LC LastCall Customer Privacy
Customer Privacy Customer Terms Account Deletion Restaurant Privacy Restaurant Terms

PRIVACY POLICY

LastCall — Customer Application (India) | Version 1.0 | Effective Date: 18/07/2026 | Last Updated: 18/07/2026

Effective Date: 18/07/2026Last Updated: 18/07/2026

This Privacy Policy (“Policy”) is published by LastCall Technologies IN, a company incorporated under the laws of India / Kozhikode, Kerala, having its registered office at Kozhikode, Kerala (hereinafter referred to as “LastCall”, the “Company”, “we”, “us” or “our”), and governs the collection, use, storage, processing, disclosure, transfer and protection of information in connection with the LastCall customer mobile application (also branded “LastBite”) (the “App”), the LastCall marketplace it connects to (the “Platform”), and the website lastcall.co.in (collectively, the “Services”).

This Policy is an electronic record within the meaning of the Information Technology Act, 2000 (“IT Act”) and the rules made thereunder, and is published in compliance with Rule 3(1) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), and the Digital Personal Data Protection Act, 2023 (“DPDP Act”) together with any rules notified thereunder. Being generated by a computer system, it does not require any physical or digital signature.

This Policy applies to individuals who download, register on, access or use the App to browse, reserve, purchase and collect surplus food offered by our partner food businesses (“Customer(s)”, “you” or “your”). The food businesses that list food on the Platform (restaurants, cafés, bakeries, grocery stores, cloud kitchens and similar operators) are referred to as “Partners” or “Stores”.

BY DOWNLOADING, INSTALLING, REGISTERING ON OR USING THE APP, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS POLICY AND CONSENT TO THE COLLECTION, USE, PROCESSING, STORAGE, DISCLOSURE AND TRANSFER OF YOUR INFORMATION AS DESCRIBED HEREIN. IF YOU DO NOT AGREE WITH THIS POLICY, PLEASE DO NOT USE THE SERVICES.

1. Definitions

In this Policy, unless the context otherwise requires:

  • “Personal Data” means any data about an individual who is identifiable by or in relation to such data, as defined under Section 2(t) of the DPDP Act;
  • “Sensitive Personal Data or Information” or “SPDI” has the meaning assigned under Rule 3 of the SPDI Rules and includes, inter alia, passwords and financial information such as bank account, card or payment-instrument details;
  • “Data Fiduciary” means the person who alone or with others determines the purpose and means of processing of Personal Data (in respect of your customer account data, LastCall is the Data Fiduciary);
  • “Data Principal” means the individual to whom the Personal Data relates — you, in respect of your own Personal Data;
  • “Data Processor” means any person who processes Personal Data on behalf of a Data Fiduciary (e.g., our cloud infrastructure and payment providers);
  • “Processing” means a wholly or partly automated operation performed on Personal Data, including collection, recording, storage, use, sharing, disclosure, erasure or destruction;
  • “Surprise Bag” or “Food Bag” means a listing of surplus food offered by a Partner at a discounted price through the Platform, whose exact contents may be undisclosed until pickup;
  • “Order” means your purchase of a Surprise Bag from a Partner through the Platform;
  • “Pickup Code” means the unique code generated for an Order which you present to the Partner to collect it.

2. Scope and Applicability

This Policy applies to all information collected through the App, communications between you and LastCall (including email to lastcallfoodteam@gmail.com, in-app support, WhatsApp or telephone), and the registration and ordering process. It applies to Customers located in, or using the Services in, India. Where you access the Services from outside India, additional or different terms may apply, and you remain responsible for compliance with local law.

This Policy does not apply to third-party websites, applications or services linked from the Services (for example, the Google Play Store or Apple App Store, payment gateway pages, or mapping services). It also does not govern the independent practices of the Partner Stores from which you buy food. Your use of such third-party services is governed by their respective privacy policies, and we encourage you to review them.

3. Information We Collect

We collect information in three ways: (a) information you provide to us directly; (b) information collected automatically when you use the App; and (c) information received from third parties. We follow the principle of data minimisation and collect only such Personal Data as is necessary for the specified purposes.

