Privacy Policy
Version 2026-08-04 — Last updated: 4 August 2026
This policy explains what PrepDine collects about you, why, who we share it with, how long we keep it, and what you can do about it.
If anything here is unclear, write to us at support@prepdine.com.
1. Who we are
PrepDine is a campus food pre-ordering service. You browse stalls at your campus, place an order, pay the stall, and collect your food using a pickup code.
PrepDine is operated by Movva Chenna Kesav, contactable at Flat No. 201, Lakshmi Narayana Enclave, Sandipani Nagar, Yendada, Visakhapatnam, Andhra Pradesh – 530045 and at team@prepdine.com. Under the Digital Personal Data Protection Act, 2023, we are the Data Fiduciary responsible for the personal data described below.
We do not hold your money. When you pay for an order, your payment goes directly to the stall's own payment account through our payment provider. PrepDine never receives, pools, or holds customer funds.
This policy covers students who order food, vendors who run stalls and their staff, and administrators who operate the platform.
2. What we collect
From students
| What | Why |
|---|---|
| Email address | Your login identity, and where we send one-time codes and order updates |
| Display name | Shown to the stall so they know whose order to hand over |
| Password | Stored only as a cryptographic hash — we never store your actual password |
| Campus | Sets which stalls you see by default; you can change it any time |
| Your acceptance of this policy, and which version | A record of your consent |
| Your confirmation at signup that you are 18 or older, or that a parent or guardian has agreed to your use of PrepDine | A record of the declaration required under the DPDP Act — see section 9 |
| Order details — items, quantities, pickup slot, and any note you add | To place and fulfil your order |
| Pickup code and QR token | So the stall can confirm the right person is collecting |
| Missed-pickup count | To limit repeated no-shows, which cost stalls money |
| Your IP address when a one-time code is sent | To detect and block automated abuse |
| A basic device identifier for each login session | So you can manage your active sessions and we can detect a stolen one |
If you joined our waitlist before signing up, we collected your email address, optionally your phone number, and your campus. This is used once, at signup, to apply your early-access promotion. It is not a marketing list.
We also keep a security log of login attempts, as standard protection against password-guessing attacks.
From vendors and their staff
Business and contact details, stall information, FSSAI registration details and supporting documents, bank details for receiving payments, and staff account details. Vendor documents are stored privately and are not publicly accessible.
3. What we do not collect
- No advertising and no ad tracking. We show no ads and run no advertising trackers.
- No behavioural analytics. We do not use Google Analytics, Meta Pixel, or any comparable product, and we do not build a behavioural profile of you.
- No location tracking. We never ask for or record your device location. The only location-linked information we hold is which campus you selected.
- No card, UPI, or bank details from students. Payment details are entered inside our payment provider's own secure flow and never reach PrepDine's servers. We store only the provider's reference numbers and the payment method type, such as "UPI".
- We never sell your data. We do not sell, rent, or trade personal data to anyone, for any purpose.
4. Why we process your data
Under the DPDP Act, personal data is processed with your consent or for certain legitimate uses. Here is which applies:
- Your consent — creating and running your account, sending order notifications, applying promotions. You give this at signup, and we record when you gave it and which version of this policy you accepted.
- Providing the service you asked for — passing your order to the stall, confirming pickup, handling refunds.
- Preventing fraud and abuse — login attempt logs, one-time-code limits, no-show counts, pickup-code attempt limits.
- Legal obligations — order and payment records are retained for tax and accounting purposes. This continues even after you delete your account. See section 7.
5. Permissions and what we store on your device
Notifications (optional). If you allow them, your browser provides a subscription address and encryption keys for your device so we can tell you when your order is accepted or ready. You can revoke this in your browser settings at any time, and we delete the subscription when you delete your account. Lock-screen notification text is kept generic — it says your order is ready, not what you ordered or what it cost.
Camera (stall staff only). Stall staff use the camera to scan pickup QR codes. Scanning happens on the device and camera images are not uploaded.
Stored on your device. We store only what keeps you logged in and remembers your cart — a login token, a secure refresh cookie, and your current cart. There are no advertising or tracking cookies, because we do no advertising or tracking.
6. Who else sees your data
The stall you order from sees your display name, what you ordered, your pickup slot, any note you added, and the information needed to verify your pickup — so they can prepare and hand over your order.
PrepDine administrators can access account and order records to resolve support issues and refunds. Actions affecting money are recorded in an audit log showing who did what and why.
