Privacy Policy
✓ Compliant with India Digital Personal Data Protection (DPDP) Act 2023 & GDPR Data Subject Rights.
1. Information We Collect
We collect information necessary to deliver a seamless coffee and cycling lounge experience:
- Personal & Contact Data: Name, 10-digit mobile phone number, email address, and profile details provided during account creation or checkout.
- Order & Transaction History: Records of menu items purchased, payment methods used, table numbers assigned, discount codes redeemed, and accrued loyalty points.
- GPS & Location Data: Precise device coordinates collected solely when placing self-orders to verify that you are within the 15-meter proximity threshold of the cafe.
2. Social Auth Integrations (Google, Facebook, Instagram, Strava)
When you sign in using social login providers, we receive authenticated user data strictly through official OAuth 2.0 protocols:
Retrieves your primary Google email address, verified display name, and profile picture to create your café account instantly.
Retrieves public profile information (name, avatar, user ID) to verify account identity and enable social ordering features.
For rider club members, Strava OAuth syncs cycling activity milestones, rider badge status, and club ride check-ins for exclusive café member perks.
3. Google Analytics & Tracking Technologies
We utilize Google Analytics and standard browser cookies to analyze aggregate web traffic, measure application performance, and optimize menu navigation. Google Analytics collects anonymized usage metrics such as page views and browser device type.
4. Data Non-Sale Guarantee
WE DO NOT SELL, RENT, LEASE, TRADE, OR SHARE YOUR PERSONAL INFORMATION WITH ANY THIRD-PARTY DATA BROKERS OR ADVERTISERS UNDER ANY CIRCUMSTANCES.
Your personal profile details, contact information, order history, and social authentication tokens are strictly used to fulfill orders, reward loyalty points, and deliver personalized cycling experience features.
5. Marketing & Communications
We may send order status updates via SMS / WhatsApp / PWA push notifications. You may opt out of non-essential promotional messages at any time.
6. Data Security & Infrastructure
All customer records and order data are transmitted using HTTPS encryption and hosted on enterprise-grade Cloud databases (Google Cloud Firebase Firestore) protected by end-to-end security rules.
7. Your Rights & Account Deletion Requests
Under DPDP Act 2023 and GDPR, you have the absolute right to access, rectify, or request complete account and data deletion:
To Submit a Data Access or Deletion Request:
Send an email to cyclistcafe.cc@gmail.com with the subject "Data Privacy Request" along with your registered 10-digit mobile number. Deletion requests are processed within 5 business days.