3.1 Information You Provide Directly

  • Identity and contact information: your name or display name, mobile telephone number (verified via one-time password (“OTP”)), and email address;
  • Profile information: an optional profile photograph and food or dietary preferences (for example, vegetarian, vegan) that you choose to save to personalise your experience;
  • Location and address information: your delivery-area or collection preferences, saved localities, and — with your permission — your device location, used to show nearby Stores and Surprise Bags and to help you navigate to a Store for pickup;
  • Order information: the Surprise Bags you reserve or purchase, quantities, pickup dates and windows, Pickup Codes, and your order history;
  • Payment information: payments are processed by our third-party payment provider (Stripe) and other RBI-regulated payment aggregators. You enter card, UPI or other payment-instrument details on the payment provider’s secure interface. LastCall does not store your full card number, CVV or UPI PIN; we receive only limited tokens, a masked instrument reference, and the status of each transaction. Payment-instrument information constitutes SPDI and is handled with heightened safeguards;
  • Ratings, reviews and feedback: the star ratings, review text, complaints, grievances, survey responses and support messages you submit through the App or by email, together with associated metadata such as timestamps;
  • Media: photographs or images you optionally capture with your device camera or select from your photo library (for example, a profile photo or an image attached to a review or support request), where you grant the CAMERA and READ_MEDIA_IMAGES / READ_EXTERNAL_STORAGE permissions for this purpose.

3.2 Information Collected Automatically

  • Device and technical information: device model, manufacturer, operating system and version, application version, unique application-instance identifiers, Firebase installation identifiers, push-notification registration tokens (Firebase Cloud Messaging (“FCM”) tokens), device language and time zone;
  • Location information: with your permission (ACCESS_COARSE_LOCATION and/or ACCESS_FINE_LOCATION), we collect device location to detect your area, sort Stores and Surprise Bags by distance, and display Stores on a map. You may decline or revoke location permission through your device settings; in that case you can search by locality manually and certain map features may be limited;
  • Advertising identifier: your device advertising ID (AD_ID) may be accessed by our analytics tools to measure app performance and, where enabled, to limit and personalise in-app messaging; you can reset or limit this identifier in your device settings;
  • Network information: network connection state and type (ACCESS_NETWORK_STATE), used to monitor connectivity and manage actions taken while offline;
  • Usage and interaction data: screens viewed, searches run, Stores and listings viewed, items favourited, Orders placed, cancelled or completed, notification interactions, and session start and end times;
  • Transaction and performance data: Order identifiers, Order values, Pickup Codes, Order statuses and status timestamps, cancellation events and the party responsible (customer, store or system), cancellation reasons, refund statuses, and ratings you give;
  • Trust, safety and integrity data: signals generated by our automated systems in respect of unusual or potentially abusive activity (for example, repeated no-shows, chargeback abuse, or fraudulent ordering), including flag type, counts, timestamps, and any resulting account status;
  • Crash, diagnostic and error data: crash logs, stack traces, error reports and performance measurements used to diagnose and fix defects;
  • Local storage: the App stores limited session data on your device (for example, user ID, display name, login state and preferences) in application storage to keep you signed in and operate efficiently. The App does not use browser cookies, but analogous local-storage technologies serve similar functions.

3.3 Information Received from Third Parties

  • Authentication providers: confirmation of your verified telephone number and authentication tokens from Google Firebase Authentication;
  • Payment providers: payment confirmations, payment identifiers, masked instrument references, settlement statuses, refund statuses and chargeback information from Stripe, payment aggregators and banks;
  • Partner Stores: order-fulfilment updates, pickup confirmations, no-show reports and any complaints a Store raises concerning an Order;
  • Mapping providers: geocoding results and map data from Google Maps Platform used to locate Stores and provide directions;
  • App distribution platforms: install, update and, where applicable, aggregated statistics from the Google Play Store or Apple App Store.

3.4 Information We Do Not Knowingly Collect

We do not knowingly collect biometric data, health data, caste or religious information, or data revealing political opinions. We do not request access to your contacts, call logs, SMS (other than device-level OTP auto-read facilitated by the operating system, where applicable), or microphone. The Services are not directed at children; see Section 12.

