Partner Privacy Policy
Version 1.0 (Final) · Effective 29 May 2026
This document is an electronic record under the Information Technology Act, 2000.
Business: Feesto (Sole Proprietorship) · UDYAM: UDYAM-BR-05-0035249
Contact: hello@feesto.app
Grievance Officer: Feesto (Sole Proprietorship) | hello@feesto.app
Complies with: Digital Personal Data Protection Act, 2023 (DPDP Act) · DPDP Rules, 2025 · IT Act, 2000 · IT (Intermediary Guidelines) Rules, 2021
This Privacy Policy describes how Feesto collects, uses, and protects personal data provided by Restaurant Partners and their Authorised Representatives in connection with the Feesto Restaurant Partner App and Platform.
This Policy must be read alongside the Restaurant Partner Agreement and Partner Terms of Use.
Feesto acts as the “Data Fiduciary” as defined under the Digital Personal Data Protection Act, 2023 in respect of personal data provided to Feesto by Restaurant Partners and their Authorised Representatives.
AADHAAR NOTICE
Feesto does not collect, store, or process Aadhaar numbers. In compliance with the Aadhaar Act, 2016 and the Supreme Court’s judgment in Justice K.S. Puttaswamy v. Union of India (2018), private entities may not collect Aadhaar numbers without specific UIDAI authorisation. Identity verification is conducted using PAN card (mandatory) and optionally Voter ID or Driving Licence.
B2B NOTICE
This Policy governs a commercial B2B relationship. The Consumer Protection Act, 2019 does not apply. Data protection obligations are governed by the DPDP Act, 2023 and the Indian Contract Act, 1872.
Your Consent
Before collecting your personal data, Feesto will present a clear, plain-language consent notice specifying: (a) The categories of personal data being collected, (b) The specific purpose for each category, (c) How you may exercise your rights as a Data Principal, (d) How to withdraw consent at any time.
By accepting the Restaurant Partner Agreement and these Terms, you consent to the data practices described in this Policy.
You may withdraw consent for optional data processing at any time by contacting hello@feesto.app. Note that withdrawing consent for data essential to the partnership — including PAN, bank account details, and GSTIN — will prevent Feesto from processing settlements and tax deductions and may necessitate termination of the partnership. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
1. Information We Collect
1.1 Business Registration Information
Data: Restaurant name, business address, type of cuisine, operating hours, FSSAI licence number and category, GST registration number (GSTIN, if applicable), PAN of the business or proprietor.
Purpose: Verifying your eligibility to register; listing your restaurant on the Platform; GST/TCS/TDS compliance and regulatory reporting to government authorities as required by law.
1.2 Authorised Representative Information
Data: Full name, mobile number, email address, designation, PAN, and optionally Voter ID or Driving Licence for identity verification (Aadhaar is NOT collected).
Purpose: Account creation and authentication; identity verification; communication regarding your account and the partnership; TDS deduction and reporting against your PAN to the Income Tax Department.
1.3 Bank Account Information
Data: Bank name, account number, IFSC code, account holder name, cancelled cheque (for verification).
Purpose: Processing weekly settlements and any applicable deductions; verifying payment details to prevent fraud and misdirected payments.
Retention: Bank details are retained for 7 years for tax and audit compliance. Previous bank details superseded by an update are deleted within 30 days unless required for a pending settlement dispute or regulatory inquiry.
1.4 Menu and Content Data
Data: Food item details, descriptions, photographs, prices, allergen information uploaded by you.
Purpose: Displaying your listing on the Feesto Platform; enabling Customers to place Orders; operating the marketplace.
1.5 Order and Transaction Data
Data: All Orders received, accepted, rejected, or cancelled; Order values; preparation times; delivery status; refund records; chargeback records.
Purpose: Processing Orders; calculating Commission, TCS, TDS, and settlements; generating reports; resolving disputes; income tax and GST regulatory reporting and compliance.
1.6 Partner App Usage Data
Data: Login times, features used, device information, app version, crash reports, IP address.
Purpose: Maintaining Partner App security; improving Partner App performance; detecting and preventing fraud and unauthorised access.
1.7 Communication Data
Data: Support queries, dispute communications, review responses submitted through the Partner App.
Purpose: Resolving queries and disputes; improving partner support quality; maintaining records of communications for dispute resolution.
1.8 Rating and Review Data
Data: Customer ratings and reviews received for your restaurant; your responses to reviews.
Purpose: Displaying on the Platform; quality and compliance monitoring; partner performance assessment.
