PRIVACY POLICY
LastCall Restaurant — Partner Application (India) | Version 1.0 | Effective Date: 27/02/2026 | Last Updated: 27/02/2026
This Privacy Policy ("Policy") is published by LastCall Technologies IN, a company incorporated under the laws of India / Kozhikode, Kerala, having its registered office at Kozhikode, Kerala (hereinafter referred to as "LastCall", the "Company", "we", "us" or "our"), and governs the collection, use, storage, processing, disclosure, transfer and protection of information in connection with the LastCall Restaurant mobile application (the "Partner App"), the LastCall consumer marketplace it connects to (the "Platform"), and the website lastcall.co.in (collectively, the "Services").
This Policy is an electronic record within the meaning of the Information Technology Act, 2000 ("IT Act") and the rules made thereunder, and is published in compliance with Rule 3(1) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and the Digital Personal Data Protection Act, 2023 ("DPDP Act") together with any rules notified thereunder. Being generated by a computer system, it does not require any physical or digital signature.
This Policy applies primarily to restaurant owners, café operators, bakeries, grocery stores, cloud kitchens, and other food business operators and their authorised representatives who register on, access or use the Partner App ("Partner(s)", "you" or "your"). Where the Partner App displays limited personal data of end customers of the Platform ("Customers") for the purpose of order fulfilment, this Policy also describes how that data is handled.
BY DOWNLOADING, INSTALLING, REGISTERING ON OR USING THE PARTNER APP, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS POLICY AND CONSENT TO THE COLLECTION, USE, PROCESSING, STORAGE, DISCLOSURE AND TRANSFER OF YOUR INFORMATION AS DESCRIBED HEREIN. IF YOU DO NOT AGREE WITH THIS POLICY, PLEASE DO NOT USE THE SERVICES.
1. Definitions
In this Policy, unless the context otherwise requires:
- "Personal Data" means any data about an individual who is identifiable by or in relation to such data, as defined under Section 2(t) of the DPDP Act;
- "Sensitive Personal Data or Information" or "SPDI" has the meaning assigned under Rule 3 of the SPDI Rules and includes, inter alia, passwords, financial information such as bank account details, and biometric information;
- "Data Fiduciary" means the person who alone or in conjunction with others determines the purpose and means of processing of Personal Data (for the purposes of Partner account data, LastCall is the Data Fiduciary);
- "Data Principal" means the individual to whom the Personal Data relates — you, in respect of your own Personal Data;
- "Data Processor" means any person who processes Personal Data on behalf of a Data Fiduciary (e.g., our cloud infrastructure providers);
- "Processing" means a wholly or partly automated operation or set of operations performed on Personal Data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure, dissemination, restriction, erasure or destruction;
- "Surprise Bag" or "Food Bag" means a listing of surplus food offered by a Partner at a discounted price through the Platform;
- "Order" means a Customer's purchase of a Surprise Bag from a Partner through the Platform.
2. Scope and Applicability
This Policy applies to all information collected through the Partner App, the Partner web dashboard (if any), communications between you and LastCall (including email to lastcallfoodteam@gmail.com , in-app support, WhatsApp or telephone), and the onboarding process. It applies to Partners located in, operating in, or offering food in India. Where you access the Services from outside India, additional or different terms may apply, and you remain responsible for compliance with local law.
This Policy does not apply to third-party websites, applications or services that may be linked from the Services (for example, the Google Play Store, payment gateway pages, or mapping services). Your use of such third-party services is governed by their respective privacy policies, and we encourage you to review them.
If you are an employee, manager or authorised representative operating a Partner account on behalf of a food business, you represent that you are authorised to accept this Policy on behalf of that business and to provide any Personal Data of the business's personnel that is submitted to us.
3. Information We Collect
We collect information in three ways: (a) information you provide to us directly; (b) information collected automatically when you use the Partner App; and (c) information received from third parties. We follow the principle of data minimisation and collect only such Personal Data as is necessary for the specified purposes.
