Legal

Privacy policy

What personal data BiteSite collects, why, who it is shared with, how long it is kept, and the rights you have over it.

Last updated 20 August 2026.

Who this policy is from

This policy explains how Yash Gadia (trading as Anvaya Labs) handles personal data in BiteSite, the canteen pre-ordering service. It covers the marketing site at www.bitesite.in and the student, canteen and administration portals on the bitesite.in domain.

It describes what the service actually does today, and is written to align with India's Digital Personal Data Protection Act.

What we collect

  • Account details. Your name, email address and password. The password is stored only as a bcrypt hash and is never held in a readable form. A mobile number and a roll number are optional and are stored only if you provide them.
  • Verification codes. One-time codes sent to your email or phone, stored only as hashes, with their expiry and attempt count.
  • Your college. The single college your account belongs to, which determines the canteens and menus you can see.
  • Order data. What you ordered, from which outlet, at what price, when, and the status of the order through preparation and collection.
  • Payment references. The order amount, Razorpay's order and payment reference identifiers, and the payment status Razorpay reports back to us.
  • Support requests. The subject and text of any grievance you raise, the order it relates to, and the response from canteen or administration staff.
  • Push notification subscriptions. If you opt in to order-ready alerts, the browser-issued subscription endpoint and keys needed to deliver them.
  • Operational and audit logs. Records of significant actions such as menu price changes, order status changes and account deletions, kept for accountability and fraud investigation.

What we never collect

Your payment credentials never reach us

Card numbers, CVVs, UPI PINs, bank credentials and similar details are entered on Razorpay's checkout and are processed by Razorpay. BiteSite never receives, sees or stores them. We hold only the amount, Razorpay's reference identifiers, and whether the payment succeeded or failed.

Why we process it, and on what basis

We process personal data to provide the service you asked for, and for no unrelated purpose. Specifically, to:

  • create and authenticate your account, and verify that you are reachable
  • show you your own college's canteens and menus
  • take payment and confirm it before your order enters the kitchen queue
  • let canteen staff prepare your order and hand it to you
  • notify you when your order is ready or has been cancelled
  • process refunds
  • let you raise support issues and let staff respond to them
  • investigate misuse and keep records the canteen needs for its accounts

The basis for this processing is the consent you give when you register and place an order, together with what is necessary to perform that order and to meet our legal and accounting obligations. We do not use your data for advertising, and we do not sell it.

Who your data is shared with

  • Your college's canteen staff. Staff at the outlet you ordered from can see your order and the name attached to it, so they can prepare it and hand it over. They cannot see other colleges' data.
  • Razorpay. Our payment gateway, which processes your payment and any refund under its own privacy policy.
  • Infrastructure and communication providers. The cloud hosting, email and SMS providers we use to run the service and to send you verification codes.
  • Authorities, where we are legally required to disclose something.

We do not sell or rent personal data, and we do not share it for advertising.

How we protect it

  • Passwords are stored as bcrypt hashes; verification codes as SHA-256 hashes.
  • All traffic to the service is served over HTTPS.
  • Access is role-based, and each college's data is isolated so one college can never read another's.
  • Sensitive staff and administrative actions are recorded in an audit log.
  • Rate limiting is applied to sign-in, registration, checkout, verification and support forms to limit abuse.

How long we keep it

Account data is kept while your account is active. Order and payment records are kept afterwards because the canteen has a legitimate accounting and tax need for them, but with the details identifying you removed if you delete your account. Verification codes are short-lived and expire within minutes. Audit logs are retained for accountability.

Your rights

You can:

  • Access and review the account details we hold, from your account page in the app
  • Correct your details by editing them in the app
  • Delete your account, which removes or anonymises your name, email, phone number and roll number and signs you out immediately
  • Withdraw consent for optional processing, such as turning off push notifications
  • Raise a grievance about how your data has been handled, and have it addressed by our grievance officer

When you delete your account, anonymised order and payment records remain so the canteen's books stay complete. They can no longer be linked back to you.

Children

BiteSite is intended for college students and staff. It is not directed at children. If you believe a child has created an account without appropriate consent, contact us and we will remove it.

Cookies and local storage

The app sets a session cookie so you stay signed in, and a security token used to protect forms against cross-site request forgery. These are necessary for the service to work. We do not use advertising or cross-site tracking cookies. This marketing site does not set analytics or advertising cookies.

Where your data is processed

The service is hosted in India. Some providers we rely on may process limited data outside India; where that happens we rely on the provider's own safeguards and on transfers being permitted under applicable Indian law.

Changes to this policy

If this policy changes, the updated version is published on this page with a new effective date. Material changes affecting how we use your data will be brought to your attention in the app.

Grievance officer

In line with India's information technology rules and the Digital Personal Data Protection Act, we publish a grievance officer who is responsible for addressing complaints about your data or your use of the service.

Grievance officer

Yash Gadia
yash113gadia@gmail.com

We acknowledge grievances within a reasonable period and aim to resolve them within the timeframes required under applicable Indian law. For an issue with a specific order, using in-app Support at app.bitesite.in is faster, because it attaches your message to that order. Our contact page lists all routes.