Privacy Policy

How Detecto LLP collects, uses, and protects your information.

Last updated: 30 June 2026
This Privacy Policy explains how Detecto LLP ("Detecto", "we", "us", or "our") collects, uses, shares, and protects your personal information when you use the Food Detecto mobile application and related services (collectively, the "Service"). By using Food Detecto, you agree to the practices described in this policy.

1. Information We Collect

We collect information that you provide directly, information generated through your use of the Service, and information from third-party sign-in providers.

Information you provide

  • Account details: your name, mobile phone number, and email address when you sign up as a user or restaurant owner.
  • Profile details: optional information such as date of birth and gender that you choose to add.
  • Restaurant details (owners): restaurant name, address, pincode, category, dish information, minimum spend rules, and images you upload.
  • Claim details: the dish you claim, table number, and the bill amount entered by the restaurant for verification.
  • Communications: messages you send us through the contact form or by email.

Information collected automatically

  • Device & usage data: app interactions, device type, and operating system used to operate and improve the Service.
  • Push notification token: a token used to deliver claim and account notifications to your device.
  • Location data: your approximate or precise location, only with your permission (see Section 3).
  • Camera & photos: the camera is used only to scan restaurant QR codes; photo-library access is used only to let you choose images to upload. We do not access your camera or photos in the background (see Section 3).

Information from sign-in providers

If you sign in with Google or use phone-number (OTP) authentication, we receive basic profile information (such as your name, email, profile photo, or phone number) from that provider to create and secure your account.

2. How We Use Information

  • To create and manage your account and authenticate you securely.
  • To show restaurants near you and let you discover and claim hero dishes.
  • To process and verify claims, including checking bill amounts against minimum-spend rules.
  • To process subscription payments for restaurant and user plans.
  • To send claim status updates, account notifications, and important service messages.
  • To provide customer support and respond to your enquiries.
  • To detect, prevent, and address fraud, abuse, and security issues.
  • To comply with legal obligations and enforce our Terms & Conditions.

3. Location, Camera & Device Permissions

Location. Food Detecto uses your device location to find restaurants near you and to calculate distances. We request location permission only when needed, and you can choose to select your city or pincode manually instead. You can disable location access at any time in your device settings; some discovery features may then be limited. Location is used only while you use the app and is not continuously tracked in the background.

Camera. Camera access is used solely to scan restaurant QR codes in real time so we can open the right restaurant for you. We do not record, store, or upload camera images during scanning.

Photos. Photo-library access is used only when you choose to upload an image (for example, a restaurant logo or dish photo). We access only the images you select; we do not scan your photo library.

All of these permissions are optional and can be granted or revoked at any time in your device settings.

4. How We Share Information

We do not sell your personal information. We share information only as needed to operate the Service:

  • With restaurants: when you submit a claim, the relevant restaurant sees a display tag, the dish claimed, and your table number so they can verify and serve you.
  • With service providers: trusted vendors who help us run the app (see Section 5), bound by confidentiality and data-protection obligations.
  • For legal reasons: when required by law, regulation, legal process, or to protect the rights, safety, and property of users, the public, or Detecto LLP.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this policy.

5. Third-Party Services

We rely on the following trusted providers, each with their own privacy policies:

  • Google Firebase & Google Cloud: authentication, database, cloud functions, storage, and hosting.
  • Google Sign-In: optional account authentication.
  • Expo Push Notifications: delivery of push notifications to your device.
  • Razorpay: secure processing of subscription payments. Payment card details are handled by Razorpay and are not stored by us.

6. Where We Store Your Data

Your information is stored on Google's secure cloud infrastructure (Google Cloud Platform and Firebase), which we use for authentication, database, file storage, and hosting. Our primary database and storage are hosted in the Mumbai, India region (asia-south1).

International transfers. Some of our service providers (such as Google, Expo, and Razorpay) may process limited data on infrastructure located outside India. Where data is transferred across borders, we rely on these providers' contractual and technical safeguards to protect it in line with this policy and applicable law. Payment-card data is processed by Razorpay on its own PCI-DSS-compliant systems and is never stored on our servers.

7. Data Retention

We retain your information for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. When data is no longer required, we delete or anonymise it. Some records, such as transaction history, may be retained longer where required by law (for example, tax and accounting rules).

8. Security

We implement technical and organisational measures to protect your information, including secure authentication, encrypted connections (HTTPS/TLS), server-side verification of all claim and payment logic, rate limiting, and restricted access controls. No method of transmission or storage is completely secure, but we work continuously to safeguard your data.

9. Account & Data Deletion

You can request deletion of your Food Detecto account and the personal data associated with it at any time, free of charge:

  • By email: email sujith@detecto.in from your registered email address with the subject "Delete my account".
  • By web: submit a request through our Contact page, choosing the "Account & privacy" topic.

What is deleted: your profile (name, phone, email, date of birth, gender), your push tokens, your claim history, and — for restaurant owners — your restaurant listing, dishes, and uploaded images.

What may be retained: we may retain a limited set of records (such as transaction and payment records) for as long as required by law, and anonymised or aggregated data that no longer identifies you. We complete verified deletion requests within 30 days.

10. Your Rights & Choices

  • Access & update: view and edit your profile information within the app.
  • Account & data deletion: delete your account and data as described in Section 9.
  • Permissions: control location, camera, photos, and notification permissions through your device settings.
  • Communications: manage push notifications in your device settings.

Depending on your location, you may also have rights under applicable data-protection laws (such as India's Digital Personal Data Protection Act, 2023). To exercise any of these rights, email us at sujith@detecto.in.

11. Children's Privacy

Food Detecto is not directed to children under the age of 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us and we will take steps to remove it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you through the app. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.

13. Contact Us & Grievances

If you have any questions, concerns, or grievances about this Privacy Policy or your data, contact us at:

We aim to acknowledge grievances within 48 hours and resolve them within a reasonable timeframe in accordance with applicable law.