Details marked to be published are being finalised and will appear here once confirmed.
In short
- We collect only what we need to run Stataa: your account details, orders, support tickets and security logs. We use your location only if you allow it.
- We do not sell your personal data and do not use it for third-party advertising.
- Customers' card and UPI details go to our payment partner, not to us; we never see a card number or UPI PIN. Shops' payout bank account or UPI ID is stored by us, encrypted, only to pay them.
- During the pilot, your data is stored on our server in Germany and passes through Cloudflare's worldwide network.
- You can access, correct or delete your data, withdraw consent, nominate someone, and complain. Write to privacy@stataa.com.
1. Who is responsible for your data
to be published (to be published) decides how your personal data is used on Stataa. Under the Digital Personal Data Protection Act, 2023 (the DPDP Act) we are the "Data Fiduciary" and you are the "Data Principal".
Questions about your data: privacy@stataa.com. Complaints: our Grievance Officer, to be published, to be published, grievance@stataa.com.
You can ask for this notice in Hindi or in any other language listed in the Eighth Schedule to the Constitution by writing to privacy@stataa.com.
2. What we collect and why
Everyone
- Name, email address and phone number: to create and secure your account, send order and security messages, and answer your support requests.
- Location, only if you allow it (approximate or precise, your choice on your device): to show shops near you and sort them by distance. You can switch it off and search by area instead. We do not keep a history of your precise location.
- Orders: what you reserved, from which shop, price, pickup window, pickup code status, cancellations and refunds. We need this to run your order, process refunds, keep tax and accounting records and handle disputes.
- Payment records: payment status, amount, the type of method used and reference numbers from our payment partner. Never your card number, CVV, UPI PIN or bank password.
- Support tickets: your messages, the photos you upload and the ticket reference (like STA-12345), so we can resolve complaints, follow up on food safety and give refunds.
- Device and security information: device type, operating system, app or browser version, IP address, time of access and security logs. We use this to keep you logged in, enforce order limits, detect fraud and abuse, fix bugs and keep Stataa secure.
If you report an illness or allergic reaction, your report may include health information. We use it only to handle your report and follow up with the shop, and we share it only as described in section 4.
Shops (sellers)
In addition: the owner's name, shop name, shop address and map pin, shop photos, logo, FSSAI number and certificate image, shop contact details, and GSTIN or PAN where you give them. We use these to verify your shop, show it to customers, pay you and meet tax and food-safety rules. For payouts we also keep the bank account (with IFSC) or UPI ID and account holder name you give us. The account number or UPI ID is stored encrypted; our staff see the full value only to verify it or to pay you, and every such view is logged.
Staff
In addition: work contact details, role, and a log of every action taken in staff tools. We use these for security and accountability.
3. Consent and other lawful grounds
- Consent. When you create an account, you agree to the uses in section 2 after reading this notice. Location and marketing messages are separate choices that you can turn on or off at any time.
- Legitimate uses. The DPDP Act (section 7) also lets us use data without fresh consent in some cases, such as when you voluntarily give it for a purpose (for example, a support ticket), to comply with a law or a court order, or in a medical emergency.
- Withdrawing consent. You can withdraw consent in the app settings or by writing to privacy@stataa.com. It is as easy as giving it. We will then stop using your data for that purpose. Some data is essential to run an account, so withdrawing consent for it means closing your account. Withdrawal does not undo lawful use before it, and we will still keep what the law requires (section 6).
4. Who we share data with
Shops and customers
- The shop you order from sees your name, what you ordered, the pickup window and the order status. If you report a problem, it sees the details and photos it needs to respond. Shops never see your payment details, and they may use your data only to complete your order.
- Customers see a shop's name, address, map pin, photos, logo, FSSAI number and contact details, as consumer law requires.
Service providers who work for us under contract
- Cloudflare: website and app network, security (such as blocking attacks and bots), domain name service, and forwarding emails sent to our @stataa.com addresses.
- Our payment partner, a payment aggregator authorised by the Reserve Bank of India: customer payments and refunds. For some of this it acts under its own legal duties and its own privacy policy.
- Our bank: to send shops their payouts (account holder name, account number or UPI ID, IFSC, amount).
- Email providers: to send account, order and support emails and to receive email sent to us.