3.1 Information You Provide Directly
- Identity and contact information: your name, mobile telephone number (verified via one-time password ("OTP")), email address, and designation within the food business;
- Business and store profile information: legal and trade name of the establishment, store category (e.g., restaurant, bakery, café, grocery), business description, store address, geographic coordinates (latitude and longitude) of the store, opening and closing times, pickup windows, cuisine tags and dietary attributes (vegetarian, vegan, gluten-free), and photographs of the storefront, kitchen or food items uploaded by you;
- Regulatory and compliance information: your Food Safety and Standards Authority of India ("FSSAI") licence or registration number, Goods and Services Tax Identification Number ("GSTIN"), Permanent Account Number ("PAN") of the business or proprietor, shop and establishment registration, and any other licences or documents we reasonably request during onboarding or periodic verification;
- Financial and settlement information: bank account number, IFSC code, account holder name, UPI identifiers, cancelled cheque images or bank statements provided for payout verification, invoices, and commission or settlement records. Bank account details and payment instrument information constitute SPDI under the SPDI Rules and are handled with heightened safeguards;
- Listing and inventory information: Surprise Bag titles, sub-categories, descriptions, original and discounted prices, available quantities, pickup dates and times, estimated weights of food saved, and item photographs;
- Communications and support data: the content of messages, complaints, grievances, feedback, survey responses and FAQ interactions you submit through the Help & Support section of the Partner App or by email, together with associated metadata such as timestamps;
- Verification media: photographs or documents captured using your device camera or selected from your photo library, where you grant the CAMERA and READ_MEDIA_IMAGES / READ_EXTERNAL_STORAGE permissions for this purpose.
3.2 Information Collected Automatically
- Device and technical information: device model, manufacturer, operating system and version, application version, unique application instance identifiers, Firebase installation identifiers, push notification registration tokens (Firebase Cloud Messaging ("FCM") tokens), device language, and time zone;
- Approximate and precise location information: with your permission (ACCESS_COARSE_LOCATION and/or ACCESS_FINE_LOCATION), we collect device location for the limited purposes of automatically detecting your country and region during setup, verifying and geocoding your store address, and displaying your store correctly to Customers on the map. You may decline or revoke location permission through your device settings; in that case you may enter your store location manually and certain map features may be limited;
- Network information: network connection state and type, collected via the ACCESS_NETWORK_STATE permission, used to monitor connectivity and queue actions taken while offline;
- Usage and interaction data: screens viewed, features used, listings created or edited, orders accepted, marked ready, completed or cancelled, notification interactions, session start and end times, and in-app settings;
- Transaction and performance data: order identifiers, order values, pickup codes, order statuses and status timestamps, cancellation events and the party responsible for cancellation (customer, store or system), cancellation reasons, running counts of accepted-order cancellations, daily and total revenue figures, number of orders completed, ratings and review comments received from Customers, and estimated kilograms of food saved;
- Trust, safety and integrity data: flags generated by our automated monitoring systems in respect of unusual or potentially abusive activity (for example, a pattern of accepting Orders and subsequently cancelling them), including flag type, occurrence counts, first and last occurrence timestamps, an assigned risk level (low, medium or high), flag status (active, cleared or restricted), and the resulting account status of your store (active, restricted or blocked), together with an audit trail of such events;
- Crash, diagnostic and error data: crash logs, stack traces, error reports and performance measurements used to diagnose and fix defects;
- Local storage: the Partner App stores limited session data on your device (for example, store ID, store name, owner ID, owner email, login state and store active state) in application preferences to keep you signed in and to operate the app efficiently. The Partner App does not use browser cookies, but analogous local storage technologies serve similar functions.
3.3 Information Received from Third Parties
- Authentication providers: confirmation of your verified telephone number and authentication tokens from Google Firebase Authentication;
- Payment and settlement providers: payment confirmations, payment identifiers, settlement statuses, refund statuses and chargeback information from the payment aggregators and banks that process Platform transactions;
- Customers of the Platform: ratings, reviews and complaints concerning your store submitted by Customers;
- Mapping providers: geocoding results and map data from Google Maps Platform used to locate and display your store;
- Public and governmental sources: verification of FSSAI licence status, GSTIN status or other public registers, where permitted by law;
- App distribution platforms: install, update and, where applicable, aggregated statistics from the Google Play Store.
3.4 Customer Personal Data Displayed to You
To enable order fulfilment, the Partner App displays limited Personal Data of Customers to you, namely the Customer's first name (or display name), a masked or full contact number where necessary for pickup coordination, the pickup code, order details, payment method and payment status. You receive this data solely as necessary for fulfilling the specific Order. You must treat all Customer Personal Data as confidential, must not copy, export, scrape, store outside the Partner App, sell, or use it for marketing, profiling or any purpose other than fulfilling that Order, and must comply with the DPDP Act in respect of any processing you undertake. Misuse of Customer Personal Data is a material breach of our Terms & Conditions and may result in immediate suspension, termination and reporting to relevant authorities.
3.5 Information We Do Not Knowingly Collect
We do not knowingly collect biometric data, health data, caste or religious information, or data revealing political opinions. We do not request access to your contacts, call logs, SMS (other than device-level OTP auto-read facilitated by the operating system, where applicable), or microphone. The Services are business tools and are not directed at children; see Section 12.