Service providers we rely on:
| Provider | What they handle |
|---|---|
| Cashfree Payments | Payment processing. Your card or UPI credentials are handled by Cashfree, not by us. |
| Resend | Email delivery — one-time codes and order updates |
| Cloudflare R2 | File storage — stall photos, vendor documents |
| Supabase | Database hosting |
| Your browser's push service (Google, Mozilla, Apple, or similar) | Notification delivery, only if you enable notifications |
Our service providers may store data on servers located outside India. Where they do, we rely on providers that offer appropriate security protections, and such transfers are permitted under the DPDP Act.
Beyond the above, we share your data with no one, except where we are legally required to.
7. How long we keep your data
| Data | Retention |
|---|---|
| One-time login codes | Deleted as soon as they expire |
| Abandoned carts | Deleted as soon as they expire |
| Login sessions | Deleted 90 days after expiry |
| Login attempt records | 180 days, then deleted |
| Order and payment records | 7 years, as required by Indian tax law |
| Your account record | Until you delete it — see section 8 |
Login attempt records — the email address used, the IP address, and the browser or device identifier — are retained for 180 days and then deleted. We keep them for this period because the CERT-In Directions of 2022 require providers to maintain authentication logs for a rolling 180 days.
8. Your rights
Access your data. You can request a copy of everything we hold about you from your account settings. You will be asked to re-enter your password. We prepare a file and give you a private download link that expires after a short period. It contains only your own data.
Correct your data. You can update your display name, email address, campus, and password from your account settings.
Delete your account. You can delete your account from your settings, confirming with your password. Here is exactly what happens:
- You cannot delete while an order is in progress. Complete it, or wait for it to close, first.
- Your account is immediately closed and all login sessions are ended.
- You have 30 days before anything is permanently scrubbed.
- After 30 days, an automated process permanently removes your personal information: your email address is replaced with an unusable placeholder, your name becomes "Deleted User", your password is erased, your order notes are cleared, and your saved devices and notification subscriptions are deleted.
- What remains: the financial record that an order took place, for what amount, and whether it was paid or refunded. These are retained for 7 years because tax law requires it. They no longer identify you — they reference an anonymised account.
Login attempt records are an exception to deletion. Because we are required by law to keep them for 180 days, they are not removed when you delete your account. They age out on the same 180-day schedule and are then deleted permanently.
Nominate someone. You may nominate another person to exercise these rights on your behalf if you are unable to do so. Write to support@prepdine.com.
Raise a grievance. See section 11.
9. Users under 18
Under the Digital Personal Data Protection Act, 2023, anyone under 18 is a child, and consent from a parent or guardian is required before their personal data is processed. At signup we ask you to confirm that you are 18 or older, or that a parent or guardian has agreed to your use of PrepDine. We do not track, profile, or serve advertising to any user, of any age. If you believe we hold a child's data without the required consent, write to support@prepdine.com and we will delete it.
You can browse stalls, menus, prices, and availability without an account. This declaration applies to creating an account and placing orders.
10. How we protect your data
- Passwords are stored as salted cryptographic hashes. We cannot read your password, and neither could anyone who obtained our database.
- One-time login codes are stored hashed, expire within minutes, and limit how many times they can be attempted.
- Repeated failed login attempts temporarily lock the account.
- Login tokens are separately signed for students, vendors, and administrators, so a token issued in one context cannot be used in another.
- Login sessions rotate. If a stolen session token is reused, we detect it and revoke that entire chain of sessions.
- Vendor owners use two-factor authentication.
- Private files, including vendor documents, are stored privately and reachable only through short-lived signed links.
- Real-time and push messages carry minimal information, so a misdirected message cannot reveal order contents.
No system is perfectly secure and we will not claim otherwise. If a breach affects your personal data, we will notify you and the Data Protection Board of India as required by law.
11. Contact and grievances
| Purpose | Contact |
|---|---|
| Phone — support and privacy questions | +91 94902 51635 |
| Support and privacy questions | support@prepdine.com |
| Business and legal matters | team@prepdine.com |
| Automated emails (not monitored) | noreply@prepdine.com |
Our phone line is answered 9:00 AM – 10:00 PM IST, daily.
Grievance Officer
| Name | Jagadeesh Kumar Balina, FCA, CMA |
| Phone | 9966552896 |
| jagadeesh@vnv.ca | |
| Address | D.No. 50-96-4/4, Office No. 101, KIMS (NRI) Hospital Road, Seethammadhara, B.S. Layout, Visakhapatnam – 530013 |
If you have a complaint about how we handle your personal data, write to the Grievance Officer. We will acknowledge your complaint and respond within a reasonable period. If you are not satisfied with our response, you may escalate it to the Data Protection Board of India.
12. Changes to this policy
If we make a material change to this policy, we will tell you. The version and date at the top of this page always reflect the current version, and they change to the date of the update whenever we make one.
13. Governing law
This policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023. Any disputes are subject to the courts at Visakhapatnam, Andhra Pradesh.
© PrepDine