4. Purposes of Processing and Legal Bases

We process Personal Data for the following purposes and, in each case, on the legal basis of your consent obtained at registration and/or the legitimate uses recognised under Section 7 of the DPDP Act, and, where applicable, performance of our contract with you:

  • Account creation and authentication: to register your account, verify your telephone number via OTP, authenticate sessions and secure access;
  • Provision of the Services: to show you nearby Stores and Surprise Bags, let you search, favourite, reserve and purchase Orders, generate Pickup Codes, track Order status, and maintain your order history and preferences;
  • Payments and refunds: to process your payments through our payment providers, apply any applicable taxes and fees, generate receipts, and process refunds and reversals;
  • Communications: to send transactional and service messages — order confirmations, pickup reminders, status changes, refund notices, policy updates and administrative announcements — via push notification (FCM), SMS, email, WhatsApp or in-app message; and, subject to your right to opt out, marketing and promotional communications;
  • Personalisation: to recommend Stores, cuisines and Surprise Bags likely to interest you based on your location, preferences and past activity;
  • Trust, safety and fraud prevention: to detect, investigate, prevent and act upon fraud, chargeback abuse, repeated no-shows, and policy-violating activity, and to protect Customers, Partners, LastCall and the public;
  • Quality, analytics and improvement: to analyse usage in aggregate, measure performance, understand food-rescue impact, debug and fix errors, and develop new features using de-identified or aggregated data;
  • Compliance and legal claims: to comply with applicable laws (including the Consumer Protection Act, 2019, the Consumer Protection (E-Commerce) Rules, 2020 and tax laws), respond to lawful requests, handle disputes and chargebacks, and establish, exercise or defend legal claims;
  • Business transactions: to evaluate or carry out a merger, acquisition, financing, reorganisation or sale of assets, subject to appropriate confidentiality safeguards.

Where processing is based on consent, you may withdraw consent at any time as described in Section 10; withdrawal does not affect the lawfulness of processing carried out before withdrawal and may result in our inability to continue providing some or all of the Services.

5. Disclosure and Sharing of Information

We do not sell your Personal Data. We share information only as described below and, in the case of Data Processors, under contracts requiring them to process data only on our instructions and with appropriate security safeguards:

  • With Partner Stores: to fulfil an Order, we share with the relevant Store your first name or display name, the Pickup Code, order details and, where necessary for pickup coordination, a masked or full contact number. Stores are required to use this data solely to fulfil your Order and not for marketing or any other purpose;
  • Payment providers: Stripe, payment aggregators, banks and financial institutions, to process your payments, refunds and chargebacks in compliance with directions of the Reserve Bank of India;
  • Cloud infrastructure and analytics providers: we use Google Firebase services (Authentication, Cloud Firestore, Cloud Storage, Cloud Messaging, and crash and analytics services) operated by Google LLC and its affiliates to host data, authenticate users, store images, deliver notifications and analyse aggregate usage; and Google Maps Platform for geocoding and maps. Google acts as our Data Processor for hosted content;
  • Communication providers: SMS gateways, email service providers and messaging platforms engaged to deliver OTPs and notifications;
  • Professional advisers and auditors: lawyers, accountants, auditors and insurers, under duties of confidentiality;
  • Governmental, regulatory and law-enforcement authorities: where required by applicable law, court order or lawful request, including disclosures to consumer authorities, tax authorities, the Data Protection Board of India, CERT-In, or police; and where we believe in good faith that disclosure is necessary to protect the rights, property or safety of any person or to prevent or investigate fraud or illegality;
  • Group companies and successors: our affiliates, and any acquirer or successor in a corporate transaction, subject to this Policy or an equally protective policy;
  • With your direction or consent: any other disclosure you request or authorise.

We may disclose aggregated or de-identified information — for example, total kilograms of food saved in a city, or aggregate order volumes — that cannot reasonably be used to identify you, for impact reporting, marketing, investor communications and research.

6. Cross-Border Transfer of Data

Our infrastructure and payment providers, including Google and Stripe, may store and process data on servers located outside India. By using the Services, you understand that your information may be transferred to, stored in and processed in jurisdictions other than India. We will effect such transfers in compliance with Section 16 of the DPDP Act and any notifications issued by the Central Government restricting transfer to specified countries, and, where the SPDI Rules apply, only to entities ensuring the same level of data protection as required under Indian law. Where the law requires particular categories of data (including certain payment data pursuant to Reserve Bank of India directions) to be stored in India, we and our payment providers will comply with such localisation requirements.

