Privacy Policy

Effective Date: 22 June, 2026

Harkara AI Private Limited | Jaipur, Rajasthan, India | team@harkara-ai.in | harkara.in / harkara-ai.in


1. Introduction and Scope

1.1 Harkara AI Private Limited (“Company”, “We”, “Us”, “Our”), a company incorporated under the Companies Act 2013, is committed to protecting and respecting the privacy of all individuals who use the Harkara platform at harkara.in / harkara-ai.in (“Platform”). This Privacy Policy explains how We collect, use, store, share, and protect personal data in connection with Your use of the Platform and its Services.

1.2 This Privacy Policy is published in compliance with the Digital Personal Data Protection Act 2023 (“DPDPA 2023”), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 (“SPDI Rules”), and other Applicable Laws governing the protection of personal data in India.

1.3 By accessing or using the Platform, You acknowledge that You have read, understood, and consent to the collection, use, and processing of Your personal data as described in this Privacy Policy. If You do not consent to any part of this Privacy Policy, You must immediately cease using the Platform.

1.4 This Privacy Policy should be read together with the Company’s Terms of Service, Cookie Policy, and Disclaimer, which collectively govern Your use of the Platform.

1.5 We may update this Privacy Policy from time to time to reflect changes in our practices, the Services offered, or Applicable Law. Where material changes are made, We shall notify registered Users via email or a prominent notice on the Platform. The revised Privacy Policy shall take effect upon publication, and Your continued use of the Platform following notification shall constitute acceptance of the revised terms.

2. Definitions

In this Privacy Policy, the following definitions apply:

“Consent”

means a freely given, specific, informed, and unambiguous indication of a Data Principal’s wishes, signified by a clear affirmative action, to agree to the processing of personal data for a specified purpose.

“Data Fiduciary”

means the Company, which alone or jointly with others determines the purpose and means of processing of personal data, as defined under the DPDPA 2023.

“Data Principal”

means the individual to whom the personal data relates, i.e., the User of the Platform.

“Data Processor”

means any entity that processes personal data on behalf of the Company and in accordance with the Company’s instructions.

“DPDPA 2023”

means the Digital Personal Data Protection Act 2023, as enacted by the Parliament of India and as amended from time to time, along with all rules, regulations, and guidelines issued thereunder.

“Personal Data”

means any data about an individual who is identifiable by or in relation to such data, including but not limited to name, email address, mobile number, device identifiers, location data, and usage information, as defined under the DPDPA 2023.

“Processing”

means any operation or set of operations performed on personal data, whether by automated means or otherwise, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure, dissemination, or erasure.

“Sensitive Personal Data”

means financial information, health information, passwords, and such other categories of personal data that are prescribed as sensitive under the SPDI Rules or any applicable regulation.

3. Personal Data We Collect

3.1 Data Provided by You

We collect the following categories of personal data that You voluntarily provide to Us:

  • Registration Information: Your full name, email address, and mobile phone number when You create a User account on the Platform.
  • Order and Reservation Information: details of food orders and reservations placed through the Platform, including items ordered, special requests, and transaction history.
  • User Content: reviews, ratings, photographs, and feedback submitted through the Platform.
  • Communications: the content of messages and correspondence You submit to Us through customer support channels, feedback forms, or email.
  • Payment Data: limited payment information necessary to initiate transactions; full payment card details are processed directly by Razorpay and are NOT stored by the Company.

3.2 Data Collected Automatically

When You use the Platform, We may automatically collect the following technical and usage data:

  • Device Information: device type, model, operating system, browser type and version, unique device identifiers, and app version.
  • Log Data: IP address, date and time of access, pages viewed, referring URLs, and clickstream data.
  • Usage Data: features accessed, search queries, interaction patterns, and session duration on the Platform.
  • Cookies and Tracking Technologies: data collected through cookies, web beacons, and similar technologies, as more fully described in Our Cookie Policy.