4. Purposes of Processing and Legal Bases
We process Personal Data for the following purposes and, in each case, on the legal basis of your consent obtained at registration and/or the legitimate uses recognised under Section 7 of the DPDP Act (including voluntary provision of data for a specified purpose, compliance with law and judgments, and employment-related purposes), and, where applicable, performance of our contract with you:
- Account creation and authentication: to register your Partner account, verify your telephone number via OTP, authenticate sessions, and secure access to your account;
- Provision of the Services: to create and manage your store profile, publish Surprise Bag listings to Customers, transmit Orders to you in real time, generate and verify pickup codes, track order lifecycles, and operate dashboards showing your orders, revenue, ratings and food-saved metrics;
- Payments and settlements: to calculate amounts payable to you, process payouts to your designated bank account, apply commissions and fees, generate invoices and statements, process refunds, and maintain accounting records;
- Communications: to send you transactional and service communications, including new-order alerts, order status updates, pickup reminders, settlement notifications, policy updates and administrative announcements via push notification (FCM), SMS, email, WhatsApp or in-app notification; and, subject to your right to opt out, marketing and promotional communications;
- Verification and compliance: to verify your identity, business credentials, FSSAI licence, GSTIN and bank details; to comply with applicable laws, including tax laws (such as collection of tax at source under Section 52 of the Central Goods and Services Tax Act, 2017, where applicable), the Food Safety and Standards Act, 2006, the Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020; and to respond to lawful requests from governmental and regulatory authorities;
- Trust, safety and fraud prevention: to detect, investigate, prevent and act upon fraudulent, abusive, unsafe or policy-violating activity, including automated flagging of unusual cancellation patterns, application of account restrictions or blocks in accordance with our published thresholds, maintenance of audit trails, and protection of Customers, Partners, LastCall and the public;
- Quality, analytics and improvement: to analyse usage in aggregate, measure Platform performance, understand food-rescue impact, debug and fix errors, develop new features, and conduct research using de-identified or aggregated data;
- Dispute resolution and legal claims: to handle complaints, grievances, chargebacks and disputes, enforce our Terms & Conditions, and establish, exercise or defend legal claims;
- Business transactions: to evaluate or carry out a merger, acquisition, financing, reorganisation or sale of assets, subject to appropriate confidentiality safeguards.
Where processing is based on consent, you may withdraw consent at any time as described in Section 10; withdrawal does not affect the lawfulness of processing carried out before withdrawal and may result in our inability to continue providing some or all of the Services.
5. Disclosure and Sharing of Information
We do not sell your Personal Data. We share information only as described below and, in the case of Data Processors, under contracts requiring them to process data only on our instructions and with appropriate security safeguards:
- With Customers: your store name, category, description, photographs, address, map location, opening hours, pickup windows, listings, prices, dietary tags, ratings and reviews are displayed publicly on the consumer Platform. Your store contact number may be made available to a Customer with an active Order for pickup coordination;
- Cloud infrastructure and analytics providers: we use Google Firebase services (including Firebase Authentication, Cloud Firestore, Firebase Cloud Storage, Firebase Cloud Messaging, and Firebase crash and analytics services) operated by Google LLC and its affiliates to host data, authenticate users, store images, deliver push notifications and analyse aggregate usage; and Google Maps Platform for geocoding and maps. Google acts as our Data Processor for hosted content and processes certain service data as described in Google's own privacy documentation;
- Payment aggregators, banks and financial institutions: to process Customer payments, Partner payouts, refunds and reconciliations, in compliance with directions of the Reserve Bank of India applicable to such entities;
- Communication providers: SMS gateways, email service providers and messaging platforms engaged to deliver OTPs and notifications;
- Professional advisers and auditors: lawyers, accountants, auditors and insurers, under duties of confidentiality;
- Governmental, regulatory and law-enforcement authorities: where required by applicable law, court order, or lawful request, including disclosures to the FSSAI, tax authorities, the Data Protection Board of India, CERT-In, or police authorities; and where we believe in good faith that disclosure is necessary to protect the rights, property or safety of any person or to prevent or investigate fraud or illegality;
- Group companies and successors: our affiliates, and any acquirer or successor in the event of a corporate transaction, subject to this Policy or an equally protective policy;
- With your direction or consent: any other disclosure you request or authorise.
We may disclose aggregated or de-identified information — for example, total kilograms of food saved in a city, or aggregate order volumes — that cannot reasonably be used to identify you, for impact reporting, marketing, investor communications and research.