2. How We Use Your Information
2.1 To Operate the Partnership
- Listing and managing your restaurant on the Platform
- Processing Orders and calculating weekly settlements
- Collecting and remitting TCS on your behalf under Section 52 of the CGST Act, 2017
- Deducting and remitting TDS against your PAN under applicable Income Tax provisions
- Generating settlement statements and TDS/TCS certificates for your tax compliance
- Verifying FSSAI licence validity and GST compliance
2.2 To Improve Our Services
- Analysing Partner App performance and usage patterns
- Improving Partner App features and support processes
- Conducting internal research and analytics
2.3 To Communicate With You
- Settlement notifications and weekly statements
- Monthly TCS statements (by 10th of following month)
- Order-related alerts and operational notifications
- Policy updates and Agreement amendment notices
- Compliance reminders (FSSAI renewal, GST deadlines)
2.4 Legal and Regulatory Compliance
- Complying with DPDP Act 2023, IT Act 2000, Income Tax Act / ITA 2025, CGST Act 2017, and FSSAI regulations
- Responding to lawful government and court orders
- Reporting to tax authorities (TCS/TDS remittance and partner PAN reporting)
2.5 Safety and Fraud Prevention
- Detecting and preventing fraudulent Orders, fake reviews, Order Diversion, or settlement manipulation
- Verifying identity and business credentials during and after onboarding
- Enforcing the Restaurant Partner Agreement
3. How We Share Your Information
We do not sell your personal or business data.
3.1 With Customers (Limited)
Your restaurant name, cuisine type, Menu, FSSAI licence number, ratings, operating hours, and review responses are displayed to Customers on the Platform.
3.2 With Delivery Partners
For Feesto-delivered Orders, your restaurant name, address, and Order details are shared with the assigned Delivery Partner for Order pickup.
3.3 With Service Providers
- Payment processing and settlement banking partners (PCI-DSS compliant)
- Cloud infrastructure providers (data may be stored in India or abroad subject to DPDP Rules 2025)
- SMS and notification service providers
- Analytics and app performance providers
All service providers are bound by data processing agreements.
3.4 With Tax and Regulatory Authorities
- Income Tax Department: for TDS remittance and reporting against your PAN
- GST authorities: for TCS remittance and reporting under CGST Act, 2017
- FSSAI: in the event of a food safety complaint or compliance issue
3.5 Legal Requirements
We may disclose your data to government authorities or courts when legally required under applicable Indian law.
3.6 Business Transfers
In the event of a merger, acquisition, or asset sale involving Feesto, your data may be transferred to the successor entity with prior written notice to you.
4. Data Retention
| Category | Retention Period |
|---|---|
| Business registration data | Duration of partnership + 7 years |
| Bank and settlement data | 7 years (tax compliance) |
| Previous bank details | 30 days after superseded |
| Order and transaction data | 7 years (tax compliance) |
| TDS/TCS records | 7 years (IT Act / CGST) |
| Partner App usage data | 2 years |
| Communication data | 3 years |
| Consent records | 7 years (DPDP Rules 2025) |
After the applicable retention period, data is securely deleted or irreversibly anonymised.
5. Data Security and Breach Notification
We implement industry-standard security including:
- TLS/HTTPS encryption for all data in transit
- Encrypted storage of sensitive credentials and financial information
- PCI-DSS compliant payment data handling
- Strict access controls on Partner data
- Regular security reviews and audits
Data Breach Notification: In the event of a personal data breach, Feesto will (a) notify the Data Protection Board of India within 72 hours, (b) notify you promptly with details and steps taken, (c) take immediate remedial action.
If you believe your Partner App account has been compromised, contact hello@feesto.app immediately.
6. Your Rights as a Data Principal
Under the DPDP Act, 2023, you have the following rights:
- Right to Access (Section 11): Request a summary of personal data we hold about you and the processing activities being carried out.
- Right to Correction and Erasure (Section 12): Request correction of inaccurate data or erasure of data no longer necessary for its stated purpose, subject to legal retention requirements.
- Right to Grievance Redressal (Section 13): Raise data protection complaints with Feesto. Resolved within 90 days per DPDP Rules.
- Right to Nominate (Section 14): Nominate another person to exercise your data rights in the event of your death or incapacity.
- Right to Withdraw Consent: Withdraw consent for optional data processing at any time via hello@feesto.app.
General requests: Response within 30 days. DPDP Act data protection requests: Within 90 days.
7. Customer Data — Your Obligations
Customer personal data shared with you for Order fulfilment is provided by Feesto in its capacity as an intermediary. You process this data solely as a limited data processor.
As a data processor for Customer data, you must:
- Process Customer data only for Order fulfilment
- Not retain Customer data beyond 48 hours post-delivery
- Not share Customer data with any third party
- Implement reasonable security measures
- Immediately notify Feesto of any Customer data breach
Misuse of Customer data constitutes a violation of the DPDP Act, 2023, carrying penalties of up to ₹250 crore per breach, and may result in immediate permanent delisting.
8. Grievance Officer
In accordance with IT (Intermediary Guidelines) Rules 2021, Rule 3(2), and the DPDP Act, 2023:
Designation: Grievance Officer & Data Fiduciary Contact Person
Email: hello@feesto.app
Service grievances: Resolved within 15 days
Data protection grievances (DPDP Act): Resolved within 90 days
External authority: Data Protection Board of India (DPBI) — dpboard.gov.in (once operational)
9. Amendments
We may update this Policy with 7 days’ prior notice for material changes via the Partner App or registered email. Your continued use of the Partner App after the notice period constitutes acceptance.
10. Contact
Feesto (Sole Proprietorship)
UDYAM: UDYAM-BR-05-0035249
Email: hello@feesto.app
© 2026 Feesto. All rights reserved. Version 1.0 (Final) | 29 May 2026