7. Data Retention

We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal, tax, accounting and regulatory obligations, to resolve disputes, and to enforce our agreements. Illustratively:

  • Account and profile data is retained for the life of your account and thereafter as described below;
  • Order, transaction, payment and refund records are retained for the minimum periods required under Indian tax and company law;
  • Trust-and-safety flags, chargeback and fraud logs are retained for as long as reasonably necessary to protect the Platform against fraud and abuse, including after account closure;
  • Support communications and grievance records are retained for at least the period required under the Consumer Protection (E-Commerce) Rules, 2020 and the IT Rules, 2021;
  • Device tokens and diagnostic data are retained for short rolling periods consistent with their technical purpose.

Upon deletion or termination of your account, your record is removed from active systems and an archival copy may be moved to a segregated deletion archive for a limited period to permit account restoration in cases of accidental deletion, to complete pending refunds and disputes, to comply with retention laws, and to prevent circumvention of restrictions through re-registration. Thereafter, data is deleted or irreversibly anonymised. Anonymised and aggregated data may be retained indefinitely.

8. Security of Information

We implement reasonable security practices and procedures as contemplated under Section 43A of the IT Act, the SPDI Rules, and Section 8(5) of the DPDP Act, designed to protect Personal Data against unauthorised access, disclosure, alteration, loss and destruction. These include, without limitation:

  • encryption of data in transit using industry-standard TLS, with cleartext (unencrypted HTTP) traffic disabled at the application level;
  • encryption at rest applied by our cloud infrastructure providers;
  • processing of card and payment details through PCI-DSS-compliant payment providers, so that LastCall does not hold your full payment-instrument data;
  • authentication via OTP-verified telephone numbers and secure session management;
  • granular database security rules restricting each Customer’s access to their own account, orders and data;
  • role-based access controls, with elevated administrative functions restricted to authorised LastCall personnel;
  • logging, monitoring and automated anomaly detection;
  • organisational measures such as confidentiality undertakings, need-to-know access, and periodic review of security practices.

No method of transmission over the internet or electronic storage is completely secure. While we strive to protect your Personal Data, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your device, SIM and OTPs, for enabling device-level security, and for notifying us immediately at lastcallfoodteam@gmail.com of any suspected unauthorised access to your account.

9. Personal Data Breach

In the event of a personal data breach, we will notify the Data Protection Board of India and each affected Data Principal in the form and manner prescribed under the DPDP Act and rules thereunder, and will report cyber security incidents to the Indian Computer Emergency Response Team (CERT-In) within the timelines prescribed under the CERT-In directions dated 28 April 2022 (currently six hours from noticing or being notified of specified incidents). We maintain internal incident-response procedures and system logs in accordance with applicable CERT-In requirements.

10. Your Rights as a Data Principal

Subject to the DPDP Act and applicable exemptions, you have the following rights in respect of your Personal Data:

  • Right to access: to obtain a summary of the Personal Data being processed, the processing activities undertaken, the identities of Data Fiduciaries and Data Processors with whom the data has been shared, and any other prescribed information;
  • Right to correction and updating: to have inaccurate or misleading data corrected, incomplete data completed, and data updated. You can edit most profile details directly in the App; changes to your verified telephone number are effected through an OTP-verified phone-change process;
  • Right to erasure: to request erasure of Personal Data no longer necessary for the specified purpose, subject to retention required by law. You may initiate account deletion through the App or by written request to lastcallfoodteam@gmail.com;
  • Right to withdraw consent: at any time, with the ease with which it was given, by adjusting device permissions, disabling notification categories, or writing to us; consequences of withdrawal are described in Section 4;
  • Right of grievance redressal: to have your grievances addressed by our Grievance Officer within the timelines specified in Section 15;
  • Right to nominate: to nominate another individual to exercise your rights in the event of your death or incapacity;
  • Right to complain to the Board: if unsatisfied with our response, to lodge a complaint with the Data Protection Board of India in the manner prescribed under the DPDP Act.