3.3 Location Data

3.3.1 With Your explicit permission, the Platform accesses real-time GPS location data from Your device for the following purposes: (a) assisting You in discovering restaurants in Your vicinity; and (b) for Takeaway Orders and Dine-In Pre-Orders, continuously calculating the proximity between Your device and the Restaurant Partner’s location to trigger a kitchen preparation notification when You are approaching. GPS location data is used transiently for proximity calculation only; it is not stored by the Company, and it is not transmitted to or shared with the Restaurant Partner. The Restaurant Partner receives only a preparation trigger notification and does not receive Your location coordinates.

3.3.2 GPS location access for Takeaway Orders and Dine-In Pre-Orders is active only during the period from Order placement until the User arrives at the Restaurant Partner’s premises. The Company does not store GPS location data at any point. GPS data is processed transiently in-device or in-session solely to calculate proximity and generate the preparation trigger, and is discarded immediately upon use.

3.3.3 You may disable location sharing at any time through Your device settings, though this may limit the functionality of certain Platform features.

3.4 Data from Third Parties

3.4.1 We may receive personal data about You from third-party sources, including: (a) Razorpay, in connection with payment processing and fraud prevention; and (b) analytics providers, in relation to anonymised or aggregated usage analytics.

3.5 AI-Generated Data

3.5.1 Menu descriptions and estimated nutritional information are generated by Google Gemini API using menu item names and descriptions provided by Restaurant Partners. The Company transmits menu data to Google for this purpose but does not transmit any User personal data to Google in this context.

4. Legal Basis for Processing Personal Data

Under the DPDPA 2023, We process Your personal data on the following legal bases:

  • Consent: for the collection and processing of personal data where You have voluntarily provided such data and given Your express consent, including for location sharing and optional marketing communications.
  • Contractual Necessity: for processing necessary to perform Our obligations under the Terms of Service, including Order processing, Reservation management, and payment facilitation.
  • Legitimate Interests: for fraud prevention, platform security, analytics, and improving the quality and safety of the Platform, where such processing does not override Your fundamental privacy rights.
  • Legal Obligation: where processing is necessary to comply with a legal obligation, court order, or regulatory requirement imposed under Applicable Law.

5. How We Use Your Personal Data

We process Your personal data for the following specified and lawful purposes:

5.1 Service Delivery

  • To enable You to register and maintain an account on the Platform.
  • To process and facilitate food Orders, Pre-Orders, and Reservations.
  • To communicate Order confirmations, updates, status notifications, and receipts to You.
  • To share relevant Order and contact information with Restaurant Partners to enable fulfilment.
  • To enable GPS proximity-based kitchen preparation trigger notifications for Takeaway Orders and Dine-In Pre-Orders (GPS data is not stored or shared with Restaurant Partners).

5.2 Platform Operations and Improvement

  • To maintain, administer, and improve the technical functionality and user experience of the Platform.
  • To conduct internal research, analytics, and testing to develop new features and Services.
  • To monitor and enforce compliance with these Terms and Applicable Law.
  • To detect, investigate, and prevent fraudulent transactions, security incidents, and misuse of the Platform.

5.3 Communications

  • To send transactional notifications, service updates, and responses to Your enquiries and support requests.
  • To send You marketing or promotional communications with Your prior consent, which You may withdraw at any time.

5.4 Legal and Regulatory Compliance

  • To comply with Applicable Law, court orders, regulatory directions, or to respond to lawful requests from competent authorities.
  • To exercise or defend legal claims.

6. Disclosure and Sharing of Personal Data

6.1 Restaurant Partners

6.1.1 To facilitate Order fulfilment and Reservations, We share the following data with the relevant Restaurant Partner: Your name, mobile number (or a masked identifier where feasible), Order details, and special requests. GPS location data is not shared with Restaurant Partners. The Restaurant Partner receives only an automated preparation trigger notification generated by the Platform’s proximity algorithm and does not receive Your location coordinates. Restaurant Partners are contractually bound to use shared data only for the purpose of fulfilling the relevant Order or Reservation.

6.2 Payment Processors

6.2.1 We share transaction data with Razorpay for the purpose of processing payments and facilitating daily settlement. Razorpay processes such data in accordance with PCI-DSS standards and its own privacy policy. We encourage You to review Razorpay’s privacy policy.

