Privacy Policy
Last updated: July 26, 2026
1. Introduction
Oordo ("we", "our", or "us") is a white-label ordering platform for independent cafés. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, website, and services (collectively, the "Service").
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the Service.
2. Information We Collect
Information you provide:
- Account credentials (email, password) when you sign up as a café manager, staff, or chef.
- Phone number and optional name when placing an order as a customer.
- Menu data, branding, pricing, and table configurations uploaded by café managers.
- Reviews, ratings, and feedback submitted by customers.
- Payment method preference (UPI, card, pay at counter) — we do not store card numbers or UPI PINs.
Information collected automatically:
- Device information (browser type, OS, screen resolution) for rendering the platform.
- Geolocation data (only when you explicitly grant permission) for café geofence verification.
- Usage analytics (page visits, checkout events, order flow) to help café owners improve their service.
- Cookies and session tokens required for authentication and platform functionality.
3. How We Use Your Information
- To provide, maintain, and improve the Service.
- To process orders and facilitate communication between customers and cafés.
- To authenticate users and protect against unauthorized access.
- To send service-related notifications (order status updates, staff alerts).
- To provide analytics and insights to café owners about their business.
- To comply with legal obligations.
4. Data Sharing
We do not sell your personal data. We may share information in the following cases:
- With cafés: When a customer places an order, the café receives the order details, customer name, and phone number for order fulfillment.
- Service providers: We use third-party services (MongoDB for database, Cloudinary for images, Firebase for phone authentication, Redis for caching) that process data on our behalf under strict contractual obligations.
- Legal requirements: We may disclose information if required by law or in response to valid legal process.
5. Data Security
We implement industry-standard security measures including encrypted data transmission (TLS/HTTPS), secure session management, and access controls. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
6. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. Café managers can request deletion of their café data at any time. Customer order data may be retained in anonymized form for analytics purposes.
7. Your Rights
- Access and review the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your personal data.
- Opt out of non-essential data collection (analytics, geolocation).
To exercise these rights, contact us at privacy@oordo.in.
8. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.
10. Contact Us
If you have any questions about this Privacy Policy, please contact us at privacy@oordo.in.