- OpenStreetMap: our server fetches map images from OpenStreetMap's servers and keeps a copy for a week. Your device never contacts OpenStreetMap, so it never sees your IP address or where you're looking.
Others
- Authorities: when the law requires it, for example the police, FSSAI or food safety officers, tax authorities, CERT-In or a court. We check that each request is lawful and share only what is required.
- A new owner, if Stataa's business is sold or merged. Your data stays protected by this policy, and we will tell you.
5. Data stored outside India
During the pilot, Stataa's main server is located in Germany. Your data is stored there and travels through Cloudflare's worldwide network. Some service providers may also process data in other countries.
The DPDP Act and the DPDP Rules, 2025 allow personal data to be transferred outside India, subject to any restrictions the Central Government notifies. We will follow any such restriction, and we will update this policy if our server location changes. Data is encrypted in transit, and our providers are bound by contract to protect it.
6. How long we keep data
| Data | How long |
|---|---|
| Account profile | While your account is open, then deleted within 30 days of closing |
| Registration details after closing | 180 days (Information Technology Rules, 2021) |
| Orders, payments, refunds, invoices, payouts | 8 years (tax and company law) |
| Support tickets and their photos | 3 years after the ticket is closed |
| Security logs, IP addresses, device data | 1 year |
| Shop verification documents (FSSAI, photos) | While the shop is active, then 8 years |
| Rejected seller applications | 1 year |
| Records of accounts closed for fraud or safety | Up to 8 years, to stop repeat abuse |
| Staff action logs | 3 years |
If an account has had no login and no order for 3 years, we will delete it, and we will warn you at least 48 hours before. After these periods we delete data or make it anonymous.
7. How we protect data
We take reasonable security safeguards as the DPDP Act requires: encryption in transit, access limited by role, logs of every staff action, and monitoring for misuse. Staff may open personal data only when their task needs it. No system is perfectly secure, so please protect your password and pickup codes too.
8. If there is a data breach
If a breach affects your data, we will tell you without delay: what happened, what it may mean for you, what we are doing, what you can do to protect yourself, and whom to contact. We will report it to the Data Protection Board of India as the DPDP Rules require (including a detailed report within 72 hours) and to CERT-In, where required, within 6 hours.
9. Your rights
You can:
- get a summary of the personal data we hold about you, how we use it, and who we have shared it with;
- correct, complete or update your data;
- ask us to erase your data, unless the law requires us to keep it;
- withdraw consent (section 3);
- nominate someone to use these rights for you if you die or cannot act yourself; and
- complain to us and, after that, to the Data Protection Board of India.
To use these rights, use the settings in the app where available, or write to privacy@stataa.com from the email address on your account. We may ask you to confirm your identity. There is no fee. We will acknowledge your request within 24 hours and aim to complete it within 15 days. If it will take longer, we will tell you why, and it will never take more than the 90 days the DPDP Rules allow.
The DPDP Act also asks you to give true information, not to pretend to be someone else, and not to file false or frivolous complaints.
10. Children
Stataa is only for people aged 18 and over. The DPDP Act treats everyone under 18 as a child. Using a child's data needs verifiable consent from a parent, and tracking or targeted advertising aimed at children is not allowed. Stataa is a paid marketplace for adults, and a minor cannot make a binding contract, so we do not offer accounts to anyone under 18 and do not knowingly collect children's data. If we learn that an account belongs to a child, we will close it, refund open orders and delete the data, except what the law requires us to keep. Parents can write to privacy@stataa.com.
11. Cookies and similar technology
We use only essential cookies and similar storage, to keep you logged in and remember your settings. Cloudflare may set security cookies to detect bots and attacks. We do not use advertising or cross-site tracking cookies.
12. Messages we send
We send service messages that you need: order confirmations, pickup reminders, refund updates, security alerts and policy changes. We send offers or news only if you opt in, and you can unsubscribe at any time.
13. Changes to this policy
Each version has a number and an effective date. For important changes, we will tell you in the app or by email before they apply. If we want to use your data for a new purpose, we will ask for your consent first.
14. Contact
- Data requests: privacy@stataa.com
- Grievance Officer: to be published, to be published, grievance@stataa.com
- Security vulnerabilities: security@stataa.com
- Post: to be published, to be published
Questions about this page? Write to hello@stataa.com, or to our Grievance Officer at grievance@stataa.com. How complaints are handled.