6.3 Cloud Infrastructure

6.3.1 All platform data, including personal data, is hosted on Supabase infrastructure, with servers located in Singapore and Tokyo (Japan). Additionally, certain data may be stored on infrastructure located in India. Supabase is certified to SOC 2 Type II standards, and all data is encrypted in transit and at rest. Supabase acts as a Data Processor and processes data solely on Our instructions.

6.4 AI Service Providers

6.4.1 We transmit restaurant menu item names and descriptions (not personal data) to Google’s Gemini API for the purpose of generating estimated nutritional information. No personal data of Users is transmitted to Google in this context.

6.5 Analytics and Communications Providers

6.5.1 We may engage third-party providers for email communications, SMS OTP delivery, and analytics services. Such providers act as Data Processors and process personal data strictly in accordance with Our instructions and applicable data processing agreements.

6.6 Legal Disclosures

6.6.1 We may disclose Your personal data to competent governmental authorities, law enforcement agencies, or courts if required by Applicable Law, a court order, or a lawful regulatory direction. We shall endeavour to notify You of such disclosures where legally permissible.

6.7 Business Transfers

6.7.1 In the event of a merger, acquisition, restructuring, or sale of assets involving the Company, Your personal data may be transferred to a successor entity, subject to the successor entity assuming equivalent data protection obligations. We shall notify You of such transfer.

6.8 No Sale of Personal Data

6.8.1 The Company does not sell, rent, or trade Your personal data to any third party for commercial purposes.

7. International Transfers of Personal Data

7.1 Your personal data may be transferred to and processed in countries outside India, including Singapore and Japan (Tokyo), where Supabase servers are located. Additionally, certain data may be processed and stored within India. Such transfers are necessary for the provision of the Services.

7.2 The Company takes reasonable steps to ensure that all cross-border transfers of personal data are conducted in compliance with the DPDPA 2023 and any applicable regulations governing international data transfers issued by the Government of India. We ensure that recipients of transferred personal data are contractually bound to standards of data protection equivalent to those required under Indian law.

8. Data Retention

8.1 We retain Your personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy, comply with Our legal obligations, resolve disputes, and enforce Our agreements.

8.2 Typical retention periods applicable to different categories of data are as follows:

  • Account data (name, email, mobile number): retained for the duration of account activity and for a period of three (3) years following account closure, or as required by Applicable Law.
  • Transaction and Order data: retained for a minimum of seven (7) years in compliance with applicable tax, accounting, and consumer protection laws.
  • GPS/location data for Takeaway Orders and Dine-In Pre-Orders: not stored by the Company. GPS data is processed transiently for proximity calculation only and is not retained on any server or device of the Company.
  • User Content (reviews, ratings): retained for the duration of platform availability unless removed by Us or upon a valid erasure request.
  • Log and technical data: retained for up to ninety (90) days for security and debugging purposes.

8.3 Upon expiry of the applicable retention period, We shall securely delete or anonymise Your personal data in accordance with Our data disposal procedures.

9. Data Security Measures

9.1 The Company implements reasonable technical, organisational, and administrative security measures designed to protect Your personal data from unauthorised access, disclosure, alteration, or destruction. These measures include:

  • Encryption of personal data in transit (using TLS/SSL protocols) and at rest.
  • Access controls restricting access to personal data to authorised personnel on a need-to-know basis.
  • Regular security assessments and vulnerability testing of the Platform.
  • Data processing agreements with all Data Processors requiring equivalent security standards.
  • Cloud infrastructure hosted on Supabase, which maintains SOC 2 Type II certification.

9.2 While the Company takes all reasonable precautions, no method of electronic transmission or storage is entirely secure. We cannot guarantee absolute security of Your personal data. In the event of a personal data breach that is likely to result in high risk to Your rights and freedoms, We shall notify You and the relevant regulatory authority in accordance with the DPDPA 2023.

10. Your Rights Under the DPDPA 2023

As a Data Principal under the Digital Personal Data Protection Act 2023, You have the following rights with respect to Your personal data:

10.1 Right of Access

10.1.1 You have the right to obtain a summary of the personal data held by Us about You and information about the manner in which such data has been processed.

10.2 Right of Correction and Updation

10.2.1 You have the right to request the correction of inaccurate or misleading personal data and the completion of incomplete personal data held by Us.