6. Cross-Border Transfer of Data
Our infrastructure providers, including Google, may store and process data on servers located outside India. By using the Services, you understand that your information may be transferred to, stored in and processed in jurisdictions other than India. We will effect such transfers in compliance with Section 16 of the DPDP Act and any notifications issued by the Central Government restricting transfer to specified countries, and, where the SPDI Rules apply, only to entities ensuring the same level of data protection as required under Indian law. Where the law requires particular categories of data (including certain payment data pursuant to Reserve Bank of India directions) to be stored in India, we and our payment providers will comply with such localisation requirements.
7. Data Retention
We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal, tax, accounting and regulatory obligations, to resolve disputes, and to enforce our agreements. Illustratively:
- Account and store profile data is retained for the life of your account and thereafter as described below;
- Order, transaction, settlement and invoice records are retained for a minimum of eight (8) years in accordance with obligations under Indian tax and company law;
- Trust-and-safety flags, cancellation logs and audit trails are retained for as long as reasonably necessary to protect the Platform against fraud and abuse, including after account closure, and to demonstrate compliance;
- Support communications and grievance records are retained for at least the period required under the Consumer Protection (E-Commerce) Rules, 2020 and the IT Rules, 2021;
- Device tokens and diagnostic data are retained for short rolling periods consistent with their technical purpose.
Upon deletion or termination of your account, your store record is removed from active systems and an archival copy may be moved to a segregated deletion archive for a limited period to permit account restoration in cases of accidental deletion, to complete pending settlements, refunds and disputes, to comply with retention laws, and to prevent circumvention of restrictions or blocks through re-registration. Thereafter, data is deleted or irreversibly anonymised. Anonymised and aggregated data may be retained indefinitely.
8. Security of Information
We implement reasonable security practices and procedures as contemplated under Section 43A of the IT Act, the SPDI Rules, and Section 8(5) of the DPDP Act, designed to protect Personal Data against unauthorised access, disclosure, alteration, loss and destruction. These include, without limitation:
- encryption of data in transit using industry-standard TLS, with cleartext (unencrypted HTTP) traffic disabled at the application level;
- encryption at rest applied by our cloud infrastructure providers;
- authentication via OTP-verified telephone numbers and secure session management;
- granular database security rules restricting each Partner's access to its own store, listings, orders and statistics, and separating Partner-side data from Customer-side data;
- role-based access controls, with elevated administrative functions restricted to authorised LastCall personnel;
- disabling of device backup of application data and avoidance of storing sensitive data in device backups;
- logging, monitoring and automated anomaly detection, including the suspicious-activity systems described in this Policy;
- organisational measures such as confidentiality undertakings, need-to-know access, and periodic review of security practices.
No method of transmission over the internet or electronic storage is completely secure. While we strive to protect your Personal Data, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your device, SIM and OTPs, for enabling device-level security, and for notifying us immediately at lastcallfoodteam@gmail.com of any suspected unauthorised access to your account.
9. Personal Data Breach
In the event of a personal data breach, we will notify the Data Protection Board of India and each affected Data Principal in the form and manner prescribed under the DPDP Act and rules thereunder, and will report cyber security incidents to the Indian Computer Emergency Response Team (CERT-In) within the timelines prescribed under the CERT-In directions dated 28 April 2022 (currently six hours from noticing or being notified of specified incidents). We maintain internal incident response procedures and system logs in accordance with applicable CERT-In requirements.
10. Your Rights as a Data Principal
Subject to the DPDP Act and applicable exemptions, you have the following rights in respect of your Personal Data:
- Right to access: to obtain a summary of the Personal Data being processed, the processing activities undertaken, the identities of Data Fiduciaries and Data Processors with whom the data has been shared, and any other prescribed information;
- Right to correction and updating: to have inaccurate or misleading data corrected, incomplete data completed, and data updated. You can edit most store profile details directly in the Partner App; changes to your verified telephone number are effected through an OTP-verified phone-change process; other corrections may be requested through support;
- Right to erasure: to request erasure of Personal Data that is no longer necessary for the specified purpose, subject to retention required by law. You may initiate account deletion through the Partner App or by written request to lastcallfoodteam@gmail.com ;
- Right to withdraw consent: at any time, with the ease with which it was given, by adjusting device permissions, disabling notification categories, or writing to us; consequences of withdrawal are described in Section 4;
- Right of grievance redressal: to have your grievances addressed by our Grievance Officer within the timelines specified in Section 15;
- Right to nominate: to nominate another individual to exercise your rights in the event of your death or incapacity;
- Right to complain to the Board: if unsatisfied with our response, to lodge a complaint with the Data Protection Board of India in the manner prescribed under the DPDP Act.
