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.
5.3 Breach Notification
In the event of a data breach that is likely to result in a risk to your rights, we will notify affected users and the relevant Data Protection Board of India as required under the DPDPA 2023, within 72 hours of becoming aware of the breach.
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Active account data | As long as your account is active |
| Deactivated account data | 30 days after deactivation (then permanently deleted) |
| Messages | Retained while both users have active accounts. Deleted when either user deletes their account. |
| Reviews | Retained to maintain platform trust. Anonymized if the reviewer's account is deleted. |
| Log/analytics data | 90 days (aggregated/anonymized data may be retained indefinitely) |
| Legal compliance data | As required by applicable law (typically 3-8 years for financial/legal records) |
7. Your Rights
Under the DPDPA 2023 and applicable law, you have the following rights:
7.1 Right to Access
You may request a summary of your personal data that we process. Your profile information is always accessible through the app.
7.2 Right to Correction
You may update or correct your personal data at any time through the Edit Profile feature in the app, or by contacting us.
7.3 Right to Erasure (Right to be Forgotten)
You may delete your account through Settings > Delete My Account. This will:
- Immediately hide your profile from other users.
- Cancel all active meal listings and pending requests.
- Cancel all upcoming confirmed meals.
- Permanently delete your personal data within 30 days.
Certain data may be retained beyond 30 days where required by law or for legitimate business purposes (e.g., preventing re-registration of banned users, legal compliance).
7.4 Right to Withdraw Consent
You may withdraw your consent to data processing at any time by deleting your account. Withdrawal of consent does not affect the lawfulness of processing based on consent before withdrawal.
7.5 Right to Grievance Redressal
If you believe your data has been processed in violation of your rights, you may raise a grievance with our Grievance Officer (see Section 12) or file a complaint with the Data Protection Board of India.
7.6 Right to Nominate
Under the DPDPA 2023, you have the right to nominate another individual to exercise your data rights on your behalf in the event of your death or incapacity. To register a nominee, contact us at privacy@eatingminds.com.
8. Location Data
We collect location data in two ways:
- GPS (precise location): Collected only when you explicitly grant location permission in your browser or device settings. Used to show nearby meals and calculate distances. You can revoke this permission at any time through your device settings.
- City/area (approximate location): Your home city, which you manually provide in your profile. Used as a fallback when GPS is not available.
We do not track your location in the background. Location is only accessed when you actively use the Discover or Circles features.
9. Cookies and Local Storage
We use the following client-side storage:
| Type | Name | Purpose | Duration |
|---|---|---|---|
| Local Storage | eatingminds-auth | Stores your authentication session | Until logout |
| Local Storage | em-theme | Stores your dark/light mode preference | Persistent |
| Local Storage | em-email-notif, em-push-notif | Notification preferences | Persistent |
| Session Storage | linkedin_oauth_state | CSRF protection during LinkedIn login | Session only |
We do not use third-party tracking cookies. We do not use cookies for advertising purposes. If we implement analytics in the future (e.g., Google Analytics), we will update this Policy and provide opt-out mechanisms.
10. Children's Privacy
The Service is strictly intended for users aged 18 and above. We do not knowingly collect personal data from anyone under the age of 18. If we become aware that we have collected data from a person under 18, we will promptly delete that data. If you believe a minor is using the Service, please report it to safety@eatingminds.com.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes:
- We will update the "Last updated" date at the top of this page.
- We will notify you via in-app notification or email at least fifteen (15) days before the changes take effect.
- For significant changes that affect how we use your data, we will request your renewed consent where required by law.
Your continued use of the Service after the effective date of changes constitutes acceptance of the updated Policy.
12. Grievance Officer
In accordance with the Information Technology Act 2000 and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, the Grievance Officer for EatingMinds is:
Grievance Officer
EatingMinds
Email: eatingminds.care@gmail.com
Response time: Acknowledgment within 24 hours; resolution within 15 days of receipt
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India as established under the DPDPA 2023.
13. Contact Us
For any questions, concerns, or requests related to your privacy, contact us at:
EatingMinds
Email: eatingminds.care@gmail.com
By using EatingMinds, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and use of your data as described herein. This Policy should be read together with our Terms of Service.