10.3 Right of Erasure

10.3.1 You have the right to request the erasure of Your personal data where such data is no longer necessary for the purpose for which it was collected, subject to Our legal obligations to retain certain data under Applicable Law. We shall process erasure requests within thirty (30) days of receipt. Account deletion shall be completed within thirty (30) days.

10.4 Right to Withdraw Consent

10.4.1 Where We process Your personal data on the basis of Your Consent, You have the right to withdraw such Consent at any time. Withdrawal of Consent shall not affect the lawfulness of processing carried out prior to such withdrawal. Withdrawal of Consent may affect Your ability to access certain features of the Platform that rely on such processing.

10.5 Right to Grievance Redressal

10.5.1 You have the right to have Your grievances regarding processing of Your personal data addressed expeditiously by the Company’s Data Protection Officer. See Clause 16 for contact details.

10.6 Right to Nominate

10.6.1 You have the right to nominate any individual to exercise Your rights under the DPDPA 2023 on Your behalf in the event of Your death or incapacity.

10.7 Exercising Your Rights

10.7.1 To exercise any of the above rights, please submit a written request to team@harkara-ai.in. We shall acknowledge Your request within seventy-two (72) hours and respond substantively within fifteen (15) days, or within such period as may be prescribed under the DPDPA 2023.

11. Children’s Privacy

11.1 The Platform is not directed at or intended for use by children under the age of eighteen (18) years. We do not knowingly collect personal data from minors. If We become aware that We have inadvertently collected personal data from a person under the age of eighteen (18) without appropriate consent, We shall take prompt steps to delete such data.

11.2 Parents and legal guardians who believe that their child’s personal data may have been collected through the Platform are encouraged to contact Us immediately at team@harkara-ai.in.

12. Cookies and Tracking Technologies

12.1 The Platform uses cookies, web beacons, and similar tracking technologies to enhance user experience, analyse usage, and facilitate certain Services. A detailed description of the types of cookies used, their purposes, and Your options for managing them is set out in Our Cookie Policy, which is incorporated into this Privacy Policy by reference.

12.2 Where cookies require Your Consent under Applicable Law, We shall seek Your Consent prior to deploying such cookies. You may manage Your cookie preferences through Your browser settings or through Our Cookie Preference Centre, if available.

13. Third-Party Services and Links

13.1 The Platform may contain links to or integrations with third-party websites and services. This Privacy Policy does not apply to such third-party services, and We are not responsible for the privacy practices of third parties. We encourage You to review the privacy policies of any third-party services You access through the Platform.

14. Changes to This Privacy Policy

14.1 We reserve the right to update or modify this Privacy Policy at any time. The revised Privacy Policy shall be published on the Platform with the date of the most recent update. We shall notify registered Users of material changes via their registered email address or through a prominent notice on the Platform.

14.2 Your continued use of the Platform after the effective date of any revised Privacy Policy constitutes Your acceptance of the changes. If You do not agree to the revised Privacy Policy, You must cease using the Platform and may submit an erasure request in accordance with Clause 10.3.

15. Data Protection Officer

15.1 The Company has designated a Data Protection Officer (DPO) responsible for overseeing compliance with the DPDPA 2023 and related data protection obligations. The DPO can be reached at:

Name: Vidit Kumar Jain

Designation: Data Protection Officer

Email: team@harkara-ai.in

16. Grievance Officer and Contact Information

16.1 In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 and the DPDPA 2023, the Company has appointed a Grievance Officer to address data privacy complaints and grievances from Users:

Name: Milind Raj

Designation: Grievance Officer

Email: team@harkara-ai.in

16.2 All grievances shall be acknowledged within twenty-four (24) hours of receipt and resolved within fifteen (15) days, or within such period as may be prescribed under Applicable Law. You also have the right to escalate unresolved grievances to the Data Protection Board of India, once constituted under the DPDPA 2023.

16.3 For any general enquiries regarding this Privacy Policy or Our data practices, please contact Us at team@harkara-ai.in.

— End of Privacy Policy —

© 2026 Harkara AI Private Limited. All Rights Reserved.