Privacy Policy
Privacy Policy
Last updated: 13 June 2026
This Privacy Policy describes how CNM Food (also referred to as "we", "us", or "our") collects, uses, stores, and shares information when you use our websites, APIs, and mobile applications that connect to the CNM Food platform. Depending on configuration, the operating company may appear on invoices or legal notices as CNM Food Pvt Ltd or another entity name shown in the app or on receipts.
This policy applies together with our Terms & Conditions, Refund Policy, and any in-app notices presented at the time you use a feature.
1. Apps and services covered
We operate a multi-sided food and delivery ecosystem. This policy covers personal information processed in connection with:
- CNM Food (consumer app) — browse restaurants, build carts, place orders, track delivery, manage your profile, addresses, offers, and related features.
- CNM Food Partner / vendor app — restaurant and seller onboarding, menu and catalogue management, order handling, payouts and business reporting, and partner support tools.
- CNM Rider (driver / delivery partner app) — driver registration and KYC, going online for assignments, navigation and live location while fulfilling orders, earnings, and operational communications.
All of these clients communicate with our CNM Food backend and shared services (for example authentication, orders, notifications, and maps). Information collected in one app may be combined with information from the same account or device where needed to operate the service and keep accounts secure.
2. Categories of information we collect
The exact data depends on which app you use and which features you enable. Broadly, we collect the following categories.
2.1 Account and identity
- Phone number — used for OTP login, account recovery, fraud prevention, and operational SMS where enabled.
- Name and profile details — display name, saved addresses, preferences, and similar fields you choose to provide.
- Consumer app: optional Google or Apple sign-in identifiers when you use those login methods (subject to their respective terms and privacy notices).
- Vendor app: business legal name, trade name, GST or tax identifiers, registered address, bank or payout details, authorised contacts, and onboarding documents you upload for verification.
- Rider app: driver legal name, contact details, vehicle or licence information, and KYC documents (for example photographs of ID or vehicle documents) that you submit through the app or as requested by operations.
2.2 Orders, payments, and logistics
- Order contents — items, quantities, special instructions, restaurant or vendor identifiers, timestamps, and status history.
- Delivery information — pickup and drop addresses or coordinates, contact numbers shared for delivery, proof-of-delivery where captured, and route-related data generated during fulfilment.
- Payments — when you pay in-app, payment processing is performed by authorised payment partners (such as Razorpay). We receive limited payment metadata (for example transaction references, amounts, and status) needed to reconcile orders. We do not store full card numbers on our servers; card data is handled by the payment provider under their PCI-compliant flows.
- Support and disputes — messages, call logs, or tickets you send through Help & Support, chat, or email channels we operate.
2.3 Location
- Consumer app — approximate or precise device location when you grant permission, used to show nearby restaurants, delivery ETAs, and map experiences.
- Rider app — precise location while you are online or on active delivery, including in the background, so we can assign orders, show customers live tracking, verify completion, and meet safety obligations. If you deny location permissions, certain features may be unavailable.
- Vendor app — location where relevant (for example store coordinates or delivery radius configuration).
2.4 Device, diagnostics, and security
- Device and app metadata — device model, operating system version, app version, language, time zone, and network type.
- Identifiers — push notification tokens (for example via Firebase Cloud Messaging), installation-related identifiers used for messaging delivery, and internal account IDs.
- Logs and performance — error reports, API usage patterns, and diagnostic events used to secure the platform and fix bugs.
- Anti-fraud — signals such as IP address, device fingerprints, or velocity checks to detect abuse, duplicate accounts, or payment fraud.
2.5 Content you upload
- Photos and files — menu images, profile photos, KYC images, invoices you export, or attachments you send to support.
- Reviews and ratings — where the consumer app allows feedback, we process the text and metadata you submit subject to our content policies.
2.6 Communications
- Push notifications — order updates, promotions where permitted, and operational alerts (you can disable many categories in device settings).
- Email or SMS — transactional messages (OTP, order confirmations) and, where you opt in, marketing.
3. How we use your information
We use personal information for the following purposes (as applicable to your role):
- Creating and maintaining your account; authenticating you; and enforcing our terms.
- Displaying menus, prices, and availability; processing orders; and coordinating between customers, vendors, and riders.