You also have corresponding duties under Section 15 of the DPDP Act, including the duty not to impersonate another person, not to suppress material information, not to register false or frivolous grievances, and to furnish only verifiably authentic information when exercising the rights of correction or erasure. We will respond to verified requests within the timelines prescribed by applicable law, and may require you to verify your identity (for example, via OTP) before acting on a request.

11. Notifications, Marketing and Communication Preferences

Transactional and service notifications — such as order confirmations, pickup reminders, cancellation and refund notices, and safety communications — are integral to the Services and are sent for as long as you maintain an account; disabling them may cause you to miss time-sensitive pickup information. On Android 13 and above, push notifications require the POST_NOTIFICATIONS permission, which you may grant or revoke in device settings. Promotional and marketing communications will be sent only in accordance with applicable law, including the Telecom Commercial Communications Customer Preference Regulations, 2018, and you may opt out of them at any time via in-app settings, unsubscribe links, or by writing to lastcallfoodteam@gmail.com, without affecting transactional messages.

12. Children’s Privacy

The Services are intended solely for use by persons who are at least eighteen (18) years of age and competent to contract under the Indian Contract Act, 1872. We do not knowingly collect Personal Data from children (persons under 18 years of age) and do not undertake tracking, behavioural monitoring or targeted advertising directed at children, consistent with Section 9 of the DPDP Act. If you believe a child has provided Personal Data to us, please contact the Grievance Officer, and we will take steps to delete such data.

13. Automated Processing and Personalisation

We use automated systems to personalise the Stores and Surprise Bags shown to you, to sort listings by distance and relevance, and to detect fraud, chargeback abuse and repeated no-shows. Where automated trust-and-safety measures result in a restriction on your account, you will be informed and may seek human review by contacting the Grievance Officer. We do not use automated decision-making to produce legal effects concerning you without a mechanism for human review.

14. Third-Party Services and Links

The App is built on and interoperates with third-party services, including Google Firebase, Google Maps Platform, Google Play services, Stripe and other payment aggregators. Those providers may collect certain service and diagnostic data directly, as described in their own privacy policies (for Google, at policies.google.com/privacy; for Stripe, at stripe.com/privacy). Links from the Services to external websites are provided for convenience only; we are not responsible for the privacy practices or content of third parties, including the independent practices of Partner Stores.

15. Grievance Officer and Data Protection Contact

In accordance with the IT Act and rules thereunder, the Consumer Protection (E-Commerce) Rules, 2020, and the DPDP Act, the name and contact details of the Grievance Officer are provided below. The Grievance Officer shall acknowledge grievances within forty-eight (48) hours and endeavour to resolve them within the shorter of the timelines prescribed by applicable law (currently fifteen (15) days under the IT Rules, 2021, and one (1) month under the E-Commerce Rules for consumer grievances):

  • Grievance Officer: Salman N and Govind Amilkanthwar
  • Designation: Grievance Officer, LastCall Technologies IN
  • Email: lastcallfoodteam@gmail.com
  • Hours: Monday to Friday, 10:00–18:00 IST (excluding public holidays)

For data-protection-specific queries, requests to exercise Data Principal rights, or consent withdrawals, you may also write to lastcallfoodteam@gmail.com with the subject line “Data Principal Request”.

16. Changes to This Policy

We may update this Policy from time to time to reflect changes in law, technology or our practices. Material changes will be notified to you through the App, by push notification, or by email to your registered address, and the “Last Updated” date above will be revised. Your continued use of the Services after the effective date of an updated Policy constitutes acceptance; where the law requires fresh consent for new purposes of processing, we will seek it. We encourage you to review this Policy periodically. Prior versions may be obtained on request.

17. Governing Law

This Policy shall be governed by and construed in accordance with the laws of India. Subject to the dispute-resolution provisions of the Terms & Conditions and to your rights under consumer-protection law, the courts at Kozhikode, Kerala shall have jurisdiction over disputes arising out of or relating to this Policy.

18. Contact Us

If you have questions, concerns or requests regarding this Policy or our data practices, please contact us at:

  • LastCall Technologies IN
  • Email: lastcallfoodteam@gmail.com
  • Website: https://lastcall.co.in
HomeCustomer PrivacyCustomer TermsAccount DeletionRestaurant PrivacyRestaurant Terms
© 2026 LastCall Technologies IN · Kozhikode, Kerala · lastcallfoodteam@gmail.com