You also have corresponding duties under Section 15 of the DPDP Act, including the duty not to impersonate another person, not to suppress material information, not to register false or frivolous grievances or complaints, and to furnish only verifiably authentic information when exercising the rights of correction or erasure.
We will respond to verified requests within the timelines prescribed by applicable law. To protect your account, we may require you to verify your identity (for example, via OTP to your registered number) before acting on a request.
11. Notifications, Marketing and Communication Preferences
Transactional and service notifications — such as new-order alerts, cancellation notices, account-status changes and safety communications — are integral to the Services and are sent for as long as you maintain an account; disabling them may materially impair your ability to fulfil Orders on time. On Android 13 and above, push notifications require the POST_NOTIFICATIONS permission, which you may grant or revoke in device settings. Promotional and marketing communications will be sent only in accordance with applicable law, including the Telecom Commercial Communications Customer Preference Regulations, 2018, and you may opt out of them at any time via in-app settings, unsubscribe links, or by writing to lastcallfoodteam@gmail.com , without affecting transactional messages.
12. Children's Privacy
The Services are intended solely for use by persons who are at least eighteen (18) years of age and competent to contract under the Indian Contract Act, 1872. We do not knowingly collect Personal Data from children (persons under 18 years of age) and do not undertake tracking, behavioural monitoring or targeted advertising directed at children, consistent with Section 9 of the DPDP Act. If you believe a child has provided Personal Data to us, please contact the Grievance Officer, and we will take steps to delete such data.
13. Automated Decision-Making, Account Restrictions and Profiling
To protect the integrity of the Platform, we employ automated systems that monitor operational conduct — in particular, patterns of accepting Customer Orders and subsequently cancelling them. When such a pattern crosses published internal thresholds, the system may automatically generate a flag with an assigned risk level; repeated flags may result in an automatic change of your account status from "active" to "restricted", and serious or persistent conduct may result in a "blocked" status pending review. These measures are applied uniformly, are based on objective operational events recorded in the audit trail, and are used solely for trust-and-safety and service-quality purposes.
Where your account is restricted or blocked, you will be informed of that status through the Partner App and may seek human review by contacting the Grievance Officer. Where an administrator lifts a restriction, an "account restored" confirmation is presented to you in the Partner App. We do not use automated decision-making to produce legal effects concerning you without a mechanism for human review.
14. Third-Party Services and Links
The Partner App is built on and interoperates with third-party services, including Google Firebase, Google Maps Platform, Google Play services and payment aggregators. Those providers may collect certain service and diagnostic data directly, as described in their own privacy policies (for Google, at policies.google.com/privacy). Links from the Services to external websites are provided for convenience only; we are not responsible for the privacy practices or content of third parties.
15. Grievance Officer and Data Protection Contact
In accordance with the IT Act and rules thereunder, the Consumer Protection (E-Commerce) Rules, 2020, and the DPDP Act, the name and contact details of the Grievance Officer are provided below. The Grievance Officer shall acknowledge grievances within forty-eight (48) hours and endeavour to resolve them within the shorter of the timelines prescribed by applicable law (currently fifteen (15) days under the IT Rules, 2021, and one (1) month under the E-Commerce Rules for consumer grievances):
- Grievance Officer: Salman N
- Designation: Grievance Officer, LastCall Technologies IN,
- Email: lastcallfoodteam@gmail.com
- Hours: Monday to Friday, 10:00–18:00 IST (excluding public holidays)
For data-protection-specific queries, requests to exercise Data Principal rights, or consent withdrawals, you may also write to lastcallfoodteam@gmail.com with the subject line "Data Principal Request".
16. Changes to This Policy
We may update this Policy from time to time to reflect changes in law, technology or our practices. Material changes will be notified to you through the Partner App, by push notification, or by email to your registered address, and the "Last Updated" date above will be revised. Your continued use of the Services after the effective date of an updated Policy constitutes acceptance of the updated Policy; where the law requires fresh consent for new purposes of processing, we will seek it. We encourage you to review this Policy periodically. Prior versions may be obtained on request.
17. Governing Law
This Policy shall be governed by and construed in accordance with the laws of India. Subject to the dispute-resolution provisions of the Terms & Conditions, the courts at Kozhikode, Kerala shall have exclusive jurisdiction over disputes arising out of or relating to this Policy.
18. Contact Us
If you have questions, concerns or requests regarding this Policy or our data practices, please contact us at:
- LastCall Technologies IN
- Email: lastcallfoodteam@gmail.com
- Website: https://lastcall.co.in