- Calculating fees, taxes, settlements, and payouts; generating invoices or statements where required.
- Showing maps, routes, and ETAs using providers such as Google Maps or other map services integrated in the apps.
- Delivering push notifications and in-app messages through services such as Firebase and platform notification frameworks.
- Detecting, investigating, and preventing fraud, abuse, or illegal activity; enforcing geographic or eligibility rules.
- Complying with law, court orders, or lawful requests from authorities.
- Improving reliability, performance, and user experience through analytics derived from operational data (for example conversion funnels and error rates). We do not sell your personal information to data brokers, and we do not use your phone number for cross-app advertising "tracking" as defined by Apple for unrelated third-party ad networks.
- Contacting you about safety incidents, product changes, or this policy.
4. Legal bases (where applicable)
If you reside in a region that requires a stated legal basis (for example the EEA or UK), we rely on one or more of: performance of a contract (providing the service you requested); legitimate interests (security, fraud prevention, product improvement, and internal reporting, balanced against your rights); legal obligation; and consent where we expressly ask it (for example optional marketing or certain permissions).
5. How we share information
We share personal information only as needed to operate the platform:
- With other users on the service — for example riders see delivery addresses and customer contact options needed to complete a trip; customers may see rider or store names shown in the app during an order.
- With restaurants and vendors — order details, preparation notes, and customer contact information required to fulfil the order.
- With service providers — hosting, database, email/SMS gateways, push delivery, payment processing, maps, analytics sub-processors bound by confidentiality and processing terms.
- For legal reasons — to regulators, law enforcement, or private parties when we believe in good faith that disclosure is required by law or to protect rights, safety, or property.
- Business transfers — in connection with a merger, acquisition, or asset sale, subject to appropriate safeguards and notice where required.
We require processors to use information only on our instructions and to implement appropriate security measures. We do not sell personal information for monetary consideration.
6. International transfers
Our servers and subprocessors may be located in India or other countries. Where we transfer personal data across borders, we implement safeguards consistent with applicable law (such as contractual clauses or adequacy decisions where required).
7. Retention
We retain information for as long as your account is active and for a reasonable period afterward to resolve disputes, enforce agreements, and meet legal, tax, or accounting requirements. KYC and transaction records may be kept longer where the law requires. When retention periods expire, we delete or anonymise data where feasible.
8. Security
We use administrative, technical, and organisational measures designed to protect personal information (including encryption in transit, access controls, and secure credential storage patterns in our apps). No method of transmission over the Internet is 100% secure; you should protect your device and OTP codes.
9. Your choices and rights
- Access and correction — update profile fields in the app where available, or contact support for assistance.
- Deletion — you may request account closure or deletion of personal data subject to legal retention exceptions. We will verify your identity before processing sensitive requests.
- Marketing opt-out — follow unsubscribe instructions in messages or adjust notification preferences in the app or device settings.
- Permissions — location, camera, photo library, microphone (if used), and notifications can be controlled through your device settings. Withdrawing permission may limit features.
- Regional rights — depending on your jurisdiction (including GDPR, Indian DPDP Act, or state privacy laws), you may have additional rights such as portability, objection to certain processing, or the right to lodge a complaint with a supervisory authority.
10. Children
Our services are not directed to children under the age required to enter a binding contract in your jurisdiction (typically 18 for commercial contracts in India). We do not knowingly collect personal information from children. If you believe we have collected a child's data, contact us and we will take appropriate steps to delete it.
11. Third-party links and SDKs
Our apps may contain links to third-party sites or integrate third-party SDKs (maps, payments, sign-in, notifications). Their collection and use of information are governed by their respective privacy policies. We encourage you to read those policies.
12. Automated decisions
We may use automated rules to support fraud checks, rider assignment, surge or pricing logic where applicable, and content moderation. Where required by law, we will provide meaningful information about logic and your rights to human review.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version at this URL and update the "Last updated" date. If changes are material, we may provide additional notice (for example an in-app banner or email). Continued use after the effective date constitutes acceptance of the updated policy where permitted by law.
14. Contact
For privacy questions, data subject requests, or complaints, contact us through Help & Support or the contact channels shown in your app or on official CNM Food correspondence. Please include your registered phone number or account identifier so we can assist you safely.